mcp-doctor adds CI-friendly health and security audits for MCP servers
sticky_block · reddit · 2026-07-22
A developer built mcp-doctor, a zero-dependency Python CLI that launches an MCP server, runs the initialize handshake, introspects its surface, and returns a real exit code for CI use. It checks three areas: health (startup and handshake), quality (tool bloat, weak descriptions, bad schemas), and security (prompt-injection wording in descriptions, suspicious shell/eval behavior, leaked secrets). The author says the checks are conservative and asks for feedback on useful signals versus noise.
More from coding & agent
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11