Scan
Connect to an MCP server and enumerate tools, prompts, resources, schemas, and security boundaries.
Find broken tools, risky permissions, and changes that could break your agents. Start with a free local scan; keep release history and hosted CI with Pro.
npx -y @kryptosai/mcp-observatory@latestNode.js 20+ · macOS, Windows, Linux · Step-by-step setup guide
Used by developers at
Every mark below opens the exact MCP package, scope, score, and findings behind the evaluation.
Every agent is only as trustworthy as the tools it can reach. Observatory turns a server connection into a visible approve, gate, or defer decision before production.
Inspect the Kubernetes evidenceOne evidence loop for local development, CI, and production release review.
Connect to an MCP server and enumerate tools, prompts, resources, schemas, and security boundaries.
Run deterministic behavioral, security, permission, and drift checks with receipts behind every finding.
Write a deny-default Seatbelt policy from the findings and start the runtime proxy. Local scan stays free.
Approve, gate, or defer with a report, CI status, SARIF output, and an owner-ready next action.
Set the decision once, then keep it running in CI. The Release Gate Pilot gives platform and security teams private evidence, owner-ready remediation, and a durable rule for every critical MCP dependency.
Run locally, sign in with GitHub through cloud upload, and keep one latest snapshot free. Upgrade only when retained history and hosted CI become useful.
Watch MCP Observatory connect to a server, enumerate its capabilities, run security checks, and produce the evidence behind the decision.
View the open-source package
7 credential-free targets were verified on Sep 9, 2026. The full Safety Index contains 176 indexed servers with scope and evidence labels.
@modelcontextprotocol/server-everything
Exercises tools, prompts, and resources in one official reference server.
Inspect the evidence@modelcontextprotocol/server-filesystem
Filesystem tools need harmless test roots and clear read/write boundaries.
Inspect the evidence@upstash/context7-mcp
Documentation retrieval tools can return untrusted text into agent context.
Inspect the evidenceRun the free scan locally, then use cloud upload to see one hosted snapshot before paying.