signsimple.app
https://signsimple.app/mcp
49
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 1d ago
Why this score
| mcp.unauthenticated_consequential_tools | -8 |
| tls_present_and_valid | +4 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
| reachable | +2 |
Findings (3)
| medium | Capabilities are listable without authentication, including 1 whose name suggests state change (send_for_signature) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (8)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 1d ago | ee8e74296d1a4ca9… |
| http_response_observation | 1d ago | 7d3abbd58c5d4889… |
| availability_observation | 1d ago | da8c6d5c435add24… |
| hosting_provider_observation | 1d ago | 32f443b02a0f05d7… |
| tls_certificate_observation | 1d ago | 864849b6f7070fc2… |
| oauth_metadata_observation | 1d ago | 615f775b32312439… |
| mcp_protocol_observation | 1d ago | 57c1a7323d536881… |
| mcp_capability_observation | 1d ago | b80b2b9801da5ce9… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of signsimple.app to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.