token-safety.api.klymax402.com
https://token-safety.api.klymax402.com/mcp
67
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 1h ago
Why this score
| oauth_metadata_present | +14 |
| tls_present_and_valid | +12 |
| mcp.unauthenticated_consequential_tools | -8 |
| mcp.consequential_capability_added | -8 |
| reachable | +6 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
Findings (4)
| medium | Capabilities are listable without authentication, including 1 whose name suggests state change (token_check_safety_post) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
| medium | New state-changing capability exposed: token_check_safety_post mcp.consequential_capability_added @ 1.0.0 |
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (8)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 1h ago | 9aaece7c1bd7febe… |
| http_response_observation | 1h ago | 21cc5717bf99e0a2… |
| availability_observation | 1h ago | e053fcfcc320d703… |
| tls_certificate_observation | 1h ago | f169de765c8d4ea9… |
| oauth_metadata_observation | 1h ago | d80926a21ccff4b4… |
| mcp_protocol_observation | 1h ago | 8e22c0fe2b1603f1… |
| mcp_capability_observation | 1h ago | 63308bb5aee1b2a5… |
| mcp_capability_drift | 1h ago | 1ec5da29efa39c72… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of token-safety.api.klymax402.com to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.