Your setup

What are you actually running?

Paste your MCP config. You get every risk we hold about each server — advisories at the version you would install today, install-time scripts, abandonment, and anything vulnerable in the dependency tree. Free, no account, nothing to install.

Your keys never leave this page. An MCP config keeps API tokens and database URLs right next to the package name, so the parsing happens in your browser and only the bare package names are sent. The env block is never read.

or try an example config

Absence is not safety. A package we have never measured is reported as unmeasured, never as clean — and a clean result means nothing known is wrong, not that nothing is wrong. We read public evidence: we do not run the server, read its source, or test it for prompt injection. What that does and does not cover is written out in the methodology.