mcp-doctor adds CI-friendly health and security audits for MCP servers
sticky_block · reddit · 2026-07-22
A developer built mcp-doctor, a zero-dependency Python CLI that launches an MCP server, runs the initialize handshake, introspects its surface, and returns a real exit code for CI use. It checks three areas: health (startup and handshake), quality (tool bloat, weak descriptions, bad schemas), and security (prompt-injection wording in descriptions, suspicious shell/eval behavior, leaked secrets). The author says the checks are conservative and asks for feedback on useful signals versus noise.
More from coding & agent
- Building a Secure AI Agent Gateway: Self-Hosting OAuth for Multiple SaaS Apps — Defiant_Cod_2654 · 2026-07-22
- Rowboat launches as an open-source, local-first AI coworker with memory — ycombinator · 2026-07-22
- Scoble says AI “loops” really means long-running multi-agent workspaces — Scobleizer · 2026-07-22
- Kimi Code opens a waitlist as Moonshot rolls out its coding product — Fabulous_Bonus_8981 · 2026-07-22
- Open-source runtime lets each repo define its own AI code reviewer — ibabufrik · 2026-07-22
- Indie Dev Asks: What's Actually Broken in Your AI Agent's Memory Today? — AcceptableTime7937 · 2026-07-22