Read-only static diagnostics for local stdio MCP configuration
Project description
MCP Config Doctor 0.1
MCP Config Doctor is a local, read-only static scanner for one named MCP server. It checks known configuration surfaces for Claude Desktop, Claude Code, Codex, and VS Code, then prints deterministic findings and manual next steps.
Version 0.1.0 is a deliberately narrow public beta. It performs static checks only, makes no runtime-success promise, and does not include checkout or license enforcement. USD 19 remains a pricing hypothesis rather than a current charge.
Install and run locally
Python 3.11 or newer is the supported runtime. The package has no runtime dependencies and does not require network access.
python3 -m venv .venv
.venv/bin/pip install .
mcp-doctor scan --server filesystem
Narrow the scan or emit machine-readable output:
mcp-doctor scan --server filesystem --client codex --format json
The command prints the paths it checked, but replaces the home and project roots
with ~ and <project>. It never prints environment values or argument values.
What v0 checks
- known user and project/workspace configuration locations;
- duplicate, shadowed, absent, and ambiguous-scope definitions;
- local stdio command resolution in the current process environment;
- configured
cwd, path-like arguments, and named environment references; - wrapper/no-TTY and container/localhost risk patterns;
- malformed, duplicate-key, unreadable, oversized, and unsupported configs;
- text and JSON reports using the same versioned finding catalog.
The full path matrix is in docs/config-matrix.md, and the stable code contract is in docs/findings.md.
Exit codes
0: reliable static scan with no actionableFAIL; warnings may remain.1: reliable scan found at least one actionableFAIL.2: invalid input, parsing, permission, unsupported transport/shape, or ambiguous precedence prevented a reliable conclusion.
Safety and privacy boundary
The installed mcp-doctor command only reads bounded supported config files and
uses filesystem metadata plus the current process environment for static checks.
It contains no network, subprocess-launch, file-write, installer, elevation, or
auto-fix path. It does not start an MCP server, invoke JSON-RPC, call a tool, or
claim that a GUI client inherits the shell's environment.
Environment values are inspected only for empty/present status and placeholder
resolution. They are never retained in the report. Command arguments are not
rendered. No telemetry is collected by the CLI; funnel measurement belongs to
external repository, package, checkout, and support surfaces rather than this
command. The external event names and data boundary are recorded in
metrics/event-contract.json.
See SECURITY.md for the exact threat and disclosure boundary.
Known limitations
- Static checks cannot prove client or server runtime behavior.
- Claude Desktop's Linux path is a compatibility convention tested by v0, not a claim that Anthropic ships Claude Desktop on every Linux environment.
- VS Code manages user profiles; v0 checks the default stable profile path and the current workspace, not every named, portable, Insiders, or remote profile.
- VS Code's official MCP docs distinguish user/workspace scopes without defining
deterministic duplicate-name precedence. v0 therefore returns exit
2when the same server appears in both. - Codex project configuration is subject to project trust.
- Python 3.9/3.10 source execution can parse Codex only when a compatible
tomlimodule is already present; packaged support starts at Python 3.11. - Remote HTTP/SSE, OAuth, client-specific runtime bugs, and third-party server correctness are explicit non-goals.
Verify
From this product directory:
python3 -m pip install --no-deps -e .
python3 -m unittest discover -s tests -v
python3 scripts/dry_run.py
Uninstalling the package removes the product. The CLI creates no state, edits no configuration, and has no hosted user data to migrate or delete.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file mcp_config_doctor-0.1.0.tar.gz.
File metadata
- Download URL: mcp_config_doctor-0.1.0.tar.gz
- Upload date:
- Size: 20.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ceeaf34c6a22221f6c88512f0aefaf381ecbe88b1de82e3e19e76999e6f9a238
|
|
| MD5 |
86df5c0c0c9d96f05f2eaaf44245b2b4
|
|
| BLAKE2b-256 |
b5413270ec8a549a32c89df33c13af354bf0af0fd6dc9b2db66bdff5601b1280
|
Provenance
The following attestation bundles were made for mcp_config_doctor-0.1.0.tar.gz:
Publisher:
publish.yml on haozhn/mcp-config-doctor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
mcp_config_doctor-0.1.0.tar.gz -
Subject digest:
ceeaf34c6a22221f6c88512f0aefaf381ecbe88b1de82e3e19e76999e6f9a238 - Sigstore transparency entry: 2203227818
- Sigstore integration time:
-
Permalink:
haozhn/mcp-config-doctor@1c4eec171a9448c3b9975618ae917d660571db2d -
Branch / Tag:
refs/heads/main - Owner: https://github.com/haozhn
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@1c4eec171a9448c3b9975618ae917d660571db2d -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file mcp_config_doctor-0.1.0-py3-none-any.whl.
File metadata
- Download URL: mcp_config_doctor-0.1.0-py3-none-any.whl
- Upload date:
- Size: 19.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a6c6a06e9e9462c1c6880716a6cc45d0fbf1acf93ea8b8e3c7d639b678572173
|
|
| MD5 |
e20069e277fcddf27154c853c7ad82be
|
|
| BLAKE2b-256 |
a5dcc2c9253efc45a28580ab26a9f684502211df9520f192ab04497c1dd3d9ed
|
Provenance
The following attestation bundles were made for mcp_config_doctor-0.1.0-py3-none-any.whl:
Publisher:
publish.yml on haozhn/mcp-config-doctor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
mcp_config_doctor-0.1.0-py3-none-any.whl -
Subject digest:
a6c6a06e9e9462c1c6880716a6cc45d0fbf1acf93ea8b8e3c7d639b678572173 - Sigstore transparency entry: 2203227843
- Sigstore integration time:
-
Permalink:
haozhn/mcp-config-doctor@1c4eec171a9448c3b9975618ae917d660571db2d -
Branch / Tag:
refs/heads/main - Owner: https://github.com/haozhn
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@1c4eec171a9448c3b9975618ae917d660571db2d -
Trigger Event:
workflow_dispatch
-
Statement type: