stefanoamorelli/sec-edgar-mcp
A SEC EDGAR MCP (Model Context Protocol) Server
Block For Production
trustsnap_28965f3a95807bad.- Utility Coverage
- Transport Compliance
- Tool Surface Design
- Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
- Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.
- Compare initialize responses between the latest two runs and restore the previous stable behavior.
- Search crawler activity
- profile / badge SVG inspection
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risk
Security posture
Tool capability & risk inventory
No tool inventory available from the latest validation run.
Write-action governance
Status detail: No write-action governance evidence is available yet.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
Need at least two validation runs before diffing action controls.
Critical alerts
Compatibility
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• Errortools_list• Skippedtransport_compliance_probe• Skippedstep_up_auth_probe• Missingconnector_replay_probe• Missing — Frozen tool snapshots must survive refresh.request_association_probe• Warning — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• Errortools_list• Skippedtransport_compliance_probe• Skipped
Evidence provenance
action_safety_probe• Not_Assessed
Evidence provenance
tool_snapshot_probe• Missingconnector_replay_probe• Missing
Client compatibility gate details
Remediation checklist
OpenAI connectors expect OAuth for remote server auth.Dynamic client registration materially improves connector setup.Initialize must be reachable.tools/list must succeed.Transport compliance failed or did not complete successfully.OAuth interoperability should be strong.
Remediation checklist
Initialize must succeed or cleanly request auth.tools/list must succeed.Transport behavior should match Claude-compatible HTTP expectations.A useful Claude integration needs at least one exposed tool.The tool surface is not limited to search/fetch-style read tools.OAuth is not configured, so this client cannot authenticate without additional setup.
Remediation checklist
Add a clearer auth boundary around risky write actions.Add confirmation or dry-run semantics for risky actions.Production readiness is blocked by an active alert: Latest validation is failing.Production readiness is blocked by an active alert: Initialize flow regressed.Production readiness is blocked by an active alert: tools/list regressed.
Verdict traces
server_failing• critical • Latest validation is failinginitialize_regressed• critical • Initialize flow regressedtools_list_regressed• critical • tools/list regressed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Likely to fail
- auth_connect: Likely to fail
- safe_write_review: Degraded
Recommended for
No recommendation profile is available yet.
Evidence
Current trust snapshot
trustsnap_28965f3a95807badCanonical machine links
Evidence confidence
Latest validation evidence
Failures
initializeClient error '405 Method Not Allowed' for url 'https://sec-edgar-mcp.amorelli.tech/' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/405oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization server
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Not_Assessed | n/a | No write-action risk evidence recorded. |
advanced_capabilities_probe |
Warning | n/a | Only 1 capability signal(s): roots. |
connector_publishability_probe |
Error | n/a | Publishability blockers: initialize, tools list, protocol version, session resume, +4 more. |
connector_replay_probe |
Missing | n/a | No connector replay evidence recorded. |
determinism_probe |
Skipped | n/a | initialize unreachable |
initialize |
Error | 318.9 ms | Client error '405 Method Not Allowed' for url 'https://sec-edgar-mcp.amorelli.tech/' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/405 |
interactive_flow_probe |
Missing | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 123.6 ms | Client error '404 Not Found' for url 'https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
Missing | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 432.0 ms | Fetched https://sec-edgar-mcp.amorelli.tech/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Skipped | n/a | initialize unreachable |
protocol_version_probe |
Missing | n/a | No protocol version was advertised. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Warning | n/a | Advertised=roots; observed=none. |
resource_read |
Missing | n/a | no resource uri |
resources_list |
Skipped | n/a | initialize unreachable |
schema_divergence_probe |
Missing | n/a | no live tools |
server_card |
OK | 2175.8 ms | authentication, capabilities, description, name |
session_resume_probe |
Skipped | n/a | initialize unreachable |
step_up_auth_probe |
Missing | n/a | No OAuth or incremental-scope signals detected. |
tool_snapshot_probe |
Missing | n/a | no tools |
tools_list |
Skipped | n/a | initialize unreachable |
transport_compliance_probe |
Skipped | n/a | Session header=no, protocol header=no, bad protocol=n/a. |
utility_coverage_probe |
Missing | n/a | No completions evidence; no pagination evidence; tasks skipped. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": false,
"confirmation_signals": [],
"reason": "empty_observation_set",
"safeguard_count": 0,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {},
"declared_non_read_only_tools": 0,
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"has_mutating_capability": false,
"has_non_read_capability": false,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 0,
"medium": 0
},
"secret_tools": 0,
"tool_count": 0
}
},
"latency_ms": null,
"status": "not_assessed"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": true,
"sampling": false,
"structured_outputs": false
},
"enabled": [
"roots"
],
"enabled_count": 1,
"initialize_capability_keys": []
},
"latency_ms": null,
"status": "warning"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"initialize",
"tools_list",
"protocol_version",
"session_resume",
"transport_compliance",
"action_safety",
"tool_surface",
"auth_flow"
],
"criteria": {
"action_safety": false,
"auth_flow": false,
"connector_replay": true,
"initialize": false,
"protocol_version": false,
"remote_transport": true,
"request_association": true,
"server_card": true,
"session_resume": false,
"step_up_auth": true,
"tool_surface": false,
"tools_list": false,
"transport_compliance": false
},
"high_risk_tools": 0,
"tool_count": 0,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "error"
},
"connector_replay_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"determinism_probe": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"initialize": {
"details": {
"error": "Client error '405 Method Not Allowed' for url 'https://sec-edgar-mcp.amorelli.tech/'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/405",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 405,
"payload": {},
"url": "https://sec-edgar-mcp.amorelli.tech/"
},
"latency_ms": 318.85,
"status": "error"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": []
},
"latency_ms": null,
"status": "missing"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource"
},
"latency_ms": 123.6,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": false,
"official_peer_count": 0,
"registry_source": "github_topic_registry"
},
"latency_ms": null,
"status": "missing"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/plain",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"url": "https://sec-edgar-mcp.amorelli.tech/robots.txt",
"validation_disallowed": false
},
"latency_ms": 431.99,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"protocol_version_probe": {
"details": {
"latest_known_version": "2025-11-25",
"reason": "no_protocol_version",
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "missing"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": false,
"drift_fields": [],
"metadata_document_count": 2,
"readable_sources": [
"server_card"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": "SEC Edgar MCP Documentation Docs MCP",
"server_card_version": "1.0.0"
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"advertised_capabilities": [
"roots"
],
"protocol_version": "2025-03-26",
"reason": "no_session_id_for_idle_observation"
},
"latency_ms": null,
"status": "warning"
},
"resource_read": {
"details": {
"reason": "no_resource_uri"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"schema_divergence_probe": {
"details": {
"card_server_name": "SEC Edgar MCP Documentation Docs MCP",
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_server_name": null,
"reason": "no_live_tools",
"server_name_mismatch": false
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"authentication": "none",
"capabilities": {
"resources": true,
"tools": true
},
"description": "Search and retrieve SEC Edgar MCP Documentation documentation",
"name": "SEC Edgar MCP Documentation Docs MCP",
"serverInfo": {
"name": "SEC Edgar MCP Documentation Docs MCP",
"version": "1.0.0"
},
"tools": [
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Search across the SEC Edgar MCP Documentation knowledge base to find relevant information, code examples, API references, and guides. Use this tool when you need to answer questions about SEC Edgar MCP Documentation, find specific documentation, understand how features work, or locate implementation details. The search returns contextual content with titles and direct links to the documentation pages. If you need the full content of a specific page, use the query_docs_filesystem tool to `head` or `cat` the page path (append `.mdx` to the path returned from search \u2014 e.g. `head -200 /api-reference/create-customer.mdx`).",
"inputSchema": {
"properties": {
"query": {
"description": "A query to search the content with.",
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "search_sec_edgar_mcp_documentation"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true
},
"description": "Run a read-only shell-like query against a virtualized, in-memory filesystem rooted at `/` that contains ONLY the SEC Edgar MCP Documentation documentation pages and OpenAPI specs. This is NOT a shell on any real machine \u2014 nothing runs on the user's computer, the server host, or any network. The filesystem is a sandbox backed by documentation chunks.\n\nThis is how you read documentation pages: there is no separate \"get page\" tool. To read a page, pass its `.mdx` path (e.g. `/quickstart.mdx`, `/api-reference/create-customer.mdx`) to `head` or `cat`. To search the docs with exact keyword or regex matches, use `rg`. To understand the docs structure, use `tree` or `ls`.\n\n**Workflow:** Start with the search tool for broad or conceptual queries like \"how to authenticate\" or \"rate limiting\". Use this tool when you need exact keyword/regex matching, structural exploration, or to read the full content of a specific page by path.\n\nSupported commands: rg (ripgrep), grep, find, tree, ls, cat, head, tail, stat, wc, sort, uniq, cut, sed, awk, jq, plus basic text utilities. No writes, no network, no process control. Run `--help` on any command for usage.\n\nEach call is STATELESS: the working directory always resets to `/` and no shell variables, aliases, or history carry over between calls. If you need to operate in a subdirectory, chain commands in one call with `&&` or pass absolute paths (e.g., `cd /api-reference && ls` or `ls /api-reference`). Do NOT assume that `cd` in one call affects the next call.\n\nExamples:\n- `tree / -L 2` \u2014 see the top-level directory layout\n- `rg -il \"rate limit\" /` \u2014 find all files mentioning \"rate limit\"\n- `rg -C 3 \"apiKey\" /api-reference/` \u2014 show matches with 3 lines of context around each hit\n- `head -80 /quickstart.mdx` \u2014 read the top 80 lines of a specific page\n- `head -80 /quickstart.mdx /installation.mdx /guides/first-deploy.mdx` \u2014 read multiple pages in one call\n- `cat /api-reference/create-customer.mdx` \u2014 read a full page when you need everything\n- `cat /openapi/spec.json | jq '.paths | keys'` \u2014 list OpenAPI endpoints\n\nOutput is truncated to 30KB per call. Prefer targeted `rg -C` or `head -N` over broad `cat` on large files. To read only the relevant sections of a large file, use `rg -C 3 \"pattern\" /path/file.mdx`. Batch multiple file reads into a single `head` or `cat` call whenever possible.\n\nWhen referencing pages in your response to the user, convert filesystem paths to URL paths by removing the `.mdx` extension. For example, `/quickstart.mdx` becomes `/quickstart` and `/api-reference/overview.mdx` becomes `/api-reference/overview`.",
"inputSchema": {
"properties": {
"command": {
"description": "A shell command to run against the virtualized documentation filesystem (e.g., `rg -il \"keyword\" /`, `tree / -L 2`, `head -80 /path/file.mdx`).",
"type": "string"
}
},
"required": [
"command"
],
"type": "object"
},
"name": "query_docs_filesystem_sec_edgar_mcp_documentation"
}
],
"transport": "http",
"url": "https://stefanoamorelli.main-kill-isr.mintlify.me/mcp",
"version": "1.0.0"
},
"url": "https://sec-edgar-mcp.amorelli.tech/.well-known/mcp/server-card.json"
},
"latency_ms": 2175.78,
"status": "ok"
},
"session_resume_probe": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "missing"
},
"tool_snapshot_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"tools_list": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"transport_compliance_probe": {
"details": {
"reason": "initialize_unreachable"
},
"latency_ms": null,
"status": "skipped"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": null,
"probe_status": "skipped"
}
},
"latency_ms": null,
"status": "missing"
}
},
"failures": {
"initialize": {
"error": "Client error '405 Method Not Allowed' for url 'https://sec-edgar-mcp.amorelli.tech/'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/405",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 405,
"payload": {},
"url": "https://sec-edgar-mcp.amorelli.tech/"
},
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://sec-edgar-mcp.amorelli.tech/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
}
},
"remote_url": "https://sec-edgar-mcp.amorelli.tech/",
"server_card_payload": null,
"server_identifier": "github-stefanoamorelli/sec-edgar-mcp"
}
Known versions
- No versions recorded.
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 10, 2026 04:01:29 AM UTC | Failing | 0.0 | 3188.9 ms | 0 |
| Aug 09, 2026 04:01:15 PM UTC | Failing | 0.0 | 928.6 ms | 0 |
| Aug 09, 2026 04:00:51 AM UTC | Failing | 0.0 | 1041.3 ms | 0 |
| Aug 08, 2026 03:57:39 PM UTC | Failing | 0.0 | 1142.5 ms | 0 |
| Aug 08, 2026 03:18:50 AM UTC | Failing | 0.0 | 1129.1 ms | 0 |
| Aug 07, 2026 03:17:04 PM UTC | Failing | 0.0 | 984.3 ms | 0 |
| Aug 07, 2026 03:15:35 AM UTC | Failing | 0.0 | 971.1 ms | 0 |
| Aug 06, 2026 03:14:29 PM UTC | Failing | 0.0 | 2092.9 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 10, 2026 04:01:29 AM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 09, 2026 04:01:15 PM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 09, 2026 04:00:51 AM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 08, 2026 03:57:39 PM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 08, 2026 03:18:50 AM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 07, 2026 03:17:04 PM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 07, 2026 03:15:35 AM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 03:14:29 PM UTC | Failing | 0.0 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 02:45:44 AM UTC | Failing | 0.5 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 06:33:26 PM UTC | Failing | 8.0 | unknown | unknown | 0 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 10, 2026 04:01:26 AM UTC | Completed | Failing | 3188.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 09, 2026 04:01:14 PM UTC | Completed | Failing | 928.6 ms | |
| Aug 09, 2026 04:00:50 AM UTC | Completed | Failing | 1041.3 ms | |
| Aug 08, 2026 03:57:38 PM UTC | Completed | Failing | 1142.5 ms | |
| Aug 08, 2026 03:18:49 AM UTC | Completed | Failing | 1129.1 ms | |
| Aug 07, 2026 03:17:03 PM UTC | Completed | Failing | 984.3 ms | |
| Aug 07, 2026 03:15:34 AM UTC | Completed | Failing | 971.1 ms | |
| Aug 06, 2026 03:14:27 PM UTC | Completed | Failing | 2092.9 ms | |
| Aug 06, 2026 02:45:43 AM UTC | Completed | Failing | 1168.0 ms | |
| Aug 05, 2026 06:33:25 PM UTC | Completed | Failing | 992.4 ms | |
Public server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 10, 2026 04:01:29 AM UTC | Latest validation: failing | Score 0.0 with status failing. |
| Aug 05, 2026 11:01:17 AM UTC | Score corrected (post-1.0.503 remediation, R1 zero-anchoring) | Prior: 11.83. Corrected: 6.54. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://sec-edgar-mcp.amorelli.tech/
- Docs: https://sec-edgar-mcp.amorelli.tech/
- Support: https://github.com/stefanoamorelli/sec-edgar-mcp
- Icon: https://avatars.githubusercontent.com/u/10986064?v=4
- Remote endpoint: https://sec-edgar-mcp.amorelli.tech/
- Server card: https://sec-edgar-mcp.amorelli.tech/.well-known/mcp/server-card.json
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Likely to fail |
|
| Read-only fetch flow | Likely to fail |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Transport compliance drilldown
Issues: none
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Tool snapshot diff & changelog
Need at least two validation runs before building a tool changelog.
Validation diff
Regressed checks: action_safety_probe, connector_publishability_probe, determinism_probe, initialize, oauth_protected_resource, prompts_list, provenance_divergence_probe, resources_list, session_resume_probe, tools_list, transport_compliance_probe
Improved checks: probe_noise_resilience, server_card
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
| No component deltas between the latest two runs. | |||
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | SEC Edgar MCP Documentation Docs MCP |
| Version | n/a | 1.0.0 |
| Homepage | n/a | n/a |
Active alerts
- Latest validation is failing (critical)
Core MCP flows did not validate successfully on the latest run. - Initialize flow regressed (critical)
A client-visible initialize behavior changed for the worse. - tools/list regressed (critical)
Tool discovery became less reliable on the latest run.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
github-stefanoamorelli/sec-edgar-mcp |
github_topic_registry | yes | n/a |
stefanoamorelli/sec-edgar-mcp |
glama_registry | no | n/a |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| Registry source | Multiple registries or registry sync paths claim this same canonical server. | github_topic_registry glama_registry |
| Remote URL | Aliases currently point at different MCP endpoints, which can indicate mirrors, stale registry data, or a real endpoint split. | https://glama.ai/mcp/servers/zs33inbr0h https://sec-edgar-mcp.amorelli.tech/ |
| Homepage | Registry entries disagree on the primary homepage for this server. | https://glama.ai/mcp/servers/zs33inbr0h https://sec-edgar-mcp.amorelli.tech/ |
| Registry identifier | Different registry-specific identifiers resolve to the same canonical server record here. | github_topic_registry:stefanoamorelli/sec-edgar-mcp glama_registry:zs33inbr0h |
Fix it
Why this score?
Algorithmic score breakdown
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| Critical | Ensure tools/list succeeds consistently | Tools discovery is the minimum viable contract for most MCP clients and directories. | Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.Playbook
|
| Critical | Make initialize deterministic and client-friendly | If initialize fails or requires undocumented auth, many MCP clients cannot connect. | Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.Playbook
|
| Critical | Respond to initialize flow regressed | A client-visible initialize behavior changed for the worse. | Compare initialize responses between the latest two runs and restore the previous stable behavior. |
| Critical | Respond to latest validation is failing | Core MCP flows did not validate successfully on the latest run. | Fix the failing checks first, then revalidate to confirm the recovery path.Playbook
|
| Critical | Respond to tools/list regressed | Tool discovery became less reliable on the latest run. | Compare tool enumeration outputs between runs and remove non-deterministic behavior. |
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Associate roots, sampling, and elicitation with active client requests | Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions. | Only send roots/list, sampling/createMessage, or elicitation/create requests while handling an active client-initiated request, never on idle sessions.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| High | Resolve conflicting endpoints across registry aliases | Registry aliases for this canonical server currently resolve to different live MCP endpoints (https://glama.ai/mcp/servers/zs33inbr0h, https://sec-edgar-mcp.amorelli.tech/). An agent following one registry entry reaches a different server than one following another. | Confirm which endpoint is canonical, correct or retire the stale registry entry, and re-sync so every alias agrees on one remote_url.Playbook
|
| High | Stabilize repeated tools/list responses | Tool enumeration drift causes client caching and planning issues. | Return the same tool surface on repeated tools/list calls unless a real version change occurred. |
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | |
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Access & Protocol score | Connectivity, auth, and transport expectations for common clients. | Tighten auth discovery, session behavior, and transport metadata until remote clients can connect without guesswork. |
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Raise Interface Quality score | How well the tool/resource interface communicates and behaves under automation. | Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically. |
| Medium | Raise Reliability & Trust score | Operational stability, consistency, and trustworthiness over time. | Stabilize behavior over time and reduce failure drift between validation runs. |
| Medium | Raise Security Posture score | How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs. | Reduce destructive, egress, exec, secret, and freeform-input risk across the exposed tool surface.Playbook
|
| Medium | Repair prompts/list or stop advertising prompts | Prompt metadata should either work live or be removed from the advertised capability set. | Only advertise prompts if prompts/list works and prompt arguments are documented.Playbook
|
| Medium | Repair resources/list or stop advertising resources | Resource metadata should either work live or be removed from the advertised capability set. | Only advertise resources if resources/list works and resources expose stable URIs/types.Playbook
|
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Persist session state keyed by Mcp-Session-Id and honor Last-Event-ID on GET reconnects so clients can resume a dropped Streamable HTTP session.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
| Low | Publish or reconcile the server in the official MCP registry | Official registry presence improves discovery confidence and cross-source consistency. |
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 0/4 | -4.0 |
| Transport Compliance | 0/4 | -4.0 |
| Tool Surface Design | 0/4 | -4.0 |
| Tool Snapshot Churn | 0/4 | -4.0 |
| Tool Namespace Clarity | 0/4 | -4.0 |
| Tool Capability Clarity | 0/4 | -4.0 |
| Task Success | 0/4 | -4.0 |
| Step Up Auth | 0/4 | -4.0 |
| Spec Recency | 0/4 | -4.0 |
| SLO Health | 0/4 | -4.0 |
| Session Semantics | 0/4 | -4.0 |
| Session Resume | 0/4 | -4.0 |
Compatibility profiles
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Governance
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.github-stefanoamorelli/sec-edgar-mcp.