MCP Config security check — check your config in browser
Lints mcp.json / .mcp.json / claude_desktop_config.json for the lines that hand an AI agent more than you meant: unpinned servers, literal secrets, plaintext transport. Runs entirely in your browser — nothing is uploaded.
Free here: Check the MCP config file you have open against every rule - line number, why it is wrong, and the exact line that replaces it.. In the editor: Scan every MCP config in the workspace and in the client config folders at once, export the dated audit as CSV/JSON/HTML, and emit machine-readable output a CI step can fail on. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.