
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@rixtay/mcp-usage
Advanced tools
Find out which of your MCP servers you actually use. Local, read-only audit of Claude Code transcripts: used, unused, failing and needs-auth servers.
A small, focused MCP server and CLI that reads your local Claude Code transcripts and tells you, for every MCP server you have connected, whether it is actually used, sits idle in every session, fails to connect, or has been waiting for authorization for weeks — and what to disconnect.
Built for one job: answer "which of my MCP servers should I keep?" — locally, read-only, without ever exposing a word of your conversations.
Four tools, all read-only:
| Tool | What it does |
|---|---|
usage_summary | One row per server: status, tools exposed, sessions, calls, error rate, estimated result tokens, last use |
unused_servers | Servers that were connected but never called, failed to connect, or are waiting for authorization |
server_details | One server in full, with per-tool calls, errors and result size (accepts the id or the label, case-insensitive) |
recommendations | A prioritized action list: disconnect, fix or remove, authorize or remove, investigate errors, heavy results |
Design choices:
SECRET_* markers everywhere private content lives in a real transcript, and the tests assert none of them reach the library, the CLI or the MCP output.JSON.parse: ~360 MB of history (including a 90 MB session) scans in about 3 seconds.readOnlyHint, idempotentHint) so hosts can auto-approve them.No install needed, npx fetches the package from npm (@rixtay/mcp-usage, the installed command is mcp-usage):
npx -y @rixtay/mcp-usage
Or from a clone:
git clone https://github.com/Rixtayz/mcp-usage.git
cd mcp-usage
npm install && npm run build
node dist/bin/cli.js
| Option | Purpose |
|---|---|
--since <days> | Look back this many days (default 30) |
--project <path> | Only scan projects whose path contains this text |
--min-sessions <n> | Sessions before an unused server is flagged (default 5) |
--dir <path> | Claude config directory (default: $CLAUDE_CONFIG_DIR or ~/.claude) |
--json | Print the full report as JSON, including per-tool stats |
Text output truncates long lists; --json always contains everything.
claude mcp add --scope user --transport stdio mcp-usage -- npx -y @rixtay/mcp-usage serve
Edit ~/Library/Application Support/Claude/claude_desktop_config.json on macOS (or %APPDATA%\Claude\claude_desktop_config.json on Windows), reachable through Settings → Developer → Edit Config.
{
"mcpServers": {
"mcp-usage": {
"command": "npx",
"args": ["-y", "@rixtay/mcp-usage", "serve"]
}
}
}
If the host cannot find npx (it may not inherit your shell PATH), use absolute paths instead: "command": "/absolute/path/to/node", "args": ["/absolute/path/to/mcp-usage/dist/bin/cli.js", "serve"].
The server reads Claude Code's transcripts wherever it runs, so it only makes sense in local sessions, on the machine where you use Claude Code.
Typical flow: recommendations → the assistant proposes a cleanup list, you confirm → server_details on anything surprising → you disconnect the servers yourself. The tools never touch your MCP configuration.
Each server gets one status:
| Status | Meaning |
|---|---|
used | Called at least once in the window |
unused | Its tools were available, but nothing ever called them |
failed | Never exposed a tool; Claude Code reported a connection failure |
needs-auth | Never exposed a tool; waiting for authorization |
Recommendations, in priority order:
| Action | Rule |
|---|---|
disconnect | Unused, and available in ≥ 5 sessions (--min-sessions) |
fix-or-remove | Failed to connect in ≥ 3 sessions |
authorize-or-remove | Waiting for authorization in ≥ 3 sessions |
investigate-errors | ≥ 5 calls and ≥ 30 % of them failed |
heavy-results | Results average ≥ 10,000 estimated tokens per call |
npm test # vitest: name parsing, streaming parser, aggregation, rules, CLI, MCP tools over an in-memory transport
npm run typecheck
npm run inspect # MCP Inspector against the built server
Layout:
src/bin/cli.ts entry point: `mcp-usage` prints the report, `mcp-usage serve` serves stdio
src/cli.ts argument parsing and output
src/server.ts builds the McpServer and registers the four tools
src/analyze.ts options → report; the one function both shells call
src/parser.ts streaming JSONL reader → typed events
src/aggregate.ts events → per-server stats
src/recommend.ts stats → prioritized recommendations
src/report.ts text table rendering
src/scan.ts transcript discovery (--since, --project)
src/adapters/claude-code.ts the only client-specific code, behind a small ClientAdapter interface
src/names.ts `mcp__<server>__<tool>` parsing and server id mangling
Stack: @modelcontextprotocol/sdk v1, zod v4, nothing else at runtime. Design notes: docs/DESIGN.md.
__ after the mcp__ prefix. Server ids can contain underscores, hyphens, dots or be a bare UUID, and tool names can contain __ themselves, so a naive split("__") miscounts.ccd_*) are reported but never flagged for disconnection: you cannot remove them.--since window only sees what is still on disk.Bug reports, fixes and adapters for other MCP clients are welcome: see CONTRIBUTING.md. If Claude Code updates and the report suddenly looks wrong, open a bug with your Claude Code version. Found a way the tool could leak transcript content? Please report it privately, as described in SECURITY.md.
Release history: CHANGELOG.md.
MIT
FAQs
Find out which of your MCP servers you actually use. Local, read-only audit of Claude Code transcripts: used, unused, failing and needs-auth servers.
The npm package @rixtay/mcp-usage receives a total of 91 weekly downloads. As such, @rixtay/mcp-usage popularity was classified as not popular.
We found that @rixtay/mcp-usage demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.