api.chieflab.io/api
https://api.chieflab.io/api/mcp
53
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 2h ago
Why this score
| mcp.unauthenticated_consequential_tools | -8 |
| tls_present_and_valid | +4 |
| mcp_capabilities_discoverable | +4 |
| reachable | +2 |
| hsts_enabled | +1 |
Findings (2)
| medium | Capabilities are listable without authentication, including 14 whose names suggest state change (chieflab_approve_action, chieflab_create_next_move_action, chieflab_create_work_request, …) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (8)
| Type | Observed | SHA-256 |
|---|---|---|
| availability_observation | 2h ago | b07a4011499dee18… |
| dns_resolution_observation | 2h ago | 6057ba4d730d4e07… |
| http_response_observation | 2h ago | 3292690047903ea0… |
| hosting_provider_observation | 2h ago | 07b610f7cd67ffa2… |
| tls_certificate_observation | 2h ago | a98333428394616c… |
| oauth_metadata_observation | 2h ago | 8e3ae137198d8767… |
| mcp_protocol_observation | 2h ago | 973ec4e37d5ab962… |
| mcp_capability_observation | 2h ago | 67e7954557a1e55d… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of api.chieflab.io/api to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.