Evaluate an MCP server with scout and verify scout attestations, from inside the agent. Read-only.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
scout, the Model Context Protocol server diagnostic, as MCP tools β so an agent can evaluate a server, or check an attestation about one, from inside the editor. Read-only, allowlisted, and it never sends a credential.
Getting started
go install, the container image, and an MCP host configurationThe scout-mcp ecosystem
scout, scout-reporting, scout-action, scout-mcp, scout-lsp, scout-census at a glanceReference
Operational
scout_check runs the scout program. scout must be installed and on
PATH, or named with --scout, for that tool to work; the container
image carries it. scout_verify_attestation needs nothing but scout-mcp.
Release binaries for Linux, macOS and Windows on amd64 and arm64 are on the releases page, with signed checksums and SLSA provenance.
The image is scout's own release image with scout-mcp added: distroless,
non-root, linux/amd64 and linux/arm64, with scout at /usr/local/bin/scout
and scout-mcp started with --scout pointing at it.
scout-mcp speaks MCP over stdio, so a host starts it as a child process.
For Claude Desktop (claude_desktop_config.json), Claude Code (.mcp.json)
and other hosts that read an mcpServers block:
With the container image instead:
Inside a container, loopback is the container itself. To evaluate a server
on the host, run the container with --network host on Linux, or point at
host.docker.internal and add -e SCOUT_MCP_ALLOW=host.docker.internal
to the arguments.
The server is listed in the official MCP Registry as
io.github.sebastienrousseau/scout-mcp; server.json is
that listing.
| Requirement | Floor | Enforced by |
|---|---|---|
| scout | on PATH, or --scout; the version this one is in lockstep with | CI builds scout at that tag and evaluates this server with it |
| Go (building from source) | the go directive in go.mod | CI tests on that version and on latest stable, on Linux, macOS and Windows |
| An MCP host | any that starts stdio servers and speaks revision 2025-03-26 or later | the handshake negotiates 2025-11-25, 2025-06-18 or 2025-03-26, and 2026-07-28 through server/discover |
| The server under test | a Streamable HTTP endpoint on the allowlist | scout_check refuses any other URL before scout runs |
The Go floor is raised only when a release needs a language feature, on a patch release like everything else pre-1.0, and the changelog says so.
Then, with an MCP server of your own listening on
http://127.0.0.1:3000/mcp, ask the agent:
Evaluate my MCP server at http://127.0.0.1:3000/mcp with scout and fix what fails.
The agent calls scout_check, which runs
scout check http://127.0.0.1:3000/mcp --auth none --output json and
returns the score, the grade and every failing check with its detail and a
link to the fix. Loopback needs no configuration; any other host must be
named with --allow first.
One engine, three surfaces, five satellites. This repository is the distribution surface: its deliverable is a registry listing, so scout is where agents look for tools.
| Component | Purpose | Use case |
|---|---|---|
scout | The engine, every check, and the CLI, TUI and web surfaces (GPL-3.0-only) | Evaluate a server and write the statement |
scout-reporting | The attestation format, its schema and the offline verifier (Apache-2.0) | Gate on a statement in a gateway, registry or pipeline |
scout-action | The GitHub Action and GitLab template wrapping the published image by digest (Apache-2.0) | Run scout in CI without installing it |
scout-mcp | scout's diagnostics as read-only MCP tools (GPL-3.0-only) | Evaluate a server from inside an editor |
scout-lsp | A language server over MCP artefacts (planned) | Hover a check id for its remediation |
scout-census | The published reliability census (planned) | Reproduce the numbers |
The family manifest lives in scout at
docs/ecosystem.md;
make family checks this repository's row against it. Every lockstep
repository carries scout's version; this one wraps scout's release, so its
version is scout's latest, exactly.
| Area | Capability | Status |
|---|---|---|
| Evaluate | scout_check: score, grade, counts and up to 25 failing checks for an allowlisted Streamable HTTP endpoint, optionally narrowed to some of scout's nine phases | Stable |
| Verify | scout_verify_attestation: structure, subject digest and target of a scout attestation, offline | Stable |
| Identify | scout_version: scout-mcp's version and the scout it runs | Stable |
| Results | Text for the agent, plus structuredContent matching each tool's outputSchema | Stable |
| Protocol | stdio; handshake 2025-11-25, 2025-06-18, 2025-03-26; server/discover for 2026-07-28; ping | Stable |
Servers that are programs (--stdio) | not through a tool; run scout check --stdio yourself | Out of scope |
| Credentials | never sent; every run is --auth none | Out of scope by design |
The alternative is running scout in a terminal and pasting the report into the conversation, or poking the server by hand in an inspector. scout-mcp is the first with the decisions made for an agent: which hosts it may reach, that no credential travels, and a result sized for a context window.
| Approach | An agent can call it | Targets limited by the operator | Scored, with remediation links |
|---|---|---|---|
| scout-mcp | yes | yes β loopback unless --allow | yes |
scout check in a terminal | no | the operator types the URL | yes |
| MCP Inspector | no β a UI for a person | the operator types the URL | no |
The server adds a process start and a JSON round trip to a run; the run itself is scout's, and bounded at five minutes. Measured with hyperfine on the binaries built from this tree.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/scout-5)<a href="https://allmcps.com/mcp/scout-5"><img src="https://allmcps.com/api/badge/scout-5?style=directory" alt="Scout on AllMCPs" /></a>