vitrine - offline static auditor for MCP Apps (SEP-1865) UI resource bundles: audits server-supplied HTML against its own tool declarations (CSP egress, bridge hygiene, DOM sinks, UI mimicry)
Or install with pip: pip install dev-experiment-027
README Excerpt
**Offline static auditor for MCP Apps (SEP-1865) UI resource bundles.** MCP Apps let a server ship interactive HTML that the host renders *inside the assistant's own surface*. The spec answers "is that safe?" with a sandboxed iframe and a host-built Content-Security-Policy derived from metadata the server