Observatory
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Work: Security review · Infrastructure and deployment
Who it is for: Security engineer · DevOps / SRE
Install (Claude Code):
claude mcp add observatory -- npx -y @kryptosai/mcp-observatory“5 tools documented (check_server, score_server, diff_runs…); 15 worked examples; setup and auth covered; states a limit — “Request/response doesn't support long-polling”; read with 4 linked doc(s)”
This grade is wrong ›- tashan score: 71.0
- Instruction depth: 87.0 (deep — documents every tool, with worked examples, setup and a stated limitation)
- Adoption: 3.4k/wk
- Upkeep: 73.0
- Freshness: 99.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- License: MIT
Security audit
scanned 2026-08-22Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.
node scripts/postinstall.mjsWhat changed recently
- 2026-08-14 mcp-observatory published 1.36.5, was 1.36.4 A new release is available.
- 2026-08-22 mcp-observatory published 1.43.0, was 1.36.5 A new release is available.
You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
We recorded 2 changes to Observatory in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
npm ↗ · source ↗ · pkg:@kryptosai/mcp-observatory
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-08-23 · scorer s5 · how · something wrong here?