← Back to search
ai.nothumansearch/search

Not Human Search

Search engine for AI agents. Find websites and APIs ranked by agentic readiness.

DECISION SUMMARY

Block For Production

Score
3.8
Rank suppressed while production readiness shows a blocking verdict.
Confidence
Low
Based on evidence completeness, recency, and validation density.
Evidence age
9.7h old
Freshness: fresh. Snapshot trustsnap_c8e548ad009e66ab.
Top risk drivers
  • Utility Coverage
  • Tool Surface Design
  • Tool Snapshot Churn
Recommended actions
  • Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
  • Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.
  • Compare initialize responses between the latest two runs and restore the previous stable behavior.
Next action
revalidate, add safeguards, export policy
score below evaluation threshold
Compare alternatives Export policy Open report JSON Dispute this assessment
Observed Attention
No observed attention
No observed attention in the current 30-day window.
  • No segmented attention signals observed in the current window.
Bucketed signal based on recent segmented Verify telemetry. Crawler and evaluator activity is not treated as confirmed human demand.
Status
Unknown
Score
3.8
Transport
streamable-http
Tools
14
DISPUTE THIS ASSESSMENT

Dispute this assessment

If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.

Verify responds to disputes within 5 business days and resolves them within 15.

Dispute history

No disputes filed for this server.

Risks

Security posture
Tools analyzed
0
High-risk tools
0
Destructive tools
0
Exec tools
0
Egress tools
0
Secret tools
0
Bulk-access tools
0
Risk distribution
none
Tool capability & risk inventory

No tool inventory available from the latest validation run.

Write-action governance
Governance status
Not_Assessed
Safe to publish
Auth boundary
public_or_unclear
Blast radius
Low
High-risk tools
0
Confirmation signals
none
Safeguard count
0

Status detail: No write-action governance evidence is available yet.

ToolRiskFlagsSafeguards
High-risk tool assessment unavailable -- no tools were analyzed.
Action-controls diff
Snapshot changed
yes
Disabled-by-default candidates
none
New actions
ActionRiskFlags
No newly added actions.
Changed actions
ActionChange typesRisk
No materially changed actions.
Critical alerts
High/critical-severity alerts
11
Production verdicts degrade quickly when high or critical-severity alerts are active.

Compatibility

Client compatibility verdicts

Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.

Client compatibility: ChatGPT
Not client-compatible
OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Initialize must be reachable.; tools/list must succeed.; Transport compliance failed or did not complete successfully.; Step-up auth signals should be documented and connector-friendly.
Confidence: low (46.25)
Evidence provenance
Winner: live_validation
Supporting sources: live_validation, history, server_card
Disagreements: none
  • initializeNot_Assessed
  • tools_listNot_Assessed
  • transport_compliance_probeNot_Assessed
  • step_up_auth_probeNot_Assessed
  • connector_replay_probeNot_Assessed — Frozen tool snapshots must survive refresh.
  • request_association_probeNot_Assessed — Roots, sampling, and elicitation should stay request-scoped.
Client compatibility: Claude
Not client-compatible
Initialize must succeed or cleanly request auth.; tools/list must succeed.; Transport behavior should match Claude-compatible HTTP expectations.; The tool surface is not limited to search/fetch-style read tools.; OAuth is not configured, so this client cannot authenticate without additional setup.; Not yet safe for company-knowledge use: requires a search/fetch-only surface with no export, bulk, mutating, or high-blast-radius exposure.
Confidence: low (46.25)
Evidence provenance
Winner: live_validation
Supporting sources: live_validation, history, server_card
Disagreements: none
  • initializeNot_Assessed
  • tools_listNot_Assessed
  • transport_compliance_probeNot_Assessed
Write-action publishing
Publishing blocked
action_safety_probe has not run yet -- no tool surface was observed, so write-action safety could not be assessed. Active alert(s) affecting production readiness: Score dropped materially, Initialize flow regressed, tools/list regressed.
Confidence: low (46.25)
Evidence provenance
Winner: live_validation
Supporting sources: live_validation, history
Disagreements: none
  • action_safety_probeNot_Assessed
Snapshot churn risk
Medium
The live tool surface changed between recent validations.
Confidence: low (46.25)
Evidence provenance
Winner: history
Supporting sources: history, live_validation
Disagreements: none
  • tool_snapshot_probeNot_Assessed
  • connector_replay_probeNot_Assessed
Client compatibility gate details
ChatGPT custom connector
Not client-compatible
OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Initialize must be reachable.; tools/list must succeed.; Transport compliance failed or did not complete successfully.; Step-up auth signals should be documented and connector-friendly.
Remediation checklist
  • Add OAuth-based authentication for remote connector auth.
  • Support dynamic client registration (DCR) to simplify connector setup.
  • Fix the server so its initialize handshake succeeds.
  • Fix the server so tools/list returns successfully.
  • Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
  • Document step-up auth requirements in a connector-friendly way.
Claude remote MCP
Not client-compatible
Initialize must succeed or cleanly request auth.; tools/list must succeed.; Transport behavior should match Claude-compatible HTTP expectations.; The tool surface is not limited to search/fetch-style read tools.; OAuth is not configured, so this client cannot authenticate without additional setup.; Not yet safe for company-knowledge use: requires a search/fetch-only surface with no export, bulk, mutating, or high-blast-radius exposure.
Remediation checklist
  • Fix the server so initialize succeeds or cleanly requests auth.
  • Fix the server so tools/list returns successfully.
  • Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
  • Limit the exposed surface to search/fetch-style read tools.
  • Configure OAuth for authenticated remote MCP access.
  • Remove export, bulk, mutating, and high-blast-radius exposure before certifying company-knowledge use.
Write-safe publishing
Blocked
Production readiness is blocked by an active alert: Score dropped materially.; Production readiness is blocked by an active alert: Initialize flow regressed.; Production readiness is blocked by an active alert: tools/list regressed.
Remediation checklist
  • Resolve the active alert: Score dropped materially.
  • Resolve the active alert: Initialize flow regressed.
  • Resolve the active alert: tools/list regressed.
Verdict traces
Production verdict
Needs remediation
Current validation evidence shows operational or discovery gaps that should be fixed first.
Confidence: low (46.25)
Winning source: metadata
Triggering alerts
  • score_drop • high • Score dropped materially
  • tool_count_drop • medium • Tool count decreased
  • initialize_regressed • critical • Initialize flow regressed
  • tools_list_regressed • critical • tools/list regressed
  • tool_snapshot_changed • high • Tool snapshot changed
  • auth_mode_changed • high • Auth mode changed
Client verdict trace table
VerdictStatusChecksWinning sourceConflicts
openai_connectors Not client-compatible initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe live_validation none
claude_desktop Not client-compatible initialize, tools_list, transport_compliance_probe live_validation none
unsafe_for_write_actions Publishing blocked action_safety_probe live_validation none
snapshot_churn_risk Medium tool_snapshot_probe, connector_replay_probe history none
Publishability policy profiles
ChatGPT custom connector compatibility
Not connector-compatible
OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Initialize must be reachable.; tools/list must succeed.; Transport compliance failed or did not complete successfully.; Step-up auth signals should be documented and connector-friendly. Compatibility is not a production approval; company knowledge and Messages API gates remain separate.
  • Search Fetch Only: No
  • Write Actions Present: No
  • Oauth Configured: No
  • Admin Refresh Required: No
  • Safe For Company Knowledge: No
  • Safe For Messages Api Remote Mcp: No
Claude remote MCP compatibility
Not connector-compatible
Initialize must succeed or cleanly request auth.; tools/list must succeed.; Transport behavior should match Claude-compatible HTTP expectations.; The tool surface is not limited to search/fetch-style read tools.; OAuth is not configured, so this client cannot authenticate without additional setup.; Not yet safe for company-knowledge use: requires a search/fetch-only surface with no export, bulk, mutating, or high-blast-radius exposure. Compatibility is not a production approval; company knowledge and Messages API gates remain separate.
  • Search Fetch Only: No
  • Write Actions Present: No
  • Oauth Configured: No
  • Admin Refresh Required: No
  • Safe For Company Knowledge: No
  • Safe For Messages Api Remote Mcp: No
Compatibility fixtures
ChatGPT custom connector fixture
Degraded
OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Initialize must be reachable.; tools/list must succeed.; Transport compliance failed or did not complete successfully.; Step-up auth signals should be documented and connector-friendly.; OAuth interoperability should be strong.
  • remote_http_endpoint: Passes
  • oauth_discovery: Degraded
  • frozen_tool_snapshot_refresh: Passes
  • request_association: Likely to fail
Anthropic remote MCP fixture
Degraded
Initialize must succeed or cleanly request auth.; tools/list must succeed.; Transport behavior should match Claude-compatible HTTP expectations.
  • remote_transport: Passes
  • tool_discovery: Likely to fail
  • auth_connect: Likely to fail
  • safe_write_review: Degraded
Recommended for
Metadata-first exploration only
Evidence confidence is still low, so verify the server manually before depending on it.

Evidence

Current trust snapshot
Snapshot ID
trustsnap_c8e548ad009e66ab
Use this ID to compare server page, report, policy, MCP, homepage, ranking, and shortlist surfaces.
Snapshot generated
Aug 11, 2026 05:22:06 PM UTC
All page, report, policy, and MCP surfaces use this same server-detail snapshot shape.
Last validated
Aug 11, 2026 07:38:00 AM UTC
Age: 9.74h • evidence age tier: Verified in last 24h • display score: 3.75

Canonical machine links

Evidence confidence
Confidence score
46.2
Based on 1 recent validations, 0 captured checks, and validation age of 9.7 hours.
Live checks captured
0
More direct checks increase trust in the current verdict.
Validation age
9.7h
Lower age means fresher evidence.
Latest validation evidence
Latest summary
Unknown
Validation profile
remote_mcp
Started
Aug 11, 2026 07:37:50 AM UTC
Latency
10111.5 ms

Failures

  • probe_noise_resilience The read operation timed out

Checks

CheckStatusLatencyEvidence
action_safety_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
advanced_capabilities_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
connector_publishability_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
connector_replay_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
determinism_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
initialize Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
interactive_flow_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
oauth_authorization_server Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
oauth_protected_resource Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
official_registry_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
openid_configuration Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
probe_noise_resilience Error 10086.2 ms The read operation timed out
prompt_get Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
prompts_list Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
protocol_version_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
provenance_divergence_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
request_association_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
resource_read Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
resources_list Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
schema_divergence_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
server_card Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
session_resume_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
step_up_auth_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
tool_snapshot_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
tools_list Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
transport_compliance_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
utility_coverage_probe Not_Assessed n/a Not assessed -- robots.txt consent could not be confirmed.
Known versions
  • 1.0.0
Public server reputation
Validation success 7d
1.0
Validation success 30d
1.0
Mean time to recover
n/a
Breaking diffs 30d
1
Registry drift frequency 30d
0
Snapshot changes 30d
1
Benchmark tasks
Benchmark taskStatusEvidence
Discover tools Likely to fail
  • initializeNot_Assessed
  • tools_listNot_Assessed
Read-only fetch flow Likely to fail
  • resource_readNot_Assessed
  • read_only_tool_surfaceMissing
OAuth-required connect Degraded
  • oauth_protected_resourceNot_Assessed
  • step_up_auth_probeNot_Assessed
Safe write flow with confirmation Likely to fail
  • action_safety_probeNot_Assessed
Utility coverage
Probe status
Not_Assessed
Completions
not detected
Completion probe target: none
Pagination
not detected
No nextCursor evidence.
Tasks
Missing
Advertised: no
Tool snapshot diff & changelog
Snapshot changed
yes
Added tools
none
Removed tools
check_url find_mcp_servers get_site_details get_stats get_top_sites handoff_provider_action list_categories prepare_provider_action recent_additions record_action_interest register_monitor search_agents submit_site verify_mcp
Required-argument changes
ToolAdded required argsRemoved required args
No required-argument changes detected.
Output-schema drift
ToolPrevious propertiesLatest properties
No output-schema drift detected.
Validation diff
Score delta
-59.73
Summary changed
yes
Tool delta
-14
Prompt delta
0
Auth mode changed
yes
Write surface expanded
no
Protocol regressed
no
Registry drift changed
no

Regressed checks: action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, utility_coverage_probe

Improved checks: oauth_protected_resource, server_card, transport_compliance_probe

Newly assessed dimensions: none

No longer assessed dimensions: abuse_noise_ratio_score, action_safety_score, destructive_operation_safety_score, egress_ssrf_resilience_score, execution_sandbox_safety_score, least_privilege_scope_score, secret_handling_hygiene_score, transport_compliance_score

ComponentPreviousLatestDelta
interactive_flow_safety_score4.00.0-4.0
session_semantics_score4.00.0-4.0
task_success_score4.00.0-4.0
tool_capability_clarity_score4.00.0-4.0
tool_namespace_clarity_score4.00.0-4.0
tool_snapshot_churn_score4.00.0-4.0
backward_compatibility_score4.01.0-3.0
connector_publishability_score3.00.0-3.0
Registry & provenance divergence
Probe status
Not_Assessed
Direct official match
no
Drift fields
none
Cross-registry alias disagreements
none
FieldRegistryLive server card
Titlen/an/a
Versionn/an/a
Homepagen/an/a
Active alerts
  • Score dropped materially (high)
    Score fell by 59.7 points versus the previous run.
  • Tool count decreased (medium)
    Advertised tool count dropped by 14.
  • Initialize flow regressed (critical)
    A client-visible initialize behavior changed for the worse.
  • tools/list regressed (critical)
    Tool discovery became less reliable on the latest run.
  • Tool snapshot changed (high)
    Tools were added, removed, or materially changed between the latest two validations.
  • Auth mode changed (high)
    Auth mode changed from public to unknown.
Aliases & registry graph
IdentifierSourceCanonicalIdentity evidenceScore
ai.nothumansearch/search official_registry yes canonical 3.8
Alias consolidation

Strong alias identity requires matching remote URL, server-card URL, repository slug, or explicit registry cross-reference; shared provider namespace alone is not identity.

Canonical identifier
ai.nothumansearch/search
Duplicate aliases
0
Registry sources
official_registry
Source disagreements
FieldWhat differsObserved values
No source disagreements detected.

Fix it

Why this score?
Access & Protocol
5/44
Connectivity, auth, and transport expectations for common clients.
Interface Quality
7/56
How well the tool/resource interface communicates and behaves under automation.
Security Posture
0/36
How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.
Reliability & Trust
10/24
Operational stability, consistency, and trustworthiness over time.
Discovery & Governance
14/28
How well the server is documented, listed, and governed in public registries.
Adoption & Market
2/8
Adoption clues and public evidence that the server is intended for external use.
Algorithmic score breakdown
Auth Operability
0/4
Measures whether auth discovery and protected access behave predictably for clients.
Error Contract Quality
0/4
Grades machine-readable error structure, status alignment, and remediation hints.
Rate-Limit Semantics
2/4
Checks whether quota/throttle responses are deterministic and automation-friendly.
Schema Completeness
0/4
Completeness of tool descriptions, parameter docs, examples, and schema shape.
Backward Compatibility
1/4
Stability score across tool schema/name drift relative to prior validations.
SLO Health
3/4
Availability, latency, and burst-failure profile across recent validation history.
Security Hygiene
0/4
HTTPS posture, endpoint hygiene, and response-surface hardening checks.
Task Success
0/4
Can an agent reliably initialize, enumerate tools, and execute core MCP flows?
Trust Confidence
3/4
Confidence-adjusted reliability score that penalizes low evidence volume.
Prompt Contract
2/4
Quality of prompt metadata, argument shape, and prompt discoverability for clients.
Resource Contract
2/4
How completely resources and resource templates describe URIs, types, and usage shape.
Discovery Metadata
2/4
Homepage, docs, icon, repository, support, and license coverage for directory consumers.
Registry Consistency
2/4
Agreement between stored registry metadata, live server-card data, and current validation output.
Installability
1/4
How cleanly a real client can connect, initialize, enumerate tools, and proceed through auth.
Session Semantics
0/4
Determinism and state behavior across repeated MCP calls, including sticky-session surprises.
Tool Surface Design
0/4
Naming clarity, schema ergonomics, and parameter complexity across the tool surface.
Result Shape Stability
0/4
Stability of declared output schemas across validations, with penalties for drift or missing shapes.
OAuth Interop
0/4
Depth and client compatibility of OAuth/OIDC metadata beyond the minimal protected-resource check.
Recovery Semantics
0/4
Whether failures include actionable machine-readable next steps such as retry or upgrade guidance.
Maintenance Signal
3/4
Versioning, update recency, and historical validation cadence that indicate active stewardship.
Adoption Signal
2/4
Directory presence and distribution clues that suggest the server is intended for external use.
Freshness Confidence
3/4
Confidence that recent validations are current enough and dense enough to trust operationally.
Transport Fidelity
1/4
Whether declared transport metadata matches the observed endpoint behavior and response formats.
Spec Recency
0/4
How close the server’s claimed MCP protocol version is to the latest known public revision.
Session Resume
1/4
Whether Streamable HTTP session identifiers and resumed requests behave cleanly for real clients.
Step-Up Auth
1/4
Whether OAuth metadata and WWW-Authenticate challenges support granular, incremental consent instead of broad upfront scopes.
Utility Coverage
0/4
Signals support for completions, pagination, and task-oriented utility surfaces that larger clients increasingly expect.
Advanced Capability Coverage
0/4
Coverage of newer MCP surfaces like roots, sampling, elicitation, structured output, and related metadata.
Connector Publishability
0/4
How ready the server looks for client catalogs and managed connector programs.
Tool Snapshot Churn
0/4
Stability of the tool surface across recent validations, including add/remove and output-shape drift.
Connector Replay
1/4
Whether a previously published frozen connector snapshot would remain backward compatible after the latest tool refresh.
Request Association
1/4
Whether roots, sampling, and elicitation appear tied to active client requests instead of arriving unsolicited on idle sessions.
Interactive Flow Safety
0/4
Whether prompts and docs steer users toward safe auth flows instead of pasting secrets directly.
Official Registry Presence
4/4
Whether the server appears directly or indirectly in the official MCP registry.
Safety Transparency
2/4
Clarity of docs, auth disclosure, support links, and other trust signals visible to integrators.
Tool Capability Clarity
0/4
How clearly the tool surface communicates whether each action reads, writes, deletes, executes, or exports data.
Data Exfiltration Resilience
0/4
Assesses export, dump, backup, and bulk-read behavior against the surrounding auth and safeguard signals.
Supply Chain Signal
1/4
Public metadata signal for repository, changelog, license, versioning, and recency that supports supply-chain trust.
Input Sanitization Safety
0/4
Penalizes risky freeform string inputs when schemas do not constrain URLs, code, paths, queries, or templates.
Tool Namespace Clarity
0/4
Measures naming uniqueness and ambiguity across the tool namespace to reduce collision and confusion risk.

9 component(s) not assessed for this run: Abuse/Noise Resilience, Transport Compliance, Action Safety, Provenance Divergence, Destructive Operation Safety, Egress / SSRF Resilience, Execution / Sandbox Safety, Least Privilege Scope, Secret Handling Hygiene

Experimental candidate components
Personal Data Exposure
1.5
Experimental candidate, weight 0. Export and bulk-access evidence only; no impact on totals, verdicts, rankings, or gates.
Actionable remediation
SeverityRemediationWhy it mattersRecommended action
Critical Ensure tools/list succeeds consistently Tools discovery is the minimum viable contract for most MCP clients and directories. Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
Playbook
  • Make `tools/list` deterministic across repeated calls.
  • Document or relax auth requirements for discovery routes.
  • Check that tool names, descriptions, and schemas remain stable across deploys.
Critical Make initialize deterministic and client-friendly If initialize fails or requires undocumented auth, many MCP clients cannot connect. Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.
Playbook
  • Allow `initialize` to succeed unauthenticated when possible.
  • If auth is required, return a deterministic auth-required response and matching metadata.
  • Retest against `https://nothumansearch.ai/mcp` from a clean client session.
Critical Respond to initialize flow regressed A client-visible initialize behavior changed for the worse. Compare initialize responses between the latest two runs and restore the previous stable behavior.
Critical Respond to tools/list regressed Tool discovery became less reliable on the latest run. Compare tool enumeration outputs between runs and remove non-deterministic behavior.
High Align session and protocol behavior with Streamable HTTP expectations Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
Playbook
  • Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.
  • Honor `DELETE` session teardown and return `404` when a deleted session is reused.
  • Reject invalid protocol-version headers with `400 Bad Request`.
High Expose /.well-known/oauth-protected-resource Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.
Playbook
  • Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.
  • Point it at the authorization server metadata URL.
  • Confirm clients receive consistent auth hints before tool execution.
High Publish OAuth authorization-server metadata Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.
Playbook
  • Publish `/.well-known/oauth-authorization-server` from the issuer.
  • Add `registration_endpoint` if DCR is supported.
  • Verify issuer, authorization, token, and jwks metadata are all reachable.
High Publish a complete server card Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.
Playbook
  • Publish `/.well-known/mcp/server-card.json`.
  • Include homepage, repository, support, tools, prompts/resources, and auth metadata.
  • Revalidate the server after publishing the card.
High Respond to auth mode changed Auth mode changed from public to unknown. Document the new auth posture and confirm protected-resource and challenge metadata still match reality.
High Respond to score dropped materially Score fell by 59.7 points versus the previous run. Inspect the latest diff to find which checks and component scores regressed.
High Respond to tool snapshot changed Tools were added, removed, or materially changed between the latest two validations. Publish a first-class changelog for tool additions, removals, and breaking schema changes.
Playbook
  • Review the tool snapshot diff for adds, removals, required-arg changes, and output-schema drift.
  • Publish a changelog before managed connector clients refresh their frozen tool snapshots.
  • Revalidate after the changelog and connector metadata are in sync.
Medium Adopt a current MCP protocol revision Older protocol revisions reduce compatibility with newer clients and registry programs. Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.
Playbook
  • Update the server's advertised protocol version to a current MCP revision (2025-06-18 or later).
  • Return the negotiated version consistently in both the `initialize` response and the `MCP-Protocol-Version` header.
  • Revalidate and confirm `protocol_version_probe` reports `ok`.
Medium Close connector-publishing gaps Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.
Medium Document minimal scopes and return cleaner auth challenges Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.
Playbook
  • Advertise the narrowest viable scopes in OAuth metadata.
  • Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.
  • Revalidate with both public discovery and auth-required flows.
Medium Publish OpenID configuration OIDC metadata improves token validation and client compatibility. Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.
Playbook
  • Serve `/.well-known/openid-configuration` with `issuer`, `jwks_uri`, `authorization_endpoint`, and `token_endpoint`.
  • List supported grant types in `grant_types_supported` and scopes in `scopes_supported`.
  • Revalidate and confirm the `openid_configuration` check returns `ok`.
Medium Raise Access & Protocol score Connectivity, auth, and transport expectations for common clients. Tighten auth discovery, session behavior, and transport metadata until remote clients can connect without guesswork.
Medium Raise Adoption & Market score Adoption clues and public evidence that the server is intended for external use. Increase external documentation and directory coverage so users can discover and evaluate the server.
Medium Raise Interface Quality score How well the tool/resource interface communicates and behaves under automation. Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically.
Medium Raise Security Posture score How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs. Reduce destructive, egress, exec, secret, and freeform-input risk across the exposed tool surface.
Playbook
  • Classify each tool by read/write/delete/exec/network capability and confirm the classification is intentional.
  • Gate high-risk tools behind scoped auth, narrow their schemas, and document safeguards such as allowlists or dry-run paths.
  • Revalidate after the risky tools are tightened so the security posture score reflects the current surface.
Medium Respond to tool count decreased Advertised tool count dropped by 14. Confirm whether the tool removal was intentional and, if so, publish an updated changelog.
Low Expose modern utility surfaces like completions, pagination, or tasks Utility coverage improves interoperability with larger clients and long-lived agent workflows. Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.
Playbook
  • Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.
  • Return `nextCursor` on large list operations when pagination is available.
  • Document task support and whether it requires step-up auth.
Low Harden generic GET handling Simple probe requests should not surface server instability or noisy failures. Harden generic GET handlers around the origin of https://nothumansearch.ai/mcp so incidental traffic does not produce noisy failures.
Low Publish newer MCP capability signals Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.
Playbook
  • Add the capabilities you actually support (`roots`, `sampling`, `elicitation`) to the `capabilities` object returned from `initialize`.
  • Only advertise a capability once the corresponding request/response flow is implemented end to end.
  • Revalidate and confirm `advanced_capabilities_probe` reflects the updated capability set.
Low Publish or reconcile the server in the official MCP registry Official registry presence improves discovery confidence and cross-source consistency.
Point loss breakdown
ComponentCurrentPoints missing
Utility Coverage 0/4 -4.0
Tool Surface Design 0/4 -4.0
Tool Snapshot Churn 0/4 -4.0
Tool Namespace Clarity 0/4 -4.0
Tool Capability Clarity 0/4 -4.0
Task Success 0/4 -4.0
Spec Recency 0/4 -4.0
Session Semantics 0/4 -4.0
Security Hygiene 0/4 -4.0
Schema Completeness 0/4 -4.0
Result Shape Stability 0/4 -4.0
Recovery Semantics 0/4 -4.0
Compatibility profiles
OpenAI Connectors
22.2
blocked (2 of 9 requirements met)
OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Initialize must be reachable.; tools/list must succeed.; Transport compliance failed or did not complete successfully.; Step-up auth signals should be documented and connector-friendly.; OAuth interoperability should be strong.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Claude Desktop
50.0
blocked (3 of 6 requirements met)
Initialize must succeed or cleanly request auth.; tools/list must succeed.; Transport behavior should match Claude-compatible HTTP expectations.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Smithery
40.0
blocked (2 of 5 requirements met)
Tool discovery must succeed.; Initialize should work before execution.; Machine-readable failure semantics should be present.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Generic Streamable HTTP
33.3
blocked (2 of 6 requirements met)
Initialize must succeed.; tools/list must succeed.; Transport behavior should match metadata.; Session behavior should be predictable.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.

Governance

MCP TrustOps

TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.

Evidence age tier
Verified in last 24h
Policy SLA (contractual, distinct from the public 24h freshness window): 168.0h • confidence-weighted score (display score discounted for evidence age and confidence -- an internal TrustOps input, not the public score): 1.7 • evidence too old to display:
Policy exports
Formats: json, rego, yaml, github_action, gateway_config, client_report
Runtime routing
/v1/decide
Returns allowed tools, blocked tools, approval requirement, and reason.
Hosted runtime
Deploy trusted servers from GitHub with secrets, egress controls, releases, rollback, and audit events.
Authenticated validation
Premium publisher feature: paid authenticated runs verify scopes, write-action safeguards, and authorized tool execution.
Active trust badges
none
Semantic benchmarks
available
Templates cover GitHub, database, healthcare, web search, and CRM least-privilege jobs.
Supply chain
metadata signal
Deep scan checks are marked separately from public metadata signals.
Compliance metadata
Terms, privacy, SOC 2, HIPAA, GDPR, retention, deletion, and audit-log fields are tracked as enterprise metadata.
Alert subscription types
Status changes Score drops or recovers Freshness SLA breach Validation schema drift OAuth or auth behavior changes Tool surface changes New or changed write tool Supply-chain signal changes Legal or compliance metadata changes
MCP Runtime hosting

Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.

Activation readiness
Trusted hosted runtimes require fresh validation, a passing server state, a remote endpoint, and a minimum score.
Minimum tier
TrustOps
Publisher claim plus paid TrustOps tier are required before secrets or releases can be created.
Hosted endpoint
/hosted/{namespace}/{name}/mcp
The endpoint enforces egress allowlists and records audit/usage events.
Blockers
score_below_hosting_threshold server_not_healthy_or_degraded latest_validation_not_passing blocked_by_active_alerts blocked_by_production_readiness
DeploymentStatusEndpointRelease
No hosted runtime deployments yet.
Authenticated validation sessions

Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.

Latest profile
remote_mcp
Authenticated session used
Public score isolation
Preview endpoint
/v1/verify
CI preview endpoint
/v1/ci/preview
Install snippets
Openai Connectors
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Claude Desktop
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Smithery
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Generic Http
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Unavailable Reason
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Agent access & tool surface
Live server tools
No live tool surface captured yet.
Observed from the latest live validation against https://nothumansearch.ai/mcp. This is the target server surface, not Verify's own inspection tools.
Live capability counts
14 tools • 0 prompts • 0 resources
Counts come from the latest tools/list, prompts/list, and resources/list checks.
Inspect with Verify
search fetch search_servers recommend_servers get_server_report compare_servers
Use Verify itself to search, recommend, compare, and fetch the full report for ai.nothumansearch/search.
Direct machine links

History

Validation history
7 day score delta
n/a
30 day score delta
n/a
Recent healthy ratio
100%
Freshness
9.7h
TimestampStatusScoreLatencyTools
Aug 11, 2026 07:38:00 AM UTC Unknown 2.2 10111.5 ms 0
Aug 10, 2026 07:37:30 PM UTC Healthy 62.0 1123.9 ms 14
Aug 10, 2026 07:37:11 AM UTC Healthy 62.0 1355.9 ms not fetched
Aug 09, 2026 07:37:05 PM UTC Healthy 62.0 1100.7 ms not fetched
Aug 09, 2026 07:36:48 AM UTC Healthy 62.0 1230.5 ms not fetched
Aug 08, 2026 07:36:26 PM UTC Healthy 62.0 1087.2 ms not fetched
Aug 08, 2026 07:36:18 AM UTC Healthy 62.0 1013.7 ms not fetched
Aug 07, 2026 07:36:01 PM UTC Healthy 62.0 1422.0 ms not fetched
Validation timeline
ValidatedSummaryScoreProtocolAuth modeToolsHigh-risk toolsChanges
Aug 11, 2026 07:38:00 AM UTC Unknown n/a unknown unknown 0 0 summary_changed auth_mode_changed tool_snapshot_changed
Aug 10, 2026 07:37:30 PM UTC Healthy 62.0 2025-06-18 public 14 0 none
Aug 10, 2026 07:37:11 AM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 09, 2026 07:37:05 PM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 09, 2026 07:36:48 AM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 08, 2026 07:36:26 PM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 08, 2026 07:36:18 AM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 07, 2026 07:36:01 PM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 07, 2026 07:35:50 AM UTC Healthy n/a unknown unknown not fetched 0 none
Aug 06, 2026 07:35:35 PM UTC Healthy n/a unknown unknown not fetched 0 none
Recent validation runs
Recent validation runs for this MCP server
StartedStatusSummaryLatencyChecks
Aug 11, 2026 07:37:50 AM UTC Completed Unknown 10111.5 ms action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe (not counted in confidence)
Aug 10, 2026 07:37:29 PM UTC Completed Healthy 1123.9 ms action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe
Aug 10, 2026 07:37:10 AM UTC Completed Healthy 1355.9 ms not fetched (not counted in confidence)
Aug 09, 2026 07:37:04 PM UTC Completed Healthy 1100.7 ms not fetched (not counted in confidence)
Aug 09, 2026 07:36:47 AM UTC Completed Healthy 1230.5 ms not fetched (not counted in confidence)
Aug 08, 2026 07:36:25 PM UTC Completed Healthy 1087.2 ms not fetched (not counted in confidence)
Aug 08, 2026 07:36:17 AM UTC Completed Healthy 1013.7 ms not fetched (not counted in confidence)
Aug 07, 2026 07:35:59 PM UTC Completed Healthy 1422.0 ms not fetched (not counted in confidence)
Aug 07, 2026 07:35:48 AM UTC Completed Healthy 1155.3 ms not fetched (not counted in confidence)
Aug 06, 2026 07:35:34 PM UTC Completed Healthy 1207.8 ms not fetched (not counted in confidence)
Incident & change feed
TimestampEventDetails
Aug 11, 2026 07:38:00 AM UTC Latest validation: unknown Score 3.8 with status unknown.
Aug 11, 2026 07:38:00 AM UTC Validation summary changed Summary moved from healthy to unknown.
Aug 11, 2026 07:38:00 AM UTC Score changed Score delta -59.7 versus the previous run.
Aug 11, 2026 07:38:00 AM UTC Tool snapshot changed Added 0, removed 14, and changed 0 tool contracts.
Aug 11, 2026 07:38:00 AM UTC Auth mode changed Auth mode moved from public to unknown.
Aug 05, 2026 11:00:24 AM UTC Score corrected (post-1.0.503 remediation, R1 zero-anchoring) Prior: 67.82. Corrected: 64.92.

Technical details

Raw evidence view
Show raw JSON evidence
{
  "checks": {
    "action_safety_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "advanced_capabilities_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "connector_publishability_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "connector_replay_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "determinism_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "initialize": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "interactive_flow_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "oauth_authorization_server": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "oauth_protected_resource": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "official_registry_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "openid_configuration": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "probe_noise_resilience": {
      "details": {
        "consent_error": "robots.txt fetch failed; consent is unknown",
        "error": "The read operation timed out",
        "url": "https://nothumansearch.ai/robots.txt",
        "validation_disallowed": "unknown"
      },
      "latency_ms": 10086.22,
      "status": "error"
    },
    "prompt_get": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "prompts_list": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "protocol_version_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "provenance_divergence_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "request_association_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "resource_read": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "resources_list": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "schema_divergence_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "server_card": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "session_resume_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "step_up_auth_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "tool_snapshot_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "tools_list": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "transport_compliance_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    },
    "utility_coverage_probe": {
      "details": {
        "reason": "consent_unknown"
      },
      "latency_ms": null,
      "status": "not_assessed"
    }
  },
  "failures": {
    "probe_noise_resilience": {
      "consent_error": "robots.txt fetch failed; consent is unknown",
      "error": "The read operation timed out",
      "url": "https://nothumansearch.ai/robots.txt",
      "validation_disallowed": "unknown"
    }
  },
  "remote_url": "https://nothumansearch.ai/mcp",
  "server_card_payload": null,
  "server_identifier": "ai.nothumansearch/search"
}
Capabilities
Use-case taxonomy
search
Transport compliance drilldown
Probe status
Not_Assessed
Transport
unknown
Session header
no
Protocol header
no
Bad protocol response
n/a
DELETE teardown
n/a
Expired session retry
n/a
Last-Event-ID visible
no

Issues: none

Request association
Status
Not_Assessed
Advertised capabilities
none
Observed idle methods
none
Violating methods
none
Probe HTTP status
n/a
Issues
none
Connector replay
Status
Not_Assessed
Backward compatible
Would break after refresh
Added tools
none
Removed tools
none
Additive output changes
none
Required-argument replay breaks
ToolAdded required argsRemoved required args
No required-argument replay breaks detected.
Output-schema replay breaks
ToolRemoved propertiesAdded properties
No output-schema replay breaks detected.