merlonix-mcp
Provides live infrastructure monitoring for AI agents, including domain health checks, MCP server security posture, email blacklists, broken-link scans, and cloud vendor status. No signup or API key needed for public tools.
Block For Production
trustsnap_fd0323dece3844af.- Utility Coverage
- Transport Compliance
- Step Up Auth
- Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tool…
- Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
- Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.
- No segmented attention signals observed in the current window.
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risks
Security posture
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes | Evidence |
|---|---|---|---|---|---|
check_domain_health |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
check_agent_readiness |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
check_mcp_health |
read network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The MCP endpoint URL, e.g. https://example.com/mcp",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
check_email_blacklist |
read network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"domain": {
"description": "A public domain or IP address, e.g. example.com or 203.0.113.10",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
check_broken_links |
read network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The exact page URL to scan, e.g. https://example.com/pricing",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
list_vendor_status |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
get_vendor_status |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"slug": {
"description": "Vendor slug, e.g. cloudflare",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
list_plans |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
list_my_assets |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
get_asset_checks |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
list_my_alerts |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"capabilities": [
"read"
],
"input_schema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
create_asset |
write network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": false,
"readOnlyHint": false,
"requiresAuth": true
},
"capabilities": [
"write",
"network"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"asset_type": {
"description": "Asset kind: \"hostname\" (a website/host), \"domain\", \"certificate\", or \"dns_record\".",
"enum": [
"domain",
"hostname",
"certificate",
"dns_record"
],
"type": "string"
},
"dns_enabled": {
"description": "Monitor DNS records.",
"type": "boolean"
},
"domain_enabled": {
"description": "Monitor domain-registration (RDAP) expiry.",
"type": "boolean"
},
"hostname": {
"description": "The hostname to monitor, e.g. example.com",
"type": "string"
},
"label": {
"description": "Optional human label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Monitor the TLS certificate (default on for hostnames).",
"type": "boolean"
},
"uptime_check_url": {
"description": "Optional URL to probe for uptime (enables uptime checks).",
"type": "string"
}
},
"required": [
"hostname",
"asset_type"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
update_asset |
write | Medium | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"capabilities": [
"write"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
},
"dns_enabled": {
"description": "Enable/disable DNS monitoring.",
"type": "boolean"
},
"domain_enabled": {
"description": "Enable/disable domain-registration (RDAP) monitoring.",
"type": "boolean"
},
"label": {
"description": "New label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Enable/disable TLS-certificate monitoring.",
"type": "boolean"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
delete_asset |
write delete | Medium | destructive operation | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": true,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"capabilities": [
"write",
"delete"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"risk_flags": [
"destructive_operation"
]
}
Dispute this classification
|
acknowledge_alert |
write | Medium | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"capabilities": [
"write"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
resolve_alert |
write | Medium | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"capabilities": [
"write"
],
"input_schema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
},
"resolution": {
"description": "Why the alert is being closed.",
"enum": [
"fixed",
"false_positive",
"wontfix"
],
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
Write-action governance
Status detail: 1 destructive tool(s) are exposed without a clear auth boundary; 0 safeguard(s) and 1 confirmation signal(s) detected.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Recommended runtime policy
No policy blockers under the default policy stance.
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
| No newly added actions. | ||
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Critical alerts
Compatibility
Client readiness verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Errorstep_up_auth_probe• Missingconnector_replay_probe• OK — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Error
Evidence provenance
action_safety_probe• Error
Evidence provenance
tool_snapshot_probe• OKconnector_replay_probe• OK
Client readiness gate details
Remediation checklist
- Add OAuth-based authentication for remote connector auth.
- Support dynamic client registration (DCR) to simplify connector setup.
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Document step-up auth requirements in a connector-friendly way.
- Improve OAuth interoperability -- see the OAuth Interop score breakdown.
- Limit the exposed surface to search/fetch-style read tools.
Remediation checklist
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Limit the exposed surface to search/fetch-style read tools.
- Remove or isolate write, delete, and exec-capable tools before using this read/search-only client profile.
- Configure OAuth for authenticated remote MCP access.
- Remove export, bulk, mutating, and high-blast-radius exposure before certifying company-knowledge use.
- Satisfy OAuth, compatibility, and connector-refresh requirements before using the Messages API remote MCP path.
Remediation checklist
- Add a clearer auth boundary around risky write actions.
- Resolve the blocking production-readiness verdict before treating this as write-safe.
Verdict traces
- No active alert triggers.
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Not Assessed
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Degraded
Recommended for
Evidence
Current trust snapshot
trustsnap_fd0323dece3844afCanonical machine links
Evidence confidence
Latest validation evidence
Failures
oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://api.merlonix.com/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization serverserver_cardClient error '404 Not Found' for url 'https://api.merlonix.com/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404transport_compliance_probeIssues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=200).
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Error | n/a | 1 destructive, 6 egress-capable, 5 declared non-read-only, non-read capabilities: write, delete tool(s); no clear auth boundary; safeguards=0; confirmation=delete asset. |
advanced_capabilities_probe |
Missing | n/a | No advanced MCP capability signals detected. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: protocol version, session resume, step up auth, transport compliance, +3 more. |
connector_replay_probe |
OK | n/a | Backward compatible with no breaking tool-surface changes. |
determinism_probe |
OK | 29.3 ms | Check completed |
initialize |
OK | 539.9 ms | Protocol 2025-03-26 |
instruction_tool_reference_probe |
OK | n/a | Check completed |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 729.2 ms | Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
Missing | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 841.1 ms | Fetched https://api.merlonix.com/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Missing | 29.2 ms | not supported |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Missing | 27.9 ms | not supported |
schema_divergence_probe |
Missing | n/a | no server card tools |
server_card |
Error | 29.0 ms | Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
session_resume_probe |
Warning | n/a | no session id |
step_up_auth_probe |
Missing | n/a | No OAuth or incremental-scope signals detected. |
tool_snapshot_probe |
OK | n/a | Check completed |
tools_list |
OK | 29.7 ms | 16 tool(s) exposed |
transport_compliance_probe |
Error | 31.2 ms | Issues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=200). |
utility_coverage_probe |
Missing | 29.1 ms | No completions evidence; no pagination evidence; tasks missing. |
Known versions
- No versions recorded.
Public server reputation
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Degraded |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Tool snapshot diff & changelog
Required-argument changes
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument changes detected. | ||
Output-schema drift
| Tool | Previous properties | Latest properties |
|---|---|---|
| No output-schema drift detected. | ||
Validation diff
Regressed checks: none
Improved checks: connector_replay_probe, instruction_tool_reference_probe, tool_snapshot_probe
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
backward_compatibility_score | 2.0 | 4.0 | 2.0 |
connector_replay_score | 3.0 | 4.0 | 1.0 |
installability_score | 3.0 | 4.0 | 1.0 |
result_shape_stability_score | 2.0 | 3.0 | 1.0 |
tool_snapshot_churn_score | 3.0 | 4.0 | 1.0 |
Registry & provenance divergence
Active alerts
No active alerts for the current server state.
Aliases & registry graph
| Identifier | Source | Canonical | Identity evidence | Score |
|---|---|---|---|---|
cmhenry79/merlonix-mcp |
glama_registry | yes | canonical | 54.7 |
Alias consolidation
Strong alias identity requires matching remote URL, server-card URL, repository slug, or explicit registry cross-reference; shared provider namespace alone is not identity.
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
1 component(s) not assessed for this run: Provenance Divergence
Experimental candidate components
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| High | Add confirmation and dry-run semantics for risky actions | High-risk write, delete, exec, or egress tools should communicate safeguards clearly. | Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tools before they can make destructive changes.Playbook
|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| High | Publish a complete server card | Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. | Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | Resolve every blocker named by connector_publishability_probe, then rerun it before submitting or refreshing a connector listing.Playbook
|
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Persist session state keyed by Mcp-Session-Id and honor Last-Event-ID on GET reconnects so clients can resume a dropped Streamable HTTP session.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
| Low | Publish or reconcile the server in the official MCP registry | Official registry presence improves discovery confidence and cross-source consistency. | Create or update the official MCP registry entry with the canonical MCP endpoint and matching repository metadata, then rerun official_registry_probe.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 0/4 | -4.0 |
| Transport Compliance | 0/4 | -4.0 |
| Step-Up Auth | 0/4 | -4.0 |
| Resource Contract | 0/4 | -4.0 |
| Request Association | 0/4 | -4.0 |
| Recovery Semantics | 0/4 | -4.0 |
| Prompt Contract | 0/4 | -4.0 |
| OAuth Interop | 0/4 | -4.0 |
| Supply Chain Signal | 0/4 | -4.0 |
| Advanced Capability Coverage | 0/4 | -4.0 |
| Trust Confidence | 1/4 | -3.0 |
| Least Privilege Scope | 1/4 | -3.0 |
Technical compatibility profiles
These scores measure technical client compatibility only. Client publishability and production readiness are evaluated separately against policy, transport, and write-surface blockers.
Connector URL: https://api.merlonix.com/mcp # No OAuth metadata detected. # Server: cmhenry79/merlonix-mcp
{
"mcpServers": {
"merlonix-mcp": {
"command": "npx",
"args": ["mcp-remote", "https://api.merlonix.com/mcp"]
}
}
}
smithery mcp add "https://api.merlonix.com/mcp"
curl -sS https://api.merlonix.com/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: validation targets and SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://api.merlonix.com/mcp # No OAuth metadata detected. # Server: cmhenry79/merlonix-mcp
{
"mcpServers": {
"merlonix-mcp": {
"command": "npx",
"args": ["mcp-remote", "https://api.merlonix.com/mcp"]
}
}
}
smithery mcp add "https://api.merlonix.com/mcp"
curl -sS https://api.merlonix.com/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.cmhenry79/merlonix-mcp.History
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 14, 2026 03:18:37 AM UTC | Healthy | 54.7 | 2440.4 ms | 16 |
| Aug 13, 2026 03:59:41 PM UTC | Healthy | 51.6 | 2473.9 ms | 16 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 14, 2026 03:18:37 AM UTC | Healthy | 54.7 | 2025-03-26 | public | 16 | 0 | none |
| Aug 13, 2026 03:59:41 PM UTC | Healthy | 51.6 | 2025-03-26 | public | 16 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 14, 2026 03:18:35 AM UTC | Completed | Healthy | 2440.4 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 13, 2026 03:59:39 PM UTC | Completed | Healthy | 2473.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 14, 2026 03:18:37 AM UTC | Latest validation: healthy | Score 54.7 with status healthy. |
| Aug 14, 2026 03:18:37 AM UTC | Score changed | Score delta +3.1 versus the previous run. |
Technical details
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": false,
"confirmation_signals": [
"delete_asset"
],
"reason": null,
"safeguard_count": 0,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {
"delete": 1,
"network": 6,
"read": 11,
"write": 5
},
"declared_non_read_only_tools": 5,
"destructive_tools": 1,
"egress_tools": 6,
"exec_tools": 0,
"has_mutating_capability": true,
"has_non_read_capability": true,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 6,
"medium": 10
},
"secret_tools": 0,
"tool_count": 16
}
},
"latency_ms": null,
"status": "error"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [],
"enabled_count": 0,
"initialize_capability_keys": [
"tools"
]
},
"latency_ms": null,
"status": "missing"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"protocol_version",
"session_resume",
"step_up_auth",
"transport_compliance",
"request_association",
"action_safety",
"server_card"
],
"criteria": {
"action_safety": false,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": false,
"remote_transport": true,
"request_association": false,
"server_card": false,
"session_resume": false,
"step_up_auth": false,
"tool_surface": true,
"tools_list": true,
"transport_compliance": false
},
"high_risk_tools": 0,
"tool_count": 16,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"connector_replay_probe": {
"details": {
"added_tools": [],
"additive_output_changes": [],
"backward_compatible": true,
"output_breaks": [],
"removed_tools": [],
"required_arg_breaks": [],
"would_break_after_refresh": false
},
"latency_ms": null,
"status": "ok"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "0ebc5009c978323ecd975ade0c047365ee4d2b94bb96713b03594b60ee55c26d",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 29.26,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"tools": {
"listChanged": false
}
},
"instructions": "Merlonix monitoring tools. PUBLIC (no auth): query the live SSL/DNS/registration health of any public domain (check_domain_health), score a site for AI-agent readiness (check_agent_readiness), health-check a live MCP server by URL (check_mcp_health), check a domain or IP against the mail DNS blocklists (check_email_blacklist), scan one page for dead links and mixed content (check_broken_links), and read the status of the third-party vendors Merlonix monitors (list_vendor_status / get_vendor_status / list_plans). AUTHED (set \"Authorization: Bearer mk_\u2026\" with an API key from app.merlonix.com \u2192 Settings \u2192 API keys): READ your own monitored assets (list_my_assets), the latest check results for one asset (get_asset_checks), and your recent alerts (list_my_alerts); and WRITE (needs a write-scoped API key): start monitoring an asset (create_asset), update or remove one (update_asset / delete_asset), and acknowledge or resolve an alert (acknowledge_alert / resolve_alert). Read tools are read-only; the write tools mutate only YOUR account and are tenant-scoped + write-scope-gated server-side.",
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "merlonix",
"title": "Merlonix",
"version": "1.0.0"
}
}
},
"url": "https://api.merlonix.com/mcp"
},
"latency_ms": 539.89,
"status": "ok"
},
"instruction_tool_reference_probe": {
"details": {
"missing_tools": [],
"observed_tool_count": 16,
"referenced_tools": []
},
"latency_ms": null,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": [
"browser"
]
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.merlonix.com/.well-known/oauth-protected-resource"
},
"latency_ms": 729.2,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": false,
"official_peer_count": 0,
"registry_source": "glama_registry"
},
"latency_ms": null,
"status": "missing"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"consent_error": null,
"headers": {
"content-type": "text/plain; charset=utf-8"
},
"http_status": 200,
"url": "https://api.merlonix.com/robots.txt",
"validation_disallowed": false
},
"latency_ms": 841.07,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found: prompts/list"
},
"id": 3,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://api.merlonix.com/mcp"
},
"latency_ms": 29.21,
"status": "missing"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": false,
"drift_fields": [],
"metadata_document_count": 1,
"readable_sources": [],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": null,
"server_card_version": null
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found: resources/list"
},
"id": 5,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://api.merlonix.com/mcp"
},
"latency_ms": 27.9,
"status": "missing"
},
"schema_divergence_probe": {
"details": {
"auth_scheme_mismatch": false,
"card_server_name": null,
"card_server_version": null,
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_server_name": "merlonix",
"live_server_version": "1.0.0",
"reason": "no_server_card_tools",
"server_name_mismatch": false,
"server_version_mismatch": false
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"error": "Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.merlonix.com/.well-known/mcp/server-card.json"
},
"latency_ms": 28.96,
"status": "error"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "missing"
},
"tool_snapshot_probe": {
"details": {
"added": [],
"changed_outputs": [],
"current_tool_count": 16,
"previous_tool_count": 16,
"removed": [],
"similarity": 1.0
},
"latency_ms": null,
"status": "ok"
},
"tools_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"readOnlyHint": true
},
"description": "Check the live SSL/TLS certificate (validity + expiry + issuer), DNS records (A/AAAA/MX/NS resolution), and domain-registration (RDAP) expiry of any public hostname. Each leg fails soft and is reported independently.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_domain_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Score how ready a website is for AI agents and answer engines. Fetches /llms.txt, /robots.txt, and the homepage and returns a letter grade with per-signal findings. No browser rendering or LLM call \u2014 deterministic HTTP/parse.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_agent_readiness"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Health-check a live MCP (Model Context Protocol) server by URL: performs a real JSON-RPC initialize handshake, then tools/list, and returns whether it is up/degraded/down, its protocol version, server name/version, the callable tool/resource/prompt inventory, transport, and handshake latency. Deterministic \u2014 no LLM. Use it to verify your own MCP server is alive and spec-compliant.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The MCP endpoint URL, e.g. https://example.com/mcp",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_mcp_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Check whether a domain or IP is listed on the major DNS blocklists (DNSBLs) that mail providers consult before accepting mail \u2014 the usual reason legitimate mail silently lands in spam. Returns each zone checked, whether it is listed, and the return code. Deterministic DNS lookups, no LLM.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"domain": {
"description": "A public domain or IP address, e.g. example.com or 203.0.113.10",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_email_blacklist"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Scan one web page for dead links (4xx/5xx/unreachable) and mixed content (http subresources on an https page). Returns each link with its status. Single-page scan, not a crawl \u2014 pass the exact page URL. Rate-limited to a few scans per minute, so batch calls will be throttled.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The exact page URL to scan, e.g. https://example.com/pricing",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_broken_links"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List the current operational status and recent incidents of every third-party vendor Merlonix monitors (e.g. Cloudflare, GitHub, Stripe). Returns each vendor's slug, current status, and 24h incident count.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Get the current status plus 30-day status history of one monitored vendor by slug (e.g. \"cloudflare\"). Use list_vendor_status to discover valid slugs.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"slug": {
"description": "Vendor slug, e.g. cloudflare",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"name": "get_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List Merlonix subscription plans and pricing (Starter, Team, Agency, Compliance) with their monitoring limits.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_plans"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List the monitored assets (websites/domains) in YOUR Merlonix account. Returns each asset id, hostname, type, and monitoring status. Requires an API key (Authorization: Bearer mk_\u2026 from app.merlonix.com \u2192 Settings \u2192 API keys).",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_assets"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "Get the latest check results (SSL, DNS, uptime, heartbeat, port) for ONE of your monitored assets, by its asset id (from list_my_assets). Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "get_asset_checks"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List recent alerts across YOUR monitored assets (SSL changes, downtime, DNS drift, vendor incidents, etc.) with their severity and lifecycle status. Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_alerts"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": false,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Start monitoring a new asset (website/domain) in YOUR Merlonix account. Provide a hostname and asset_type; optionally a label and which checks to enable. Returns the created asset. Requires an API key with write scope. Subject to your plan asset quota (a full or non-paying plan returns an error).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_type": {
"description": "Asset kind: \"hostname\" (a website/host), \"domain\", \"certificate\", or \"dns_record\".",
"enum": [
"domain",
"hostname",
"certificate",
"dns_record"
],
"type": "string"
},
"dns_enabled": {
"description": "Monitor DNS records.",
"type": "boolean"
},
"domain_enabled": {
"description": "Monitor domain-registration (RDAP) expiry.",
"type": "boolean"
},
"hostname": {
"description": "The hostname to monitor, e.g. example.com",
"type": "string"
},
"label": {
"description": "Optional human label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Monitor the TLS certificate (default on for hostnames).",
"type": "boolean"
},
"uptime_check_url": {
"description": "Optional URL to probe for uptime (enables uptime checks).",
"type": "string"
}
},
"required": [
"hostname",
"asset_type"
],
"type": "object"
},
"name": "create_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Update one of YOUR monitored assets by its asset id (from list_my_assets): relabel it or toggle which checks run. Returns the updated asset. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
},
"dns_enabled": {
"description": "Enable/disable DNS monitoring.",
"type": "boolean"
},
"domain_enabled": {
"description": "Enable/disable domain-registration (RDAP) monitoring.",
"type": "boolean"
},
"label": {
"description": "New label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Enable/disable TLS-certificate monitoring.",
"type": "boolean"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "update_asset"
},
{
"annotations": {
"destructiveHint": true,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "STOP monitoring one of YOUR assets and remove it, by its asset id (from list_my_assets). This is irreversible \u2014 its check history goes too. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "delete_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Acknowledge one of YOUR alerts by its alert id (from list_my_alerts) \u2014 marks it as seen/being-handled without resolving it. Optionally attach a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "acknowledge_alert"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Resolve one of YOUR alerts by its alert id (from list_my_alerts) \u2014 closes it. Optionally set resolution (\"fixed\" | \"false_positive\" | \"wontfix\") and a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
},
"resolution": {
"description": "Why the alert is being closed.",
"enum": [
"fixed",
"false_positive",
"wontfix"
],
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "resolve_alert"
}
]
}
},
"url": "https://api.merlonix.com/mcp"
},
"latency_ms": 29.71,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"bad_protocol_payload": {
"id": 410,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"readOnlyHint": true
},
"description": "Check the live SSL/TLS certificate (validity + expiry + issuer), DNS records (A/AAAA/MX/NS resolution), and domain-registration (RDAP) expiry of any public hostname. Each leg fails soft and is reported independently.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_domain_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Score how ready a website is for AI agents and answer engines. Fetches /llms.txt, /robots.txt, and the homepage and returns a letter grade with per-signal findings. No browser rendering or LLM call \u2014 deterministic HTTP/parse.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_agent_readiness"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Health-check a live MCP (Model Context Protocol) server by URL: performs a real JSON-RPC initialize handshake, then tools/list, and returns whether it is up/degraded/down, its protocol version, server name/version, the callable tool/resource/prompt inventory, transport, and handshake latency. Deterministic \u2014 no LLM. Use it to verify your own MCP server is alive and spec-compliant.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The MCP endpoint URL, e.g. https://example.com/mcp",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_mcp_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Check whether a domain or IP is listed on the major DNS blocklists (DNSBLs) that mail providers consult before accepting mail \u2014 the usual reason legitimate mail silently lands in spam. Returns each zone checked, whether it is listed, and the return code. Deterministic DNS lookups, no LLM.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"domain": {
"description": "A public domain or IP address, e.g. example.com or 203.0.113.10",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_email_blacklist"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Scan one web page for dead links (4xx/5xx/unreachable) and mixed content (http subresources on an https page). Returns each link with its status. Single-page scan, not a crawl \u2014 pass the exact page URL. Rate-limited to a few scans per minute, so batch calls will be throttled.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The exact page URL to scan, e.g. https://example.com/pricing",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_broken_links"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List the current operational status and recent incidents of every third-party vendor Merlonix monitors (e.g. Cloudflare, GitHub, Stripe). Returns each vendor's slug, current status, and 24h incident count.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Get the current status plus 30-day status history of one monitored vendor by slug (e.g. \"cloudflare\"). Use list_vendor_status to discover valid slugs.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"slug": {
"description": "Vendor slug, e.g. cloudflare",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"name": "get_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List Merlonix subscription plans and pricing (Starter, Team, Agency, Compliance) with their monitoring limits.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_plans"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List the monitored assets (websites/domains) in YOUR Merlonix account. Returns each asset id, hostname, type, and monitoring status. Requires an API key (Authorization: Bearer mk_\u2026 from app.merlonix.com \u2192 Settings \u2192 API keys).",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_assets"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "Get the latest check results (SSL, DNS, uptime, heartbeat, port) for ONE of your monitored assets, by its asset id (from list_my_assets). Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "get_asset_checks"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List recent alerts across YOUR monitored assets (SSL changes, downtime, DNS drift, vendor incidents, etc.) with their severity and lifecycle status. Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_alerts"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": false,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Start monitoring a new asset (website/domain) in YOUR Merlonix account. Provide a hostname and asset_type; optionally a label and which checks to enable. Returns the created asset. Requires an API key with write scope. Subject to your plan asset quota (a full or non-paying plan returns an error).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_type": {
"description": "Asset kind: \"hostname\" (a website/host), \"domain\", \"certificate\", or \"dns_record\".",
"enum": [
"domain",
"hostname",
"certificate",
"dns_record"
],
"type": "string"
},
"dns_enabled": {
"description": "Monitor DNS records.",
"type": "boolean"
},
"domain_enabled": {
"description": "Monitor domain-registration (RDAP) expiry.",
"type": "boolean"
},
"hostname": {
"description": "The hostname to monitor, e.g. example.com",
"type": "string"
},
"label": {
"description": "Optional human label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Monitor the TLS certificate (default on for hostnames).",
"type": "boolean"
},
"uptime_check_url": {
"description": "Optional URL to probe for uptime (enables uptime checks).",
"type": "string"
}
},
"required": [
"hostname",
"asset_type"
],
"type": "object"
},
"name": "create_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Update one of YOUR monitored assets by its asset id (from list_my_assets): relabel it or toggle which checks run. Returns the updated asset. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
},
"dns_enabled": {
"description": "Enable/disable DNS monitoring.",
"type": "boolean"
},
"domain_enabled": {
"description": "Enable/disable domain-registration (RDAP) monitoring.",
"type": "boolean"
},
"label": {
"description": "New label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Enable/disable TLS-certificate monitoring.",
"type": "boolean"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "update_asset"
},
{
"annotations": {
"destructiveHint": true,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "STOP monitoring one of YOUR assets and remove it, by its asset id (from list_my_assets). This is irreversible \u2014 its check history goes too. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "delete_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Acknowledge one of YOUR alerts by its alert id (from list_my_alerts) \u2014 marks it as seen/being-handled without resolving it. Optionally attach a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "acknowledge_alert"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Resolve one of YOUR alerts by its alert id (from list_my_alerts) \u2014 closes it. Optionally set resolution (\"fixed\" | \"false_positive\" | \"wontfix\") and a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
},
"resolution": {
"description": "Why the alert is being closed.",
"enum": [
"fixed",
"false_positive",
"wontfix"
],
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "resolve_alert"
}
]
}
},
"bad_protocol_status_code": 200,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 31.21,
"status": "error"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 200,
"probe_status": "missing"
}
},
"latency_ms": 29.1,
"status": "missing"
}
},
"failures": {
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.merlonix.com/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
},
"server_card": {
"error": "Client error '404 Not Found' for url 'https://api.merlonix.com/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.merlonix.com/.well-known/mcp/server-card.json"
},
"transport_compliance_probe": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000; includeSubDomains"
},
"bad_protocol_payload": {
"id": 410,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"readOnlyHint": true
},
"description": "Check the live SSL/TLS certificate (validity + expiry + issuer), DNS records (A/AAAA/MX/NS resolution), and domain-registration (RDAP) expiry of any public hostname. Each leg fails soft and is reported independently.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_domain_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Score how ready a website is for AI agents and answer engines. Fetches /llms.txt, /robots.txt, and the homepage and returns a letter grade with per-signal findings. No browser rendering or LLM call \u2014 deterministic HTTP/parse.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"hostname": {
"description": "A public hostname, e.g. example.com",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_agent_readiness"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Health-check a live MCP (Model Context Protocol) server by URL: performs a real JSON-RPC initialize handshake, then tools/list, and returns whether it is up/degraded/down, its protocol version, server name/version, the callable tool/resource/prompt inventory, transport, and handshake latency. Deterministic \u2014 no LLM. Use it to verify your own MCP server is alive and spec-compliant.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The MCP endpoint URL, e.g. https://example.com/mcp",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_mcp_health"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Check whether a domain or IP is listed on the major DNS blocklists (DNSBLs) that mail providers consult before accepting mail \u2014 the usual reason legitimate mail silently lands in spam. Returns each zone checked, whether it is listed, and the return code. Deterministic DNS lookups, no LLM.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"domain": {
"description": "A public domain or IP address, e.g. example.com or 203.0.113.10",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_email_blacklist"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Scan one web page for dead links (4xx/5xx/unreachable) and mixed content (http subresources on an https page). Returns each link with its status. Single-page scan, not a crawl \u2014 pass the exact page URL. Rate-limited to a few scans per minute, so batch calls will be throttled.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The exact page URL to scan, e.g. https://example.com/pricing",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_broken_links"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List the current operational status and recent incidents of every third-party vendor Merlonix monitors (e.g. Cloudflare, GitHub, Stripe). Returns each vendor's slug, current status, and 24h incident count.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "Get the current status plus 30-day status history of one monitored vendor by slug (e.g. \"cloudflare\"). Use list_vendor_status to discover valid slugs.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"slug": {
"description": "Vendor slug, e.g. cloudflare",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"name": "get_vendor_status"
},
{
"annotations": {
"readOnlyHint": true
},
"description": "List Merlonix subscription plans and pricing (Starter, Team, Agency, Compliance) with their monitoring limits.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_plans"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List the monitored assets (websites/domains) in YOUR Merlonix account. Returns each asset id, hostname, type, and monitoring status. Requires an API key (Authorization: Bearer mk_\u2026 from app.merlonix.com \u2192 Settings \u2192 API keys).",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_assets"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "Get the latest check results (SSL, DNS, uptime, heartbeat, port) for ONE of your monitored assets, by its asset id (from list_my_assets). Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "get_asset_checks"
},
{
"annotations": {
"readOnlyHint": true,
"requiresAuth": true
},
"description": "List recent alerts across YOUR monitored assets (SSL changes, downtime, DNS drift, vendor incidents, etc.) with their severity and lifecycle status. Requires an API key.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_my_alerts"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": false,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Start monitoring a new asset (website/domain) in YOUR Merlonix account. Provide a hostname and asset_type; optionally a label and which checks to enable. Returns the created asset. Requires an API key with write scope. Subject to your plan asset quota (a full or non-paying plan returns an error).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_type": {
"description": "Asset kind: \"hostname\" (a website/host), \"domain\", \"certificate\", or \"dns_record\".",
"enum": [
"domain",
"hostname",
"certificate",
"dns_record"
],
"type": "string"
},
"dns_enabled": {
"description": "Monitor DNS records.",
"type": "boolean"
},
"domain_enabled": {
"description": "Monitor domain-registration (RDAP) expiry.",
"type": "boolean"
},
"hostname": {
"description": "The hostname to monitor, e.g. example.com",
"type": "string"
},
"label": {
"description": "Optional human label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Monitor the TLS certificate (default on for hostnames).",
"type": "boolean"
},
"uptime_check_url": {
"description": "Optional URL to probe for uptime (enables uptime checks).",
"type": "string"
}
},
"required": [
"hostname",
"asset_type"
],
"type": "object"
},
"name": "create_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Update one of YOUR monitored assets by its asset id (from list_my_assets): relabel it or toggle which checks run. Returns the updated asset. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
},
"dns_enabled": {
"description": "Enable/disable DNS monitoring.",
"type": "boolean"
},
"domain_enabled": {
"description": "Enable/disable domain-registration (RDAP) monitoring.",
"type": "boolean"
},
"label": {
"description": "New label (max 120 chars).",
"type": "string"
},
"ssl_enabled": {
"description": "Enable/disable TLS-certificate monitoring.",
"type": "boolean"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "update_asset"
},
{
"annotations": {
"destructiveHint": true,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "STOP monitoring one of YOUR assets and remove it, by its asset id (from list_my_assets). This is irreversible \u2014 its check history goes too. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asset_id": {
"description": "The asset id from list_my_assets (a UUID).",
"type": "string"
}
},
"required": [
"asset_id"
],
"type": "object"
},
"name": "delete_asset"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Acknowledge one of YOUR alerts by its alert id (from list_my_alerts) \u2014 marks it as seen/being-handled without resolving it. Optionally attach a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "acknowledge_alert"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"readOnlyHint": false,
"requiresAuth": true
},
"description": "Resolve one of YOUR alerts by its alert id (from list_my_alerts) \u2014 closes it. Optionally set resolution (\"fixed\" | \"false_positive\" | \"wontfix\") and a note. Requires an API key with write scope.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alert_id": {
"description": "The alert id from list_my_alerts (a UUID).",
"type": "string"
},
"note": {
"description": "Optional note (max 500 chars).",
"type": "string"
},
"resolution": {
"description": "Why the alert is being closed.",
"enum": [
"fixed",
"false_positive",
"wontfix"
],
"type": "string"
}
},
"required": [
"alert_id"
],
"type": "object"
},
"name": "resolve_alert"
}
]
}
},
"bad_protocol_status_code": 200,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
}
},
"remote_url": "https://api.merlonix.com/mcp",
"server_card_payload": null,
"server_identifier": "cmhenry79/merlonix-mcp"
}
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://glama.ai/mcp/servers/dmnw0faper
- Docs: none
- Support: https://github.com/cmhenry79/merlonix-mcp
- Icon: none
- Remote endpoint: https://api.merlonix.com/mcp
- Directory listing: none
- Server card: none
Transport compliance drilldown
Issues: missing_session_id, missing_protocol_header, bad_protocol_not_rejected
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||