Best for
- Development teams building custom MCP servers.
- Security teams needing to validate MCP server security in the AI supply chain.
- DevOps engineers looking for CI integration for MCP server testing.
MCP Observatory is a powerful security scanner and testing tool for MCP servers. It offers unique attack simulation and schema drift detection, and can act as an MCP server itself. This is a valuable tool for teams looking to integrate security testing into their MCP development workflow.
Strongest · Documentation 14/20 Weakest · Reliability 6/20
Static review · not runListed 2026-08-07
Read the FMRS scoring method →Runtime:Node.js 20+
MCP_SERVER_API_KEY
Only needed when testing an authenticated remote HTTP/SSE target via a target config's authToken/headers; obtain it from the target service provider.
MCP_OBSERVATORY_ORG
Optional; sets internal account attribution in CI, e.g. your-company.com.
MCP_OBSERVATORY_CONTACT
Optional; team contact used in enterprise reports.
npx @kryptosai/mcp-observatory or npx @kryptosai/mcp-observatory demo.mcpServers entry in your client config, e.g., {
"mcpServers": {
"mcp-observatory": {
"command": "npx",
"args": ["-y", "@kryptosai/mcp-observatory", "serve"]
}
}
}
claude mcp add mcp-observatory -- npx -y @kryptosai/mcp-observatory serve.setup-ci --all --command "npx -y my-mcp-server" --sarif to generate a workflow.{
"mcpServers": {
"mcp-observatory": {
"command": "npx",
"args": [
"-y",
"@kryptosai/mcp-observatory",
"serve"
]
}
}
}
Shown for Claude Desktop. Other clients may use a different file or key (VS Code uses "servers") — the configurator below converts it.
{
"servers": {
"mcp-observatory": {
"command": "npx",
"args": [
"-y",
"@kryptosai/mcp-observatory",
"serve"
]
}
}
}
Goes in your project's .vscode/mcp.json (VS Code uses a "servers" key).
claude mcp add mcp-observatory -- npx -y @kryptosai/mcp-observatory serve
Run it in a terminal; replace any <…> placeholders with your own values first.
The client's tool list should show the 10 tools (scan, check_server, score_server, etc.); asking "scan my configured MCP servers" and getting a health score and verdict confirms the connection works.
Once connected, you can ask your AI assistant things like:
No matching tools
Listed from the project's documentation, not tested by this site.
MCP Observatory is a CI-native security tool for testing custom MCP servers. It detects schema drift, simulates attacks, generates compliance evidence (e.g., SARIF reports), and provides health scoring before agents depend on your servers. It can run as a CLI or as an MCP server, allowing AI agents to directly test other MCP servers.
Upstash's official server providing up-to-date third-party library docs for AI coding assistants
AI-powered NPM package analysis MCP server
An independent control layer that gives AI coding agents budgets, brakes, and receipts
GitHub's official MCP server for managing repos, issues, PRs, and workflows via natural language
Source revision 8f148e6fa035 Data synced 2026-10-11 Read the FMRS scoring method