Inspect an MCP server before you install it.
Tool descriptions are instructions your agent may follow. Learn how to review embedded imperatives, invisible characters, out-of-scope paths, and schema mismatches—then inspect the manifest entirely in your browser.
Start here · 8 min
How to inspect an MCP server before you install it
A practical pre-install review for MCP manifests: tool descriptions, schemas, Unicode controls, filesystem scope, commands, endpoints, and secrets.
Read the guideField guide
MCP review library
8 guides
MCP tool poisoning: what it is and what static inspection can prove
Understand the tool-metadata trust boundary, realistic poisoning signals, and the limits of static MCP manifest analysis.
Read insightMCP tool descriptions are instructions: how to review them
Review MCP tool names and descriptions for embedded imperatives, concealed behavior, excessive scope, and contradictions with JSON Schema.
Read insightInvisible Unicode characters in MCP manifests
Find bidirectional controls and zero-width characters that can make MCP tool metadata render differently from its underlying text.
Read insightHow to review filesystem paths and roots in MCP configurations
Check MCP roots, working directories, path defaults, traversal, and sibling-prefix escapes without overclaiming runtime containment.
Read insightMCP schema-description mismatches: a deterministic review guide
Compare MCP inputSchema properties with parameters explicitly documented in tool descriptions and interpret mismatches carefully.
Read insightStatic MCP manifest inspection vs live server probing
Compare offline manifest review with active MCP server testing, including evidence, risk, privacy, and when to use each approach.
Read insightLocal vs hosted MCP manifest analysis
Compare in-browser and server-upload MCP manifest inspection across privacy, reproducibility, policy, scale, and operational tradeoffs.
Read insight