MCP Risk

Directory / server

au.com.totalparks/mcp

This directory entry reports an automated security scan of au.com.totalparks/mcp, scanned 2026-07-28. Trust grade C rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via remote-tools-list

C 72/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as au.com.totalparks/mcp. 1 finding
  • Registry entry: au.com.totalparks/mcp
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
11 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 11
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://mcp.totalparks.com.au/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint unreachable: Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits

UNVERIFIABLE OAuth protected-resource metadata published §3.3

Metadata endpoint unreachable: Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits

INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

WARN Server-supplied instructions free of poisoning indicators §5.1–§5.4
6 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 6 findings
  • server instructions: oversized: 4683 chars (limit 4096)
  • tp_search_parks description: oversized: 2917 chars (limit 2048)
  • tp_search_stays description: oversized: 4331 chars (limit 2048)
  • tp_assess_stay description: oversized: 3482 chars (limit 2048)
  • server instructions: cross-tool shadowing: before calling search tool
  • tp_get_room_type_details: cross-tool shadowing: instead of room_type_ref
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.