atx/registry

token-safety.api.klymax402.com

https://token-safety.api.klymax402.com/mcp

67
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 1h ago

Why this score

oauth_metadata_present+14
tls_present_and_valid+12
mcp.unauthenticated_consequential_tools-8
mcp.consequential_capability_added-8
reachable+6
mcp_capabilities_discoverable+4
headers.missing_hsts-3

Findings (4)

mediumCapabilities are listable without authentication, including 1 whose name suggests state change (token_check_safety_post) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
mediumNew state-changing capability exposed: token_check_safety_post
mcp.consequential_capability_added @ 1.0.0
lowNo Strict-Transport-Security header
headers.missing_hsts @ 1.0.0
infoCORS allows any origin
cors.wildcard_origin @ 1.0.0

Evidence (8)

TypeObservedSHA-256
dns_resolution_observation1h ago9aaece7c1bd7febe…
http_response_observation1h ago21cc5717bf99e0a2…
availability_observation1h agoe053fcfcc320d703…
tls_certificate_observation1h agof169de765c8d4ea9…
oauth_metadata_observation1h agod80926a21ccff4b4…
mcp_protocol_observation1h ago8e22c0fe2b1603f1…
mcp_capability_observation1h ago63308bb5aee1b2a5…
mcp_capability_drift1h ago1ec5da29efa39c72…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of token-safety.api.klymax402.com to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →