Inspect before connecting

MCP tool annotations checker

Check server-declared MCP hints locally, then compare two tools/list inventories to distinguish added tools, changed hints, and unchanged defaults. Annotations are declarations, not permission enforcement. Paste one response for a current review, or compare before and after snapshots to see inventory changes, annotation coverage, and read-only applicability.

01 / Add tool metadata

Check the hints.

Up to 1 MiB of UTF-8 JSON and 1,000 tools. Accepts result.tools, a {"tools": [...]} object, or a tool array. Never paste credentials. Tool names must be non-empty and unique within the response.

No account or server connection needed.

Load a sample or paste your tools/list response.

Release review / Compare two inventories

What changed since your last snapshot?

A new tool and a changed annotation need different review. Match exact tool names across a before and after inventory. Track declared values, default or invalid origins, and read-only applicability separately.

Read the capture evidence ↓

Each inventory has the same 1 MiB / 1,000-tool limits and accepted JSON shapes as the single-inventory checker. An empty before field means an empty baseline. Names match exactly; a rename counts as a removal and an addition. For multiple servers, use names such as serverSlug/toolName.

Choose the synthetic example, load the real release snapshots, or add your own inventories.

How to read a changed hint
  • Default → declared: An omitted openWorldHint and an explicit true have the same effective value, but different coverage. The comparison reports that distinction.
  • Read-only applicability: A readOnlyHint flip can move destructive and idempotent hints into or out of N/A without changing their declared values.
  • Declarations while N/A: Changing an idempotent declaration on a read-only tool remains visible as a declared-value change; it does not change its N/A interpretation.
  • Invalid values: Missing and invalid origins remain distinct. Invalid raw values are not compared or exported; two different malformed values with the same invalid origin do not produce a new event.

An observed release delta

More tools. Stable retained declarations.

Two independently dated captures cover 46 → 55 first-party endpoints and 97 → 124 functions. The qualified-name comparison finds 9 additional observed endpoints, 27 added functions, 97 retained functions, and 0 removals.

Among the 97 retained functions, 0 have changed annotation values, origins, or applicability. Expanded observation scope explains the additional functions; it does not establish that existing server behavior or permissions changed.

The real sample uses serverSlug/toolName to prevent cross-server name collisions. Your ordinary one-server responses keep their original names.

Inspect both snapshots, source hashes, and the delta →

Capture provenance

Baseline report time
Current fetch started
Current observations ended
Changed retained tools
0 / 97

The baseline time is its source report timestamp; the current time marks fetch start. Individual endpoint observations and SHA-256 source hashes are in the linked JSON. Captures used anonymous metadata discovery with no tools/call, credentials, or host installation checks. These are server declarations from a selected first-party collection.

Capture inventories for a comparison.

Export a complete tools/list response from your MCP client. Save one before a release and another after it, then load those files in the comparison above. Use the same server and observation scope; a wider capture can explain added tools without a server change.

For an anonymous HTTPS Streamable HTTP endpoint, download our local metadata collector. With Node.js 22 or later, run it from your terminal, replacing the example address with your endpoint.

node collect-mcp-tools.mjs --server https://your-server.example/mcp > before.json

Repeat after the release, changing before.json to after.json. The script contacts your chosen server to initialize a session and collect every tools/list page. It never invokes tools/call or uploads the captured inventory to ToolRoutine.

It sends no authentication headers or cookies, rejects embedded credentials and query strings, and stops for repeated cursors, duplicate names, HTTP failures, or incomplete pagination. It exports at most 1,000 tools and 1 MiB. Authenticated endpoints, legacy SSE transports, and local stdio servers need your existing MCP client.

On 11 October 2026, this collector retrieved the JSON Diff endpoint's inventory anonymously. Protocol, pagination, malformed-response, and output-bound tests are separate from the browser checker's privacy tests. Metadata collection does not test tool behavior.

Method and boundaries

How we interpret the hints.

Annotations describe behavior; they do not manage permissions. The checker does not run tools, validate inputSchema, inspect server code, or test network access. Use the result to ask better questions before connecting a server.

Only JSON booleans count as declared hints. A string such as "true", a number, or null is invalid. This checker applies a conservative fallback and labels it invalid; the specification does not define malformed values as valid defaults. Missing hints are labeled “default”; they are optional, not a failed check.

Specification defaults for missing hints; checker fallbacks for invalid values
AnnotationDefaultHow to read it
readOnlyHintfalseAssume the tool may modify its environment.
destructiveHinttrueFor a tool that may write, assume changes could be destructive.
idempotentHintfalseFor a tool that may write, do not assume repeating the call has the same effect.
openWorldHinttrueAssume the tool may interact with an open set of external entities.

When readOnlyHint is true, destructive and idempotent hints are marked N/A. Their declared values remain visible; the checker does not call them contradictions.

First-party metadata snapshot

What our 124 tool declarations say.

On , saved MCP discovery metadata covered 124 functions across 55 ToolRoutine catalog endpoints. The “Load 124 catalog tools” button uses those saved names and annotations, embedded in this page. It makes no live endpoint requests.

Our catalog is a first-party snapshot, not a representative survey of MCP servers. Discovery captured declarations; it did not prove implementation behavior or installation inside ChatGPT or Claude.

Inspect the catalog and endpoint details →
Inspect snapshot JSON →

Declared values, counted from the snapshot

readOnlyHint: true
124 / 124
destructiveHint: false
124 / 124
openWorldHint: false
124 / 124
idempotentHint: true
91
idempotentHint: false
11
idempotentHint omitted
22

All 124 tools declare read-only behavior, so destructive and idempotent hints are not applicable to their effective interpretation. The 22 omitted idempotent hints are not negative findings. “Closed world” does not establish that a server makes no network requests.

Questions before you connect

Does readOnlyHint mean a tool is safe?

No. It is a server declaration about modification behavior. Check the operator, data access, authorization, and actual implementation separately. This checker cannot certify those properties.

Is openWorldHint false proof of no network access?

No. A closed set of entities can still be accessed over a network. Treat the hint as scope metadata; use server documentation and implementation checks to establish network behavior.

Why do read-only tools show N/A for destructive and idempotent hints?

Those hints describe effects of tools that modify their environment. The checker keeps any declared values in the report, while marking their effective interpretation as not applicable for read-only tools.

Can I check a paginated response or an empty tool list?

Yes. An empty array is valid. If the supplied envelope includes nextCursor, the report warns that the inventory may be partial. Obtain the remaining pages with your MCP client; this page does not fetch them.

Are my JSON file and report stored anywhere?

The checker holds them in page memory. Use Clear input for the single-inventory workspace and Clear comparison for both release inventories, or close the tab. A downloaded report is a file on your device; clearing the page does not delete that file. Analytics follow the site's separate consent setting and do not receive checker input.

Sources and review

Annotation behavior follows the MCP specification dated 28 July 2026. Source review: 11 October 2026. Michael Lip maintains this checker and the ToolRoutine catalog.

Automated browser checks on 11 October 2026 covered missing and invalid hints, read-only interpretation, file import, report downloads, malicious tool names, mobile controls, and input privacy before and after analytics consent. These checks test the checker; they do not test the behavior of your MCP server.

Discuss a scoped build through custom MCP products. Find Michael on GitHub, or support his work through GitHub Sponsors. Sponsorship does not buy a custom project.