Observatory MCP server
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
139 stars383 downloads/wk
Reviews
Write oneNobody has reviewed Observatory yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Observatory tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it
- Code scan231 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 2 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- mediumnpm install lifecycle script present
install.script - mediumnpm install lifecycle script present
install.scriptpackage.json: ….", "prepack": "npm run build", "postinstall": "node scripts/postinstall.mjs", "pr…
What the publisher says
From the Observatory repository's README, as published. We do not edit it. Read it on GitHub
MCP Observatory
More badges
Secure the MCP servers you're building. MCP Observatory is the CI-native security tool for teams shipping custom MCP servers. Test during development, catch schema drift, simulate attacks, and generate compliance evidence — before agents depend on your servers.
Also available in Simplified Chinese.
Runtime enforcement: Use mcp-seatbelt to block dangerous MCP tool calls at runtime based on observatory scan results.
Get Started
Step-by-step setup guide · macOS, Windows, Linux · Node.js 20+ and npm (install Node.js LTS).
1. Run your first scan
Open Terminal or PowerShell in your project folder and paste:
npx -y @kryptosai/mcp-observatory@latestThis downloads Observatory and checks your first configured MCP server. With no configured server, it uses an included example. To try only that example, run npx -y @kryptosai/mcp-observatory@latest demo --example.
2. Read the result
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y @kryptosai/mcp-observatory on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mcp-observatory -- npx -y @kryptosai/mcp-observatory
Observatory: common questions
- Is Observatory MCP server safe?
- Mostly: it is graded B (77/100). Read the Observatory safety report
- How do I install Observatory?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Observatory need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Observatory maintained?
- The last commit was 2 days ago (2026-09-22). The latest release is v1.36.1.
- What can I use instead of Observatory?
- Servers from other publishers that do the same job: Git MCP server, Contentrain MCP server and Weavatrix MCP server. Compare all Observatory alternatives.
Alternatives to Observatory
Same job from other publishers: the closest match first, then the best rated.
- GitComprehensive Git MCP server enabling native git tools including clone, commit, worktree, & more.not reviewedEstablishedA
- ContentrainGit-native content governance for AI agents — 27 deterministic MCP tools over stdio and HTTP.not reviewedEstablishedA
- WeavatrixNative Weavatrix MCP: 67 read-only tools for code, local CI, n8n, Dify, agents, Mermaid, Web3.not reviewedGrowingA
- GntGit-native policy layer for AI agents: check_action verdicts against rules approved via PR.not reviewedGrowingA
BorealHostAgent-native web hosting — deploy sites, manage DNS, register domains, scale infrastructurenot reviewedGrowingB