Inspect before connecting
MCP tool annotations checker
Check server-declared MCP hints locally, then compare two tools/list inventories to distinguish added tools, changed hints, and unchanged defaults. Annotations are declarations, not permission enforcement. Paste one response for a current review, or compare before and after snapshots to see inventory changes, annotation coverage, and read-only applicability.
01 / Add tool metadata
Check the hints.
Up to 1 MiB of UTF-8 JSON and 1,000 tools. Accepts result.tools, a {"tools": [...]} object, or a tool array. Never paste credentials. Tool names must be non-empty and unique within the response.
Load a sample or paste your tools/list response.
02 / Review declared behavior
Hints, defaults, and gaps.
0 tools have at least one omitted hint. Optional omissions are not errors. These counts are not a safety score.
The export includes every checked tool, declared and effective values, defaults, invalid-value notes, and the check time. Filtering does not change the download. It omits descriptions, schemas, and unrelated response fields.
Release review / Compare two inventories
What changed since your last snapshot?
A new tool and a changed annotation need different review. Match exact tool names across a before and after inventory. Track declared values, default or invalid origins, and read-only applicability separately.
Each inventory has the same 1 MiB / 1,000-tool limits and accepted JSON shapes as the single-inventory checker. An empty before field means an empty baseline. Names match exactly; a rename counts as a removal and an addition. For multiple servers, use names such as serverSlug/toolName.
Choose the synthetic example, load the real release snapshots, or add your own inventories.
How to read a changed hint
- Default → declared: An omitted
openWorldHintand an explicittruehave the same effective value, but different coverage. The comparison reports that distinction. - Read-only applicability: A
readOnlyHintflip can move destructive and idempotent hints into or out of N/A without changing their declared values. - Declarations while N/A: Changing an idempotent declaration on a read-only tool remains visible as a declared-value change; it does not change its N/A interpretation.
- Invalid values: Missing and invalid origins remain distinct. Invalid raw values are not compared or exported; two different malformed values with the same invalid origin do not produce a new event.
Release review / Read the delta
Inventory and hint changes.
0 declared-value changes · 0 coverage/origin changes · 0 effective-value changes · 0 applicability changes. One changed hint can affect several dimensions.
The complete export includes both reviewed inventories, every change event, all count dimensions, origins, N/A states, check time, and warnings. Filters affect the table only. Raw invalid flag values, descriptions, schemas, and unrelated JSON fields are excluded.
An observed release delta
More tools. Stable retained declarations.
Two independently dated captures cover 46 → 55 first-party endpoints and 97 → 124 functions. The qualified-name comparison finds 9 additional observed endpoints, 27 added functions, 97 retained functions, and 0 removals.
Among the 97 retained functions, 0 have changed annotation values, origins, or applicability. Expanded observation scope explains the additional functions; it does not establish that existing server behavior or permissions changed.
The real sample uses serverSlug/toolName to prevent cross-server name collisions. Your ordinary one-server responses keep their original names.
Capture provenance
- Baseline report time
- Current fetch started
- Current observations ended
- Changed retained tools
- 0 / 97
The baseline time is its source report timestamp; the current time marks fetch start. Individual endpoint observations and SHA-256 source hashes are in the linked JSON. Captures used anonymous metadata discovery with no tools/call, credentials, or host installation checks. These are server declarations from a selected first-party collection.
Capture inventories for a comparison.
Export a complete tools/list response from your MCP client. Save one before a release and another after it, then load those files in the comparison above. Use the same server and observation scope; a wider capture can explain added tools without a server change.
For an anonymous HTTPS Streamable HTTP endpoint, download our local metadata collector. With Node.js 22 or later, run it from your terminal, replacing the example address with your endpoint.
node collect-mcp-tools.mjs --server https://your-server.example/mcp > before.jsonRepeat after the release, changing before.json to after.json. The script contacts your chosen server to initialize a session and collect every tools/list page. It never invokes tools/call or uploads the captured inventory to ToolRoutine.
It sends no authentication headers or cookies, rejects embedded credentials and query strings, and stops for repeated cursors, duplicate names, HTTP failures, or incomplete pagination. It exports at most 1,000 tools and 1 MiB. Authenticated endpoints, legacy SSE transports, and local stdio servers need your existing MCP client.
On 11 October 2026, this collector retrieved the JSON Diff endpoint's inventory anonymously. Protocol, pagination, malformed-response, and output-bound tests are separate from the browser checker's privacy tests. Metadata collection does not test tool behavior.
Method and boundaries
How we interpret the hints.
Annotations describe behavior; they do not manage permissions. The checker does not run tools, validate inputSchema, inspect server code, or test network access. Use the result to ask better questions before connecting a server.
Only JSON booleans count as declared hints. A string such as "true", a number, or null is invalid. This checker applies a conservative fallback and labels it invalid; the specification does not define malformed values as valid defaults. Missing hints are labeled “default”; they are optional, not a failed check.
| Annotation | Default | How to read it |
|---|---|---|
readOnlyHint | false | Assume the tool may modify its environment. |
destructiveHint | true | For a tool that may write, assume changes could be destructive. |
idempotentHint | false | For a tool that may write, do not assume repeating the call has the same effect. |
openWorldHint | true | Assume the tool may interact with an open set of external entities. |
When readOnlyHint is true, destructive and idempotent hints are marked N/A. Their declared values remain visible; the checker does not call them contradictions.
First-party metadata snapshot
What our 124 tool declarations say.
On , saved MCP discovery metadata covered 124 functions across 55 ToolRoutine catalog endpoints. The “Load 124 catalog tools” button uses those saved names and annotations, embedded in this page. It makes no live endpoint requests.
Our catalog is a first-party snapshot, not a representative survey of MCP servers. Discovery captured declarations; it did not prove implementation behavior or installation inside ChatGPT or Claude.
Inspect the catalog and endpoint details →Inspect snapshot JSON →
Declared values, counted from the snapshot
- readOnlyHint: true
- 124 / 124
- destructiveHint: false
- 124 / 124
- openWorldHint: false
- 124 / 124
- idempotentHint: true
- 91
- idempotentHint: false
- 11
- idempotentHint omitted
- 22
All 124 tools declare read-only behavior, so destructive and idempotent hints are not applicable to their effective interpretation. The 22 omitted idempotent hints are not negative findings. “Closed world” does not establish that a server makes no network requests.
Questions before you connect
Does readOnlyHint mean a tool is safe?
No. It is a server declaration about modification behavior. Check the operator, data access, authorization, and actual implementation separately. This checker cannot certify those properties.
Is openWorldHint false proof of no network access?
No. A closed set of entities can still be accessed over a network. Treat the hint as scope metadata; use server documentation and implementation checks to establish network behavior.
Why do read-only tools show N/A for destructive and idempotent hints?
Those hints describe effects of tools that modify their environment. The checker keeps any declared values in the report, while marking their effective interpretation as not applicable for read-only tools.
Can I check a paginated response or an empty tool list?
Yes. An empty array is valid. If the supplied envelope includes nextCursor, the report warns that the inventory may be partial. Obtain the remaining pages with your MCP client; this page does not fetch them.
Are my JSON file and report stored anywhere?
The checker holds them in page memory. Use Clear input for the single-inventory workspace and Clear comparison for both release inventories, or close the tab. A downloaded report is a file on your device; clearing the page does not delete that file. Analytics follow the site's separate consent setting and do not receive checker input.
Sources and review
Annotation behavior follows the MCP specification dated 28 July 2026. Source review: 11 October 2026. Michael Lip maintains this checker and the ToolRoutine catalog.
Automated browser checks on 11 October 2026 covered missing and invalid hints, read-only interpretation, file import, report downloads, malicious tool names, mobile controls, and input privacy before and after analytics consent. These checks test the checker; they do not test the behavior of your MCP server.
- MCP specification: ToolAnnotations schema ↗
- MCP specification: tools and discovery ↗
- MCP maintainers: Understanding Tool Annotations ↗
- MDN: browser File API ↗ · Blob downloads ↗
Discuss a scoped build through custom MCP products. Find Michael on GitHub, or support his work through GitHub Sponsors. Sponsorship does not buy a custom project.