Skip to main content
Glama

Sigistry Plugin & Skill Catalog

Check an MCP App for safety and spec conformance (runs locally)

check_mcp_app
Read-onlyIdempotent

Get the Sigistry MCP App safety criteria to audit an MCP App (MCP Apps / SEP-1865: a tool that returns an interactive ui:// HTML resource the host renders in a sandboxed iframe) BEFORE shipping it. Returns two groups of checks: spec conformance (ui:// scheme, the text/html;profile=mcp-app mimeType, tool-to-UI linkage via _meta.ui.resourceUri, a text fallback, visibility values, and CSP coverage of external origins) and security hygiene the iframe sandbox does not cover (unsafe DOM sinks, embedded secrets, host-message origin handling, remote scripts). Call this when the user is building or reviewing an MCP App; then apply each check to the app source you have in context and report findings. Nothing is sent to this server; an interactive browser version is at https://sigistry.com/mcp-app-checker.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
stepsYeswhat the agent should do, in order
checksYesthe checks to apply to the MCP App
hubUrlYeshuman-readable MCP Apps hub
specUrlYesthe MCP Apps (SEP-1865) specification
nextStepsYes
runsWhereYesalways "local": the agent applies the criteria in context; no app code reaches this server
checkerUrlYesinteractive in-browser checker
interpretingYes
rubricVersionYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/openWorld=false, but the description adds real context beyond them: the tool returns criteria rather than checking for you, nothing is sent to the server, and the two output groups are enumerated in detail (spec conformance list, security hygiene list). It also preempts the biggest wrong expectation (that the tool audits the app itself) by telling the agent to apply the checks to source in context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose, then progressively more detailed. The parenthetical definition of an MCP App and the enumerated check groups are dense but each earns its place; the enumerations are long inside one sentence, which is slightly heavy, but nothing is redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter tool with annotations fully covering the safety profile and an output schema present, the description still supplies what annotations cannot: the intended workflow (audit-before-ship), the division of labor (agent applies checks to its own context), the no-server-call privacy guarantee, and the scope of the two criteria groups. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There are no parameters, so the baseline is 4. The description properly describes its argument-less nature across the whole passage and the schema carries 100% coverage; no parameter meaning is lost.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Get the Sigistry MCP App safety criteria to audit an MCP App'), and defines what an MCP App is (SEP-1865, returns a ui:// HTML resource rendered in a sandboxed iframe), which sharply distinguishes it from siblings like get_plugin/get_skill/get_scorecard that fetch other artifact types.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit timing ('Call this when the user is building or reviewing an MCP App'), explicit workflow ('BEFORE shipping it', 'then apply each check to the app source you have in context and report findings'), and an alternative channel ('an interactive browser version is at https://sigistry.com/mcp-app-checker'). That is when/when-not plus the alternative routing target.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources