noemic.app
https://noemic.app/mcp
53
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 1d ago
Why this score
| mcp.unauthenticated_consequential_tools | -8 |
| tls_present_and_valid | +4 |
| mcp_capabilities_discoverable | +4 |
| reachable | +2 |
| hsts_enabled | +1 |
Findings (1)
| medium | Capabilities are listable without authentication, including 2 whose names suggest state change (begin_sign_in, finish_sign_in) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
Evidence (8)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 1d ago | 06302fbdbf5bfa67… |
| http_response_observation | 1d ago | 8a9a5d7f8bbfa6b3… |
| availability_observation | 1d ago | f2887c8239eebe10… |
| hosting_provider_observation | 1d ago | e7292135d1d3f6bd… |
| tls_certificate_observation | 1d ago | df0b69c1b2aa2dde… |
| oauth_metadata_observation | 1d ago | f785f0c8fef5741d… |
| mcp_protocol_observation | 1d ago | fdd62bcfddd17ad5… |
| mcp_capability_observation | 1d ago | 5e2f857abe313d8d… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of noemic.app to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.