Skip to main content
Glama
tylerscomic-lab

mcp-schema-audit-mcp

mcp-schema-audit-mcp

License: MIT Live on MCPize

An MCP server that audits other MCP tool definitions and marketplace listings for the specific patterns that make models call tools wrong, never call them, or mis-fill their parameters — vague descriptions, missing parameter docs, non-verb-first naming, oversized enums, deeply nested schemas — plus MCPize's own 500-character description limit, which fails at deploy time with no warning until you hit it.

Most tool-definition bugs don't throw errors. They just make a model call the wrong tool, or call the right tool with the wrong arguments, silently and intermittently. This scores every tool 0-100 and tells you exactly which line to fix.

Why this exists

Verb-first naming, parameter descriptions, and schema depth aren't cosmetic — they measurably change how reliably a model picks and fills a tool. This project encodes those patterns as an actual auditor instead of a blog post you have to remember to re-read every time you write a new tool.

Related MCP server: agentvet-mcp

Tools

audit_tool_definition

Audit a single tool (name, description, inputSchema). Returns a 0-100 friendliness score and a list of concrete issues, each with severity, why it matters, and the fix.

audit_tool_batch

Same checks across an entire server's tool list, plus cross-tool checks: duplicate names, inconsistent naming convention (snake_case vs camelCase mixed in one server), and a worst-offenders summary.

check_marketplace_description

Validates a marketplace-facing short/long description against known platform limits — specifically catches MCPize's 500-character short-description cap before you burn a deploy attempt finding out the hard way.

Use it

Hosted (recommended, no setup): subscribe on MCPize — free tier included, $7/mo for higher limits.

Self-host:

npm install
node server.js

Exposes a Streamable HTTP MCP endpoint on :8080 (/mcp), health check at /health.

Part of a small suite

Built alongside three sibling correctness-audit tools for Claude Code / MCP builders: cron-schedule-audit-mcp (DST-correct cron validation), regex-safety-audit-mcp (ReDoS detection), and claude-cost-audit-mcp (exact Claude API cost + cache-economics calculator).

License

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Static security linter for MCP servers. Scans tool definitions for vulnerabilities (path traversal, SQL injection, SSRF), scores description quality, and auto-rewrites descriptions for safer agent tool selection.
    2
    10
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Lint agent SKILL.md files and MCP tool schemas to catch issues like missing descriptions, similar skills, unconstrained parameters, and destructive tools without confirmation gates.
    2
    MIT