Moonlings — Local Business Intelligence
AI visibility + fact-checks (ChatGPT/Perplexity), review gaps & competitor scans, local SEO.
Allow With Approval
trustsnap_1b6b2f22fa90da0a.- Utility Coverage
- Recovery Semantics
- Advanced Capability Coverage
- Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
- Only send roots/list, sampling/createMessage, or elicitation/create requests while handling an active client-initiated…
- Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.
- No segmented attention signals observed in the current window.
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risk
Security posture
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes |
|---|---|---|---|---|
ping |
read | Low | none | No explicit safeguard hints detected. |
check_visibility |
read | Low | none | No explicit safeguard hints detected. |
review_gap |
read | Low | none | No explicit safeguard hints detected. |
check_facts |
read | Low | none | No explicit safeguard hints detected. |
run_scan |
read | Low | none | No explicit safeguard hints detected. |
start_deep_report |
undetermined | Low | none | No explicit safeguard hints detected. |
check_report_status |
read | Low | none | No explicit safeguard hints detected. |
get_report_result |
read | Low | none | No explicit safeguard hints detected. |
Write-action governance
Status detail: No unsafe write-action governance gaps detected on the latest validation.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
check_facts | Low | none |
check_report_status | Low | none |
check_visibility | Low | none |
get_report_result | Low | none |
ping | Low | none |
review_gap | Low | none |
run_scan | Low | none |
start_deep_report | Low | none |
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Critical alerts
Compatibility
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Warningstep_up_auth_probe• Warningconnector_replay_probe• OK — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Warning
Evidence provenance
action_safety_probe• OK
Evidence provenance
tool_snapshot_probe• OKconnector_replay_probe• OK
Client compatibility gate details
Remediation checklist
The tool surface is not limited to search/fetch-style read tools.This client profile expects a read/search-only tool surface, but write, delete, or exec-capable tools are present.Not yet safe for company-knowledge use: requires a search/fetch-only surface with no write actions present.Not yet safe for the Messages API remote MCP path: requires OAuth, a compatible connector profile, and no pending connector-refresh risk.Transport compliance issues should be resolved before wider client rollout.
Remediation checklist
The tool surface is not limited to search/fetch-style read tools.This client profile expects a read/search-only tool surface, but write, delete, or exec-capable tools are present.Not yet safe for company-knowledge use: requires a search/fetch-only surface with no write actions present.Not yet safe for the Messages API remote MCP path: requires OAuth, a compatible connector profile, and no pending connector-refresh risk.Transport compliance issues should be resolved before wider client rollout.
Remediation checklist
- No explicit blockers recorded.
Verdict traces
tool_snapshot_changed• high • Tool snapshot changedauth_mode_changed• high • Auth mode changed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing allowed | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Medium | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Passes
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Passes
Recommended for
Evidence
Current trust snapshot
trustsnap_1b6b2f22fa90da0aCanonical machine links
Evidence confidence
Latest validation evidence
Failures
server_cardClient error '404 Not Found' for url 'https://moonlings.ai/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
OK | n/a | No high-risk write, destructive, or exec tools detected. |
advanced_capabilities_probe |
Missing | n/a | No advanced MCP capability signals detected. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: server card. |
connector_replay_probe |
OK | n/a | Backward compatible with no breaking tool-surface changes. |
determinism_probe |
OK | 85.3 ms | Check completed |
initialize |
OK | 59.2 ms | Protocol 2025-03-26 |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
OK | 45.4 ms | authorization_endpoint, claims_supported, code_challenge_methods_supported, grant_types_supported |
oauth_protected_resource |
OK | 91.2 ms | 1 authorization server(s) |
official_registry_probe |
OK | n/a | Check completed |
openid_configuration |
OK | 20.3 ms | authorization_endpoint, backchannel_logout_supported, claims_supported, code_challenge_methods_supported |
probe_noise_resilience |
OK | 71.4 ms | Fetched https://moonlings.ai/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Missing | 80.5 ms | not supported |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Missing | 103.7 ms | not supported |
schema_divergence_probe |
Missing | n/a | no server card tools |
server_card |
Error | 72.5 ms | Client error '404 Not Found' for url 'https://moonlings.ai/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
session_resume_probe |
Warning | n/a | no session id |
step_up_auth_probe |
Warning | n/a | Scopes=email, offline access, openid, private metadata, +3 more. |
tool_snapshot_probe |
OK | n/a | Check completed |
tools_list |
OK | 135.5 ms | 8 tool(s) exposed |
transport_compliance_probe |
Warning | 168.2 ms | Issues: missing session id, missing protocol header (bad protocol=400). |
utility_coverage_probe |
Missing | 533.2 ms | No completions evidence; no pagination evidence; tasks missing. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": true,
"confirmation_signals": [],
"reason": null,
"safeguard_count": 0,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {
"read": 7,
"undetermined": 1
},
"declared_non_read_only_tools": 1,
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 8,
"medium": 0
},
"secret_tools": 0,
"tool_count": 8
}
},
"latency_ms": null,
"status": "ok"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [],
"enabled_count": 0,
"initialize_capability_keys": [
"tools"
]
},
"latency_ms": null,
"status": "missing"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"server_card"
],
"criteria": {
"action_safety": true,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": true,
"remote_transport": true,
"request_association": true,
"server_card": false,
"session_resume": true,
"step_up_auth": true,
"tool_surface": true,
"tools_list": true,
"transport_compliance": true
},
"high_risk_tools": 0,
"tool_count": 8,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"connector_replay_probe": {
"details": {
"added_tools": [],
"additive_output_changes": [],
"backward_compatible": true,
"output_breaks": [],
"removed_tools": [],
"required_arg_breaks": [],
"would_break_after_refresh": false
},
"latency_ms": null,
"status": "ok"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "bac446dd532f3682555115324f4631101e8f373a4d7617e2fb21bd79d27bf59c",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 85.26,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"tools": {
"listChanged": true
}
},
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "moonlings",
"version": "0.3.0"
}
}
},
"url": "https://moonlings.ai/api/mcp"
},
"latency_ms": 59.19,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": true,
"prompt_available": false,
"risk_hits": [],
"safe_hits": []
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"headers": {
"content-type": "application/json",
"set-cookie": "_cfuvid=SC4TwQVwULPakpC7IhQ.9XiiDrXDfbkrJx3NLMTsokU-1786000334.1383617-1.0.1.1-13UHC481EMzePVAD97mMZ_ZDxDpIT38zpVSvqlUM9Ok; HttpOnly; SameSite=None; Secure; Path=/; Domain=clerkprod-cloudflare.net, __cf_bm=Uc03kVQHkPZ3d.egIHC5fjV2XfJE8_K92l1.ZMO92BY-1786000334-1.0.1.1-80HGpSjteX1R5WzBh8B6WhvDcUMpIWafjj_nU0tXdHJXsiMgx_y97U.KEKw4oAk__h2cSocgqvVhaKKPDcDQDshMkCl4jdbfFg50Dlcqd.U; path=/; expires=Thu, 06-Aug-26 07:42:14 GMT; domain=.clerk.moonlings.ai; HttpOnly; Secure; SameSite=None, _cfuvid=tMiYOn._Egnp0owiSEvUasU99LZfT22v0KuEAnDdzGY-1786000334144-0.0.1.1-604800000; path=/; domain=.clerk.moonlings.ai; HttpOnly; Secure; SameSite=None",
"strict-transport-security": "max-age=63072000;"
},
"http_status": 200,
"payload": {
"authorization_endpoint": "https://clerk.moonlings.ai/oauth/authorize",
"claims_supported": [
"sub",
"iss",
"aud",
"exp",
"iat",
"email",
"name",
"org_id"
],
"code_challenge_methods_supported": [
"S256"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"issuer": "https://clerk.moonlings.ai",
"jwks_uri": "https://clerk.moonlings.ai/.well-known/jwks.json",
"op_tos_uri": "https://clerk.com/legal/standard-terms",
"registration_endpoint": "https://clerk.moonlings.ai/oauth/register",
"response_types_supported": [
"code"
],
"revocation_endpoint": "https://clerk.moonlings.ai/oauth/token/revoke",
"scopes_supported": [
"openid",
"profile",
"email",
"public_metadata",
"private_metadata",
"offline_access",
"user:org:read"
],
"service_documentation": "https://clerk.com/docs/oauth/scoped-access",
"subject_types_supported": [
"public"
],
"token_endpoint": "https://clerk.moonlings.ai/oauth/token",
"token_endpoint_auth_methods_supported": [
"client_secret_basic",
"none",
"client_secret_post"
],
"ui_locales_supported": [
"en"
]
},
"url": "https://clerk.moonlings.ai/.well-known/oauth-authorization-server"
},
"latency_ms": 45.43,
"status": "ok"
},
"oauth_protected_resource": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"authorization_data_locations_supported": [
"header",
"body"
],
"authorization_data_types_supported": [
"oauth_scope"
],
"authorization_servers": [
"https://clerk.moonlings.ai"
],
"jwks_uri": "https://clerk.moonlings.ai/.well-known/jwks.json",
"key_challenges_supported": [
{
"challenge_algs": [
"S256"
],
"challenge_type": "urn:ietf:params:oauth:pkce:code_challenge"
}
],
"resource": "https://moonlings.ai",
"service_documentation": "https://moonlings.ai/mcp",
"token_introspection_endpoint": "https://clerk.moonlings.ai/oauth/token",
"token_introspection_endpoint_auth_methods_supported": [
"client_secret_post",
"client_secret_basic"
],
"token_types_supported": [
"urn:ietf:params:oauth:token-type:access_token"
]
},
"url": "https://moonlings.ai/.well-known/oauth-protected-resource"
},
"latency_ms": 91.25,
"status": "ok"
},
"official_registry_probe": {
"details": {
"direct_match": true,
"official_peer_count": 1,
"registry_identifier": "ai.moonlings/moonlings",
"registry_source": "official_registry"
},
"latency_ms": null,
"status": "ok"
},
"openid_configuration": {
"details": {
"headers": {
"content-type": "application/json",
"set-cookie": "_cfuvid=ZOKzl7nrGWyfgDFIGfEXWfuq6kqWukrI1jGyxRjUO9w-1786000334.1613648-1.0.1.1-4YqvlJNO3NP_lg4Mc0BbNdFfHtchuWQo3n6hudVxyKg; HttpOnly; SameSite=None; Secure; Path=/; Domain=clerkprod-cloudflare.net",
"strict-transport-security": "max-age=63072000;"
},
"http_status": 200,
"payload": {
"authorization_endpoint": "https://clerk.moonlings.ai/oauth/authorize",
"backchannel_logout_supported": false,
"claims_supported": [
"preferred_username",
"aud",
"iss",
"email",
"email_verified",
"family_name",
"picture",
"sub",
"exp",
"iat",
"given_name",
"name",
"org_id"
],
"code_challenge_methods_supported": [
"S256"
],
"frontchannel_logout_supported": false,
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"introspection_endpoint": "https://clerk.moonlings.ai/oauth/token_info",
"issuer": "https://clerk.moonlings.ai",
"jwks_uri": "https://clerk.moonlings.ai/.well-known/jwks.json",
"response_modes_supported": [
"form_post",
"query"
],
"response_types_supported": [
"code"
],
"revocation_endpoint": "https://clerk.moonlings.ai/oauth/token/revoke",
"scopes_supported": [
"openid",
"offline_access",
"user:org:read",
"email",
"profile",
"public_metadata",
"private_metadata"
],
"subject_types_supported": [
"public"
],
"token_endpoint": "https://clerk.moonlings.ai/oauth/token",
"token_endpoint_auth_methods_supported": [
"client_secret_basic",
"none",
"client_secret_post"
],
"userinfo_endpoint": "https://clerk.moonlings.ai/oauth/userinfo"
},
"url": "https://clerk.moonlings.ai/.well-known/openid-configuration"
},
"latency_ms": 20.31,
"status": "ok"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/html; charset=utf-8",
"strict-transport-security": "max-age=63072000"
},
"http_status": 404,
"url": "https://moonlings.ai/robots.txt",
"validation_disallowed": false
},
"latency_ms": 71.37,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found"
},
"id": 3,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://moonlings.ai/api/mcp"
},
"latency_ms": 80.46,
"status": "missing"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": true,
"drift_fields": [],
"metadata_document_count": 2,
"readable_sources": [
"registry"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": null,
"server_card_version": null
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found"
},
"id": 5,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://moonlings.ai/api/mcp"
},
"latency_ms": 103.74,
"status": "missing"
},
"schema_divergence_probe": {
"details": {
"compared_dimensions": [
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"reason": "no_server_card_tools"
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"error": "Client error '404 Not Found' for url 'https://moonlings.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://moonlings.ai/.well-known/mcp/server-card.json"
},
"latency_ms": 72.46,
"status": "error"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": true,
"scope_specificity_ratio": 0.25,
"step_up_signals": [],
"supported_scopes": [
"email",
"offline_access",
"openid",
"private_metadata",
"profile",
"public_metadata",
"user:org:read"
]
},
"latency_ms": null,
"status": "warning"
},
"tool_snapshot_probe": {
"details": {
"added": [],
"changed_outputs": [],
"current_tool_count": 8,
"previous_tool_count": 8,
"removed": [],
"similarity": 1.0
},
"latency_ms": null,
"status": "ok"
},
"tools_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"readOnlyHint": true
},
"description": "Returns server status, the price list, and (when authenticated) your credit balance. Free \u2014 call it to check connectivity and see what this server offers.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "ping",
"title": "Ping Moonlings"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Ask ChatGPT and Perplexity live (with web search) who they'd recommend in a business's category and city, and report whether THIS business appears. Returns honest appearance counts (never an invented metric), a per-engine split, who gets recommended instead, and which local sites the AI answers cite. AI answers vary substantially between runs \u2014 one check is a snapshot, not a stable measurement; re-check over time for the real picture. Call this when a user wants to know if AI assistants recommend a local business. Takes ~10-30 seconds. Price: $0.79 per delivered check.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"businessName": {
"description": "The local business to check",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"businessType": {
"description": "Category anchor, e.g. \"gym\" \u2014 the AI assistants are asked category questions, so this is required",
"maxLength": 80,
"minLength": 1,
"type": "string"
},
"location": {
"description": "City and state/region, e.g. \"Cincinnati, OH\"",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"website": {
"description": "Optional: the business website \u2014 a cited domain counts as an appearance",
"maxLength": 300,
"type": "string"
}
},
"required": [
"businessName",
"location",
"businessType"
],
"type": "object"
},
"name": "check_visibility",
"title": "AI Visibility Check"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Compare a local business's Google rating and review count against the top same-category rivals nearby, with the gap math done: who leads, the rating delta, the review-volume ratio, and a verdict (leading / rated_equal_or_better_but_outreviewed / trailing). Live Google Maps lookup at call time. Call this when a user wants to know how a business's reviews stack up against local competitors. Takes a few seconds. Price: $0.39 per delivered comparison.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"address": {
"description": "Optional: street address of the SPECIFIC location to compare, e.g. \"332 Ludlow Ave\" \u2014 use for chains/multi-location businesses so the right branch anchors the comparison",
"maxLength": 200,
"type": "string"
},
"businessName": {
"description": "The local business to check",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"businessType": {
"description": "Category anchor, e.g. \"dentist\" \u2014 rivals are the top Google Maps results for this category nearby",
"maxLength": 80,
"minLength": 1,
"type": "string"
},
"location": {
"description": "City and state/region, e.g. \"Cincinnati, OH\"",
"maxLength": 120,
"minLength": 1,
"type": "string"
}
},
"required": [
"businessName",
"location",
"businessType"
],
"type": "object"
},
"name": "review_gap",
"title": "Review Gap Check"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Find what AI assistants get WRONG about a local business. Asks ChatGPT and Perplexity live (with web search) about the business's hours, address, phone, and category, then verifies each stated fact against Google Business ground truth. Returns a severity-ranked list of conflicts (with the AI's value vs. the trusted value and source) plus discrepancies to check. Conservative by design: a claim with no trusted source is 'unverifiable' (never an error), and a conflict is only counted when it reproduces across engines \u2014 so it won't cry wolf. Call this when a user asks whether AI has the right info about a business, or 'why does ChatGPT say we're closed'. Takes ~15-30 seconds. Price: $1.49 per delivered check.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"businessName": {
"description": "The local business to fact-check",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"businessType": {
"description": "Optional category anchor, e.g. \"restaurant\" \u2014 helps resolve the business; not required",
"maxLength": 80,
"type": "string"
},
"location": {
"description": "City and state/region, e.g. \"Cincinnati, OH\"",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"website": {
"description": "Optional: the business website \u2014 if an AI answer cites this domain, a mismatch is treated as a possibly-stale discrepancy rather than an error",
"maxLength": 300,
"type": "string"
}
},
"required": [
"businessName",
"location"
],
"type": "object"
},
"name": "check_facts",
"title": "AI Fact-Check"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "A live competitor scan: a research agent finds the business's strongest same-category rival nearby and scouts it (offer, pricing signals, review positioning, what they do that this business doesn't), while two ground-truth lookups run in parallel: ChatGPT/Perplexity sampling for AI-assistant visibility, and a direct Google Places review comparison (reviewSnapshot \u2014 the authoritative numbers; finding source URLs are verified against what the agent actually retrieved). The AI-visibility portion is a single-run snapshot \u2014 AI answers vary substantially between runs. BLOCKING and slow: typically 2-4 minutes \u2014 only call it from contexts that tolerate a long tool call. Price: $1.99 per delivered scan; a failed scan is never charged.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"address": {
"description": "Optional: street address of the SPECIFIC location to scan, e.g. \"332 Ludlow Ave\" \u2014 use for chains/multi-location businesses so the right branch anchors the review comparison",
"maxLength": 200,
"type": "string"
},
"businessName": {
"description": "The local business to scan",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"businessType": {
"description": "Category anchor, e.g. \"ice cream shop\" \u2014 rival discovery and AI sampling are both category-anchored",
"maxLength": 80,
"minLength": 1,
"type": "string"
},
"location": {
"description": "City and state/region, e.g. \"Cincinnati, OH\"",
"maxLength": 120,
"minLength": 1,
"type": "string"
}
},
"required": [
"businessName",
"location",
"businessType"
],
"type": "object"
},
"name": "run_scan",
"title": "Competitor Quick Scan"
},
{
"annotations": {
"destructiveHint": false,
"readOnlyHint": false
},
"description": "Launch a full overnight-grade research report on a local business: an autonomous research crew maps the competitive landscape, reads the business's and rivals' web presence, and delivers a long-form graded report with structured findings and an action list. ASYNC: this tool returns a slug immediately; the report takes roughly 10-20 minutes. Poll check_report_status, then fetch with get_report_result. Price: $9.99, charged when the report launches; if the report fails, the charge is refunded automatically. Each call starts a NEW report \u2014 do not retry a call that already returned a slug.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"brief": {
"description": "Optional research focus, e.g. \"we're losing weekend foot traffic \u2014 figure out why\"",
"maxLength": 2000,
"type": "string"
},
"businessName": {
"description": "The local business to research",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"businessType": {
"description": "Category anchor, e.g. \"dentist\" \u2014 competitor discovery is category-anchored",
"maxLength": 80,
"minLength": 1,
"type": "string"
},
"location": {
"description": "City and state/region, e.g. \"Cincinnati, OH\"",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"website": {
"description": "Optional: the business website, read to ground services and positioning",
"maxLength": 300,
"type": "string"
}
},
"required": [
"businessName",
"location",
"businessType"
],
"type": "object"
},
"name": "start_deep_report",
"title": "Start Deep Research Report"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Poll a deep research report by slug. Free. Returns status (generating / ready / failed); a failed report triggers the automatic refund of its launch charge. Deep reports typically take 10-20 minutes \u2014 poll every few minutes, not every few seconds.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"slug": {
"description": "The slug returned by start_deep_report",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"name": "check_report_status",
"title": "Check Report Status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Fetch a completed deep research report by slug. Free. Returns the long-form report (markdown), a structured-findings JSON block, the action list, and the report card. If the report is still generating you get its status instead; if it failed, the launch charge is refunded automatically.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"slug": {
"description": "The slug returned by start_deep_report",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"name": "get_report_result",
"title": "Get Report Result"
}
]
}
},
"url": "https://moonlings.ai/api/mcp"
},
"latency_ms": 135.52,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"bad_protocol_payload": {
"error": {
"code": -32000,
"message": "Bad Request: Unsupported protocol version: 1999-99-99 (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"
},
"id": null,
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 400,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 168.21,
"status": "warning"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 200,
"probe_status": "missing"
}
},
"latency_ms": 533.23,
"status": "missing"
}
},
"failures": {
"server_card": {
"error": "Client error '404 Not Found' for url 'https://moonlings.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://moonlings.ai/.well-known/mcp/server-card.json"
}
},
"remote_url": "https://moonlings.ai/api/mcp",
"server_card_payload": null,
"server_identifier": "ai.moonlings/moonlings"
}
Known versions
0.4.1
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 06, 2026 07:12:15 AM UTC | Healthy | 73.9 | 1565.7 ms | 8 |
| Aug 06, 2026 07:12:08 AM UTC | Healthy | 44.3 | 1841.1 ms | 0 |
| Aug 06, 2026 01:11:39 AM UTC | Healthy | 44.1 | 1907.2 ms | 0 |
| Aug 05, 2026 07:06:52 PM UTC | Healthy | 45.4 | 2041.6 ms | 0 |
| Aug 04, 2026 08:51:28 PM UTC | Healthy | 44.2 | 1993.8 ms | 0 |
| Jul 31, 2026 06:42:46 AM UTC | Healthy | 43.5 | 1598.9 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 06, 2026 07:12:15 AM UTC | Healthy | 73.9 | 2025-03-26 | oauth_supported | 8 | 0 | auth_mode_changed tool_snapshot_changed |
| Aug 06, 2026 07:12:08 AM UTC | Healthy | 44.3 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 01:11:39 AM UTC | Healthy | 44.1 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 07:06:52 PM UTC | Healthy | 45.4 | unknown | unknown | 0 | 0 | none |
| Aug 04, 2026 08:51:28 PM UTC | Healthy | 44.2 | unknown | unknown | 0 | 0 | none |
| Jul 31, 2026 06:42:46 AM UTC | Healthy | 43.5 | unknown | unknown | 0 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 06, 2026 07:12:13 AM UTC | Completed | Healthy | 1565.7 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 06, 2026 07:12:06 AM UTC | Completed | Healthy | 1841.1 ms | |
| Aug 06, 2026 01:11:37 AM UTC | Completed | Healthy | 1907.2 ms | |
| Aug 05, 2026 07:06:50 PM UTC | Completed | Healthy | 2041.6 ms | |
| Aug 04, 2026 08:51:26 PM UTC | Completed | Healthy | 1993.8 ms | |
| Jul 31, 2026 06:42:45 AM UTC | Completed | Healthy | 1598.9 ms | |
Public server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 06, 2026 07:12:15 AM UTC | Latest validation: healthy | Score 73.9 with status healthy. |
| Aug 06, 2026 07:12:15 AM UTC | Score changed | Score delta +29.6 versus the previous run. |
| Aug 06, 2026 07:12:15 AM UTC | Tool snapshot changed | Added 8, removed 0, and changed 0 tool contracts. |
| Aug 06, 2026 07:12:15 AM UTC | Auth mode changed | Auth mode moved from unknown to oauth_supported. |
| Aug 06, 2026 07:12:08 AM UTC | Score changed | Score delta +0.2 versus the previous run. |
| Aug 06, 2026 01:11:39 AM UTC | Score changed | Score delta -1.3 versus the previous run. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://moonlings.ai/mcp
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://moonlings.ai/api/mcp
- Server card: none
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Degraded |
|
| OAuth-required connect | Passes |
|
| Safe write flow with confirmation | Passes |
|
Utility coverage
Transport compliance drilldown
Issues: missing_session_id, missing_protocol_header
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Tool snapshot diff & changelog
Required-argument changes
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument changes detected. | ||
Output-schema drift
| Tool | Previous properties | Latest properties |
|---|---|---|
| No output-schema drift detected. | ||
Validation diff
Regressed checks: provenance_divergence_probe, server_card
Improved checks: action_safety_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, tool_snapshot_probe, tools_list
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
| No component deltas between the latest two runs. | |||
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | n/a |
| Version | n/a | n/a |
| Homepage | n/a | n/a |
Active alerts
- Tool snapshot changed (high)
Tools were added, removed, or materially changed between the latest two validations. - Auth mode changed (high)
Auth mode changed from unknown to oauth_supported.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
ai.moonlings/moonlings |
official_registry | yes | 73.9 |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Associate roots, sampling, and elicitation with active client requests | Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions. | Only send roots/list, sampling/createMessage, or elicitation/create requests while handling an active client-initiated request, never on idle sessions.Playbook
|
| High | Publish a complete server card | Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. | Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.Playbook
|
| High | Respond to auth mode changed | Auth mode changed from unknown to oauth_supported. | Document the new auth posture and confirm protected-resource and challenge metadata still match reality. |
| High | Respond to tool snapshot changed | Tools were added, removed, or materially changed between the latest two validations. | Publish a first-class changelog for tool additions, removals, and breaking schema changes.Playbook
|
| High | Sync the published server card's tool schemas with the live tool surface | The server card and live tools/list disagree on parameter names, required sets, or types -- clients that trust the published card will construct invalid calls. | Regenerate the published server card from the live tool schemas (or vice versa) so parameter names, required sets, and types match exactly.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | |
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Reconcile registry, server-card, and repository metadata | Directory trust falls quickly when official registry fields drift from the live server card or public repo metadata. | |
| Medium | Repair prompts/list or stop advertising prompts | Prompt metadata should either work live or be removed from the advertised capability set. | Only advertise prompts if prompts/list works and prompt arguments are documented.Playbook
|
| Medium | Repair resources/list or stop advertising resources | Resource metadata should either work live or be removed from the advertised capability set. | Only advertise resources if resources/list works and resources expose stable URIs/types.Playbook
|
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Persist session state keyed by Mcp-Session-Id and honor Last-Event-ID on GET reconnects so clients can resume a dropped Streamable HTTP session.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 0/4 | -4.0 |
| Recovery Semantics | 0/4 | -4.0 |
| Advanced Capability Coverage | 0/4 | -4.0 |
| Dependency Supply Chain Signal | 1/4 | -3.0 |
| Trust Confidence | 2/4 | -2.0 |
| Transport Compliance | 2/4 | -2.0 |
| Spec Recency | 2/4 | -2.0 |
| Safety Transparency | 2/4 | -2.0 |
| Registry Consistency | 2/4 | -2.0 |
| Rate Limit Semantics | 2/4 | -2.0 |
| Error Contract | 2/4 | -2.0 |
| Discovery Metadata | 2/4 | -2.0 |
Compatibility profiles
Connector URL: https://moonlings.ai/api/mcp # Complete OAuth in the client when prompted. # Server: ai.moonlings/moonlings
{
"mcpServers": {
"moonlings": {
"command": "npx",
"args": ["mcp-remote", "https://moonlings.ai/api/mcp"]
}
}
}
smithery mcp add "https://moonlings.ai/api/mcp"
curl -sS https://moonlings.ai/api/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://moonlings.ai/api/mcp # Complete OAuth in the client when prompted. # Server: ai.moonlings/moonlings
{
"mcpServers": {
"moonlings": {
"command": "npx",
"args": ["mcp-remote", "https://moonlings.ai/api/mcp"]
}
}
}
smithery mcp add "https://moonlings.ai/api/mcp"
curl -sS https://moonlings.ai/api/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.ai.moonlings/moonlings.