mcp-tools
v0.5.0Two MCP audits. audit scores the tool definitions of a server you build against MCP-specification, Anthropic tool-design, and Claude-Code client criteria in a per-tool PASS/WARN/FAIL scorecard (Python, TypeScript, .NET). audit-posture inventories the MCP servers your Claude Code configuration runs and flags supply-chain risks such as floating package versions, without running any server.
By Melodic SoftwareLicense: MIT20 GitHub starsUpdated 59 minutes ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 2 skill or MCP entries
- Source updated
- Sep 28, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install mcp-tools for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install mcp-tools@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/melodic-software/claude-code-pluginsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/mcp-tools/.
Plugin files
├── .claude-plugin/plugin.json├── skills/audit/SKILL.md└── skills/audit-posture/SKILL.md
Included Skills2
Audit MCP server tool definitions against design quality criteria. Use when: 'audit MCP tools', 'check MCP tool descriptions', 'review MCP server quality', 'tool annotations', 'readOnlyHint missing', 'parameter descriptions missing', 'check the _meta annotations', 'maxResultSizeChars', 'requiresUserInteraction', 'alwaysLoad', 'are my server instructions too long', 'mcp audit', or before shipping MCP server changes. Optional path argument targets a single server directory; omit to audit the whole project. Produces per-tool PASS/WARN/FAIL scorecard covering description completeness, parameters, naming, annotations, and the Claude Code `_meta` annotations, plus a server-level result for the server `instructions` size budget. Language-agnostic: Python (`mcp`), TypeScript, .NET. Not for: whether configured MCP servers are safe to run (/mcp-tools:audit-posture), or MCP config correctness and connection issues (/claude-config:audit).
Audit the MCP servers configured in Claude Code for supply-chain posture, meaning whether each one is safe to run. Use when: 'is it safe to run my MCP servers', 'mcp supply chain', 'floating MCP versions', 'npx @latest MCP', 'MCP server inventory', 'mcp posture', 'unpinned MCP server', 'which MCP servers run on my host'. Reads user, local, project, managed, and passed-in config statically through a bundled inventory script and returns a dated, diffable inventory (scope, transport, launcher, package, pin state, publisher, sandboxed) with P1-P5 findings: floating versions, local stdio where a remote endpoint exists, publisher provenance, OCI image available but unused. Never runs, installs, or connects to a server and never prints env or header values. Optional arguments add config files, such as a plugin's .mcp.json. Not for: tool definition design quality (/mcp-tools:audit), or config correctness, enablement, and permissions (/claude-config:audit).
Plugin manifests1
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "mcp-tools",
"version": "0.5.0",
"description": "Two MCP audits. audit scores the tool definitions of a server you build against MCP-specification, Anthropic tool-design, and Claude-Code client criteria in a per-tool PASS/WARN/FAIL scorecard (Python, TypeScript, .NET). audit-posture inventories the MCP servers your Claude Code configuration runs and flags supply-chain risks such as floating package versions, without running any server.",
"author": {
"name": "Melodic Software",
"email": "[email protected]"
},
"license": "MIT",
"keywords": [
"mcp",
"tools",
"audit",
"quality",
"scorecard",
"skill"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[mcp-tools on Agent Plugins Marketplace](https://pluginsmp.com/plugins/mcp-tools)