gateway.pipeworx.io/opencollective
https://gateway.pipeworx.io/opencollective/mcp
60
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 59m ago
Why this score
| oauth_metadata_present | +14 |
| mcp.unauthenticated_consequential_tools | -8 |
| tls_present_and_valid | +4 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
| mcp.tool_schema_changed | -3 |
| reachable | +2 |
Findings (4)
| medium | Capabilities are listable without authentication, including 1 whose name suggests state change (subscribe) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
| low | Input schema changed without a name change: deep_research mcp.tool_schema_changed @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (9)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 59m ago | 51db5f25b7f57f91… |
| http_response_observation | 59m ago | 4e47206cb3612e1f… |
| availability_observation | 59m ago | 576921f13afe9aad… |
| hosting_provider_observation | 59m ago | e7292135d1d3f6bd… |
| tls_certificate_observation | 59m ago | 8fe003d29cdac9cf… |
| oauth_metadata_observation | 59m ago | da0dc9ab20d4ccf1… |
| mcp_protocol_observation | 59m ago | 7ac6df0b135b22cf… |
| mcp_capability_observation | 59m ago | 92f490f502f803de… |
| mcp_capability_drift | 59m ago | 0a3bc1ed780a2708… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of gateway.pipeworx.io/opencollective to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.