FREE LOCAL TOOL / MCP PRE-CONNECTION REVIEW

Inspect the contract before the agent trusts the server.

A familiar name can point to a different package, endpoint or authorization chain. Review the declared evidence before install or connection.

OPEN LOCAL INSPECTOR
PRE::CONNECTDECLARED TRUST CHAIN
  1. 01
    IDENTITYname / namespace / repository
  2. 02
    ARTIFACTpackage / version / provenance
  3. 03
    TRANSPORTremote / stdio / network boundary
  4. 04
    AUTHORITYresource / issuer / scopes / PKCE
URL_FETCH::0EXECUTION::0UPLOAD::0
LOCALDOCUMENTS STAY IN THIS BROWSER
0INPUT URLS FETCHED
0PACKAGES OR TOOLS EXECUTED
3OPTIONAL EVIDENCE LAYERS

DECLARATION REVIEW / NO REMOTE REQUESTS

Build the evidence bundle.

Paste JSON or load local files. Only server.json is required; authorization documents refine the result when the remote server is protected.

00DECLARED ACCESS MODE
01

REQUIRED / REGISTRY DECLARATION

server.json

EMPTY
0 / 500 KB
02

OPTIONAL / RFC 9728

Protected Resource Metadata

EMPTY
0 / 500 KB
03

OPTIONAL / RFC 8414 + OIDC

Authorization Server Metadata

EMPTY
0 / 500 KB
SYNTHETIC CONTRACTSDemonstrations only. Counted separately from manual inspections.
LOCAL PARSE / LOCAL HASH / SOURCE-MINIMIZED OUTPUTNo document, URL, server name, filename or secret value is sent to H/M.

STRUCTURAL EVIDENCE / DETERMINISTIC RULES

Pre-connection trust trace

SHA-256--

Declarations first. Connection later.

Load a server declaration or choose a clearly labeled synthetic contract.

THE CONTRACT IS A TRUST CLAIM, NOT PROOF

Separate identity evidence from runtime assurance.

This inspector tests relationships between declarations. It deliberately refuses to turn unverified metadata into a safety badge.

  1. 01

    Parse locally

    Read supplied JSON in the browser without fetching endpoints named inside it.

  2. 02

    Cross-check identity

    Compare namespace, repository, package, version and endpoint declarations.

  3. 03

    Trace authorization

    Relate the MCP resource to RFC 9728 metadata, issuer endpoints, scopes and PKCE.

  4. 04

    Minimize evidence

    Export rule IDs, paths and counts without raw values, URLs or server identity.

EXPLICIT LIMITS

A coherent declaration can still hide unsafe code.

  • No URL is fetched, so DNS, redirects, response headers and live endpoint ownership are not verified.
  • Packages, repositories, signatures and runtime behavior are not inspected or executed.
  • Secret detection is pattern-based and can miss custom formats or flag intentional placeholders.
  • Contract-consistent means no listed structural conflict was observed; it is not a security certification.