← Back to search

@yawlabs/mcp-compliance

jeffyaw Scanned 1h ago

CLI tool and MCP server that tests MCP servers for spec compliance

B
76.5 / 100

Versions

0.16.4latest
Jul 21, 2026
0.16.3
Jun 19, 2026
0.16.1
Jun 11, 2026
0.15.1
Jun 7, 2026
0.15.0
Jun 7, 2026
+ show 31 moreshow less
0.14.4
Jun 3, 2026
0.14.3
May 28, 2026
0.14.2
May 15, 2026
0.14.1
Apr 19, 2026
0.14.0
Apr 19, 2026
0.13.5
Apr 17, 2026
0.13.4
Apr 17, 2026
0.13.3
Apr 16, 2026
0.13.2
Apr 16, 2026
0.13.1
Apr 16, 2026
0.13.0
Apr 14, 2026
0.12.2
Apr 13, 2026
0.12.1
Apr 13, 2026
0.12.0
Apr 13, 2026
0.11.0
Apr 13, 2026
0.10.1
Apr 13, 2026
0.9.2
Apr 13, 2026
0.9.1
Apr 13, 2026
0.9.0
Apr 13, 2026
0.8.1
Apr 11, 2026
0.8.0
Apr 10, 2026
0.7.0
Apr 10, 2026
0.6.0
Apr 9, 2026
0.5.0
Apr 8, 2026
0.4.0
Apr 8, 2026
0.3.0
Apr 7, 2026
0.2.1
Apr 7, 2026
0.2.0
Apr 7, 2026
0.1.2
Apr 6, 2026
0.1.1
Apr 6, 2026
0.1.0
Apr 6, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 3

mcp_compliance_test
annotations: none low

Run the full MCP compliance test suite against a server URL. Returns grade (A-F), score, and detailed results for all 88 tests covering transport, lifecycle, tools, resources, prompts, errors, schema validation, and security.

url string auth string
mcp_compliance_explain
annotations: none low

Explain what a specific compliance test ID checks and why it matters.

testId string
echo
annotations: none low

Echoes back the input

message string

Permissions 3

filesystem low
Server uses filesystem capabilities via: fs, path
shell high
Server uses shell capabilities via: child_process, spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 22

low
Tool 'mcp_compliance_test' has no annotations annotation_checker · 100%
low
Tool 'mcp_compliance_explain' has no annotations annotation_checker · 100%
low
Tool 'echo' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: undici@8.7.0 (GHSA-4cwx-7wf7-3272) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.7.0 (GHSA-8xcm-r25x-g524) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.7.0 (GHSA-jr45-8vmc-qm54) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.7.0 (GHSA-m8rv-5g2x-5cg5) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.7.0 (GHSA-v3r7-h72x-cjcm) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@4.1.8 (GHSA-82fw-gwwq-j7x9) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: mcp_compliance_test manifest_parser · 70%
info
Tool: mcp_compliance_explain manifest_parser · 70%
info
Tool: echo manifest_parser · 70%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (12) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 270 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%