Check an MCP App for safety and spec conformance (runs locally)
check_mcp_appGet the Sigistry MCP App safety criteria to audit an MCP App (MCP Apps / SEP-1865: a tool that returns an interactive ui:// HTML resource the host renders in a sandboxed iframe) BEFORE shipping it. Returns two groups of checks: spec conformance (ui:// scheme, the text/html;profile=mcp-app mimeType, tool-to-UI linkage via _meta.ui.resourceUri, a text fallback, visibility values, and CSP coverage of external origins) and security hygiene the iframe sandbox does not cover (unsafe DOM sinks, embedded secrets, host-message origin handling, remote scripts). Call this when the user is building or reviewing an MCP App; then apply each check to the app source you have in context and report findings. Nothing is sent to this server; an interactive browser version is at https://sigistry.com/mcp-app-checker.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| steps | Yes | what the agent should do, in order | |
| checks | Yes | the checks to apply to the MCP App | |
| hubUrl | Yes | human-readable MCP Apps hub | |
| specUrl | Yes | the MCP Apps (SEP-1865) specification | |
| nextSteps | Yes | ||
| runsWhere | Yes | always "local": the agent applies the criteria in context; no app code reaches this server | |
| checkerUrl | Yes | interactive in-browser checker | |
| interpreting | Yes | ||
| rubricVersion | Yes |