Skip to main content
Glama

MCP Preflight

Review MCP config before you run it.

Turn a configuration or tool-catalog JSON snapshot into a static review report. The checker never starts or contacts the configured servers. The Python CLI has no third-party runtime dependencies and needs no account or API key.

CI

Alpha, MIT licensed. No PyPI distribution; use a reviewed GitHub release or authorized checkout. CLI and optional MCP stdio adapter are the focus. A bounded Windows socket-close fix addresses the reproduced local HTTP timeout; see scope and tests. A clean report is not proof of safety.

Try the difference

From an authorized checkout, with Python 3.12+:

python scripts/mcp_preflight.py --input examples/preflight-before.json --fail-on review
python scripts/mcp_preflight.py --input examples/preflight-after.json --fail-on review

Run the commands separately: the first intentionally exits 1; the second exits 0. No pip install, server startup or network access is needed for this demo.

Synthetic example: an unpinned package selector triggers a finding; an exact version removes that finding. Runtime remains unverified.

The only input change is example-mcp@latest → example-mcp@1.2.3. Both are synthetic strings, not package recommendations. The checker does not look up whether that package or version exists. Both inputs explicitly provide an empty catalog; this demo checks version syntax, not tool safety.

Related MCP server: yotta-verify-mcp

Use it in your workflow

You have…

Preflight gives you…

An MCP config someone wants to enable

Static indicators to review before connection

A captured tools/list response

Catalog/schema and annotation review items

A CI check

JSON or SARIF plus a configurable failure threshold

Codex with the optional adapter

preflight_review_json over stdio

python scripts/mcp_preflight.py --input your-config.json --output report.json --fail-on high
python scripts/mcp_preflight.py --input your-config.json --format sarif --output report.sarif

Reports omit supplied credential values, URLs, commands and free-form names and descriptions. Keep the original input private and inspect any report before sharing. SARIF export works; GitHub code-scanning ingestion is not yet verified.

Next: input examples · CLI reference · Codex setup · complete usage

Where it fits

Preflight is a small static review step. For agent-wide discovery, broader security analysis or live protocol debugging, compare Snyk Agent Scan, Cisco MCP Scanner, SecureAI-Scan and MCP Inspector. Some also offer offline scanning: that is not an exclusive feature here. See the dated comparison and tradeoffs.

Preflight does not inspect server source code, fetch catalogs, enforce runtime policies or certify prompt-injection resistance. Detection accuracy and competitive superiority have not been benchmarked.

Evidence you can inspect

Remote CI on 2026-10-06: 13 successful jobs covering one artifact build, four Windows/Linux × Python 3.12/3.13 core jobs, and eight MCP jobs with minimum/normal SDK resolution. The workflow checks installed CLI/HTTP and MCP behavior outside the checkout. This is evidence for that commit, not a guarantee for future changes.

Validation and open limits · HTTP behavior · Contributing · Security reporting

Help improve the alpha

Authorized reviewers: report a reproducible false positive or missing check. Use a minimal synthetic example and include the rule ID and expected behavior. Never attach live credentials or original private configurations.

Licensed under MIT. Public availability, customer adoption and a support SLA are not asserted.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    A task-scoped MCP stdio proxy that learns candidate least-privilege policies from labeled successful runs, requires human review, enforces exact decisions, detects tool-definition drift, and emits privacy-minimized JSONL events for Wazuh.
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides a deterministic pre-install security scan for Agent skills, plugins, and MCP servers via stdio, returning verdicts, audited badges, CI gates, and reports without executing code or making network calls.
    137 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to audit other MCP servers' tool definitions for agentic attack classes such as tool poisoning, sensitive-path references in metadata, and tool shadowing via invisible Unicode or homoglyphs. It can analyze a tools/list payload, check a single description string, or connect to a public remote MCP URL to fetch and audit its tool list.
    MIT