atx/registry

api.remoet.dev/mcp/oauth

https://api.remoet.dev/mcp/oauth

46
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 46m ago

Why this score

mcp.unauthenticated_consequential_tools-8
tls_present_and_valid+4
mcp_capabilities_discoverable+4
headers.missing_hsts-3
mcp.tool_schema_changed-3
reachable+2

Findings (3)

mediumCapabilities are listable without authentication, including 5 whose names suggest state change (create_linktree, delete_linktree, delete_profile_item, …) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
lowNo Strict-Transport-Security header
headers.missing_hsts @ 1.0.0
lowInput schema changed without a name change: search_listings
mcp.tool_schema_changed @ 1.0.0

Evidence (9)

TypeObservedSHA-256
dns_resolution_observation46m ago3b1d664595a4a73b…
http_response_observation46m agoaf9e44b8a1eda73a…
availability_observation46m agob2880a7bd4128a17…
hosting_provider_observation46m agoe7292135d1d3f6bd…
tls_certificate_observation46m ago9195ec19d62abb70…
oauth_metadata_observation46m ago8b1444033a432e99…
mcp_protocol_observation46m agobc8369fc7c351e0b…
mcp_capability_observation46m ago23dadc0361f05531…
mcp_capability_drift46m ago50333eb5f64397a0…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of api.remoet.dev/mcp/oauth to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →