MCPcatSAFE
AgentCat is an analytics platform for MCP server owners 🐱.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Getting Started · Features · Docs · Website · Open Source · Schedule a Demo
[!NOTE] AgentCat v2 introduces compatibility with the MCP Protocol "Stateless" 2026-07-28 Update and the coinciding MCP TypeScript SDK v2 release that puts it into effect. The stateless transition has a massive impact on analytics, as sessions were a built-in concept tying related tool calls together. AgentCat has now migrated its ses
be4f1e07912bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agentcat --env DD_API_KEY=${DD_API_KEY} --env DIAGNOSTICS_TOKEN=${DIAGNOSTICS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"agentcat": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DD_API_KEY": "${DD_API_KEY}",
"DIAGNOSTICS_TOKEN": "${DIAGNOSTICS_TOKEN}"
}
}
}
}Exposed tools (62)
55 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | |
add_note | write | |
add_todo | write | Add a new todo item |
add_with_desc | write | Adds two numbers |
bare | read | no schema |
big | read | big |
bigint | read | b |
boom | read | |
calculate | read | |
calculator_add | write | |
claims_key | read | already declares the key |
complete_todo | read | |
composed | read | composed |
echo | read | Echo a message back |
either | read | composed output |
error_result | read | isError result |
error_with_cause | read | Throws error with cause |
existing_tool | read | A tool with existing schema |
explode | read | |
get_annotated_screenshot | read | Returns a screenshot with annotations |
get_attachment | read | Returns an image attachment |
get_audio_clip | read | Returns an audio clip |
get_large_report | read | Returns a large report |
get_more_tools | read | customer version |
get_stats | read | |
get_todo_screenshot | read | Returns a screenshot of todos |
get_verbose_log | read | Returns a huge log dump |
greet | read | |
initial_tool | read | |
late_explode | read | |
late_loose | read | |
late_tool | read | |
leaky | read | |
list_todos | read | List all todo items |
loose | read | |
my_tool | read | Does something useful |
new_tool_after_track | read | A tool added after track() was called |
noop | read | |
optional_tool | read | A tool with no required fields |
own_handles | read | declares its own |
poison | read | p |
poly | read | composed output schema |
post_track_tool | write | A tool added after tracking was enabled |
process_bulk_data | read | Processes a bulk data payload |
recursive | read | r |
secret_echo | read | echoes |
simple_tool | read | A simple tool |
slow_echo | read | echoes slowly |
stats | read | returns stats |
still_works | read | fixed reply |
strict | read | |
structured | read | |
structured_only | read | structured-only reply |
test_context_removal | read | Test tool that captures callback arguments |
test_tool | read | |
throw_string | read | Throws string |
throws | read | throws |
token_probe | read | fixed reply |
tool_with_context | read | A tool that already has context |
type_error_tool | read | Throws TypeError |
union_tool | read | takes one of two shapes |
upload_file | write | Upload a file as base64 |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
const SECRET = "TOP_SECRET_PAYLOAD_abc123";
.prettierignore
diagnostics-no-payload.test.ts
import packageJson from "../../package.json" with { type: "json" };import { Event, Exporter } from "../../types.js";import { Event, Exporter } from "../../types.js";import { Event, Exporter } from "../../types.js";import KSUID from "../../thirdparty/ksuid/index.js";
it("logs a shape-fingerprint beacon when rejecting an unrecognized server shape", () => {const beacon = messages.find((m: string) =>
expect(beacon).toBeDefined();
expect(beacon).toContain("hasServerProp");expect(beacon).toContain(SUPPORT_MATRIX_SUFFIX);
return { httpServer, baseUrl: `http://127.0.0.1:${port}/mcp` };new URL(`http://127.0.0.1:${port}/mcp`),const baseUrl = `http://127.0.0.1:${port}/mcp`;req: new Request("http://127.0.0.1:4105/mcp", {expect(extra.http.req.url).toBe("http://127.0.0.1:4105/mcp");@cloudflare/vitest-pool-workers, @cloudflare/workers-types, @modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/sdk, @modelcontextprotocol/server, @types/node, @types/uuid
docs/cats/bibi.png
docs/cats/void.jpg
Gates applied: no_behavioural_pass.
be4f1e07912bfull audit observations/trust-audit/mcp-server/mcpcat__mcpcat-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | be4f1e07912b | SAFE | B | 87 | first audit |
Questions
What is the MCPcat MCP server?
AgentCat is an analytics platform for MCP server owners 🐱.
What tools does MCPcat expose?
62 in total: 55 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MCPcat safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does MCPcat need?
It reads DD_API_KEY and DIAGNOSTICS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MCPcat run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as agentcat at 2.1.1.
How current is this page?
The grade is for one exact copy of the source (be4f1e07912b), read on 2026-10-07. The repository is watched and re-audited when it changes.