MCP Server Check

MCP server pre-install checklist

Twelve checks before you add a server. The first six take minutes; the rest are for servers that will hold real access.

Before you install

  1. Who publishes it? Prefer the service's own official server. Check the repository's owner, age and recent activity.
  2. Read every tool description in full. Look for hidden instructions, references to files or other tools, and invisible characters. MCP Server Check does the pattern pass.
  3. List what each tool can do. Run code, write files, fetch URLs, read secrets, delete. Switch off the tools you don't need.
  4. Pin the version. name@1.2.3, name==1.2.3 or image@sha256:…. Never curl … | sh.
  5. Give it the narrowest credential. One scoped, short-lived token from your client's secret store, never a personal admin token.
  6. Limit file access to one project folder.

For servers with real access

  1. Run it isolated: a container with no host network, no Docker socket and read-only mounts.
  2. Limit network egress to the domains it needs; block private address ranges (SSRF, covered in the MCP security best practices).
  3. Keep approvals on for tools that write, send, delete or pay.
  4. Check remote servers use proper authorisation and don't pass your token through to other services (token passthrough is an anti-pattern in the MCP security guidance).
  5. Log tool calls with the user and agent that made them.
  6. Name an owner who re-reviews the server on every upgrade.

Your client config matters too: check it with the MCP config security checker.

Check a server's tool list

Sources