Developer builds deliberately broken MCP server to test contract verification tools
A developer created 'mcp-worse', an intentionally deceptive Model Context Protocol server designed to violate documented API contracts by reversing tool order and omitting cache metadata. The project was built to demonstrate a core problem: MCP servers can claim statelessness, cacheable lists, and stable tool ordering without the protocol enforcing any of it. To validate a contract-checking tool called 'contrast-smoke', the developer needed a real binary that reliably fails in specific, predictable ways rather than a hypothetical scenario. The contrast-smoke test spawns both the honest server and the lying one as actual processes, inspects live wire traffic, and only exits successfully if the good server passes and the bad one fails. The project, published on GitHub, is labeled as a teaching tool and is not intended for production or registry deployment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in