Env Contract MCP server
Local value-free environment contract and configuration drift inspection. Tools include inspect...
A85/100grade A
Adoption
New
0 stars
Reviews
Write oneNobody has reviewed Env Contract yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Env Contract tools (1)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
inspect_contractInspect a local project for declared and referenced environment variable names without reading values.
Public scan report
scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it
no findings
- Code scan8 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 44 days ago12/15
- Maintainer identityregistry namespace matches repository owner6/10
Overall 85/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
Runs npx -y env-contract-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add env-contract-mcp -- npx -y env-contract-mcp
Env Contract: common questions
- Is Env Contract MCP server safe?
- Yes, by our scan: it is graded A (85/100). Read the Env Contract safety report
- How do I install Env Contract?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Env Contract need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Env Contract maintained?
- The last commit was 45 days ago (2026-08-09). The latest release is v1.0.1.