Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Small Print (MCP)New to Visual Studio Code? Get it now.
Small Print (MCP)

Small Print (MCP)

Small Print

| (0) | Free
Watch the MCP servers, skills and instruction files your agents use, and get a notice when what they tell your agent changes. Nothing is sent until you allow it.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Small Print (MCP) for VS Code and Cursor

Your AI agent follows the text that its MCP servers, skills and instruction files give it: tool descriptions, skill instructions, CLAUDE.md, AGENTS.md, rules. That text can change between versions without the version number saying so. This extension watches it for you and shows a notice when it changes.

Another program changed CLAUDE.md: Small Print shows the old file beside the new one, with the added line highlighted

What it watches

  • Instruction files such as CLAUDE.md, AGENTS.md, .mcp.json and Cursor and Windsurf rules. When one changes outside this editor, you get a notice and a side-by-side view of what changed. This runs entirely on your machine.
  • Skills that your agents load. When a skill's files change on disk, you get a notice. This also runs entirely on your machine.
  • MCP servers that come from a published package. Once you allow it, the extension looks each one up on the public record at smallprint.dev, a nightly record of more than 90,000 MCP servers, skills and plugins. You get a notice when a new release changes what a server tells your agent, when your machine moves to a version that did, and when a high or critical security advisory names the version you run.

Everything it finds is listed in the Small Print panel, and the status bar shows when something needs a look.

What leaves your machine

Nothing, until you allow the lookup. After that, one request per MCP server that has a package name, asking the record about that package: the package name is the only thing sent. No versions, no config values, no environment variables, no keys, no file paths and no file contents ever leave your machine. Run Small Print: Show what would be sent to see the exact requests. Set smallprint.lookup to never to keep every watch on your machine.

Settings

  • smallprint.lookup: ask (the default), allow or never.
  • smallprint.notify: high (the default) pops a notice for changed instruction files and skills, advisories, and changes graded high or critical; any for every graded change; none to only list them in the panel.
  • smallprint.checkEveryHours: how often to check the record, 6 by default.

What it does not do

It does not watch what a server does while it runs, it does not sit between your agent and its tools, and it cannot stop a tool call. It reads the text a server or skill gives your agent, and it tells you when that text changes.

The extension is open source under the MIT licence. It is made by EmberStack LLC, which runs smallprint.dev.

Screenshots

On first start it asks before anything is sent:

The first start: Small Print asks before looking anything up

A critical advisory names the version of a server this machine runs:

A notice for CVE-2025-6514 on mcp-remote 0.1.15, and the Small Print panel

An instruction file changed outside the editor:

A notice that CLAUDE.md changed outside this editor

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft