SRI — MCP Server Inspector
Qué hace este MCP
Inspects published MCP server source code and reports code-anchored findings such as credential access, network egress, execution, and prompt-injection surfaces.
Herramientas
Esquema de entrada
{'type': 'object', 'required': ['name', 'version'], 'properties': {'name': {'type': 'string', 'description': "The registry name (e.g. 'io.github.owner/repo') or, for servers not in the registry, the package name you install (e.g. '@modelcontextprotocol/server-filesystem'). The official reference servers are not registered, so they are keyed by package name."}, 'version': {'type': 'string', 'description': "Exact version, e.g. '1.2.3'."}, 'ecosystem': {'enum': ['mcp'], 'type': 'string', 'default': 'mcp', 'description': "Always 'mcp'. Other ecosystems are not covered."}, 'l402_token': {'type': 'string', 'description': 'Deprecated and ignored. Payment, when charged, is over x402 (USDC on Base) via HTTP 402.'}}}
Esquema de salida
{'type': 'object', 'required': ['ecosystem', 'name', 'version', 'status', 'findings', 'disclaimer'], 'properties': {'name': {'type': 'string'}, 'status': {'enum': ['analyzed', 'queued', 'rejected'], 'type': 'string', 'description': "'queued' means nothing has been checked yet — it is not a clean result. 'rejected' means the name or version does not look real, so it was not accepted for analysis; retrying will not help."}, 'message': {'type': 'string'}, 'summary': {'type': 'string'}, 'version': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['severity', 'category', 'evidence', 'why'], 'properties': {'why': {'type': 'string'}, 'category': {'type': 'string'}, 'evidence': {'type': 'string', 'description': 'The code itself, quoted verbatim.'}, 'location': {'type': ['string', 'null'], 'description': 'file:line in the published source.'}, 'severity': {'enum': ['info', 'low', 'medium', 'high'], 'type': 'string'}}}, 'description': 'Observations, not verdicts. An empty array is not a clearance.'}, 'ecosystem': {'type': 'string'}, 'price_usd': {'type': 'number'}, 'disclaimer': {'type': 'string'}, 'risk_level': {'enum': ['insufficient_evidence', 'none', 'low', 'medium', 'high', None], 'type': ['string', 'null'], 'description': "'insufficient_evidence' means the published artifact contains no implementation code to read (metadata and documentation only), so no judgement was made. It does not mean nothing is there."}, 'source_url': {'type': ['string', 'null']}, 'analyzed_at': {'type': 'string'}, 'org_decision': {'type': ['string', 'null']}, 'content_sha256': {'type': ['string', 'null'], 'description': 'Hash of exactly what was read, so the claim is checkable.'}, 'analyzer_version': {'type': 'string'}, 'quoted_price_usd': {'type': 'number'}}}
Esquema de entrada
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Esquema de salida
{'type': 'object', 'required': ['servers_read', 'not_read', 'categories', 'disclaimer'], 'properties': {'not_read': {'type': 'integer', 'description': "Retrieved but contained no implementation code. Not 'clean' - there was nothing to read."}, 'categories': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'servers'], 'properties': {'pct': {'type': ['number', 'null']}, 'servers': {'type': 'integer'}, 'category': {'type': 'string'}}}, 'description': "Share of judged servers with at least one finding in the category. Counted per server, not per finding. Most findings describe the server's stated job."}, 'disclaimer': {'type': 'string'}, 'lookup_tool': {'type': 'string'}, 'servers_read': {'type': 'integer', 'description': 'Read at source level and judged.'}, 'analyzer_version': {'type': 'string'}}}
Cambios recientes en herramientas
Servidores MCP similares
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…
PHION Agent Trust Infrastructure
Provides agent trust, policy, provenance, evidence, delegation, telemetry, and transaction-control services for MCP and agent wor…
Swamp
Coordinates security agents through scoped bug-bounty programs, target claims, vulnerability submissions, peer review, shared fin…
AgentBIT
Routes pay-per-call tools over x402 on Base, covering discovery, data conversion, company research, counterparty screening, domai…
SaSame MCP Observatory + Gold Rush Town
Audits and profiles MCP servers, provides ecosystem analytics, trust and claim records, and non-custodial transaction or escrow a…
ThinkNEO Control Plane
Provides an enterprise AI control plane for governance, guardrails, spend tracking, compliance, and model or tool routing.