atx/registry

sorsa.app

https://sorsa.app/mcp

49
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 2d ago

Why this score

mcp.unauthenticated_consequential_tools-8
tls_present_and_valid+4
mcp_capabilities_discoverable+4
headers.missing_hsts-3
reachable+2

Findings (2)

mediumCapabilities are listable without authentication, including 5 whose names suggest state change (add_storefront_monitor, add_to_sourcing_list, create_deal_task, …) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
lowNo Strict-Transport-Security header
headers.missing_hsts @ 1.0.0

Evidence (8)

TypeObservedSHA-256
dns_resolution_observation2d ago792c8ec3ee3b3c73…
http_response_observation2d agofccab790d7eeb7f5…
availability_observation2d agoe6d1f70528f17526…
hosting_provider_observation2d agoe7292135d1d3f6bd…
tls_certificate_observation2d ago574efdb3c47ea488…
oauth_metadata_observation2d ago131a7767c9a43409…
mcp_protocol_observation2d agoe59a80dde91ba2fa…
mcp_capability_observation2d ago76e80eb2d772b0fb…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of sorsa.app to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →