MCP server · Security
Small Print MCP server
by gostanos
Check what changed in an MCP server, skill or plugin before you trust or update it.

Small Print keeps a public record of the descriptions, schemas and instructions inside MCP servers, agent skills and plugins. It saves a fingerprint of each version and shows what changed between them, with each change graded by a written rule. This helper lets your AI look that record up for you, so you can see if something you rely on has quietly changed.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to a service. This one connects your AI to Small Print, the public record of what is inside MCP servers, skills and plugins. Once it is connected, you can ask your AI about a specific tool and it will go read the record for you.
What this MCP server does
You ask your AI something like whether a tool changed since you last checked it. Your AI passes that question to this helper. The helper reads the public Small Print record at smallprint.dev and nothing else. It comes back with the entry, the changes between versions, the grade for each change, or any public advisories tied to that version. Your AI then explains the answer to you in the chat.
Click to zoomWhat you can do with it
- Look up what the Small Print record holds for one tool or skill
- See which versions changed the small print and what the change was
- Filter changes by how serious the grade is
- Find public advisories that name a tool, with version ranges
- Check whether something changed since the version you reviewed
- Get a plain UNCHANGED, CHANGED or UNKNOWN answer before you use a tool
Try asking your AI
- “Has the small print for npm:some-package changed since version 1.4.2?”
- “Show me the changes to mcp-registry:io.github.owner/server since last month, only serious ones”
- “Are there any advisories for pypi:some-library at version 2.0.1?”
- “I approved skills.sh:owner/repo/skill at this content hash. Has it changed since?”
What it gives back to you
You get answers in the chat, not files. For a lookup, your AI shows what the record holds for that entry. For a change check, it lists the versions and the diffs, with the rule behind each grade. For advisories, it lists them with their sources and version ranges. The approval check answers with a single word first: UNCHANGED, CHANGED or UNKNOWN.
Before you start
What you need
- An AI app that can use MCP servers, like the Claude desktop app
- Node.js installed on your computer (the npx command needs it)
- The name of the tool, skill or plugin you want to check
Good to know
This server only reads the public record; it does not change anything, but it also does not prove a tool is safe, it just shows you what the record says.
Install it with your AI
Add Small Print MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check Small Print MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
People who review or approve MCP servers, skills and plugins before their team uses them, and anyone who wants to know when a tool they rely on quietly changes.





