MCP Preflight
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Preflightstatically review my MCP config for risky settings before I run it"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Preflight
Review MCP config before you run it.
Turn a configuration or tool-catalog JSON snapshot into a static review report. The checker never starts or contacts the configured servers. The Python CLI has no third-party runtime dependencies and needs no account or API key.
Alpha, MIT licensed. No PyPI distribution; use a reviewed GitHub release or authorized checkout. CLI and optional MCP stdio adapter are the focus. A bounded Windows socket-close fix addresses the reproduced local HTTP timeout; see scope and tests. A clean report is not proof of safety.
Try the difference
From an authorized checkout, with Python 3.12+:
python scripts/mcp_preflight.py --input examples/preflight-before.json --fail-on review
python scripts/mcp_preflight.py --input examples/preflight-after.json --fail-on reviewRun the commands separately: the first intentionally exits 1; the second exits 0. No pip install, server startup or network access is needed for this demo.
The only input change is example-mcp@latest → example-mcp@1.2.3.
Both are synthetic strings, not package recommendations. The checker does not
look up whether that package or version exists. Both inputs explicitly provide
an empty catalog; this demo checks version syntax, not tool safety.
Related MCP server: yotta-verify-mcp
Use it in your workflow
You have… | Preflight gives you… |
An MCP config someone wants to enable | Static indicators to review before connection |
A captured | Catalog/schema and annotation review items |
A CI check | JSON or SARIF plus a configurable failure threshold |
Codex with the optional adapter |
|
python scripts/mcp_preflight.py --input your-config.json --output report.json --fail-on high
python scripts/mcp_preflight.py --input your-config.json --format sarif --output report.sarifReports omit supplied credential values, URLs, commands and free-form names and descriptions. Keep the original input private and inspect any report before sharing. SARIF export works; GitHub code-scanning ingestion is not yet verified.
Next: input examples · CLI reference · Codex setup · complete usage
Where it fits
Preflight is a small static review step. For agent-wide discovery, broader security analysis or live protocol debugging, compare Snyk Agent Scan, Cisco MCP Scanner, SecureAI-Scan and MCP Inspector. Some also offer offline scanning: that is not an exclusive feature here. See the dated comparison and tradeoffs.
Preflight does not inspect server source code, fetch catalogs, enforce runtime policies or certify prompt-injection resistance. Detection accuracy and competitive superiority have not been benchmarked.
Evidence you can inspect
Remote CI on 2026-10-06: 13 successful jobs covering one artifact build, four Windows/Linux × Python 3.12/3.13 core jobs, and eight MCP jobs with minimum/normal SDK resolution. The workflow checks installed CLI/HTTP and MCP behavior outside the checkout. This is evidence for that commit, not a guarantee for future changes.
Validation and open limits · HTTP behavior · Contributing · Security reporting
Help improve the alpha
Authorized reviewers: report a reproducible false positive or missing check. Use a minimal synthetic example and include the rule ID and expected behavior. Never attach live credentials or original private configurations.
Licensed under MIT. Public availability, customer adoption and a support SLA are not asserted.
This server cannot be deployed
Maintenance
Related MCP Connectors
Statically audits MCP tool surfaces for token cost, schema quality, and design issues.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Audit MCP servers for tool poisoning and shadowing. Scan a remote server by URL or paste its tools.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceA task-scoped MCP stdio proxy that learns candidate least-privilege policies from labeled successful runs, requires human review, enforces exact decisions, detects tool-definition drift, and emits privacy-minimized JSONL events for Wazuh.1Apache 2.0

yotta-verify-mcpofficial
AlicenseNot gradedqualityBmaintenanceProvides a deterministic pre-install security scan for Agent skills, plugins, and MCP servers via stdio, returning verdicts, audited badges, CI gates, and reports without executing code or making network calls.137 npmMIT- AlicenseAqualityAmaintenanceEnables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.3MIT
- AlicenseNot gradedqualityCmaintenanceEnables users to audit other MCP servers' tool definitions for agentic attack classes such as tool poisoning, sensitive-path references in metadata, and tool shadowing via invisible Unicode or homoglyphs. It can analyze a tools/list payload, check a single description string, or connect to a public remote MCP URL to fetch and audit its tool list.MIT