Launching today

mcpward
Security & contract testing for MCP servers
1 follower
Security & contract testing for MCP servers
1 follower
Open-source CLI that tests MCP servers as black boxes. Detects silently changed tool descriptions (rug-pulls), prompt-injection patterns, hidden unicode, schema drift and protocol violations. Runs locally or in CI with JUnit and SARIF reports.


Free
Launch Team

World model AI : Sharm SEKAISimulate your idea on a living world.
Promoted

Hey @Product Hunt , I'm @tsvetang2 , the maker of mcpward.
I build AI automation for a living and publish open-source MCP servers, [one of them with 130+ tools]. That's where this came from.
Pin your MCP servers like dependencies. mcpward is an open-source CLI that snapshots an MCP server's contract into a lockfile and fails your build when it changes.
Apache-2.0, runs on Node 22+.
No account, no API key, no telemetry.
[It started because I kept worrying about MCP servers silently changing underneath my agents. I shared it on r/mcp and Hacker News, and the feedback shaped most of what's in it today.]
The problem: Your agent trusts whatever tools/list returns.
Tool descriptions aren't documentation. They're the instructions the model reads to decide what a tool does. When a server you depend on ships an update, a description can be rewritten, a required parameter can appear, or a read-only tool can start mutating state, and nothing tells you.
mcpward makes those changes fail in CI instead of in production.
What that means in practice:
A rewritten tool description (a "rug-pull") is flagged with a word-level diff, invisible characters included
Every schema change is classified as breaking or non-breaking, so only the ones you care about fail the build
Tool-poisoning checks catch injection phrasing, hidden unicode and schemas that ask for secrets
It's black-box, so it works on servers you didn't write, in any language, over stdio or HTTP
Results go where you already look: JUnit, SARIF for the GitHub Security tab, or a PR comment
Everything runs on your machine. Nothing about your servers is sent anywhere
It's free and open source.
Try it with
Then run
There's a GitHub Action too: TsvetanG2/mcpward@v1.
I read every comment and issue. My favorite check is the hidden-unicode one: add a single zero-width character to a description and watch the diff light up.