Prove an MCP server is safe for your agents: passmcp check runs 131 checks in nine phases against a live server, ties every finding to the request that showed it, and writes a signed attestation anyone can verify offline.
Fleets: passmcp fleet run checks every server in a fleet file on a schedule, attests each one, and fails on critical drift, such as a tool that stops claiming to be read-only.
Compliance evidence: every check maps to SOC 2, ISO/IEC 27001 Annex A and GDPR controls, and passmcp evidence turns attestations into the table an auditor asks for.
Agents and SIEMs: passmcp a2a check verifies A2A Agent Cards and their signatures, and --ocsf-endpoint sends findings as OCSF events to the collector you run.