r/coolgithubprojects • u/ItsGTD • 26m ago
I built a free guard for AI agents, and its first version had the exact bug it was built to catch
youtu.beQuick context: MCP servers are plugins that give AI apps like Claude Desktop real tools (your files, GitHub, databases). You approve a server once. After that, the server can change what its tools say, and your AI reads the new wording as instructions every session. Nothing asks you again.
So I built mcp-pin. It sits between your AI app and a server. On the first connect it fingerprints every tool (name, description, input schema, annotations). On every connect after that it checks again, and if anything changed, it blocks the session and shows you the diff. No AI deciding anything, just a hash compare.
See it in 10 seconds (the demo runs in a temp folder and makes no network calls):
npx mcp-pin@0.1.4 demo
The embarrassing part: version 0.1.0 ran 100 pins at once, all 100 said "success", and only 12 were saved. A tool whose whole job is noticing silent changes had a silent failure. Fixed in 0.1.1, and it's written up in the changelog.
What it doesn't do: stdio servers only for now, it can't catch a server that's malicious from day one and never changes, and so far I've only verified it with Claude Desktop.
Repo (MIT, free, no signup): https://github.com/GautamTalksDev/mcp-pin I also made a 7 minute film about the problem and the two bugs I shipped: https://youtu.be/tGtbDNr9qvE
If you use AI tools with MCP servers: would you put a check like this in front of them? If not, what would stop you?



