COUE
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@COUEAudit this machine-learning project before I deploy it."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Live endpoint
COUE is deployed and needs no account, no API key, and no sign-in:
https://coue-mcp.coue-mcp.workers.dev/mcpWebsite | |
Health | |
Transport | Streamable HTTP |
Authentication | None |
Add it to ChatGPT, Claude, or Claude Code, or try it straight away:
claude mcp add --transport http coue https://coue-mcp.coue-mcp.workers.dev/mcpRelated MCP server: Plugin Health Auditor MCP Server
What is COUE?
COUE is a Model Context Protocol server that gives an AI assistant a specialized, deterministic engineering capability: analyzing AI/ML projects for the issues that cause production incidents.
You connect it once, then ask things like:
Audit this machine-learning project before I deploy it.
Find the biggest production risks in this ML project.
Compare these three models and recommend the best one for production.
Turn these findings into a deployment checklist.
The division of labour is deliberate:
The assistant provides the reasoning. COUE provides the specialized engineering analysis.
There is no language model inside COUE. Every result is produced by deterministic static analysis, so the same input always yields the same output, and the assistant explains and contextualizes it.
Why COUE?
General-purpose code review notices general-purpose problems. The failures that take an ML service down are usually specific to ML, and they are easy to miss by reading code:
A model loaded inside the request handler, so every request pays the full load cost and memory multiplies under concurrency.
A service that passes every application health check while its accuracy quietly degrades, because nothing monitors the model as distinct from the service.
An artifact at a mutable path, so a deployment cannot be tied to the run that produced it, and a rollback has nothing to roll back to.
A training run with no seed, so a regression cannot be separated from variance.
Unpinned dependencies plus a floating
:latestbase image, so a rebuild is a different system.
COUE checks all of these, and reports what it genuinely could not determine instead of guessing.
How it works
MCP client
(ChatGPT, Claude, or other)
|
| MCP (Streamable HTTP)
v
HTTPS /mcp endpoint
|
v
+-------------+
| COUE |
| MCP Server |
+------+------+
|
Analysis Service
|
+--------+--------+-----+-----+--------+---------+
| | | | | |
Security Deps Docker Model-Serving Testing Repro /
Observability /
Deployment
| | | | | |
+--------+--------+-----+-----+--------+---------+
|
Scoring Engine
|
v
Structured Findings
|
v
MCP clientThe MCP protocol layer is separate from the analysis engine. Tool handlers call a service layer and format its output; they contain no analysis logic.
Features
Eight analysis categories with a transparent, weighted score.
Evidence-based detection. A framework is reported only when an actual import or dependency declaration is observed, never because a file is named after it.
Explicit
UNKNOWN. A check COUE could not evaluate is reported as unknown and excluded from the score, rather than counted as a failure.Conservative secret detection. Credential locations are reported; values never are.
No code execution. COUE is a static analyzer and never runs, imports, or installs anything it is given.
No network access during analysis, and no third-party API dependency at all.
Stateless and authless. Nothing is stored; nothing to sign in to.
Tools
Tool | Purpose |
| Analyzes supplied project files across all eight categories and returns a scored, prioritized set of findings. |
| Evaluates a structured description of an ML system when the files are not available. Omitted fields are |
| Ranks model configurations under an explicit optimization criterion and explains the trade-offs. |
| Turns findings into a summary, a detailed report, or a deployment checklist. |
All four are read-only, deterministic, and stateless.
Supported frameworks
Detected from real imports and dependency declarations:
Python · PyTorch · TensorFlow · Keras · scikit-learn · Hugging Face Transformers · Ultralytics / YOLO · ONNX Runtime · XGBoost · LightGBM · FastAPI · Flask
Node · TypeScript · Express
Infrastructure · Docker · Docker Compose · Kubernetes manifests · GitHub Actions · GitLab CI · Terraform and other IaC
Example prompts
Audit this ML project for production readiness.
Check whether this model-serving architecture has production risks.
Compare these three models and tell me which is best for production if latency matters most.
Turn these findings into a deployment checklist.Example output
Running COUE against the deliberately flawed project in
examples/demo-ml-project/:
COUE Production Readiness Audit
================================
Score: 37/100
Status: Not Production Ready
"demo-ml-project" scores 37/100 (Not Production Ready). 2 critical issues were
found and should be resolved before deployment. COUE detected Docker, FastAPI,
PyTorch.
Category scores
---------------
dependencies 6
security 11
testing 7
docker 0
modelServing 0
reproducibility 5
observability 2
deployment 7
Findings: 38 total (2 critical, 9 high, 22 medium, 5 low)
CRITICAL
--------
1. [CRITICAL] Model appears to be loaded on every request
Category: model-serving · Confidence: medium · ID: SERVE-MODEL-PER-REQUEST
The handler for POST /predict calls a model-loading function inside the
request body, with no visible cache or initialization guard. Every request
then re-reads the model artifact and re-initializes it, which adds the full
load time to each request's latency and multiplies memory use under
concurrency. (observed in app.py:35)
Fix: Load the model once at process startup, store it on the application
state, and reference it from the handler.
Could not be determined
-----------------------
UNKNOWN [dependencies] Whether declared dependencies contain known vulnerabilities
COUE performs offline static analysis and does not consult a
vulnerability database. Run a dedicated scanner such as pip-audit or
npm audit in CI.Scoring
Category | Weight |
Security | 20 |
Model Serving | 15 |
Dependencies | 15 |
Testing | 10 |
Reproducibility | 10 |
Docker | 10 |
Observability | 10 |
Deployment | 10 |
Total | 100 |
Score | Status |
90–100 | Production Ready |
75–89 | Mostly Ready |
60–74 | Needs Attention |
40–59 | High Risk |
0–39 | Not Production Ready |
Findings deduct from their category's budget by severity, scaled by confidence. Deductions saturate, so a category floors at zero rather than going negative, and a single low-severity finding cannot meaningfully move the total.
A category COUE could not assess is removed from the denominator, not scored as zero. The score is reported out of what was actually assessable, so "we could not see it" never reads as "it is broken".
COUE's readiness score is an engineering heuristic derived from static analysis of the files supplied. It is not a security certification, a compliance certification, or a guarantee of production safety.
Security
COUE never executes submitted code. No
python,node,pip,npm,bash,docker, or any other process is invoked against an analyzed project. This is enforced by a test that scans the source for process and dynamic-evaluation calls.COUE never fetches a URL. There is no
fetch_urltool, no URL parameter, and no outbound request during analysis. This is also enforced by a test.Detected credential values are never returned, logged, or stored. Findings carry the file, the line, and the kind of credential only.
Strict request, file, and output limits apply; see
src/utils/limits.ts.Submitted paths are normalized, so traversal sequences cannot be echoed into a result.
Caller-supplied objects are copied through a null-prototype filter to prevent prototype pollution.
See SECURITY.md to report a vulnerability.
Privacy
COUE is stateless. Files are analyzed in memory within the request that supplied them and discarded when it completes. There is no database, object store, cache, or queue. Request bodies are never logged. COUE does not access Claude conversation history, Claude memory, or any external account.
Full detail: docs/privacy.md. See also the Terms of Service and the Support page.
Limitations
COUE performs static analysis of the files you give it. It therefore:
does not execute application code, and cannot observe runtime behaviour;
does not perform dynamic or penetration testing;
does not guarantee security, and does not certify regulatory compliance;
does not consult a vulnerability database, so it never claims a dependency is vulnerable — run
pip-audit,npm audit, or an SCA tool alongside it;cannot verify production infrastructure unless the relevant configuration is supplied;
cannot determine whether an undocumented operational process exists;
matches on naming and framework idioms, so an unconventional project may yield false negatives.
Where COUE cannot determine something, it says so rather than guessing.
Architecture
src/
index.ts Worker entry point, HTTP layer, limits
mcp/
server.ts MCP server, tool registration, annotations
formatters.ts Text renderings of each result
analysis/
audit-service.ts Orchestrates analyzers for audit_project
ml-check-service.ts Metadata checks for check_ml_project
compare-models.ts Ranking engine for compare_models
report-service.ts Report rendering for generate_readiness_report
project-detector.ts Evidence-based ecosystem/framework detection
scoring.ts Weighted scoring engine
findings.ts Finding model, sorting, dedupe, redaction entry
security.ts dependencies.ts docker.ts model-serving.ts
testing.ts reproducibility.ts observability.ts deployment.ts
schemas/ Zod input schemas for the four tools
utils/
limits.ts Application limits, path and key safety
redaction.ts Secret masking
errors.ts Typed, actionable errors
privacy/
policy.ts Privacy posture, asserted by testsLocal development
npm install
npm run dev # wrangler dev on http://localhost:8787Verify the endpoints:
curl http://localhost:8787/health
npx @modelcontextprotocol/inspector --cli http://localhost:8787/mcp \
--transport http --method tools/listTesting
npm run typecheck # tsc --noEmit
npm run lint # eslint, zero warnings
npm test # vitest
npm run build # typecheck + wrangler dry-run build
npm run verify # all of the aboveThe suite covers tool schemas, valid and invalid inputs, project detection, scoring, severity classification, secret redaction, every analyzer, error handling, request and output limits, prototype pollution, path traversal, and MCP protocol behaviour against a real MCP client.
Deployment
COUE runs on Cloudflare Workers.
npx wrangler login
npm run deployThen confirm:
curl https://coue-mcp.coue-mcp.workers.dev/health
# {"status":"ok","service":"coue","version":"1.0.0"}Connecting COUE
COUE requires no authentication, no account, and no API key. Point any MCP client at:
https://coue-mcp.coue-mcp.workers.dev/mcpThe transport is Streamable HTTP.
ChatGPT
Go to Settings → Connectors → Advanced → Developer mode.
Choose Create, and enter the URL above.
Set authentication to No authentication.
Enable COUE in a conversation and ask it to audit a project.
Claude
Go to Settings → Connectors.
Choose Add custom connector.
Enter the URL above.
Open a conversation, enable COUE from + → Connectors, and ask it to audit a project.
Claude Code
claude mcp add --transport http coue https://coue-mcp.coue-mcp.workers.dev/mcpRoadmap
v1.0 — ML project audit; security, dependency, Docker, model-serving, testing, reproducibility, observability, and deployment analysis; production readiness scoring.
v1.1 — MCP Apps readiness dashboard; more framework-specific checks; more deployment checks.
v2.0 — Optional authenticated private repository integrations; CI/CD integration; pull-request auditing; model registry integrations; cloud deployment analysis; continuous readiness monitoring.
MCP Apps are deliberately not part of v1. The core connector works entirely through normal MCP tools and text results.
Support
Questions, bug reports, and requests for new checks: docs/support.md, or open an issue at github.com/bhuvan0808/coue-mcp/issues.
Contributing
See CONTRIBUTING.md.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Statically audits MCP tool surfaces for token cost, schema quality, and design issues.
Read-only, deterministic AI triage and readiness tools implementing Sophon's published rubrics.
Read-only AI coding tools for change verification, release readiness, capacity, and guidance.
Production-safety audits for AI-generated code, with a fix for every finding.
Related MCP Servers
- AlicenseAqualityAmaintenanceLocal-first production-readiness MCP server for AI-built apps. It runs read-only checks, produces an evidence-based readiness score, and guides fixes before launch.115Apache 2.0
- AlicenseNot gradedqualityDmaintenanceProvides audit_plugin_health and prepare_semantic_review tools for deterministic inspection of Codex plugins and Agent Skills, generating evidence-backed reports without executing or transmitting target code.1MIT
- AlicenseNot gradedqualityBmaintenanceAudits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.16 PyPI2Apache 2.0
- AlicenseNot gradedqualityAmaintenancePerforms explainable, deterministic static analysis of MCP tool metadata to detect misleading instructions, concealed capabilities, and schema drift without executing tools.1MIT