Agent infrastructure / release checks

MCP Server Validator.

Check whether an agent-facing service exposes the contracts another system actually needs to discover and use it. The validator focuses on MCP, A2A, Agent Card and OpenAPI surfaces.

The validator checks declared machine-readable surfaces and reports missing or inconsistent release requirements. It is a preflight tool, not a substitute for penetration testing or runtime security review.

Public utilityApify

Run the tool

The current public runtime is distributed through Apify, with API access for automated workflows.

Open on Apify ↗
Common tasks04

Where it fits

  • MCP server preflight
  • A2A Agent Card checks
  • OpenAPI contract review
  • CI release gates

The boundary of the tool matters as much as the result. These are the assumptions we do not hide.

Is this a security audit?

No. It checks release and interoperability contracts, not the full security posture of a deployed service.

Can it run in CI?

Yes. The output is structured so it can sit before deployment or publication.

Does it require one agent framework?

No. The checks are organised around MCP, A2A and OpenAPI contracts rather than one orchestration framework.

The utilities share a preference for explicit inputs, visible unknowns and machine-readable output.