What is mcpward? What does it do?
Hello everyone,
I would say this is one of my biggest projects ever and wanted to share it with you.
What is mcpward?
Security & contract testing for MCP servers in short and understandable language
What does it do?
It treats an MCP server like any other external dependency: snapshot its contract, then fail the build when it changes underneath you. Black-box, so it works against servers you didn't write. Runs entirely on your machine - no account, no API calls, no telemetry.
Catches schema drift, silently changed tool descriptions, protocol violations, error-contract mistakes, and tool-poisoning patterns. Reports to console, JSON, JUnit, SARIF or Markdown, and can post the result as a pull-request comment.
In short and non-technical summary: It catches everything that has been changed to the tool or MCP your AI uses
Since we are living now in the AI mainstream world, i think this might be useful for whoever is building Agents, Automations and AI Integration in the bussiness. People that do that job as myself know, that almost everytime we have to use external tools or MCPs, but what happens when that tool or MCP get an update? Have you thought, that maybe except the new features and tools, something else changed as well like - the access, that the Agent, that will use it get. Tool description, parameters, authentication and more! That's what mcpward is for, it detects everything changed since the last version and give you information about how it will affect your AI.
I would be happy to hear feedback from you guys!
It's open-source and all free.
If you have any ideas, features or improvements to be added please don't be shy!

Replies
Be the first to reply
Have a question or a thought to share? Add a comment above to start the conversation.