# mcpcheckup [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/fpetitit/mcpcheck  
**GitHub Stars:** 0  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/mcpcheckup

## Description
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.

## Claude Desktop Quick Installation
Remote MCP endpoint (confidence: high). Install path detected from listing signals. Add as a URL/SSE server in your client:

```json
"mcpServers": {
  "mcpcheckup": {
    "url": "https://webcheck.xyz)-style"
  }
}
```

## Documentation & README

# mcpcheck

A [webcheck.xyz](https://webcheck.xyz)-style scanner for remote [MCP](https://modelcontextprotocol.io) servers.

Enter the URL of an MCP server (Streamable HTTP or SSE transport) and get a dashboard of checks:

- **Connectivity & Handshake** — protocol negotiation, server info, advertised capabilities.
- **Tools, Resources & Prompts** — full inventory with schemas.
- **Security Heuristics** — prompt-injection-style wording in tool descriptions, tools that may expose sensitive capabilities (exec, filesystem, network), missing descriptions, plaintext transport.
- **Network & TLS** — certificate validity, HTTP security headers, CORS policy.
- **License Information** — presence of a LICENSE file or license mention in server instructions.

## Development

```bash
npm install
npm run dev
```

Open [http://localhost:3000](http://localhost:3000) and paste an MCP server URL to scan.

## Notes

- Only `http://` and `https://` targets are accepted; scanning private/internal IP ranges or `localhost` is blocked to prevent SSRF.
- Security checks are heuristic, not a substitute for a manual security review.

