mcpvitals
Vital signs for your MCP servers. One command gives you a health score, plus the checks nobody else runs.
60-second start
No install. Point it at any MCP server (a stdio command or an http url):
uvx mcpvitals check "npx -y @your/mcp-server"
mcp health: 40 (F)
x MV020 [run_sql] tool 'run_sql' appears to contain a hard-coded secret
-> never ship keys in tool metadata; use env vars
x MV022 [run_sql] description contains model-directed instructions (poisoning surface)
-> tool descriptions should describe, not instruct the model
! MV030 [run_sql] tool 'run_sql' costs ~410 tokens to expose
-> trim the description/schema; it inflates every request
! MV040 tools 'get_user' and 'fetch_user' are 0.91 similar; agents may pick the wrong one
-> differentiate names/descriptions or merge them
i MV050 protocol 2025-03-26 predates the 2026-07-28 stateless spec
What it checks
Most linters stop at basic conformance. mcpvitals runs those, plus four things no other tool does:
| Area | What it catches |
|---|---|
| Conformance | empty tool descriptions, duplicate tool names, malformed schemas |
| Reliability | parameters with no required list, untyped params, error-path gaps |
| Security hygiene | secrets in tool metadata, over-broad tools (run_sql, exec), model-directed instructions in descriptions (the tool-poisoning surface) |
| Token cost | how many tokens each tool burns in the context window, and the total cost to connect the server |
| Tool confusion | pairs of tools an agent will mix up, predicted from name/description overlap before it happens in production |
| Migration readiness | what breaks under the 2026-07-28 stateless spec |
Every check is a pure function scored deterministically. Run mcpvitals check --json for machine output.
Add the health badge to your README
mcpvitals emits a shareable badge so a good score is visible at a glance:
mcpvitals check "npx your-server" --badge badge.svg
Or use the shields.io endpoint output to keep it live.
Use it in CI
Gate your server on every push with the bundled GitHub Action:
- uses: ContextJet-ai/mcpvitals@v0
with:
target: "python -m your_server"
strict: "true" # fail the build on any error-level finding
Track and monitor (not just a one-shot check)
Pin a server's tools and get alerted when they change. This catches rug-pulls, where a server you already approved silently mutates a tool's schema or description after the fact:
mcpvitals watch "npx your-server" # pins tools to mcp.lock
mcpvitals watch "npx your-server" --check # re-run in CI; fails if a pinned tool changed
Probe a running server for live health (uptime and latency):
mcpvitals monitor "https://your-server/mcp" --count 5
# probe 1/5: up 210ms ... uptime 100.0% avg 207ms
Why this exists
The MCP ecosystem grew faster than the tooling around it. There are thousands of servers and no standard way to tell whether one is any good, safe, or cheap to run. mcpvitals gives authors a one-command checkup before they publish, and gives everyone else a way to vet a server before they trust it.
Built by ContextJet.ai. MIT licensed. Contributions welcome, see CONTRIBUTING.md.
Metadata
Release files for mcpvitals 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mcpvitals-0.1.0.tar.gz | 27.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mcpvitals-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 42.2 kB
Release files / mcpvitals-0.1.0.tar.gz
| Download URL | mcpvitals-0.1.0.tar.gz |
|---|---|
| Size | 27.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
05388ff2d048d6a96a6990f28cc0f57c9d82ae2baa3601ccf1c4d001590f2f20
|
|
BLAKE2b-256 checksum How to use checksums |
a0196bef05ab13b1e9c7c401a1394791c7ae42c200942bf237ec856dd27ac749
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 5, 2026.
Transparency logRelease files / mcpvitals-0.1.0-py3-none-any.whl
| Download URL | mcpvitals-0.1.0-py3-none-any.whl |
|---|---|
| Size | 14.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
58d6c015e71266bd6a24251cb8098c6e772e43220c8f1410c8ac1647a278b4b6
|
|
BLAKE2b-256 checksum How to use checksums |
e998a7acc73c5c8d13e4fc25b0aa02b4789dfce6bd5c82370a7a908153859322
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 5, 2026.
Transparency log