MCP Risk

Directory / server

build.exascale/osint

This directory entry reports an automated security scan of build.exascale/osint, scanned 2026-07-28. Trust grade C rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via remote-tools-list

C 70/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as build.exascale/osint. 1 finding
  • Registry entry: build.exascale/osint
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
50 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 50
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://api.exascale.build/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint rejected the probe (HTTP 400); whether it requires authentication could not be determined.

WARN OAuth protected-resource metadata published §3.3
No protected-resource metadata found - clients cannot discover the authorization server per spec. 1 finding
  • Checked: https://api.exascale.build/.well-known/oauth-protected-resource
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

WARN Server-supplied instructions free of poisoning indicators §5.1–§5.4
20 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 20 findings
  • query_power_demand_v1 description: oversized: 2256 chars (limit 2048)
  • query_power_demand_rollup_v1 description: oversized: 3144 chars (limit 2048)
  • query_power_retail_sales_v1 description: oversized: 2117 chars (limit 2048)
  • query_power_interconnection_queue_v1 description: oversized: 2678 chars (limit 2048)
  • query_power_interconnection_queue_pjm_v1 description: oversized: 3007 chars (limit 2048)
  • query_power_interconnection_queue_pjm_cycle_v1 description: oversized: 2595 chars (limit 2048)
  • query_power_interconnection_queue_caiso_v1 description: oversized: 3618 chars (limit 2048)
  • query_power_interconnection_queue_nyiso_v1 description: oversized: 4080 chars (limit 2048)
  • query_power_interconnection_queue_isone_v1 description: oversized: 3470 chars (limit 2048)
  • query_power_interconnection_queue_ercot_v1 description: oversized: 4230 chars (limit 2048)
  • query_power_interconnection_queue_spp_v1 description: oversized: 3834 chars (limit 2048)
  • query_power_price_ercot_v1 description: oversized: 3108 chars (limit 2048)
  • query_ai_infrastructure_construction_v1 description: oversized: 3090 chars (limit 2048)
  • query_ai_infrastructure_employment_v1 description: oversized: 6313 chars (limit 2048)
  • query_ai_infrastructure_trade_v1 description: oversized: 2357 chars (limit 2048)
  • query_ai_infrastructure_equipment_trade_v1 description: oversized: 2737 chars (limit 2048)
  • query_ai_infrastructure_production_v1 description: oversized: 2744 chars (limit 2048)
  • query_robotics_trade_v1 description: oversized: 2901 chars (limit 2048)
  • query_robotics_adoption_v1 description: oversized: 2836 chars (limit 2048)
  • query_space_satellite_filings_v1 description: oversized: 2940 chars (limit 2048)
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.