Supply chain security tool for Model Context Protocol (MCP) servers
MCPShield is a CLI tool for managing MCP server security, not an MCP server itself. The 10 tools are CLI commands exposed as command-line arguments via Commander.js, not MCP protocol tools. Analysis reveals: (1) No MCP server implementation detected, the codebase is a Node.js CLI application with packages for core functionality and scanning. (2) Tools lack proper input schemas, only 3 of 10 tools have visible parameter definitions (add, verify, scan, search, cache gc, test-registry); the rest (init, lock validate, doctor, cache purge) show no schema in the provided code. (3) Descriptions are present but generic and CLI-focused, not optimized for LLM agent selection. (4) No output schema documentation. (5) No error handling patterns visible for agent recovery guidance. (6) Tool names use imperative verbs ('init', 'add', 'verify') but are CLI-style, not verb_noun agent patterns. This appears to be a security supply-chain tool FOR managing MCP servers, not an MCP server offering tool primitives to agents.
Add an MCP server to your project
Garbage collect old cache entries
Purge entire cache
Run diagnostics to check tool health and environment
Initialize MCPShield in current directory
Validate lockfile structure and integrity
Scan all servers for security issues
No MCP Server Implementation, MCPShield is a CLI tool, not an MCP server. It does not expose tools via the Model Context Protocol, only via command-line arguments. This submission appears to be miscategorized.
Missing Input Schemas, 6 of 10 tools (init, lock validate, doctor, cache purge, test-registry) have no visible input schema definitions. Only add, verify, scan, search, and cache gc show parameters in the provided code.
Descriptions are Generic and CLI-Focused, Tool descriptions like 'Initialize MCPShield in current directory' and 'Run diagnostics to check tool health' do not guide LLM agent selection. They lack context about when to use each tool, what it returns, or what happens next.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 31 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Search MCP registry for servers
[DEV] Test registry client with a server name
Verify all servers in lockfile
No Output Schema Documentation, No tool documents its return type or field structure. Agents cannot plan downstream operations or extract relevant data.
No Error Handling Guidance, No visible error responses with recovery hints. Tools do not guide agents on whether to retry, ask the user, or treat errors as fatal.
Parameter Descriptions Incomplete or Missing, Parameters like 'type' (in search) and 'maxAgeDays' (in cache gc) lack context about constraints, ranges, or allowed values.
Destructive Operations Without Confirmation, cache purge is marked DESTRUCTIVE but the code does not show a dry-run or confirmation pattern. Agents should not irreversibly delete cache without explicit confirmation.
Multi-Word Tool Names, 'lock validate' and 'cache gc' use multi-word names without verb_noun consistency. 'validate_lock' or 'gc_cache' would be clearer for agent parsing.