CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
mcp-observatory is worth checking the docs before setup with strong trust signals. Check agent compatibility and use-case fit before adding it to your workflow.
gh repo view KryptosAI/mcp-observatory --webOpen the official README and confirm the supported install method.
Add the server entry to your MCP client config.
Restart your agent and verify that the server tools appear.
Repository setup guidance
Looks usable, but maintenance, license, or security notes deserve a closer look.
Last commit was about 24 days ago.
176 GitHub stars indicate community interest.
43 open issues signal maintenance load.
MIT license detected.
1 security/trust notes recorded.
Setup difficulty is 3/5.
Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch.
Browser automation CLI built for AI agents — breaks anti-bot walls, supports multi-session parallel execution.
First open-source testing agent — handles UI, API, Security, Accessibility, and Visual validations without writing code.
Fast native binary CDP-powered browser automation CLI with 63 commands — screenshots, accessibility, visual diffing, test generation.
<p align="center"> <img src="docs/assets/mcp-observatory-logo.png" alt="MCP Observatory" width="482"/> </p> <h1 align="center">MCP Observatory</h1> [](https://github.com/KryptosAI/mcp-observatory/actions/workflows/ci.yml) [](https://github.com/KryptosAI/mcp-observatory/actions/workflows/codeql.yml) [![Coverage Work
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
176
Stars
21
Forks
43
Issues
MIT
License
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
Developers
The setup section provides repository-level starting guidance, not a guarantee of an independently verified installation. Check the official README and release notes.
Run security tests only against MCP servers you are authorized to assess and review test permissions first.
Similar or complementary options to evaluate include bug-hunter, Browser Act Skills, TestZeus Hercules.
Aug 20, 2026