Nothing to hand? Load the
— unprefixed camelCase tool names, a hardcoded API key, tools with no descriptions or schemas,
a list tool that returns everything and console.log on a stdio transport — or the
,
where the correct verdict is production-ready and the useful output is what to add next.
Paste the server — the prescan is free
No upload, no AI: the prescan reads every registered tool in your browser and lists what it mechanically found. The tool inventory, then the flags — missing descriptions, missing input schemas, z.any() and bare Any parameters, generic error messages, list tools without a limit or cursor, missing readOnlyHint/destructiveHint annotations, literal secrets, console.log or print() on a stdio transport, the deprecated SSE transport, and naming inconsistencies. Each group explains why it matters. This part costs nothing and happens while you type.
The AI reviews it — this is the metered part
A senior MCP engineer's pass, grounded in the MCP Best Practices the upstream skill ships: a readiness posture with the single most important change named, the inventory with each tool's inputs and role, and prioritized findings across tool design, schemas, errors, pagination, protocol, security, docs and hygiene — each with the problem, the concrete impact on a real agent session, the fix and a corrected fragment in your paste's own language. Every prescan flag is confirmed or explicitly set aside. Findings may only cite tools that actually appear in your code. Pricing is honest: a worst-case amount is reserved before the run and only what the run actually uses is charged — the meter next to the button shows both.
Fix, export, re-run
Quick wins for the one-line changes, focus areas tied to specific findings for the real work, the findings table as CSV, review history on this device with restore (patch the server, re-review, compare), and Markdown or JSON export of the whole review.
Derived from the @anthropics/mcp-builder skill.