MCP Surface Lint
Server Details
Statically audits MCP tool surfaces for token cost, schema quality, and design issues.
- Status
- Healthy
- Uptime
- 100.0% over 53 days
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- DLeibner/mcp-surface-lint
- GitHub Stars
- 0
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusing it with another. The tool's purpose is clear and singular: auditing an MCP tool surface.
The single tool follows a clean verb_noun pattern (check_mcp_server) with no competing conventions or inconsistent naming styles.
A single tool is below the typical well-scoped range and feels thin for a server, even though the tool itself is substantive and self-contained. It is not trivial, but the surface is minimal.
The tool covers the full apparent domain: auditing an MCP server via URL or tools/list snapshot without invoking targets. No obvious dead ends or missing core operations exist for the stated purpose.
Available Tools
1 toolcheck_mcp_serverCheck MCP serverARead-onlyIdempotentInspect
Statically audit an MCP tool surface from a public HTTPS URL or tools/list snapshot. Returns deterministic scores and findings without invoking any target tool or making LLM calls. When the user asks to check another installed MCP server, read that server's complete tool definitions from client context and pass them as snapshot (MCP name or Cursor-style tool both work; do not use file paths or $ref). If those definitions are unavailable, ask the user for its public endpoint or tools/list JSON instead of inventing an audit.
| Name | Required | Description | Default |
|---|---|---|---|
| url | No | Public HTTPS Streamable HTTP MCP endpoint to inspect. | |
| headers | No | Optional HTTP headers sent only while reading the remote tools/list response. | |
| snapshot | No | A tools/list JSON response, MCP Surface Lint snapshot, or client tool dump containing a tools array. Each tool needs `name`, or the Cursor-style `tool` alias. Forward another installed server's complete tool definitions here — do not invent schemas. |
Output Schema
| Name | Required | Description |
|---|---|---|
| grade | Yes | |
| stats | Yes | |
| scores | Yes | |
| server | Yes | |
| source | Yes | |
| findings | Yes | |
| findingCounts | Yes | |
| staticAnalysis | Yes | |
| targetToolsInvoked | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnlyHint, openWorldHint, idempotentHint, destructiveHint), the description discloses that the audit is static, deterministic, and makes no LLM calls. It also states that it does not invent audits when data is missing. These are behavioral traits not covered by annotations, adding significant transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact and well-structured. It front-loads the core purpose in the first sentence, then adds operational details in subsequent sentences without redundancy. Every sentence contributes to the agent's ability to use the tool correctly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that an output schema exists (so return values are defined elsewhere) and the annotations cover the safety profile, the description covers all necessary operational aspects: how to select between URL and snapshot, how to populate snapshot from client context, and what to do when data is missing. Nothing essential is omitted.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already documents all three parameters with 100% coverage, so the baseline is 3. The description adds extra meaning for the snapshot parameter: it explains how to obtain it from client context (using MCP 'name' or Cursor-style 'tool') and explicitly forbids using file paths or $ref. This goes beyond the schema's static description, so a 4 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: to statically audit an MCP tool surface from a public HTTPS URL or a tools/list snapshot. It specifies the verb (audit), the resource (MCP tool surface), and the input sources, while also clarifying that it is static and does not invoke target tools or make LLM calls. This is specific and unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use a URL versus a snapshot, and how to handle requests to check another installed server: read its definitions from client context and pass them as snapshot. It also instructs what to do if definitions are unavailable (ask for the endpoint or JSON) and what to avoid (file paths, $ref). This is clear when-to/ when-not-to guidance with fallback behavior.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Changed
check_mcp_server1 field changed- changed
Input schema / properties / snapshot / descriptionPrevious value: -"A tools/list JSON response, mcplint snapshot, or client tool dump containing a tools array. Each tool needs `name`, or the Cursor-style `tool` alias. Forward another installed server's complete tool definitions here — do not invent schemas."New value: +"A tools/list JSON response, MCP Surface Lint snapshot, or client tool dump containing a tools array. Each tool needs `name`, or the Cursor-style `tool` alias. Forward another installed server's complete tool definitions here — do not invent schemas."
1 tool update
- Changed
check_mcp_server1 field changed- changed
Input schema / properties / snapshot / descriptionPrevious value: -"A tools/list JSON response or mcplint snapshot containing a tools array."New value: +"A tools/list JSON response, mcplint snapshot, or client tool dump containing a tools array. Each tool needs `name`, or the Cursor-style `tool` alias. Forward another installed server's complete tool definitions here — do not invent schemas."
1 tool update
- First observed
check_mcp_server
Related MCP Connectors
Free MCP tools: the only MCP linter, health checks, cost estimation, and trust evaluation.
Audits MCP tool definitions for patterns that make models call tools wrong or mis-fill args.
Monitor MCP servers, API contracts and AI outputs for schema drift. Alerts on breaking changes.
MCP Spec Compliance MCP — audits any MCP server.json against the official Model Context Protocol
Related MCP Servers
- AlicenseNot gradedqualityAmaintenancePerforms explainable, deterministic static analysis of MCP tool metadata to detect misleading instructions, concealed capabilities, and schema drift without executing tools.1MIT
- AlicenseNot gradedqualityCmaintenanceScores MCP tool definitions and tool lists from 0-100, flagging vague descriptions, missing parameter docs, non-verb-first naming, oversized enums, and nested schemas with severity, rationale, and concrete fixes. It also validates marketplace listings against platform character caps such as MCPize's 500-character short-description limit before deploy.MIT
- AlicenseNot gradedqualityBmaintenanceEnables auditing MCP servers' tools by their estimated context token cost, ranking verbose names, descriptions, and schemas before they consume the agent window. Can run as an MCP tool so agents can budget their own context.1MIT
- AlicenseAqualityCmaintenanceA stdio MCP server that audits other MCP servers by linting their tool schemas and calling tools with malformed inputs to produce a 0–100 conformance score and Markdown report.6MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.