THE MOMENT BEFORE TRUST

Check your MCP servers.
Know what to fix.

Find broken tools, risky permissions, and changes that could break your agents. Start with a free local scan; keep release history and hosted CI with Pro.

Run in your terminal · no account needed
npx -y @kryptosai/mcp-observatory@latest

Node.js 20+ · macOS, Windows, Linux · Step-by-step setup guide

After the scanNext: one hosted snapshot free.

Run this in the same project folder. It connects GitHub, uploads your result, and prints your dashboard link.

PRODUCT PROOF

Evidence for every release decision.

Every agent is only as trustworthy as the tools it can reach. Observatory turns a server connection into a visible approve, gate, or defer decision before production.

Inspect the Kubernetes evidence
Kubernetes MCP
72/100
BLOCKED
Protocol compliance100/100
Security0/100
High-risk findings3
Medium findings3
HOW IT WORKS

Scan once. Enforce at runtime. Ship with confidence.

One evidence loop for local development, CI, and production release review.

01

Scan

Connect to an MCP server and enumerate tools, prompts, resources, schemas, and security boundaries.

02

Evaluate

Run deterministic behavioral, security, permission, and drift checks with receipts behind every finding.

03

Enforce

Write a deny-default Seatbelt policy from the findings and start the runtime proxy. Local scan stays free.

04

Decide

Approve, gate, or defer with a report, CI status, SARIF output, and an owner-ready next action.

RELEASE-GATE WORKFLOW

Don’t discover your security policy in production.

Set the decision once, then keep it running in CI. The Release Gate Pilot gives platform and security teams private evidence, owner-ready remediation, and a durable rule for every critical MCP dependency.

Approve. Ship dependencies that meet the evidence threshold.
Gate. Stop unsafe capability or permission drift before release.
Defer. Keep unresolved findings visible with a clear owner and next action.
SELF-SERVE HOSTED

See the hosted result before paying.

Run locally, sign in with GitHub through cloud upload, and keep one latest snapshot free. Upgrade only when retained history and hosted CI become useful.

Free hosted snapshot. Sign in and upload one result before checkout.
Individual Pro · $29/month. 90-day history, hosted CI ingestion, regression markers, and artifact downloads for one developer.
Need a scoped decision? Request the $15,000 Release Gate Pilot
METHODOLOGY & EVIDENCE

Don’t trust a score you can’t inspect.

Watch MCP Observatory connect to a server, enumerate its capabilities, run security checks, and produce the evidence behind the decision.

View the open-source package
MCP Observatory running a real MCP server security scan
RECORDED VERIFICATION

Current evidence, not a vanity count.

7 credential-free targets were verified on Sep 9, 2026. The full Safety Index contains 176 indexed servers with scope and evidence labels.

Explore the full Safety Index
7
Passing this run
0
Gated this run
7
Verified targets
EVIDENCE FOR EVERY RELEASE DECISION

Know what your agents can reach before they reach it.

Run the free scan locally, then use cloud upload to see one hosted snapshot before paying.