{"uid":"cap_O-oQ4ui8CI1uHtwspyU5Q","slug":"hubvibe-mcp-server-inspector-789d9dac","name":"HubVibe MCP Server Inspector","description":"MCP server security scan: probe any MCP endpoint's initialize handshake and tools/list and report whether it requires authentication, which protocol version it speaks, how many tools it exposes and which are not marked read-only. Use it before connecting an agent to an unknown MCP server. Input: url of the MCP endpoint.","url":"https://hubvibe-io.com/work/security/mcp_inspect?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string"},"language":{"type":"string","pattern":"^[A-Za-z]{2,3}(-[A-Za-z0-9]{2,8})*$","maxLength":35}}},"responseSchema":{"type":"json","example":{"result":{"url":"https://mcp.example.com/mcp","tools":[{"name":"get_weather","annotations":{"readOnlyHint":true},"description":"Current weather for a city."}],"reachable":true,"tool_count":3,"server_name":"example-mcp","tools_error":null,"requires_auth":false,"server_version":"1.0.0","protocol_version":"2025-06-18","initialize_status":200,"tools_without_readonly_annotation":["delete_records"]},"status":"ok","worker":"security.mcp_inspect","price_usd":5,"provenance":{"steps":[{"ms":312,"ok":true,"step":"quote","reason":"provider_timeout","provider":"coinbase-advanced-trade-public"}],"attempts":1,"elapsed_ms":340,"providers_used":["coinbase-advanced-trade-public"]},"receipt_id":"rcpt_9f1c2b3a4d5e6f70","attribution":[{"url":"https://translate.google.com","text":"Translated by Google"}],"receipt_url":"/work/receipts/rcpt_9f1c2b3a4d5e6f70"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"5","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$5/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_O1-nA9sdjYLh1ssyWUzi3","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"5","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Probes an MCP server's initialize handshake and tools/list to reveal its protocol version, authentication requirements, and which tools are not marked read-only.","exampleAgentPrompt":"Can you inspect the MCP server at https://example.com/mcp and tell me whether it requires authentication, what protocol version it speaks, and which of its tools aren't marked read-only?","exampleUseCases":[{"title":"Pre-deployment MCP security audit","prompt":"Before I connect my agent to the MCP server at https://mycompany.com/mcp-api, can you check whether it requires auth, what protocol version it uses, and list any tools that could make changes rather than just reading data?"},{"title":"Vetting a third-party MCP integration","prompt":"I found an MCP server at https://vendor-tool.io/mcp — can you probe its initialize handshake and tell me if it's open to unauthenticated access and which of its tools have write capabilities?"},{"title":"Comparing two MCP server configurations","prompt":"Can you inspect https://staging.internal.com/mcp and report back the protocol version it speaks plus any tools that aren't flagged as read-only? I want to make sure the staging setup matches our security requirements."}],"resultDescription":"Returns details from the MCP server's initialize handshake including protocol version, whether authentication is required, and a list of tools exposed by tools/list that are not marked read-only — enabling security assessment before integration.","failureModes":["Unreachable URL returns a connection or timeout error","Non-MCP server at the URL causes handshake failure or malformed response","Server requires auth before returning tool list, limiting inspection depth","Invalid URL format causes input validation error","Server returns non-standard protocol version causing parsing issues"],"whenToPreferThis":"Use this endpoint when you need to security-audit or vet an MCP server before connecting an agent to it — specifically to assess authentication posture, protocol compatibility, and tool write-access risk. Prefer this over generic HTTP security checkers when the target is specifically an MCP server and you need protocol-level handshake details and tool-level access analysis.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:39:55.049Z","isFirstParty":false,"canonicalSlug":"hubvibe-mcp-server-inspector-789d9dac"}