Mmcp.market

MCP Observatory: one read only walk over every https endpoint in the official registry MCP server

by ogasurfproject-jpg·io.github.ogasurfproject-jpg/hs-mcp-observatory·v0.1.1

Public record of one read only walk over the official MCP registry: who answered, tools, who pays.

A88/100grade A
What users say
No reviews yet
Be the first
Safety scan
A88/100

full report

Adoption
Growing

1 stars

Reviews

Write one

Nobody has reviewed MCP Observatory: one read only walk over every https endpoint in the official registry yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

MCP Observatory: one read only walk over every https endpoint in the official registry tools (6)

write = sends, deletes, buys or posts
  • mcp_observatory_disclosure_guideFree

    How the 152 servers that stated who compensates their operator actually did it - the field names observed in the wild, with counts. Not a specification we invented.

  • mcp_observatory_lookupFree

    What happened when we contacted one address, or an aggregate for one host. Returns the record hash and the procedure to recompute it. There is no tool here that lists addresses; you must already hold the one you are asking about.

  • mcp_observatory_measure_nowFree

    Contact one https address now and report what we see: whether it speaks MCP, whether it carries an agent card, and whether that card names who compensates the operator. Read only; no tool is called. robots.txt is read first and honoured. This does NOT change the published record - the next full walk does that. Rate limited, because it contacts somebody else's server on your behalf.

  • mcp_observatory_methodFree

    How the walk was run, what we got wrong and corrected, and the four rules the report holds itself to.

  • mcp_observatory_stateFree

    What was measured, when, over what population, and what the measurement cannot tell you. Read this before quoting any number from this server.

  • mcp_observatory_summaryFree

    The counts, as published and as corrected. How many addresses answered, how many tools they exposed, how many stated who compensates their operator.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

no findings
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 398ms20/20
  • Tool poisoning6 tool descriptions checked15/15
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 88/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the MCP Observatory: one read only walk over every https endpoint in the official registry repository's README, as published. We do not edit it. Read it on GitHub

🛡️ HORIZON SHIELD

Verifiable construction estimate auditing for AI agents

Don't trust the estimate. Verify it.

An MCP server that lets AI agents check whether a Japanese construction or renovation estimate is fair, against open data, and returns a result anyone can verify against Bitcoin (OpenTimestamps). No account, no key.

NENRIN: tree rings for AI facing services

A tree adds one ring a year. Nobody can paint one in afterwards. NENRIN gives that property to software services.

In one thirty day window, measured 2026-08-17, this server appeared in 93,983 AI search results. How many of those became a call from outside, we cannot say. The usage counter deliberately stores no IP addresses, so it cannot separate our own automated checks from external traffic. An earlier version of this paragraph said the answer was 0. This instrument cannot establish that, so the claim is withdrawn here rather than quietly deleted. Discovery is solved. Choice is not. An agent picking between 90,000 servers can only read what each vendor wrote about itself. NENRIN adds the missing layer: records of conduct that the vendor did not author and cannot delete.

How it works, in three lines:

  1. Open witnessing. Anyone can measure any endpoint and submit the walk to the public ledger under their own name and vantage. The operator holds no veto: acceptance is mechanical schema checking, and the code that enforces this is in this repository.
  2. Discrepancies are the product. When two witnesses report incompatible observations of the same target, the disagreement itself becomes a permanent, citable record. The founding one is real: NENRINDISCREPANCY0001, two honest witnesses, one target, both correct.
  3. Rings. Each month the accepted records bundle into a ring that carries the hash of the previous ring, timestamped to Bitcoin. Eighteen months of rings cannot be created in an afternoon, by anyone, including us.

The specification is anchored on the public ledger as entry 19 (sha256 9ccba2e325fd2a555fcdb2dec519b8c6bf7a669064674846aea98ecfff824e3d): NENRINSPECv1.md. It names its own prior art (Certificate Transparency, Rekor, in-toto, SLSA, OpenTimestamps), states exactly which combination is claimed as new, and invites refutation into the same ledger.

The witness intake is live. Start here:

curl -s https://ledger.horizonshield.dev/witness

We are the first test subject under our own rules. The ledger keeps the record of our gate failing its own test, and the full 522 incident that started all of this. Unflattering records stay.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

claude mcp add --transport http hs-mcp-observatory https://observatory.horizonshield.dev/mcp
Add to Cursor

MCP Observatory: one read only walk over every https endpoint in the official registry: common questions

Is MCP Observatory: one read only walk over every https endpoint in the official registry MCP server safe?
Yes, by our scan: it is graded A (88/100). Read the MCP Observatory: one read only walk over every https endpoint in the official registry safety report
How do I install MCP Observatory: one read only walk over every https endpoint in the official registry?
It runs remotely at observatory.horizonshield.dev. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does MCP Observatory: one read only walk over every https endpoint in the official registry need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is MCP Observatory: one read only walk over every https endpoint in the official registry maintained?
The last commit was in the last day (2026-09-20). The latest release is v0.1.1.
Is MCP Observatory: one read only walk over every https endpoint in the official registry up?
100% of our last 8 checks got an answer. We check remote servers about four times a day.
What can I use instead of MCP Observatory: one read only walk over every https endpoint in the official registry?
Servers from other publishers that do the same job: Dashclaw MCP server.

Alternatives to MCP Observatory: one read only walk over every https endpoint in the official registry

Same job from other publishers: the closest match first, then the best rated.

  • Dashclaw
    Policy checks, approvals, records, and governed HTTP capabilities for unattended agents.
    B

More from ogasurfproject-jpg