让 agent 在用一个 MCP server 之前,先查一查它。
我们的 MCP 端点回答的是对公开 MCP server 的观测——和报告页用的是同一份证据。六个工具里有五个只根据已记录的内容作答,从不联系你问到的那台 server。
最快的办法: 很多 agent 能自己完成接入。直接跟它说:
“读一下 https://mcpcheckup.com/agents,然后把 MCP Checkup 这个 server 加上。”
或者按下面的方法手动添加:
编程工具
Claude Code
加上 --scope user,所有项目里都能用。
Cursor
.cursor/mcp.json or ~/.cursor/mcp.json
项目级写在 .cursor/mcp.json;所有项目都用则写在 ~/.cursor/mcp.json。
VS Code
.vscode/mcp.json
也可以在命令面板里运行 MCP: Add Server。
Muse Code
~/.config/muse/settings.json
缺少 "schema_version" 所有命令都会失败。"mode": "optional" 让会话在连不上我们端点时照常运行——会话里输入 /mcp 可以确认已连上。
助手与 agent
Claude
- 打开 Customize → Connectors → Add custom connector。
- 名字填 MCP Checkup,地址粘贴 https://mcpcheckup.com/mcp。
- Authentication 选 No sign-in。
claude.ai 和桌面应用都适用。Team 与 Enterprise 由 Owner 在 Organization settings → Connectors 里添加,成员再点 Connect。免费账号可以添加一个自定义连接器。
ChatGPT · dots
- 在网页版 ChatGPT 打开 Settings → Security and login,开启 Developer mode。
- 打开 chatgpt.com/plugins,点 +,填写名字和描述。
- 在 Connection 里填 https://mcpcheckup.com/mcp,认证选无。
Developer mode 适用于 Pro、Plus、Business、Enterprise 和 Education 账号。
dot 可以使用你账号里已安装并启用的受支持插件;开发者模式里添加的插件算不算在内,还没有写明。
Grok
- grok.com:打开 grok.com/connectors → New Connector → Custom,填入 https://mcpcheckup.com/mcp。
xAI API — POST /v1/responses
Business 与 Enterprise 需要管理员先开放连接器。
Grok Bot 通过它的 Marketplace 安装连接器,添加自定义 MCP 地址还没有写明。
Hermes Agent
也可以写进 ~/.hermes/config.yaml 的 mcp_servers 下,然后在运行中的会话里执行 /reload-mcp。
OpenClaw
一定带上 --transport streamable-http:不写的话 OpenClaw 默认用 SSE。也可以在 Control UI 里:Settings → MCP → Add server → Streamable HTTP。
Muse
Meta 还没有把这写进文档。我们在 2026-10-01 试过:在对话里让 Muse 读 https://mcpcheckup.com/mcp,它就自己把这个 server 加上了。你也可以这样问你的 Muse:「读一下 https://mcpcheckup.com/agents,然后把 MCP Checkup 这个 server 加上。」
还没有写明。
以上写法于 2026-10-01 对照各产品官方文档核对。
六个工具
check_mcps
Look up MCP servers
What has been observed about an MCP server — useful when choosing, adding, or debugging one. Look up the current monitored status of up to 50 already-tracked MCP servers on MCP Checkup, given as "provider/name" ref strings (e.g. "acme/weather-mcp"). Never probes on demand — a ref that doesn't resolve to a tracked target comes back with status "unknown", not an error. Each entry may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported per target as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. Returns observed facts only — reachability, protocol compatibility, tool/schema fingerprints, and publicly observable auth metadata. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score. Items not verified are returned explicitly with reasons.
get_mcp_report
Get a server's full report
The detailed view of one MCP server: every check with its state, plus the observed tool list. Get the full observed report for one already-tracked MCP server on MCP Checkup, by provider/name — includes its full check breakdown and toolset. A target this deployment doesn't track yet comes back with status "unknown", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
get_mcp_history
Get a server's recent changes
Whether an MCP server's toolset changed recently. Get recent history for one already-tracked MCP server on MCP Checkup, by "provider/name" ref (e.g. "acme/weather-mcp"). Events include the toolset's most recent change boundary (not a full change-by-change history) plus any recorded baseline-drift events, newest first, up to `limit` results (default 20, max 50). A target this deployment doesn't track yet comes back with status "unknown", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
get_attestation
Get a server's signed attestation
The signed evidence behind a report, for callers that want to inspect it themselves. Get the full signed attestation envelope (DSSE, Ed25519) for one already-tracked MCP server's latest probe run, by "provider/name" ref — the raw envelope plus its issued-at time and declared protocol revision, so a caller can inspect the signed payload rather than trust this tool's own summary of it; the public key needed to verify the signature is not published yet. A target with no run yet, no signed envelope, or a disqualified one comes back with an explicit reason, not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of "provider/name" — the resolution method used is reported back as resolution.method ("ref", "endpoint", "host", or "name"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status "ambiguous" with a short `candidates` list (each with a "provider/name" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
search_mcps
Search MCP servers by tool text
Find MCP servers by what their tools do. Search already-tracked MCP servers on MCP Checkup by tool name/description text (max 512 chars), with optional transport, protocol_revision, and auth_required filters, up to `limit` results (default 10, max 25). Ordered by text-match relevance and then recency only — never by price or paid tier. Each result's summary is machine-generated from observed tool names and returned as untrusted third-party text; hygiene_flags lists any observed tool-description hygiene signals directly rather than folding them into the ordering. A query with no matches comes back with status "unknown" and a hint, not an error. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
request_check
Request a one-off check of a URL
Ask for a one-off public observation of the MCP server at a full endpoint URL — this is the only tool here that contacts a third-party server, and it contacts exactly the host you name. `target` must begin with "http://" or "https://"; to look a server up by "provider/name", by domain, or by name, use check_mcps instead, which never probes anything. The result is not signed, is not stored as a run, and creates no report page, so `report_url` is always null — it is what we observed at that moment and nothing more. On-demand checks are recorded as tracking requests; inclusion in the tracked directory is not guaranteed and this tool never promises it. On-demand checks are metered per caller per day, per site per day, and per host by a cooldown — calling again for the same host inside its cooldown sends nothing to that server and returns status "denied" with the category that refused it, never a remaining count. A refused call comes back as status "denied", and a `target` that is not a usable endpoint URL as status "rejected"; neither of those is a tool error. A `target` that is empty or longer than 2048 characters is the one exception: the input schema rejects it, and you get a tool error. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.
回答长什么样
你问“MCP Checkup 最近一次对 mcpcheckup/mcp 观测到了什么?”
agent 调用get_mcp_report 会返回全部检查项;这里只节选了几项。
限额
每个 IP 地址每分钟约 20 次,按 Cloudflare 节点分别计数。429 响应带 Retry-After:60 秒。
这个端点不需要认证,也没有付费档。
它永远不会告诉你的
没有单一数字,也没有「该不该用」这样的结论。每项检查只落在四态之一,没跑的检查从不会被报成通过。
给机器读的: /llms.txt · /.well-known/mcp/server-card.json