Free tool

MCP Server Security Checklist

Paste a Model Context Protocol server configuration and see what a policy engine would flag. Pattern matching over the text you paste, running entirely in your browser.

Nothing to read yet

Runs entirely in your browser. Nothing you type here is transmitted, logged, or stored anywhere. There is no server-side copy because there is no transmission. Close the tab and it is gone.

How this works, and what it does not cover

This reads a configuration file. It flags shapes that are reliably a problem — root-scoped filesystem access, literal credentials, plaintext transport, shell execution, missing scope, missing audit configuration.

It reads the file, not the runtime — and runtime is where most tool-layer risk lives. Treat a clean result as a clean bill of health for your configuration, and a good reason to point a full audit at the runtime layer next.

It is not a vulnerability scanner and does not check versions against advisory databases — pair it with the scanner you already run for that. What it adds is the configuration shape, which scanners mostly do not read.

Nothing is transmitted. The analysis runs on the string in the textarea and disappears when you close the tab. If you pasted a real credential to test it, rotate it anyway — that is good practice regardless of where you pasted it.

The full rule set this checklist is a subset of, and how each rule maps to a control you can enforce deterministically.

No cookies, no tracking pixels, never shared or sold. How the data is handled.

If you would rather not do this yourself

Agent Production Audit

Two weeks: an independent read of cost, reliability, and governance across your agent stack, with every finding priced in dollars.

2 weeks · from $12K
All free tools