Avoid shell wrappers and curl-to-shell startup paths.
Free MCP Security Tool
Check MCP configs before AI agents touch files, tokens, and tools.
Paste a Model Context Protocol configuration and get a browser-local review for visible risks. Use it before approving MCP servers for Claude Desktop, Cursor, Codex, internal agents, or developer laptops.
Free MCP Security Tool
MCP Config Checker
Paste a Model Context Protocol config and get a fast local review for visible risks: shell wrappers, unpinned package runners, broad filesystem paths, hardcoded secrets, remote startup URLs, Docker socket exposure, and excessive runtime permissions.
Paste an MCP JSON config to check common security patterns locally in your browser.
Review checklist
What the checker is looking for.
Pin package versions and review updates through normal change control.
Scope filesystem access to one project, not root or the whole home directory.
Keep tokens out of config files and use least-privilege credentials.
Treat Docker socket access, production write actions, and broad network access as high risk.
Log server owner, purpose, allowed tools, approved data, and review date.
Return loop
Watch My Stack
Select the tools you care about. This browser-local selector builds a focused reading path and gives you a reason to return each Wednesday.
MCP security path
Model Context Protocol servers, tokens, tool calls, and local integrations.
GitHub security path
Repositories, pull requests, Actions, secrets, dependency alerts, and CodeQL.
AWS security path
Cloud identity, service accounts, data boundaries, AI gateways, and logging.
LiteLLM security path
Centralized GenAI gateways, model routing, token control, and provider governance.