Observatory
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Work: Security review · Infrastructure and deployment
Who it is for: Security engineer · DevOps / SRE
Install (Claude Code):
claude mcp add observatory -- npx -y @kryptosai/mcp-observatory“5 tools documented (check_server, score_server, diff_runs…); 15 worked examples; setup and auth covered; states a limit — “Request/response doesn't support long-polling”; read with 4 linked doc(s)”
This grade is wrong ›- tashan score: 69.0
- Instruction depth: 87.0 (deep — documents every tool, with worked examples, setup and a stated limitation)
- Adoption: 1.2k/wk
- Upkeep: 72.0
- Freshness: 97.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- License: MIT
Security audit
scanned 2026-09-12Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.
node scripts/postinstall.mjsWhat changed recently
- 2026-08-14 mcp-observatory published 1.36.5, was 1.36.4 A new release is available.
- 2026-08-22 mcp-observatory published 1.43.0, was 1.36.5 A new release is available.
- 2026-09-13 mcp-observatory published 1.45.5, was 1.43.0 A new release is available.
You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
We recorded 3 changes to Observatory in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
npm ↗ · source ↗ · pkg:@kryptosai/mcp-observatory
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-13 · scorer s5 · how · something wrong here?