EXAMPLE REVIEW SIGNALS
OPEN SOURCE / MCP SECURITY
Your MCP config did not change.
The code it resolves to might have.
MCP Drift Check is a free, MIT-licensed zero-execution CLI and GitHub Action that finds package references which can resolve to different code later even when the MCP configuration itself has not changed. v0.2.4 covers npx/npm exec, bunx/bun x, pnpm dlx and yarn dlx.
No MCP server execution. No package downloads. No API token. No signup. No telemetry. It emits visible GitHub pull-request annotations, Markdown and SARIF so the same check can run on every pull request.
RUN IT IN 10 SECONDS
Get the signal first.
Decide what deserves review.
No account, token or agent connection is required. Run it locally, then keep the same check in CI if the signal is useful.
uvx --from git+https://github.com/tomelias10/mcp-drift-check mcp-drift-check scan-workspaceInstall options - uses: actions/checkout@v4
- uses: tomelias10/mcp-drift-check@v0GitHub Action + SARIF What it means
A review signal.
Not a breach claim.
The goal is to make dependency mutability visible before a security team decides whether deeper review is warranted.
Does an unpinned MCP dependency mean it is compromised?
No. The check identifies a change and review risk, not proof of malicious code or exploitation.
Does the tool execute MCP servers?
No. It statically parses local configuration files. It does not run configured servers, download packages or contact package registries.
Does Orynval receive my configuration?
No. The CLI has no telemetry and does not upload scan data. Private triage is a separate, optional step if you want help interpreting a production finding.
Can I run it on every pull request?
Yes. v0.2.4 ships as a GitHub Action, writes a Markdown job summary, emits visible pull-request annotations in GitHub Checks, and can produce SARIF 2.1.0 for GitHub Code Scanning. HIGH mutable references can fail CI.
What problem is this trying to catch?
A configuration can remain unchanged while a mutable package selector resolves to different package code later. That can make a one-time review go stale without a visible config diff.
PRIVATE TRIAGE
Found this in a production environment?
Do not put credentials, private configs or customer data into a public GitHub issue. Tell us the problem and deadline privately; we can help determine whether it warrants a scoped review.