MCP Risk creates evidence-backed trust profiles for MCP repos and configs, so teams can approve a known-good state and monitor what changes.
No execution by default · Config-aware · No email to preview
The scanner only produces evidence. The product is the lifecycle around that evidence: who approved what, under which config, and what changed afterwards.
A calm chain from tool request, to trust profile, to approval, to drift.
subject: github.com/example/mcp-serverconfig: 9f1c…42abenv_key_added: GITHUB_TOKENtool_added: run_shellverdict: approveverdict: re-review requiredApproval lapsed — re-review required before this server runs again.
$ mcp-risk profile github.com/example/mcp-serversubject: github.com/example/mcp-serverconfig: 9f1c…42abverdict: approve_with_conditions$ mcp-risk diff approved latestchange: env_key_added GITHUB_TOKENchange: tool_added run_shellresult: re-review requiredThe Model Context Protocol (MCP) lets AI agents connect to external tools and data through MCP servers — local processes or remote services that expose actions like reading files, querying databases, or calling APIs.
That power is the risk. An MCP server can ship a tool whose description quietly instructs the agent to exfiltrate secrets, or change behavior after you approve it. MCP Risk reads the repo and config, produces a trust profile you can approve, and flags when the approved state drifts.
Practical review criteria for MCP repos and configs.
PlaybookApproval workflow for teamsHow to record, review, and re-approve MCP usage.
NotesTool poisoning and driftWhy descriptions and schemas need ongoing monitoring.
ExampleClaude Desktop config reviewCommon risks in local MCP configuration files.
ReferenceReading a trust profileWhat each verdict, card, and drift signal means.
TemplatePolicy pack starterBaseline rules for local dev and company laptops.
Submit a repo or config. See the verdict and summary instantly — add your email to unlock the full evidence and downloadable card.