Openapi Security Contract Lint runs on your own machine — the client starts it, so there is no endpoint to ping.
Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th
Today is the operative word: we check Openapi Security Contract Lint every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add openapi-security-contract-lint -- npx -y @readystack/openapi-security-contract-lint
{
"mcpServers": {
"openapi-security-contract-lint": {
"args": [
"-y",
"@readystack/openapi-security-contract-lint"
],
"command": "npx"
}
}
}
[mcp_servers.openapi-security-contract-lint]
command = "npx"
args = ["-y", "@readystack/openapi-security-contract-lint"]
{
"mcpServers": {
"openapi-security-contract-lint": {
"args": [
"-y",
"@readystack/openapi-security-contract-lint"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"openapi-security-contract-lint": {
"args": [
"-y",
"@readystack/openapi-security-contract-lint"
],
"command": "npx"
}
}
}
Names every line in the file you have open that starts a recurring cloud charge, with the published
GitHub MCP — wraps the GitHub public REST API (no auth required for public endpoints)
Finds the money lines that send the wrong amount to a payment API: the x100 that charges 100x in JPY
Names every schedule line in the file you have open that fires at the wrong hour, twice, or never at
MCP server (stdio): lint OpenAPI specs with Spectral via the AgentForge API
Finds the lines KSeF will reject in a Polish structured invoice XML, before you send it
Marks the lines in your test suite that current pytest no longer runs — and the config keys it silen
Finds the 12 author-side privacy duties your plugin PHP breaks, with the article and the fix on ever
Answers built from our own checks of this server.