Free tool · data by Fathom Layer

MCP Stack Check

Agents reach your systems through MCP servers. Paste the ones your team uses and see, for each, the known vulnerabilities that Fathom Layer found in OSV.dev for the version listed in the official MCP Registry.

One per line: the official MCP Registry name, the npm/PyPI package, or the GitHub repository. Up to 25. Nothing you paste is stored.

A public list shows known flaws. Your setup decides the risk.

Which servers your agents can call, with what permissions and on which data is what turns a known vulnerability into exposure. The AI-Ready Diagnosis is where we map your case.