MCP Config Checker

Paste a Model Context Protocol config and get a fast local review for visible risks: shell wrappers, unpinned package runners, broad filesystem paths, hardcoded secrets, remote startup URLs, Docker socket exposure, and excessive runtime permissions.

Local check: the text stays in your browser. Do not paste real tokens or private customer data.
Waiting for config

Paste an MCP JSON config to check common security patterns locally in your browser.

What the checker is looking for.

MCPControl

Avoid shell wrappers and curl-to-shell startup paths.

MCPControl

Pin package versions and review updates through normal change control.

MCPControl

Scope filesystem access to one project, not root or the whole home directory.

MCPControl

Keep tokens out of config files and use least-privilege credentials.

MCPControl

Treat Docker socket access, production write actions, and broad network access as high risk.

MCPControl

Log server owner, purpose, allowed tools, approved data, and review date.

Watch My Stack

Select the tools you care about. This browser-local selector builds a focused reading path and gives you a reason to return each Wednesday.

Open Wednesday Brief
WatchMCP

MCP security path

Model Context Protocol servers, tokens, tool calls, and local integrations.

WatchGitHub

GitHub security path

Repositories, pull requests, Actions, secrets, dependency alerts, and CodeQL.

WatchAWS

AWS security path

Cloud identity, service accounts, data boundaries, AI gateways, and logging.

WatchLiteLLM

LiteLLM security path

Centralized GenAI gateways, model routing, token control, and provider governance.

Turn one config review into a weekly security habit.

MCP risk changes when packages update, agents gain tools, or teams connect new data sources. Use the checker for quick reviews, then follow the Wednesday Brief for recurring AI security changes.