Audit an MCP server before you connect it.
An MCP server is a set of instructions your agent will follow. Descriptions that address the model, tools whose name hides a write, credentials reachable from an outbound call, and one tool doing everything are all decisions made inside the server before your agent ever runs.
Eight checks over the manifest, scored per tool. Nothing is executed and nothing is uploaded.
Server manifest
Documentation that issues instructions, and an upload tool that mentions a credential and a destination.
A tools array, a server manifest, or a tools/list response. Scopes, env and annotations are read when present.
Runs in this browser tab. The manifest is never uploaded and never executed.
How the audit works
- Every tool is read for name, description, schema and annotations.
- Eight rules run over that text, including cross tool checks.
- Each finding names the tool and quotes the evidence.
- The server score is a saturating composite of what was found.
What it does not do
- It reads declarations, not runtime behaviour.
- It does not execute the server or call any tool.
- A clear score is not proof of safety.
- It cannot see code behind a published manifest.