Launching today

mcpward
Security & contract testing for MCP servers
1 follower
Security & contract testing for MCP servers
1 follower
Open-source CLI that tests MCP servers as black boxes. Detects silently changed tool descriptions (rug-pulls), prompt-injection patterns, hidden unicode, schema drift and protocol violations. Runs locally or in CI with JUnit and SARIF reports.


Free
Launch Team

Framer AI AgentsDesign and publish professional sites with AI
Promoted

Hey @Product Hunt , I'm @tsvetang2 , the maker of mcpward.
I build AI automation for a living and publish open-source MCP servers, [one of them with 130+ tools]. That's where this came from.
Pin your MCP servers like dependencies. mcpward is an open-source CLI that snapshots an MCP server's contract into a lockfile and fails your build when it changes.
Apache-2.0, runs on Node 22+.
No account, no API key, no telemetry.
[It started because I kept worrying about MCP servers silently changing underneath my agents. I shared it on r/mcp and Hacker News, and the feedback shaped most of what's in it today.]
The problem: Your agent trusts whatever tools/list returns.
Tool descriptions aren't documentation. They're the instructions the model reads to decide what a tool does. When a server you depend on ships an update, a description can be rewritten, a required parameter can appear, or a read-only tool can start mutating state, and nothing tells you.
mcpward makes those changes fail in CI instead of in production.
What that means in practice:
A rewritten tool description (a "rug-pull") is flagged with a word-level diff, invisible characters included
Every schema change is classified as breaking or non-breaking, so only the ones you care about fail the build
Tool-poisoning checks catch injection phrasing, hidden unicode and schemas that ask for secrets
It's black-box, so it works on servers you didn't write, in any language, over stdio or HTTP
Results go where you already look: JUnit, SARIF for the GitHub Security tab, or a PR comment
Everything runs on your machine. Nothing about your servers is sent anywhere
It's free and open source.
Try it with
Then run
There's a GitHub Action too: TsvetanG2/mcpward@v1.
I read every comment and issue. My favorite check is the hidden-unicode one: add a single zero-width character to a description and watch the diff light up.