mcpcheck

Scan any MCP server for tool-poisoning, security, auth & license.

Community: Submitted by a user or imported; check the owner before granting accessDegradedNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.

    Server tool list (2)

    Raw names from tools/list. Only developers need these.

    check_mcp_trustCheck if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.
    scan_mcp_serverScan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.
    mcpcheck: connect to Claude, ChatGPT, Cursor · Connectors.fun