MCP/Risk

Scan report

com.aidesignblueprint/blueprint

remote, scanned 2026-09-10, tool surface via remote-tools-list

This page reports an automated security scan of com.aidesignblueprint/blueprint (remote), scanned 2026-09-10. It rates trust (provenance, transport, known vulnerabilities, instruction integrity) as grade C and capability risk (what the tools can do) separately at low. It does not certify the server is safe to connect; it reports what could be checked from outside.

Tool surface changed. This server’s tool schema differs from its previous scan (2026-07-28). Re-review §2 and §5 before continuing to trust it - silent schema changes are the "rug pull" pattern.

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as com.aidesignblueprint/blueprint. 1 finding
  • Registry entry: com.aidesignblueprint/blueprint
FAIL Source repository is public and maintained §1.2

Claimed source repository does not exist (or is private).

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
29 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 29
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://aidesignblueprint.com/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint rejected the probe (HTTP 400); whether it requires authentication could not be determined.

PASS OAuth protected-resource metadata published §3.3
Publishes /.well-known/oauth-protected-resource per the June 2025 authorization spec. 1 finding
  • Authorization server: https://aidesignblueprint.com
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

WARN Server-supplied instructions free of poisoning indicators §5.1–§5.4
6 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 6 findings
  • architect.validate description: oversized: 8708 chars (limit 2048)
  • design.validate description: oversized: 3421 chars (limit 2048)
  • spec.validate description: oversized: 3415 chars (limit 2048)
  • architect.validate_consensus description: oversized: 3312 chars (limit 2048)
  • architect.certify description: oversized: 6983 chars (limit 2048)
  • me.session_event description: oversized: 2102 chars (limit 2048)

Verify manually - the scoring model can’t judge these for you

  • §2.3 - Is the tool surface no broader than the server’s stated purpose requires?
  • §3.4 - For stdio servers: which environment credentials does it read, and are they scoped rather than org-wide tokens?
  • §6.1 - Cross this server’s capabilities with your already-connected servers: any read-capability × send-capability pairs need explicit sign-off.
  • §6.2 - Run the connecting agent with sandboxing and egress controls sized to the combined tool surface, not just this server’s.

Methodology: MCP Server Security Policy. Checks and scoring weights are open source. Unfamiliar term? See the glossary.