Free · Runs in your browser · Rubric v1.0

MCP App Safety Checker

MCP Apps (SEP-1865) let a tool return an interactive HTML surface that the host runs in a sandboxed iframe. Paste your ui:// resource and its metadata to check it against the spec and for the security hygiene the sandbox alone does not give you. Static analysis only; nothing you paste leaves your browser.

What it checks

Spec conformance

  • UI resource uses the ui:// scheme
  • mimeType is exactly text/html;profile=mcp-app
  • Tool links its UI through _meta.ui.resourceUri
  • A text fallback exists for non-apps hosts
  • visibility uses only model / app
  • External origins are declared in _meta.ui.csp

Security hygiene

  • No unsafe DOM sinks (eval, innerHTML, document.write)
  • No secrets embedded in the shipped HTML
  • Host messages validate their origin
  • App ships its own code, no remote scripts
  • No wildcard connect origins in the CSP

FAQ

What is an MCP App?

MCP Apps (SEP-1865) is the first official Model Context Protocol extension, stable since 26 January 2026. It lets a tool return an interactive HTML interface instead of only text or JSON. The UI is declared as a ui:// resource with mimeType text/html;profile=mcp-app, and the host renders it in a sandboxed iframe in Claude, ChatGPT, VS Code, Goose, and other apps-aware hosts.

What does this checker look at?

Two groups of checks. Spec conformance: the ui:// resource scheme, the exact mimeType, the tool-to-UI link via _meta.ui.resourceUri, a text fallback for non-apps hosts, valid visibility values, and whether external origins in your HTML are declared in _meta.ui.csp. Security hygiene: unsafe DOM sinks (eval, innerHTML, document.write), embedded secrets, host-message handling, and remote scripts. These are the parts the iframe sandbox alone does not protect you from.

Does my code get uploaded anywhere?

No. The analysis runs entirely in your browser on the text you paste. Nothing is sent to Sigistry or anywhere else. This is static, heuristic analysis of source, not a live probe of a running server.

Why does the iframe sandbox not make my app safe?

The sandbox limits what the iframe can reach, but it does not stop your own code from mishandling data. Your app renders tool output and host messages; if any of that reaches the DOM through innerHTML or eval, it is a stored-XSS path inside the app. The host enforces a CSP built only from the domains you declare, so an undeclared fetch breaks at runtime. The sandbox is the floor, not the ceiling.

What should I paste?

Paste the HTML of your ui:// resource in the first box. In the second box, paste the JSON for the resource declaration and the tool that links to it (the object with _meta.ui). The metadata is optional, but without it the scheme, mimeType, linkage, and CSP checks cannot run.