$ free MCP trust scan

Is that MCP server safe to connect?

The MCP registry certifies nothing, and 41% of servers ship with no auth. Scan any public MCP server in seconds before you wire it into your agent.

…or scan a remote URL, registry name, or repo
see it in action

Real scans — no server of your own needed

why

Connecting an MCP server = running someone's code in your agent.

A poisoned tool description can hijack your agent. An unmaintained server can break it. A "rug pull" can swap safe behavior for malicious after you've trusted it. A directory listing 8,000 servers doesn't tell you which are safe — this does.

🩹 Maintenance & license

Is it actively maintained, archived, or legally murky? Dead servers are a liability.

🔐 Auth & disclosure

Does it support authentication and have a way to report vulnerabilities — or neither?

🧬 Prompt-injection markers

Scans for instruction-like text that signals a tool-poisoning attempt.

the record, over time

There's no Wayback Machine for MCP. We're becoming it.

A one-time scan tells you a server looks safe today. But servers get updated — a trusted tool can quietly turn malicious after you've installed it (a "rug pull"). So every day, MCPCheck re-scans and records what changed. Over time that becomes something no one can copy: the trust record of the entire MCP ecosystem.

📅

Daily snapshots

Every tracked server, re-scanned every day, with a dated record of its score, tools, and risks.

🚨

Rug-pull detection

The moment a safe server gains a poisoned tool or changes behavior, it's flagged against yesterday's record.

🏛️

An un-copyable archive

Anyone can scan a server today. No one can go back and record the past. The history compounds into the moat.

for teams & agents

Free to check one. Paid to protect a fleet.

Scanning by hand is free forever. The paid layer is for when your agents need to check servers automatically, at scale, and stay protected as those servers change.

Free

$0

Scan any server on the web. Full report, live tool analysis, embeddable badge. No account.

API — for agents

usage-based

Route your agents' safety checks through our API. One key, metered by calls, so an agent can vet every server before it installs it. Billing in beta — join below.

Drift-watch

$19–49/mo

We re-scan the servers you depend on and alert you the moment one changes — catching the "rug pull" a one-time scan can't. Join the waitlist below.

coming: drift-watch

One-time scans are theater.

Servers pass review, then silently mutate. Drift-watch re-scans the servers you depend on every version bump and alerts you the moment something changes. Join the waitlist.

✅ On the list. We'll email you when drift-watch is live.