MCPサーバー

MCP Checkup

com.mcpcheckup/mcp
MCP・エージェント基盤 セキュリティ 公開・接続可能 MCP 2025-11-25

このMCPでできること

Monitors public MCP servers, reporting observed protocol checks, tool changes, attestations, histories, and one-off endpoint checks.

check_mcps
Look up MCP servers
What has been observed about an MCP server — useful when choosing, adding, or debugging one. Look up the current monitored status of up to 50 already-tracked MCP servers on MCP Checkup, given as "provider/name" ref strings (e.g. "acme/weather-mcp"). Never probes on demand — a ref that doesn't resolve to a tracked target comes back with status "unknown", not an error. Each entry may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported per target as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. Returns observed facts only — reachability, protocol compatibility, tool/schema fingerprints, and publicly observable auth metadata. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score. Items not verified are returned explicitly with reasons.
読み取り専用
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['targets'], 'properties': {'detail': {'enum': ['summary', 'full'], 'type': 'string'}, 'targets': {'type': 'array', 'items': {'type': 'string', 'maxLength': 512, 'minLength': 1}, 'maxItems': 50, 'minItems': 1, 'description': 'Up to 50 entries, each a "provider/name" ref, a full endpoint URL, a bare domain, or a bare provider/target name.'}, 'known_fingerprints': {'type': 'object', 'description': 'Optional, keyed by the exact same ref string used in `targets` (max 50 entries) â\x80\x94 your own last-observed toolset_fingerprint per target (format "sha256:<64 hex chars>"), to get a fingerprint_match fact back.', 'propertyNames': {'type': 'string', 'maxLength': 512}, 'additionalProperties': {'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}}}}
get_attestation
Get a server's signed attestation
The signed evidence behind a report, for callers that want to inspect it themselves. Get the full signed attestation envelope (DSSE, Ed25519) for one already-tracked MCP server's latest probe run, by "provider/name" ref — the raw envelope plus its issued-at time and declared protocol revision, so a caller can inspect the signed payload rather than trust this tool's own summary of it; the public key needed to verify the signature is not published yet. A target with no run yet, no signed envelope, or a disqualified one comes back with an explicit reason, not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
読み取り専用
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['target'], 'properties': {'target': {'type': 'string', 'maxLength': 512, 'minLength': 1, 'description': 'A tracked target as "provider/name", a full endpoint URL, a bare domain, or a bare provider/target name.'}}}
get_mcp_history
Get a server's recent changes
Whether an MCP server's toolset changed recently. Get recent history for one already-tracked MCP server on MCP Checkup, by "provider/name" ref (e.g. "acme/weather-mcp"). Events include the toolset's most recent change boundary (not a full change-by-change history) plus any recorded baseline-drift events, newest first, up to `limit` results (default 20, max 50). A target this deployment doesn't track yet comes back with status "unknown", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
読み取り専用
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['target'], 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'description': 'Max events to return (default 20, max 50).', 'exclusiveMinimum': 0}, 'target': {'type': 'string', 'maxLength': 512, 'minLength': 1, 'description': 'A tracked target as "provider/name", a full endpoint URL, a bare domain, or a bare provider/target name.'}}}
get_mcp_report
Get a server's full report
The detailed view of one MCP server: every check with its state, plus the observed tool list. Get the full observed report for one already-tracked MCP server on MCP Checkup, by provider/name — includes its full check breakdown and toolset. A target this deployment doesn't track yet comes back with status "unknown", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
読み取り専用
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['target'], 'properties': {'target': {'type': 'string', 'maxLength': 512, 'minLength': 1, 'description': 'A tracked target as "provider/name", a full endpoint URL, a bare domain, or a bare provider/target name.'}}}
request_check
Request a one-off check of a URL
Ask for a one-off public observation of the MCP server at a full endpoint URL — this is the only tool here that contacts a third-party server, and it contacts exactly the host you name. `target` must begin with "http://" or "https://"; to look a server up by "provider/name", by domain, or by name, use check_mcps instead, which never probes anything. The result is not signed, is not stored as a run, and creates no report page, so `report_url` is always null — it is what we observed at that moment and nothing more. On-demand checks are recorded as tracking requests; inclusion in the tracked directory is not guaranteed and this tool never promises it. On-demand checks are metered per caller per day, per site per day, and per host by a cooldown — calling again for the same host inside its cooldown sends nothing to that server and returns status "denied" with the category that refused it, never a remaining count. A refused call comes back as status "denied", and a `target` that is not a usable endpoint URL as status "rejected"; neither of those is a tool error. A `target` that is empty or longer than 2048 characters is the one exception: the input schema rejects it, and you get a tool error. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
外部アクセスあり
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['target'], 'properties': {'target': {'type': 'string', 'maxLength': 2048, 'minLength': 1, 'description': 'A full endpoint URL beginning with "http://" or "https://" (max 2048 characters). Not a "provider/name" ref, a bare domain, or a bare name â\x80\x94 use check_mcps for those.'}}}
search_mcps
Search MCP servers by tool text
Find MCP servers by what their tools do. Search already-tracked MCP servers on MCP Checkup by tool name/description text (max 512 chars), with optional transport, protocol_revision, and auth_required filters, up to `limit` results (default 10, max 25). Ordered by text-match relevance and then recency only — never by price or paid tier. Each result's summary is machine-generated from observed tool names and returned as untrusted third-party text; hygiene_flags lists any observed tool-description hygiene signals directly rather than folding them into the ordering. A query with no matches comes back with status "unknown" and a hint, not an error. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
読み取り専用
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 25, 'description': 'Max results to return (default 10, max 25).', 'exclusiveMinimum': 0}, 'query': {'type': 'string', 'maxLength': 512, 'minLength': 1, 'description': "Free-text search over tracked servers' observed tool names/descriptions (max 512 chars)."}, 'transport': {'enum': ['remote', 'stdio'], 'type': 'string'}, 'auth_required': {'type': 'boolean', 'description': "A target whose auth requirement can't be determined is excluded regardless of which value is passed here."}, 'protocol_revision': {'type': 'string', 'maxLength': 512, 'description': 'Exact match against a target\'s declared protocol revision, e.g. "2026-07-28" (max 512 chars).'}}}
追加
request_check
2026年9月22日2:40
追加
search_mcps
2026年9月22日2:40
追加
get_attestation
2026年9月22日2:40
追加
get_mcp_history
2026年9月22日2:40
追加
get_mcp_report
2026年9月22日2:40
追加
check_mcps
2026年9月22日2:40