io.github.joeyough/mcpcheck

mcpcheck

Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.

1.0.1
Version
remote
Transport
2
Tools

Security review

Review passed

Reviewed 22h ago.

  • tools: 2 tools scanned
  • metadata: scanned

No findings.

Tools (2)

  • check_mcp_trust

    Check if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.

  • scan_mcp_server

    Scan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.