Drillr — The financial MCP for AI agents
The financial MCP for AI agents - 90+ financial tables, SEC filings, signals, alt-data.
Block For Production
trustsnap_f04ec7fe5f0a37af.- Transport Compliance
- Resource Contract
- Request Association
- Respond to server card describes a different server: card says "drillr-agentic", live says "drillr-data"
- Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
- Document the new auth posture and confirm protected-resource and challenge metadata still match reality.
- AI-assisted user activity
- profile / compare API inspection
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risk
Security posture
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes |
|---|---|---|---|---|
sec_report_list |
read | Low | none | Safeguards hinted in metadata. |
sec_report_search |
read | Low | freeform input surface | No explicit safeguard hints detected. |
company_search |
read | Low | freeform input surface | No explicit safeguard hints detected. |
ticker_lookup |
read | Low | freeform input surface | No explicit safeguard hints detected. |
run_sql |
read | Low | none | No explicit safeguard hints detected. |
get_table_schema |
read | Low | none | No explicit safeguard hints detected. |
fiscal_utility |
read | Low | none | No explicit safeguard hints detected. |
list_tables |
read | Low | none | No explicit safeguard hints detected. |
news_search |
read | Low | freeform input surface | No explicit safeguard hints detected. |
Write-action governance
Status detail: No unsafe write-action governance gaps detected on the latest validation.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
company_search | Low | freeform input surface |
fiscal_utility | Low | none |
get_table_schema | Low | none |
list_tables | Low | none |
news_search | Low | freeform input surface |
run_sql | Low | none |
sec_report_list | Low | none |
sec_report_search | Low | freeform input surface |
ticker_lookup | Low | freeform input surface |
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Critical alerts
Compatibility
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Errorstep_up_auth_probe• Warningconnector_replay_probe• OK — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Error
Evidence provenance
action_safety_probe• OK
Evidence provenance
tool_snapshot_probe• OKconnector_replay_probe• OK
Client compatibility gate details
Remediation checklist
Transport compliance failed or did not complete successfully.Not yet safe for the Messages API remote MCP path: requires OAuth, a compatible connector profile, and no pending connector-refresh risk.Transport compliance issues should be resolved before wider client rollout.
Remediation checklist
Transport behavior should match Claude-compatible HTTP expectations.Not yet safe for the Messages API remote MCP path: requires OAuth, a compatible connector profile, and no pending connector-refresh risk.Transport compliance issues should be resolved before wider client rollout.
Remediation checklist
Add confirmation or dry-run semantics for risky actions.Production readiness is blocked by an active alert: Server card describes a different server: card says "drillr-agentic", live says "drillr-data".Production readiness is blocked by an active alert: Tool snapshot changed.Production readiness is blocked by an active alert: Auth mode changed.
Verdict traces
server_card_schema_drifted• critical • Server card describes a different server: card says "drillr-agentic", live says "drillr-data"tool_snapshot_changed• high • Tool snapshot changedauth_mode_changed• high • Auth mode changed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Medium | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: Yes
- Write Actions Present: No
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: Yes
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: Yes
- Write Actions Present: No
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: Yes
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Passes
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Degraded
Recommended for
Evidence
Current trust snapshot
trustsnap_f04ec7fe5f0a37afCanonical machine links
Evidence confidence
Latest validation evidence
Failures
openid_configurationClient error '404 Not Found' for url 'https://gateway.drillr.ai/.well-known/openid-configuration' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404schema_divergence_probeCheck completedtransport_compliance_probeIssues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=404).
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
OK | n/a | No high-risk write, destructive, or exec tools detected. |
advanced_capabilities_probe |
Missing | n/a | No advanced MCP capability signals detected. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: transport compliance. |
connector_replay_probe |
OK | n/a | Backward compatible with no breaking tool-surface changes. |
determinism_probe |
OK | 23.5 ms | Check completed |
initialize |
OK | 52.3 ms | Protocol 2025-03-26 |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
OK | 18.3 ms | authorization_endpoint, code_challenge_methods_supported, grant_types_supported, issuer |
oauth_protected_resource |
OK | 18.1 ms | 1 authorization server(s) |
official_registry_probe |
OK | n/a | Check completed |
openid_configuration |
Error | 18.0 ms | Client error '404 Not Found' for url 'https://gateway.drillr.ai/.well-known/openid-configuration' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
probe_noise_resilience |
OK | 165.1 ms | Fetched https://gateway.drillr.ai/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Missing | 21.9 ms | not supported |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Missing | 21.6 ms | not supported |
schema_divergence_probe |
Error | n/a | Check completed |
server_card |
OK | 19.8 ms | authentication, serverInfo, tools |
session_resume_probe |
Warning | n/a | no session id |
step_up_auth_probe |
Warning | n/a | Oauth detected. |
tool_snapshot_probe |
OK | n/a | Check completed |
tools_list |
OK | 25.5 ms | 9 tool(s) exposed |
transport_compliance_probe |
Error | 21.5 ms | Issues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=404). |
utility_coverage_probe |
OK | 21.1 ms | No completions evidence; no pagination evidence; tasks auth required. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": true,
"confirmation_signals": [],
"reason": null,
"safeguard_count": 1,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {
"read": 9
},
"declared_non_read_only_tools": 0,
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"has_mutating_capability": false,
"has_non_read_capability": false,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 9,
"medium": 0
},
"secret_tools": 0,
"tool_count": 9
}
},
"latency_ms": null,
"status": "ok"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [],
"enabled_count": 0,
"initialize_capability_keys": [
"tools"
]
},
"latency_ms": null,
"status": "missing"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"transport_compliance"
],
"criteria": {
"action_safety": true,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": true,
"remote_transport": true,
"request_association": true,
"server_card": true,
"session_resume": true,
"step_up_auth": true,
"tool_surface": true,
"tools_list": true,
"transport_compliance": false
},
"high_risk_tools": 0,
"tool_count": 9,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"connector_replay_probe": {
"details": {
"added_tools": [],
"additive_output_changes": [],
"backward_compatible": true,
"output_breaks": [],
"removed_tools": [],
"required_arg_breaks": [],
"would_break_after_refresh": false
},
"latency_ms": null,
"status": "ok"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "9b6db75cf7d441866d7b2781d8b7b072bf74b87cbc476cf70e40852d90634139",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 23.54,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"tools": {
"listChanged": true
}
},
"instructions": "Drillr's data backend for global financial markets \u2014 direct, predictable, call-priced.\n\nCore equity coverage: US, Japan, Hong Kong, and China A-shares. Ticker format: US bare (AAPL); Japan `.T` (6758.T); Hong Kong 5-digit `.HK` (00700.HK); A-shares `.SH`/`.SZ` (600519.SH, 300750.SZ). Quote symbols containing \".\" or \"^\" in SQL.\n\nThe core tables financial_statements, company_snapshot, and price_volume_history cover all four markets. company_search, ticker_lookup, sec_report_list/search, and news_search do too. price_volume_history also carries other global listings, indices, FX, commodities, and crypto.\n\nSpecialized datasets can be narrower: earnings calls/calendar are US+JP; analyst, ownership, executive, 8-K events, and extended-hours are US-only. Call get_table_schema(table_name) before treating an empty result as a finding \u2014 every equity-scoped table states its coverage.\n\nTools \u2014 pick the one that fits, then run_sql for anything custom:\n- list_tables / get_table_schema: discover tables; get one table's columns + coverage notes\n- run_sql: read-only SQL over the financial tables (list_tables/get_table_schema first)\n- company_search: find companies by natural-language description\n- ticker_lookup: resolve a name or ticker to its canonical symbol\n- sec_report_list / sec_report_search: list a company's SEC filings; full-text search across the whole filing\n- news_search: semantic search over company and market news\n- fiscal_utility: convert between fiscal and calendar periods",
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "drillr-data",
"version": "1.0.0"
}
}
},
"url": "https://gateway.drillr.ai/mcp/data"
},
"latency_ms": 52.29,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": true,
"prompt_available": false,
"risk_hits": [],
"safe_hits": []
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"authorization_endpoint": "https://gateway.drillr.ai/oauth/authorize",
"code_challenge_methods_supported": [
"S256"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"issuer": "https://gateway.drillr.ai",
"registration_endpoint": "https://gateway.drillr.ai/oauth/register",
"response_types_supported": [
"code"
],
"token_endpoint": "https://gateway.drillr.ai/oauth/token",
"token_endpoint_auth_methods_supported": [
"none"
]
},
"url": "https://gateway.drillr.ai/.well-known/oauth-authorization-server"
},
"latency_ms": 18.3,
"status": "ok"
},
"oauth_protected_resource": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"authorization_servers": [
"https://gateway.drillr.ai"
],
"bearer_methods_supported": [
"header"
],
"resource": "https://gateway.drillr.ai"
},
"url": "https://gateway.drillr.ai/.well-known/oauth-protected-resource"
},
"latency_ms": 18.07,
"status": "ok"
},
"official_registry_probe": {
"details": {
"direct_match": true,
"official_peer_count": 1,
"registry_identifier": "ai.drillr/drillr",
"registry_source": "official_registry"
},
"latency_ms": null,
"status": "ok"
},
"openid_configuration": {
"details": {
"error": "Client error '404 Not Found' for url 'https://gateway.drillr.ai/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gateway.drillr.ai/.well-known/openid-configuration"
},
"latency_ms": 18.03,
"status": "error"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/plain; charset=UTF-8"
},
"http_status": 404,
"url": "https://gateway.drillr.ai/robots.txt",
"validation_disallowed": false
},
"latency_ms": 165.12,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found"
},
"id": 3,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://gateway.drillr.ai/mcp/data"
},
"latency_ms": 21.86,
"status": "missing"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": true,
"drift_fields": [],
"metadata_document_count": 3,
"readable_sources": [
"registry",
"server_card"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": "drillr-agentic",
"server_card_version": "1.0.0"
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found"
},
"id": 5,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://gateway.drillr.ai/mcp/data"
},
"latency_ms": 21.59,
"status": "missing"
},
"schema_divergence_probe": {
"details": {
"auth_scheme_mismatch": true,
"card_auth_schemes": [
"api_key"
],
"card_server_name": "drillr-agentic",
"card_server_version": "1.0.0",
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_oauth_observed": true,
"live_server_name": "drillr-data",
"live_server_version": "1.0.0",
"server_name_mismatch": true,
"server_version_mismatch": false,
"severity": "critical",
"tool_divergences": [],
"tools_missing_from_card": [
"company_search",
"fiscal_utility",
"get_table_schema",
"list_tables",
"news_search",
"run_sql",
"sec_report_list",
"sec_report_search",
"ticker_lookup"
],
"tools_missing_from_live": [
"search"
],
"tools_with_omitted_schema": []
},
"latency_ms": null,
"status": "error"
},
"server_card": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"authentication": {
"required": true,
"schemes": [
"api_key"
]
},
"serverInfo": {
"name": "drillr-agentic",
"version": "1.0.0"
},
"tools": [
{
"description": "Ask natural-language questions about companies, tickers, sectors, SEC filings, earnings, and alternative data. Runs Drillr's research agent server-side and returns a synthesized answer with source attribution. Pass session_id to continue a prior research thread (~3\u00d7 faster on follow-ups via cache reuse) and context to inject background as ground truth.",
"name": "search"
}
]
},
"url": "https://gateway.drillr.ai/.well-known/mcp/server-card.json"
},
"latency_ms": 19.8,
"status": "ok"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": true,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "warning"
},
"tool_snapshot_probe": {
"details": {
"added": [],
"changed_outputs": [],
"current_tool_count": 9,
"previous_tool_count": 9,
"removed": [],
"similarity": 1.0
},
"latency_ms": null,
"status": "ok"
},
"tools_list": {
"details": {
"headers": {
"content-type": "application/json"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use to discover which SEC filings exist for a ticker before searching content.\nFor the actual content use sec_report_search instead.\n\nList indexed SEC filings for a given ticker with a summary header.\n\nReturns: summary (period coverage, per-type counts) + table of up to 50 filings\n(fiscal_year, fiscal_quarter, filing_type, filing_date, period_start, period_end).\n\nfiling_types filter: omit for main reports only (US 10-K/10-Q/20-F/S-1/DEF 14A\n+ /A amendments; JP 120/140/160; HK/A-share annual_report / quarterly_report /\nq1_report; excludes ad-hoc 8-K/6-K); pass [] for all indexed types; pass explicit\nallowlist to override.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"filing_types": {
"description": "Filter by filing type. Omit for default (periodic reports + IPO/shelf registrations + amendments; excludes ad-hoc disclosures). Pass [] for all indexed types. Pass an explicit allowlist to override \u2014 use values from the `filing_type` column of a prior unfiltered call.",
"items": {
"type": "string"
},
"type": "array"
},
"ticker": {
"description": "Stock ticker, e.g. NVDA, 6758.T, 00700.HK, 600519.SH",
"type": "string"
}
},
"required": [
"ticker"
],
"type": "object"
},
"name": "sec_report_list"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use when you need narrative content from company filings \u2014 risk factors, MD&A, guidance language, deal terms, accounting policies, share structure. For consolidated financial numbers use run_sql on financial_statements instead.\n\nSemantic search over the full text of company-filed reports; returns matching passages.\n\nCoverage: US + Japan + Hong Kong + China A-shares. US = SEC EDGAR (including foreign issuers' 20-F/6-K). Japan = EDINET, `.T` ticker (6758.T). Hong Kong = HKEX filings, 5-digit `.HK` ticker (00700.HK). A-shares = `.SH`/`.SZ` (600519.SH, 300750.SZ).\n\nParameters:\n- query (required): natural-language search; phrase it as the concept or section name you want, e.g. \"share repurchase authorization\", \"Risk Factors\". Run a few phrasings rather than one broad query.\n- ticker (required): US bare (NVDA), Japan `.T`, HK `.HK`, A-share `.SH`/`.SZ`, ADRs as their US symbol (SONY).\n- filing_types (optional): US = SEC form names (10-K, 10-Q, 8-K, 20-F, 6-K, DEF 14A, S-1/F-1, + amendments). Japan = EDINET NUMERIC codes: 120 (annual), 140 (quarterly), 160 (semi-annual). HK/A-share = plain names \u2014 annual_report; A-share quarters per-quarter (q1_report, ...); HK quarterly results all quarterly_report. OMIT to search all types.\n- period_start / period_end (optional): yyyy-mm window; omit to search all history.\n- top_k (optional): max passages to return (default 10).\n\nScope: indexes ONLY company-filed reports \u2014 NOT institutional filings (13F-HR/13D/13G; for those use insider_and_institution_activities with source='institution').\n\nSection targets: non-GAAP reconciliations \u2192 earnings 8-K (Ex 99.1); dilution / SBC / buyback \u2192 \"Shareholders' Equity\"; segment breakdown \u2192 \"Segment Information\"; guidance \u2192 \"Outlook\" in MD&A; exec comp \u2192 DEF 14A.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"filing_types": {
"items": {
"type": "string"
},
"type": "array"
},
"period_end": {
"description": "End period YYYY-MM",
"type": "string"
},
"period_start": {
"description": "Start period YYYY-MM",
"type": "string"
},
"query": {
"description": "Search query",
"type": "string"
},
"ticker": {
"description": "Stock ticker, e.g. NVDA, 6758.T, 00700.HK, 600519.SH",
"type": "string"
},
"top_k": {
"default": 10,
"maximum": 30,
"minimum": 1,
"type": "integer"
}
},
"required": [
"ticker",
"query"
],
"type": "object"
},
"name": "sec_report_search"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use for qualitative company discovery (industry, business model, supply chain, competitors, management background). For numerical screening (revenue, margins, ratios, growth rates) use run_sql on company_snapshot instead.\n\nDrillr's company knowledge base \u2014 searchable across industry classification, product offerings, business model, segment structure, competitive landscape, supply chain, management background, and customer profile.\n\nCoverage: US, Japan, Hong Kong, and China A-shares. `market` accepts one lowercase value or a list from `us | jp | hk | cn`; omit it or pass `[]` for all four. List order does not set priority.\n\nPass a natural-language description (for example, \"Hong Kong and China EV battery suppliers\"). Returns a structured list of matching companies with context snippets.\n\nONLY for finding a LIST of companies by description.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"market": {
"anyOf": [
{
"enum": [
"us",
"jp",
"hk",
"cn"
],
"type": "string"
},
{
"items": {
"$ref": "#/properties/market/anyOf/0"
},
"maxItems": 4,
"type": "array"
}
],
"description": "Optional market filter. Pass one lowercase value or a list from 'us' | 'jp' | 'hk' | 'cn'. Omit or pass [] for all four; list order does not set priority."
},
"query": {
"description": "Natural-language company description",
"minLength": 1,
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "company_search"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Resolve a company name, brand, or ticker substring to canonical ticker(s). Use this FIRST when the user mentions a company by name/brand/nickname before running any ticker-keyed tool.\n\nInput:\n- query (required): company name, brand, or ticker substring, e.g. \"Apple\", \"\u82f9\u679c\", \"AAPL\", \"OpenAI\"\n- market (optional): \"us\" | \"jp\" | \"hk\" | \"cn\" \u2014 omit to search all markets\n\nReturns up to 5 matches ranked by prefix-hit first, then name length. Returned\nsymbols carry their market suffix: US bare (AAPL), Japan `.T`, Hong Kong 5-digit\n`.HK` (00700.HK), A-share `.SH`/`.SZ` (600519.SH).",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"market": {
"description": "Optional market filter: 'us' | 'jp' | 'hk' | 'cn'. Omit to search all markets.",
"enum": [
"us",
"jp",
"hk",
"cn"
],
"type": "string"
},
"query": {
"description": "Company name or ticker substring (case-insensitive). Matches historical names + tickers too.",
"minLength": 1,
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "ticker_lookup"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "PostgreSQL SELECT over financial / market / alt-data tables \u2014 returns structured rows.\n\nHard rules (query fails otherwise):\n- SELECT only, no CTE (`WITH ... AS`) \u2014 use subqueries.\n- Period columns are TEXT, not dates \u2014 `period_end` is 'YYYY-MM'. Compare as strings (`period_end >= '2024-01'`); a `::date` cast on it fails.\n- Filter structured tables by ticker (`WHERE ticker IN ('AAPL','MSFT')`; screening: add `ticker NOT LIKE '%-%'` to drop preferred stock).\n\nCore equity coverage: US, Japan, Hong Kong, and China A-shares. Tickers are US bare (AAPL), Japan `.T` (6758.T), Hong Kong `.HK` (00700.HK), and A-shares `.SH`/`.SZ` (600519.SH, 300750.SZ). financial_statements, company_snapshot, and price_volume_history span all four. Specialized tables vary \u2014 call get_table_schema before treating an empty result as a finding.\n\nTables by domain (call get_table_schema for detail):\n- Market: price_volume_history (OHLCV history; MUST filter ticker + time_frame), index_price, equity_extended_rt (pre/after/overnight quotes)\n- Fundamentals: financial_statements (GAAP income/balance/cashflow), company_snapshot (ratios, per-share, growth)\n- Earnings: earning_call_summary, earning_call_calendar\n- Analyst: analyst_ratings, analyst_ratings_consensus\n- Ownership: insider_and_institution_activities\n- 8-K events: executive_change, company_deal_events, debt_issuance, securities_offering\n- Executives: executive_profile, executive_compensation\n- Alt-data: macro / industry / trade / AI-supply-chain \u2014 call list_tables(categories=[...])",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"sql": {
"description": "PostgreSQL SELECT query",
"type": "string"
}
},
"required": [
"sql"
],
"type": "object"
},
"name": "run_sql"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use BEFORE run_sql when you're unsure which columns a table has.\n\nLook up column definitions (name, type, description) for a data table.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"table_name": {
"enum": [
"financial_statements",
"company_snapshot",
"price_volume_history",
"earning_call_summary",
"insider_and_institution_activities",
"index_price",
"equity_extended_rt",
"analyst_ratings",
"analyst_ratings_consensus",
"earning_call_calendar",
"executive_profile",
"executive_compensation",
"executive_change",
"company_deal_events",
"debt_issuance",
"securities_offering",
"eia_generators",
"eia_retail_prices",
"eia_regional_hourly",
"epochai_data_centers",
"epochai_data_center_timelines",
"epochai_gpu_clusters",
"epochai_dc_cooling_towers",
"epochai_dc_chillers",
"epochai_chip_types",
"epochai_ml_hardware",
"epochai_chip_organizations",
"epochai_chip_sales_cumulative",
"epochai_chip_sales_by_chip",
"epochai_chip_sales_by_designer",
"epochai_chip_owners_cumulative_by_chip",
"epochai_chip_owners_cumulative_by_designer",
"epochai_chip_owners_quarters_by_chip",
"tsmc_revenue",
"twcustoms_trade",
"computeprices_gpus_dim",
"computeprices_gpu_offer_daily",
"computeprices_gpu_offers",
"computeprices_providers_dim",
"skypilot_ondemand_price",
"skypilot_spot_price",
"skypilot_instance_dim",
"epochai_models",
"epochai_benchmark_scores",
"epochai_benchmark_runs",
"epochai_ai_companies",
"epochai_ai_companies_revenue_reports",
"epochai_ai_companies_usage_reports",
"epochai_ai_companies_staff_reports",
"epochai_ai_companies_funding_rounds",
"epochai_ai_companies_compute_spend",
"epochai_polling",
"arena_leaderboard",
"litellm_price_history",
"litellm_models_dim",
"computeprices_llm_prices",
"computeprices_llm_price_daily",
"computeprices_llms_dim",
"comtrade_country",
"comtrade_hs_code",
"census_import_export",
"fred_series",
"fred_observations",
"fred_macro_daily",
"polymarket_events",
"polymarket_markets",
"polymarket_outcomes",
"polymarket_trades",
"polymarket_daily",
"polymarket_volume_daily",
"polymarket_holders_daily",
"kalshi_events",
"kalshi_markets",
"kalshi_trades",
"kalshi_daily",
"kalshi_volume_daily",
"mineral_deposit",
"mineral_deposit_commodity",
"mineral_deposit_operator",
"mineral_country_supply",
"mineral_critical_snapshot",
"fiscal_year_config"
],
"type": "string"
}
},
"required": [
"table_name"
],
"type": "object"
},
"name": "get_table_schema"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use to convert between fiscal year/quarter and calendar months for a ticker before filtering period_end columns.\n\nCoverage warning: fiscal-year configuration is primarily US, with sparse JP/HK entries and no China A-share coverage in the verified dataset. Do not assume this tool supports a ticker merely because the core equity tables do.\n\nForward: ticker + fiscal_year + fiscal_quarter \u2192 period_start/period_end. Reverse: ticker + yyyy_mm \u2192 fiscal_year/fiscal_quarter.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"fiscal_quarter": {
"description": "Quarter 1-4, or 0 for full fiscal year (required for forward conversion)",
"maximum": 4,
"minimum": 0,
"type": "integer"
},
"fiscal_year": {
"description": "Fiscal year (required for forward conversion)",
"type": "integer"
},
"ticker": {
"description": "Stock ticker. Coverage is primarily US; sparse JP/HK; no China A-share configuration.",
"type": "string"
},
"yyyy_mm": {
"description": "Calendar month yyyy-mm (required for reverse conversion)",
"pattern": "^\\d{4}-\\d{2}$",
"type": "string"
}
},
"required": [
"ticker"
],
"type": "object"
},
"name": "fiscal_utility"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "List alternative-data tables under the given categories. Returns each table's name,\none-line purpose, and column names (call get_table_schema if you need column\ntypes/comments). Batch up to 5 categories in one call; omit categories, or pass [\"all\"], to\nget the category index instead.\n\nUse this BEFORE run_sql when you want to explore alt-data \u2014 run_sql alone won't\ntell you which tables exist.\n\nAvailable categories:\n- Energy & Power \u2014 US power plants, electricity prices, regional hourly generation/demand\n- Data Centers \u2014 facilities, GPU clusters, cooling\n- Semiconductors \u2014 AI chip specs, sales, ownership, foundry revenue, customs trade\n- Compute Pricing \u2014 GPU rental, cloud VM spot/on-demand, instance specs\n- Model Development \u2014 model specs, benchmarks, AI companies, AI polling, LLM arena\n- Inference Economics \u2014 LLM API pricing across providers\n- Macro & Trade \u2014 UN Comtrade, US Census trade flows, FRED macro series\n- Prediction Markets \u2014 Polymarket and Kalshi events, markets, trades, daily aggregates\n- Critical Minerals \u2014 USGS mineral deposits, country supply, critical materials",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"categories": {
"description": "Altdata category names (see tool description for the list). Omit, or pass \"all\", for the category index.",
"items": {
"enum": [
"Energy & Power",
"Data Centers",
"Semiconductors",
"Compute Pricing",
"Model Development",
"Inference Economics",
"Macro & Trade",
"Prediction Markets",
"Critical Minerals",
"all"
],
"type": "string"
},
"maxItems": 5,
"type": "array"
}
},
"type": "object"
},
"name": "list_tables"
},
{
"annotations": {
"destructiveHint": false,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Use for any news, event, development, or statement question about a company,\ntheme, or the market.\n\nCovers US, Japan, Hong Kong and A-share markets; The `ticker` filter takes\nexchange-suffixed symbols: US bare (AAPL), Japan `.T` (7203.T), Hong Kong\n`.HK` (00700.HK), A-share `.SH`/`.SZ` (600519.SH). \n\nReturns Markdown: a `## Stories` numbered list (each storyline once), then flat\n`## Events` and `## Claims` tables (claims = attributed statements: analyst\nactions, corporate guidance, central-bank remarks). The Events `story` column\nrefers back to the Stories number. `sources` counts corroborating reports;\n`first_reported`/`last_reported` give the reporting span. Lowest-ranked stories\nare dropped to fit length; the meta line flags how many were omitted.\n\nAt least one of query/theme/ticker/since/until is required. Per-parameter detail\nis on the input schema \u2014 search_type=claims needs query/ticker/a time window,\nnot theme.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"order_by": {
"description": "Result ordering. relevance (default) | event_time (newest event time first) | create_time (most recently ingested first).",
"enum": [
"relevance",
"event_time",
"create_time"
],
"type": "string"
},
"query": {
"description": "Semantic query (English). One of query/theme/ticker/since/until required.",
"type": "string"
},
"search_type": {
"description": "all (default) | events | claims (opinions/statements only).",
"enum": [
"all",
"events",
"claims"
],
"type": "string"
},
"since": {
"description": "ISO8601; filter time_event >= since.",
"type": "string"
},
"theme": {
"description": "Theme word, resolved to the nearest canonical theme. Not valid with search_type=claims.",
"type": "string"
},
"ticker": {
"anyOf": [
{
"type": "string"
},
{
"items": {
"type": "string"
},
"type": "array"
}
],
"description": "Exact ticker symbol(s) \u2014 a single symbol, an array, or a comma-separated string; multiple tickers are an OR/overlap filter. US symbols bare (AAPL); other markets carry their exchange suffix \u2014 7203.T, 00700.HK, 600519.SH. Company names/brands are NOT resolved here; resolve a name via ticker_lookup/company_search first."
},
"top_k": {
"description": "Story count. Default 10, max 50.",
"maximum": 50,
"minimum": 1,
"type": "integer"
},
"until": {
"description": "ISO8601; filter time_event < until.",
"type": "string"
}
},
"type": "object"
},
"name": "news_search"
}
]
}
},
"url": "https://gateway.drillr.ai/mcp/data"
},
"latency_ms": 25.53,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json"
},
"bad_protocol_payload": {
"error": {
"code": -32000,
"message": "Bad Request: Unsupported protocol version (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"
},
"id": null,
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 404,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 21.47,
"status": "error"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 401,
"probe_status": "auth_required"
}
},
"latency_ms": 21.11,
"status": "ok"
}
},
"failures": {
"openid_configuration": {
"error": "Client error '404 Not Found' for url 'https://gateway.drillr.ai/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gateway.drillr.ai/.well-known/openid-configuration"
},
"schema_divergence_probe": {
"auth_scheme_mismatch": true,
"card_auth_schemes": [
"api_key"
],
"card_server_name": "drillr-agentic",
"card_server_version": "1.0.0",
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_oauth_observed": true,
"live_server_name": "drillr-data",
"live_server_version": "1.0.0",
"server_name_mismatch": true,
"server_version_mismatch": false,
"severity": "critical",
"tool_divergences": [],
"tools_missing_from_card": [
"company_search",
"fiscal_utility",
"get_table_schema",
"list_tables",
"news_search",
"run_sql",
"sec_report_list",
"sec_report_search",
"ticker_lookup"
],
"tools_missing_from_live": [
"search"
],
"tools_with_omitted_schema": []
},
"transport_compliance_probe": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json"
},
"bad_protocol_payload": {
"error": {
"code": -32000,
"message": "Bad Request: Unsupported protocol version (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"
},
"id": null,
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 404,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
}
},
"remote_url": "https://gateway.drillr.ai/mcp/data",
"server_card_payload": {
"authentication": {
"required": true,
"schemes": [
"api_key"
]
},
"serverInfo": {
"name": "drillr-agentic",
"version": "1.0.0"
},
"tools": [
{
"description": "Ask natural-language questions about companies, tickers, sectors, SEC filings, earnings, and alternative data. Runs Drillr's research agent server-side and returns a synthesized answer with source attribution. Pass session_id to continue a prior research thread (~3\u00d7 faster on follow-ups via cache reuse) and context to inject background as ground truth.",
"name": "search"
}
]
},
"server_identifier": "ai.drillr/drillr"
}
Known versions
2.1.0
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 08, 2026 06:49:12 PM UTC | Healthy | 67.7 | 475.2 ms | 9 |
| Aug 08, 2026 06:46:48 AM UTC | Healthy | 40.0 | 361.2 ms | 0 |
| Aug 08, 2026 06:46:48 AM UTC | Healthy | 40.0 | 426.6 ms | 0 |
| Aug 07, 2026 06:34:27 PM UTC | Healthy | 40.0 | 510.9 ms | 0 |
| Aug 07, 2026 06:15:36 AM UTC | Healthy | 40.0 | 394.6 ms | 0 |
| Aug 06, 2026 06:13:33 PM UTC | Healthy | 40.0 | 627.7 ms | 0 |
| Aug 06, 2026 09:55:24 AM UTC | Healthy | 42.4 | 521.4 ms | 0 |
| Aug 06, 2026 03:55:11 AM UTC | Healthy | 42.1 | 442.0 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 08, 2026 06:49:12 PM UTC | Healthy | 67.7 | 2025-03-26 | oauth_supported | 9 | 0 | auth_mode_changed tool_snapshot_changed |
| Aug 08, 2026 06:46:48 AM UTC | Healthy | 40.0 | unknown | unknown | 0 | 0 | none |
| Aug 08, 2026 06:46:48 AM UTC | Healthy | 40.0 | unknown | unknown | 0 | 0 | none |
| Aug 07, 2026 06:34:27 PM UTC | Healthy | 40.0 | unknown | unknown | 0 | 0 | none |
| Aug 07, 2026 06:15:36 AM UTC | Healthy | 40.0 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 06:13:33 PM UTC | Healthy | 40.0 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 09:55:24 AM UTC | Healthy | 42.4 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 03:55:11 AM UTC | Healthy | 42.1 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 07:33:54 PM UTC | Healthy | 43.7 | unknown | unknown | 0 | 0 | none |
| Jul 31, 2026 06:26:33 AM UTC | Healthy | 42.0 | unknown | unknown | 0 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 08, 2026 06:49:12 PM UTC | Completed | Healthy | 475.2 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 08, 2026 06:46:48 AM UTC | Completed | Healthy | 361.2 ms | |
| Aug 08, 2026 06:46:48 AM UTC | Completed | Healthy | 426.6 ms | |
| Aug 07, 2026 06:34:26 PM UTC | Completed | Healthy | 510.9 ms | |
| Aug 07, 2026 06:15:36 AM UTC | Completed | Healthy | 394.6 ms | |
| Aug 06, 2026 06:13:33 PM UTC | Completed | Healthy | 627.7 ms | |
| Aug 06, 2026 09:55:23 AM UTC | Completed | Healthy | 521.4 ms | |
| Aug 06, 2026 03:55:11 AM UTC | Completed | Healthy | 442.0 ms | |
| Aug 05, 2026 07:33:53 PM UTC | Completed | Healthy | 540.6 ms | |
| Jul 31, 2026 06:26:33 AM UTC | Completed | Healthy | 513.6 ms | |
Public server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 08, 2026 06:49:12 PM UTC | Latest validation: healthy | Score 67.7 with status healthy. |
| Aug 08, 2026 06:49:12 PM UTC | Score changed | Score delta +27.7 versus the previous run. |
| Aug 08, 2026 06:49:12 PM UTC | Tool snapshot changed | Added 9, removed 0, and changed 0 tool contracts. |
| Aug 08, 2026 06:49:12 PM UTC | Auth mode changed | Auth mode moved from unknown to oauth_supported. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://drillr.ai/?ref=mp_registry
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://gateway.drillr.ai/mcp/data
- Server card: https://gateway.drillr.ai/.well-known/mcp/server-card.json
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Degraded |
|
| OAuth-required connect | Passes |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Transport compliance drilldown
Issues: missing_session_id, missing_protocol_header, bad_protocol_not_rejected
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Tool snapshot diff & changelog
Required-argument changes
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument changes detected. | ||
Output-schema drift
| Tool | Previous properties | Latest properties |
|---|---|---|
| No output-schema drift detected. | ||
Validation diff
Regressed checks: openid_configuration, provenance_divergence_probe, schema_divergence_probe, transport_compliance_probe
Improved checks: action_safety_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, probe_noise_resilience, server_card, tool_snapshot_probe, tools_list, utility_coverage_probe
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
maintenance_signal_score | 3.0 | 4.0 | 1.0 |
trust_confidence_score | 2.0 | 3.0 | 1.0 |
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | drillr-agentic |
| Version | n/a | 1.0.0 |
| Homepage | n/a | n/a |
Active alerts
- Server card describes a different server: card says "drillr-agentic", live says "drillr-data" (critical)
Severity: critical. The published server card's serverInfo.name does not match the live server. Card declares auth scheme(s) ['api_key'] but the live server negotiates OAuth -- a client trusting the card won't know to attempt it. An agent trusting the published card will construct invalid calls. - Tool snapshot changed (high)
Tools were added, removed, or materially changed between the latest two validations. - Auth mode changed (high)
Auth mode changed from unknown to oauth_supported.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
ai.drillr/drillr |
official_registry | yes | 67.7 |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| Critical | Respond to server card describes a different server: card says "drillr-agentic", live says "drillr-data" | Severity: critical. The published server card's serverInfo.name does not match the live server. Card declares auth scheme(s) ['api_key'] but the live server negotiates OAuth -- a client trusting the card won't know to attempt it. An agent trusting the published card will construct invalid calls. | |
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Respond to auth mode changed | Auth mode changed from unknown to oauth_supported. | Document the new auth posture and confirm protected-resource and challenge metadata still match reality. |
| High | Respond to tool snapshot changed | Tools were added, removed, or materially changed between the latest two validations. | Publish a first-class changelog for tool additions, removals, and breaking schema changes.Playbook
|
| High | Sync the published server card's tool schemas with the live tool surface | The server card and live tools/list disagree on parameter names, required sets, or types -- clients that trust the published card will construct invalid calls. | Regenerate the published server card from the live tool schemas (or vice versa) so parameter names, required sets, and types match exactly.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | |
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Persist session state keyed by Mcp-Session-Id and honor Last-Event-ID on GET reconnects so clients can resume a dropped Streamable HTTP session.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Transport Compliance | 0/4 | -4.0 |
| Resource Contract | 0/4 | -4.0 |
| Request Association | 0/4 | -4.0 |
| Recovery Semantics | 0/4 | -4.0 |
| Prompt Contract | 0/4 | -4.0 |
| Advanced Capability Coverage | 0/4 | -4.0 |
| Utility Coverage | 1/4 | -3.0 |
| Error Contract | 1/4 | -3.0 |
| Dependency Supply Chain Signal | 1/4 | -3.0 |
| Spec Recency | 2/4 | -2.0 |
| Security Hygiene | 2/4 | -2.0 |
| Registry Consistency | 2/4 | -2.0 |
Compatibility profiles
Connector URL: https://gateway.drillr.ai/mcp/data # Complete OAuth in the client when prompted. # Server: ai.drillr/drillr
{
"mcpServers": {
"drillr": {
"command": "npx",
"args": ["mcp-remote", "https://gateway.drillr.ai/mcp/data"]
}
}
}
smithery mcp add "https://gateway.drillr.ai/mcp/data"
curl -sS https://gateway.drillr.ai/mcp/data -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://gateway.drillr.ai/mcp/data # Complete OAuth in the client when prompted. # Server: ai.drillr/drillr
{
"mcpServers": {
"drillr": {
"command": "npx",
"args": ["mcp-remote", "https://gateway.drillr.ai/mcp/data"]
}
}
}
smithery mcp add "https://gateway.drillr.ai/mcp/data"
curl -sS https://gateway.drillr.ai/mcp/data -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.ai.drillr/drillr.