verify.sentinelsignal.io
https://verify.sentinelsignal.io/mcp
68
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 6d ago
Why this score
| tls_present_and_valid | +12 |
| mcp.unauthenticated_consequential_tools | -8 |
| reachable | +6 |
| hsts_enabled | +4 |
| mcp_capabilities_discoverable | +4 |
Findings (1)
| medium | Capabilities are listable without authentication, including 1 whose name suggests state change (create_mandate) — inferred from tool names, not confirmed mcp.unauthenticated_consequential_tools @ 1.0.0 |
Evidence (7)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 6d ago | ef14dacc772b71df… |
| http_response_observation | 6d ago | ea8c5817bf4808f9… |
| availability_observation | 6d ago | e7abb2e6a7563368… |
| tls_certificate_observation | 6d ago | f74beb6ef95c2f1e… |
| oauth_metadata_observation | 6d ago | bc97095e672698aa… |
| mcp_protocol_observation | 6d ago | b06563cd7f713300… |
| mcp_capability_observation | 6d ago | 6b606f8380c05d00… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of verify.sentinelsignal.io to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.