🧾 mcp-proof · live audit reports

Every page below is a real, unedited delivery report produced by mcp-proof — deterministic conformance, security and regression evidence for MCP servers, fingerprinted and offline-verifiable.

Third-party servers, audited as-is

SHIP-READYOfficial filesystem server @modelcontextprotocol/server-filesystem
11/11 MUST checks · 34/34 regression replays clean · 4 write tools auto-skipped by the destructive-tool guard · one advisory finding (SEC-04)
SHIP-READYOfficial "everything" reference server @modelcontextprotocol/server-everything
20/20 MUST + 7/7 SHOULD · 0 security findings across 13 tools · protocol + security lanes (recording deliberately skipped — its get-env tool dumps environment variables)
SHIP-READYOfficial memory server @modelcontextprotocol/server-memory
16/16 MUST · 4/4 replays clean · 5 write/delete tools auto-skipped · one advisory: unconstrained search_nodes.query (SEC-04)
SHIP-READYOfficial sequential-thinking server @modelcontextprotocol/server-sequential-thinking
11/11 MUST · 1/1 replays clean · one advisory (2,781-char tool description, SEC-05) · investigating its honest TOOL-08 skip exposed the served inputSchema omitting a runtime-required field

Built-in demo pair & protocol showcase

SHIP-READY2026-07-28 modern-era server
Era auto-detected via server/discover · 23/23 MUST incl. negative probes · cross-validated against the official v2 SDK
NOT SHIP-READYDemo server with 9 planted violations
5 MUST failures + 5 security findings (3 blocking, 2 advisory) — each caught with evidence and a fix hint; the remediation queue moves to the top
SHIP-READYWell-behaved demo server
18/18 MUST · full three-lane pass including a regression baseline

Also: filesystem report as PDF · architecture diagram