← Back to search
Partial detail

Canonical readiness, evidence confidence, and active alerts are current. Deeper fields are still materializing: tool_security_inventory, security_posture_summary, write_action_governance, capability_taxonomy, remediations.

ai.com.mcp/contabo

Contabo (VPS) MCP Server

Contabo API (v1.0.0) as MCP tools for cloud provisioning, and management. Powered by HAPI MCP server

DECISION SUMMARY
Production trust decision

Allow For Production

Production readiness
Evaluation only
Score
59.4
Percentile pending
Confidence
Not Assessed
Based on evidence completeness, recency, and validation density.
Evidence age
10.7h old
Freshness: fresh. Snapshot trustsnap_8f97daf3dd77a723.
Top risk drivers
  • OAuth or protected-resource evidence is not present
Recommended actions
  • Claim the profile and attach publisher/security evidence
  • Publish OAuth or protected-resource metadata where applicable
  • Keep validation evidence fresh before production approval
Next action
watch this server, export policy, keep evidence current
score below evaluation threshold
Compare alternatives Export policy Open report JSON Dispute this assessment
Observed Attention
No observed attention
No observed attention in the current 30-day window.
  • No segmented attention signals observed in the current window.
Bucketed signal based on recent segmented Verify telemetry. Crawler and evaluator activity is not treated as confirmed human demand.
Status
Healthy
Score
59.4
Transport
streamable-http
Tools
124
DISPUTE THIS ASSESSMENT

Dispute this assessment

If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.

Verify responds to disputes within 5 business days and resolves them within 15.

Dispute history

No disputes filed for this server.

Risks

Security posture

No security posture summary available yet.

Tool capability & risk inventory

No tool inventory available from the latest validation run.

Write-action governance

No write-action governance summary is available yet.

Recommended runtime policy
Recommended runtime policy
Block
Default policy stance (medium risk ceiling, write actions require approval, no OAuth requirement). Answers "what may an agent do right now" -- a separate question from production readiness, which answers "how suitable is this server for adoption." Customize via policy export.
  • evidence_unavailable_fail_closed
Action-controls diff

Need at least two validation runs before diffing action controls.

Critical alerts
High/critical-severity alerts
0
Production verdicts degrade quickly when high or critical-severity alerts are active.

Compatibility

Client readiness verdicts

No client readiness verdicts are available yet.

Client readiness gate details

No per-client remediation checklist is available yet.

Verdict traces

No verdict trace data is available yet.

Publishability policy profiles

No publishability policy profiles are available yet.

Compatibility fixtures

No compatibility fixtures are available yet.

Recommended for

No recommendation profile is available yet.

Evidence

Current trust snapshot
Snapshot ID
trustsnap_8f97daf3dd77a723
Use this ID to compare server page, report, policy, MCP, homepage, ranking, and shortlist surfaces.
Trust evaluated
Aug 17, 2026 06:34:41 PM UTC
Evidence revision: unknown • materialization: complete
Last validated
Aug 17, 2026 07:55:14 AM UTC
Age: 10.66h • evidence age tier: Verified in last 24h • display score: 59.38

Canonical machine links

Evidence confidence
Confidence score
n/a
Full maintainer evidence will be rebuilt by the regular cache refresh path. Canonical validation history was unavailable; no confidence was assigned.
Live checks captured
0
More direct checks increase trust in the current verdict.
Validation age
n/a
Lower age means fresher evidence.
Latest validation evidence

No validation run available yet.

Known versions
  • 0.6.0
Public server reputation

No public server reputation signals are available yet.

Benchmark tasks

No benchmark tasks are available yet.

Utility coverage

No utility-coverage summary is available yet.

Tool snapshot diff & changelog

Need at least two validation runs before building a tool changelog.

Validation diff

Need at least two validation runs before diffing changes.

Registry & provenance divergence

No provenance-divergence summary is available yet.

Active alerts

No active alerts for the current server state.

Aliases & registry graph

No aliases discovered for this server.

Alias consolidation

No alias consolidation details are available yet.

Fix it

Why this score?

No score decomposition available yet.

Algorithmic score breakdown
Auth Operability
2/4
Measures whether auth discovery and protected access behave predictably for clients.
Error Contract Quality
0/4
Grades machine-readable error structure, status alignment, and remediation hints.
Rate-Limit Semantics
2/4
Checks whether quota/throttle responses are deterministic and automation-friendly.
Schema Completeness
2/4
Completeness of tool descriptions, parameter docs, examples, and schema shape.
Backward Compatibility
4/4
Stability score across tool schema/name drift relative to prior validations.
SLO Health
3/4
Availability, latency, and burst-failure profile across recent validation history.
Security Hygiene
2/4
HTTPS posture, endpoint hygiene, and response-surface hardening checks.
Task Success
4/4
Can an agent reliably initialize, enumerate tools, and execute core MCP flows?
Trust Confidence
3/4
Confidence-adjusted reliability score that penalizes low evidence volume.
Abuse/Noise Resilience
4/4
How well the server preserves core behavior in the presence of noisy traffic patterns.
Prompt Contract
3/4
Quality of prompt metadata, argument shape, and prompt discoverability for clients.
Resource Contract
3/4
How completely resources and resource templates describe URIs, types, and usage shape.
Discovery Metadata
2/4
Homepage, docs, icon, repository, support, and license coverage for directory consumers.
Registry Consistency
2/4
Agreement between stored registry metadata, live server-card data, and current validation output.
Installability
4/4
How cleanly a real client can connect, initialize, enumerate tools, and proceed through auth.
Session Semantics
4/4
Determinism and state behavior across repeated MCP calls, including sticky-session surprises.
Tool Surface Design
3/4
Naming clarity, schema ergonomics, and parameter complexity across the tool surface.
Result Shape Stability
3/4
Stability of declared output schemas across validations, with penalties for drift or missing shapes.
OAuth Interop
0/4
Depth and client compatibility of OAuth/OIDC metadata beyond the minimal protected-resource check.
Recovery Semantics
0/4
Whether failures include actionable machine-readable next steps such as retry or upgrade guidance.
Maintenance Signal
3/4
Versioning, update recency, and historical validation cadence that indicate active stewardship.
Adoption Signal
3/4
Directory presence and distribution clues that suggest the server is intended for external use.
Freshness Confidence
4/4
Confidence that recent validations are current enough and dense enough to trust operationally.
Transport Fidelity
4/4
Whether declared transport metadata matches the observed endpoint behavior and response formats.
Spec Recency
3/4
How close the server’s claimed MCP protocol version is to the latest known public revision.
Session Resume
3/4
Whether Streamable HTTP session identifiers and resumed requests behave cleanly for real clients.
Step-Up Auth
0/4
Whether OAuth metadata and WWW-Authenticate challenges support granular, incremental consent instead of broad upfront scopes.
Transport Compliance
0/4
Checks session headers, protocol-version enforcement, session teardown, and expired-session behavior.
Utility Coverage
0/4
Signals support for completions, pagination, and task-oriented utility surfaces that larger clients increasingly expect.
Advanced Capability Coverage
1/4
Coverage of newer MCP surfaces like roots, sampling, elicitation, structured output, and related metadata.
Connector Publishability
1/4
How ready the server looks for client catalogs and managed connector programs.
Tool Snapshot Churn
4/4
Stability of the tool surface across recent validations, including add/remove and output-shape drift.
Connector Replay
4/4
Whether a previously published frozen connector snapshot would remain backward compatible after the latest tool refresh.
Request Association
0/4
Whether roots, sampling, and elicitation appear tied to active client requests instead of arriving unsolicited on idle sessions.
Interactive Flow Safety
4/4
Whether prompts and docs steer users toward safe auth flows instead of pasting secrets directly.
Action Safety
1/4
Risk-weighted view of destructive, exec, egress, and confirmation semantics across the tool surface.
Official Registry Presence
4/4
Whether the server appears directly or indirectly in the official MCP registry.
Safety Transparency
2/4
Clarity of docs, auth disclosure, support links, and other trust signals visible to integrators.
Tool Capability Clarity
3/4
How clearly the tool surface communicates whether each action reads, writes, deletes, executes, or exports data.
Destructive Operation Safety
1/4
Penalizes delete/revoke/destroy style tools unless auth and safeguards reduce blast radius.
Egress / SSRF Resilience
1/4
Assesses arbitrary URL fetch, crawl, webhook, and remote-request exposure on the tool surface.
Execution / Sandbox Safety
4/4
Evaluates shell, code, script, and command-execution exposure and whether that surface appears contained.
Data Exfiltration Resilience
3/4
Assesses export, dump, backup, and bulk-read behavior against the surrounding auth and safeguard signals.
Least Privilege Scope
1/4
Rewards scoped auth metadata and penalizes broad or missing scopes around privileged tools.
Secret Handling Hygiene
3/4
Assesses secret-bearing tools, token leakage risk, and whether the public surface avoids obvious secret exposure.
Supply Chain Signal
1/4
Public metadata signal for repository, changelog, license, versioning, and recency that supports supply-chain trust.
Input Sanitization Safety
3/4
Penalizes risky freeform string inputs when schemas do not constrain URLs, code, paths, queries, or templates.
Tool Namespace Clarity
3/4
Measures naming uniqueness and ambiguity across the tool namespace to reduce collision and confusion risk.

1 component(s) not assessed for this run: Provenance Divergence

Experimental candidate components
Personal Data Exposure
0.0
Experimental candidate, weight 0. Export and bulk-access evidence only; no impact on totals, verdicts, rankings, or gates.
Actionable remediation

No remediation items. Current evidence does not show urgent client-facing fixes.

Point loss breakdown

No current score penalties are recorded.

Technical compatibility profiles

No compatibility profiles available.

Governance

MCP TrustOps

TrustOps turns this report into operational controls: validation targets and SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.

Evidence age tier
Verified in last 24h
Policy evidence-age limit (a runtime constraint, distinct from the public 24h freshness window and from a plan's validation target/SLA): 168.0h • confidence-weighted score (display score discounted for evidence age and confidence -- an internal TrustOps input, not the public score): n/a • score suppressed after the 30-day display limit:
Policy exports
Formats: json, rego, yaml, github_action, gateway_config, client_report
Runtime routing
/v1/decide
Returns allowed tools, blocked tools, approval requirement, and reason.
Hosted runtime
Deploy trusted servers from GitHub with secrets, egress controls, releases, rollback, and audit events.
Authenticated validation
Premium publisher feature: paid authenticated runs verify scopes, write-action safeguards, and authorized tool execution.
Active trust badges
Freshly Validated
Semantic benchmarks
template ready
Templates cover GitHub, database, healthcare, web search, and CRM least-privilege jobs.
Supply chain
not scanned
Deep scan checks are marked separately from public metadata signals.
Compliance metadata
Terms, privacy, SOC 2, HIPAA, GDPR, retention, deletion, and audit-log fields are tracked as enterprise metadata.
Alert subscription types
Status changes Score drops or recovers Evidence-age policy breach Validation schema drift OAuth or auth behavior changes Tool surface changes New or changed write tool Supply-chain signal changes Legal or compliance metadata changes
MCP Runtime hosting

No hosted runtime profile is available yet.

Authenticated validation sessions

No authenticated validation detail is available yet.

Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.

Install snippets

No install snippets available.

Agent access & tool surface
Live server tools
No live tool surface captured yet.
Observed from the latest live validation against https://contabo.run.mcp.com.ai/mcp. This is the target server surface, not Verify's own inspection tools.
Live capability counts
124 tools • 0 prompts • 0 resources
Counts come from the latest tools/list, prompts/list, and resources/list checks.
Inspect with Verify
search fetch search_servers recommend_servers get_server_report compare_servers
Use Verify itself to search, recommend, compare, and fetch the full report for ai.com.mcp/contabo.
Direct machine links

History

Validation history

Trend history appears after at least two validation runs. This avoids presenting a one-point validation as a trend.

Validation timeline

No validation timeline is available yet.

Recent validation runs
Recent validation runs for this MCP server
StartedStatusSummaryLatencyChecks
No validation runs yet.
Incident & change feed

No incidents or changes recorded yet.

Technical details

Raw evidence view

No raw evidence recorded.

Capabilities
Use-case taxonomy
No taxonomy tags yet.
Transport compliance drilldown

No transport compliance drilldown is available yet.

Request association

No request-association evidence is available yet.

Connector replay

No connector replay evidence is available yet.