mcp-review

Assess MCP server.json submissions for compliance, security, and registry suitability.

21|28|Updated Aug 11, 2025
One-click install
npx skills add https://github.com/stacklok/toolhive-catalog --skill mcp-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mcp-review
Source: https://github.com/stacklok/toolhive-catalog/tree/main/.claude/skills/mcp-review
Command: npx skills add https://github.com/stacklok/toolhive-catalog --skill mcp-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This MCP Review skill provides structured guidance to evaluate MCP server.json submissions for compliance, security, and quality, ensuring submissions meet ToolHive registry standards and avoid incorrect entries.

Core Features & Use Cases

  • Review server.json for namespace, required fields, and extension alignment with the identifier.
  • Assess PR submissions for MCP server entries against registry criteria and provide actionable feedback.
  • Clarify acceptance criteria and provide security and provenance considerations for entrants.
  • Use cases include reviewing new server submissions, updating existing registries, or auditing server configurations.

Quick Start

Provide a concise, formal review of a server.json submission focusing on compliance and security.

Frequently Asked Questions about mcp-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a server.json submission for MCP registry compliance?

Reviewing a server.json submission for MCP registry compliance involves checking required fields, extension-key matching against the identifier, namespace alignment, tier consistency, provenance presence, and documentation quality to meet ToolHive standards.

What security and provenance checks are needed for MCP server entries?

Security and provenance checks for MCP server entries involve verifying provenance presence, assessing security considerations, and ensuring the submission meets registry criteria for acceptance.

How do I audit existing MCP server configurations for ToolHive registry quality?

Auditing existing MCP server configurations for ToolHive registry quality requires evaluating server.json files against compliance criteria, checking namespace and extension alignment, and verifying tier consistency and documentation standards.

Does the MCP review process enforce namespace and extension-key matching for server submissions?

Yes, the MCP review process enforces namespace alignment and extension-key matching against the identifier to ensure server.json submissions maintain consistency across the ToolHive registry.

What are the acceptance criteria for new MCP server entries in the ToolHive registry?

Acceptance criteria for new MCP server entries in the ToolHive registry include required fields, correct extension-key matching, tier consistency, provenance presence, and sufficient documentation quality to pass compliance and security assessment.

Can I use this approach to evaluate PR updates for MCP server entries?

Yes, you can evaluate PR updates for MCP server entries by assessing changes against registry compliance criteria, checking namespace and extension alignment, and providing actionable feedback on security and provenance.