MCP Config Guard - agent config lint

Lints mcp.json / .mcp.json / claude_desktop_config.json for the lines that hand an AI agent more than you meant: unpinned servers, literal secrets, plaintext transport. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get one email when this rule changes
We watch the regulation and vendor sources behind MCP Config Guard - agent config lint every day. When a rule changes, you get a single email with what changed and the updated check. No newsletter.

Install free

Free for the file open in your editor - no key, no limit. The workspace sweep and the report ask for a key.

Open VSX (Cursor, VSCodium)npmMCP server (npx)Docker Hub
npx @readystack/mcp-config-guard <file>
npx @readystack/mcp-config-guard --mcp
docker run --rm -v "$PWD:/w" getreadystack/mcp-config-guard /w

Team? One key for every ReadyStack linter, 5 seats, $149 once

Get the complete version $29

This page is the working piece. The full pack has everything below.

Reads .mcp.json / .vscode/mcp.json / claude_desktop_config.json while you edit it and marks the lines that hand an AI agent more than you meant - unpinned servers, literal credentials, plain

Upwork lists cybersecurity developers at a $60 median hourly rate, $40-$90 typical (Sept 2026).

Buy the full version — $29

Questions people ask

What does MCP Config Guard actually do?

It reads an MCP client config - .mcp.json, .vscode/mcp.json, mcp.json or claude_desktop_config.json - and flags the lines that give an AI agent more reach than intended. It checks 23 rules across four groups: how the server code is fetched, which credentials it is handed, how far into the disk it reaches, and how it is reached over the network. Each finding names the line, the risk and the replacement.

Who is this for?

Engineers who added MCP servers to a shared repository so Claude Code, Copilot, Cursor or Windsurf agents can use them, and platform or security engineers who now own a config file that several people edit and nobody re-reads. It is also for reviewers who see .mcp.json in a pull request and have no checklist for it.

Why not just use a free MCP scanner or ask a chatbot?

The existing scanners connect to each server and read its tool descriptions, which means starting the code you are trying to judge, and they run as a separate command outside the editor. A chatbot needs the file pasted into it, credentials and all. This reads the text of the file you already have open, offline, and starts nothing.

What is free and what needs a licence key?

Checking the config file you have open is free, forever, with all 23 rules, no watermark and no limit on how many files you check one at a time. The licence key covers scale and hand-off: one sweep over every config in the workspace and the client config folders, a dated CSV, JSON or HTML report, and machine-readable output for CI.

What does the alternative cost?

Upwork lists cybersecurity developers at a $60 median hourly rate, $40 to $90 typical, as of September 2026. A person reading every MCP config in a monorepo and writing the findings down is an hour or two each time somebody adds a server. The extension is $29 once, one licence key per person or CI seat, with a 7-day full refund.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

ENDEJAESPT

Find a tool