Paste an MCP manifest (the JSON your client gets back from tools/list) or a single
tool description. The inspector flags tool poisoning, instruction smuggling, Unicode tag-character abuse,
wide-open parameter schemas, and confused-deputy patterns. All checks run in your browser.
additionalProperties: true and no required fields.[harmless click here](javascript:dangerous) or [docs](data:text/html;base64,โฆ).tools/list output and alert on change.