atx/registry

api.chieflab.io/api

https://api.chieflab.io/api/mcp

53
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 2h ago

Why this score

mcp.unauthenticated_consequential_tools-8
tls_present_and_valid+4
mcp_capabilities_discoverable+4
reachable+2
hsts_enabled+1

Findings (2)

mediumCapabilities are listable without authentication, including 14 whose names suggest state change (chieflab_approve_action, chieflab_create_next_move_action, chieflab_create_work_request, …) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
infoCORS allows any origin
cors.wildcard_origin @ 1.0.0

Evidence (8)

TypeObservedSHA-256
availability_observation2h agob07a4011499dee18…
dns_resolution_observation2h ago6057ba4d730d4e07…
http_response_observation2h ago3292690047903ea0…
hosting_provider_observation2h ago07b610f7cd67ffa2…
tls_certificate_observation2h agoa98333428394616c…
oauth_metadata_observation2h ago8e3ae137198d8767…
mcp_protocol_observation2h ago973ec4e37d5ab962…
mcp_capability_observation2h ago67e7954557a1e55d…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of api.chieflab.io/api to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →