oruk Speech
REMOTE · ORUK.AI · SCANNED SEP 30
Hosted speech-to-text + speech emotion/tone analysis for agents. No install; trial keys built in.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability63
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2065 tokens (~295/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management86
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 1 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the oruk Speech MCP server?
oruk Speech is a hosted endpoint at https://oruk.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · oruk.ai
claude mcp add --transport http ai-oruk-speech 'https://oruk.ai/mcp'
{
"mcpServers": {
"ai-oruk-speech": {
"url": "https://oruk.ai/mcp"
}
}
} {
"servers": {
"ai-oruk-speech": {
"type": "http",
"url": "https://oruk.ai/mcp"
}
}
} [mcp_servers.ai-oruk-speech] url = "https://oruk.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-oruk-speech": {
"type": "remote",
"url": "https://oruk.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-oruk-speech --url 'https://oruk.ai/mcp' --transport streamable-http
mcp_servers:
ai-oruk-speech:
url: "https://oruk.ai/mcp" {
"McpServers": {
"ai-oruk-speech": {
"Transport": "http",
"Url": "https://oruk.ai/mcp"
}
}
} assistant mcp add ai-oruk-speech -t streamable-http -u 'https://oruk.ai/mcp'
{
"mcpServers": {
"ai-oruk-speech": {
"type": "http",
"url": "https://oruk.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 12 Sept 26 0
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- MCP protocol version: 2025-11-25 → 2026-07-28 functional
- Server version: 1.0.0 → 1.1.0 functional
- 8 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “oruk_analyze_speech” rewrote its description, which is the text the model reads security
- Tool “oruk_analyze_tone” rewrote its description, which is the text the model reads security
- Tool “oruk_create_trial_key” rewrote its description, which is the text the model reads security
- Tool “oruk_transcribe_audio” rewrote its description, which is the text the model reads security
- “oruk_analyze_speech” reworded the description of “audio_base64” cosmetic
- “oruk_analyze_speech” reworded the description of “detail” cosmetic
- “oruk_analyze_tone” reworded the description of “audio_base64” cosmetic
- “oruk_analyze_tone” reworded the description of “detail” cosmetic
- “oruk_transcribe_audio” reworded the description of “audio_base64” cosmetic
- “oruk_transcribe_audio” reworded the description of “detail” cosmetic
- 7 Sept 26 −2
- Stability: 0.93 → fail ▼ security
- A breaking change shipped without a version bump: still 1.0.0 ▼ security
- Tool “oruk_check_credits” was removed ▼ security
- Tool “oruk_analyze_tone” rewrote its description, which is the text the model reads security
- New tool “oruk_check_usage” functional
- “oruk_analyze_speech” reworded the description of “diarize” cosmetic
- “oruk_analyze_tone” reworded the description of “diarize” cosmetic
- “oruk_transcribe_audio” reworded the description of “diarize” cosmetic
- 6 Sept 26 +1
- Tool “oruk_list_models” rewrote its description, which is the text the model reads security
- “oruk_analyze_speech” reworded the description of “diarize” cosmetic
- “oruk_analyze_speech” reworded the description of “model” cosmetic
- “oruk_analyze_tone” reworded the description of “diarize” cosmetic
- “oruk_analyze_tone” reworded the description of “model” cosmetic
- “oruk_transcribe_audio” reworded the description of “diarize” cosmetic
- “oruk_transcribe_audio” reworded the description of “model” cosmetic
- 5 Sept 26 −1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “oruk_analyze_tone” rewrote its description, which is the text the model reads security
- Tool “oruk_create_trial_key” rewrote its description, which is the text the model reads security
- Schema quality: 229 → 272 ▼ functional
- “oruk_analyze_speech” added an optional parameter “diarize” cosmetic
- “oruk_analyze_tone” added an optional parameter “diarize” cosmetic
- “oruk_transcribe_audio” added an optional parameter “diarize” cosmetic
- “oruk_analyze_speech” reworded the description of “model” cosmetic
- “oruk_analyze_tone” reworded the description of “model” cosmetic
- “oruk_transcribe_audio” reworded the description of “model” cosmetic
- 4 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 30 Sept 2026 · Probed https://oruk.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=oruk.ai | CN=WE1,O=Google Trust Services,C=US | 26 Sept 2026 | 25 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 972d4342036c6ffb0ebf669b8fb9a645 |
| SANs: oruk.ai, spectra-2-api.oruk.ai, *.spectra-2-api.oruk.ai | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of oruk.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| oruk.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://static.cloudflareinsights.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://www.youtube.com https://s.ytimg.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://www.google-analytics.com https://*.google-analytics.com https://www.googletagmanager.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://ad.doubleclick.net https://www.googleadservices.com https://www.google.com https://google.com https://nicklaunches.com https://useneedle.net https://auraplusplus.com https://www.google.ad https://www.google.ae https://www.google.com.af https://www.google.com.ag https://www.google.al https://www.google.am https://www.google.co.ao https://www.google.com.ar https://www.google.as https://www.google.at https://www.google.com.au https://www.google.az htt |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(self), display-capture=(self), geolocation=(), payment=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://oruk.ai/mcp | Verified | 200 | |
| http (plaintext) | http://oruk.ai/mcp | HTTPS enforced | 308 | https://oruk.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
oruk_analyze_speech Analyze speech (transcript + tone) ~472
Transcribe English audio AND score how it was said in one call: transcript, tagged transcript, selected scores from 15 emotion and 16 speaking-style labels, and time-local segments. Use this when the user cares about both the words and the delivery — meetings, support calls, interviews, voice notes. Accepts wav/flac/mp3/m4a/ogg/webm. Up to 30 MB via audio_url or 8 MiB decoded via audio_base64; up to 60 minutes of English speech. Returns compact summaries by default. For words only use oruk_transcribe_audio; for tone only use oruk_analyze_tone.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Only for temporary keys from oruk_create_trial_key. Permanent keys belong in your MCP client config as an "Authorization: Bearer <key>" header, never in tool arguments. |
| audio_base64 | string | – | Base64-encoded audio bytes for local files (up to 8 MiB decoded). Prefer audio_url for anything larger. |
| audio_url | string | – | Publicly fetchable audio file URL (wav, flac, mp3, m4a, ogg, webm; up to 30 MB / 60 minutes of English speech). |
| detail | string | – | compact (default) returns top label scores and condensed segments; full preserves all returned labels, segments, and word-level timings, subject to response-size limits. It does not expose unreturned… |
| diarize | boolean | – | Label speakers (oruk-resonance only; the model is switched to oruk-resonance automatically). Speaker diarization locates turns, then Resonance scores each turn with its own text, emotions, and styles… |
| filename | string | – | Original filename including extension (e.g. call.wav). Helps decoding when audio_base64 is used. |
| model | string | – | oruk-resonance (full local pipeline: transcription, emotion, style, affect, analysis) or oruk-fourier (parallel transcript and native 15-label emotion, with the shared 16-label style model). Resonanc… |
No output schema declared.
No examples provided.
oruk_analyze_tone Analyze vocal tone and emotion ~512
Score how speech sounds without transcribing it: selected emotion (happy, frustrated, worried, …) and speaking-style (sarcastic, confident, hesitant, warm, …) scores per acoustic segment. Runs the Resonance encoder and affect head only — the transcription decoder is never invoked, so nothing is transcribed and it consumes the same subscription audio minutes as unified analysis. Use this when the user asks about mood, delivery, sentiment, sarcasm, or emotional dynamics in audio. Up to 30 MB via audio_url or 8 MiB decoded via audio_base64; up to 60 minutes of English speech. Labels use model-specific thresholds; the highest-scoring emotion is returned if none passes, and styles can be empty. Outputs describe delivery, not probabilities of inner state. Need the words too? Use oruk_analyze_speech.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Only for temporary keys from oruk_create_trial_key. Permanent keys belong in your MCP client config as an "Authorization: Bearer <key>" header, never in tool arguments. |
| audio_base64 | string | – | Base64-encoded audio bytes for local files (up to 8 MiB decoded). Prefer audio_url for anything larger. |
| audio_url | string | – | Publicly fetchable audio file URL (wav, flac, mp3, m4a, ogg, webm; up to 30 MB / 60 minutes of English speech). |
| detail | string | – | compact (default) returns top label scores and condensed segments; full preserves all returned labels, segments, and word-level timings, subject to response-size limits. It does not expose unreturned… |
| diarize | boolean | – | Label speakers (oruk-resonance only; the model is switched to oruk-resonance automatically). Speaker diarization locates turns, then Resonance scores each turn with its own text, emotions, and styles… |
| filename | string | – | Original filename including extension (e.g. call.wav). Helps decoding when audio_base64 is used. |
| model | string | – | oruk-resonance (full local pipeline: transcription, emotion, style, affect, analysis) or oruk-fourier (parallel transcript and native 15-label emotion, with the shared 16-label style model). Resonanc… |
No output schema declared.
No examples provided.
oruk_check_usage Check API key, subscription, and usage ~89
Verify that an Oruk API key works and report the subscription, remaining audio minutes, and recent API usage. Use this after setup or to diagnose access and usage limits. Requires the Authorization header from your MCP config or a temporary api_key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Only for temporary keys from oruk_create_trial_key. Permanent keys belong in the Authorization header of your MCP client config. |
No output schema declared.
No examples provided.
oruk_create_trial_key Create a free trial API key ~103
Mint a real, temporary oruk API key with no account required: 3 requests, expires in 30 minutes, spends from a capped shared budget. Use this when no Authorization header is configured and the user wants to try transcription or tone analysis right now. Pass the returned key as the api_key argument of the audio tools. Share the signup link with the user so they can keep using oruk afterwards (7-day free trial on self-serve plans).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
oruk_get_started Get started with oruk ~80
Quickstart for the oruk Speech API and this MCP server: how to get an API key, per-client MCP configuration snippets, SDK install commands, and an optional routing rule the user can add to their agent instructions. No API key required. Use this when setting oruk up for the first time or when the user asks how oruk works.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
oruk_list_models List models, pricing, and labels ~75
List oruk’s speech models with lifecycle, current subscription plans, and explicitly labeled legacy reference rates, the five API tasks, the 15 emotion and 16 speaking-style labels, and audio limits. No API key required. Use this to choose a model, estimate cost before analyzing long audio, or see which labels exist.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
oruk_transcribe_audio Transcribe audio ~438
Transcribe prerecorded English audio to text with time-ordered segments and word timings. Use this when only the words matter. Accepts wav/flac/mp3/m4a/ogg/webm. Up to 30 MB via audio_url or 8 MiB decoded via audio_base64; up to 60 minutes of English speech. Does not score emotion or tone — use oruk_analyze_speech for transcript + tone together, or oruk_analyze_tone for tone alone.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Only for temporary keys from oruk_create_trial_key. Permanent keys belong in your MCP client config as an "Authorization: Bearer <key>" header, never in tool arguments. |
| audio_base64 | string | – | Base64-encoded audio bytes for local files (up to 8 MiB decoded). Prefer audio_url for anything larger. |
| audio_url | string | – | Publicly fetchable audio file URL (wav, flac, mp3, m4a, ogg, webm; up to 30 MB / 60 minutes of English speech). |
| detail | string | – | compact (default) returns top label scores and condensed segments; full preserves all returned labels, segments, and word-level timings, subject to response-size limits. It does not expose unreturned… |
| diarize | boolean | – | Label speakers (oruk-resonance only; the model is switched to oruk-resonance automatically). Speaker diarization locates turns, then Resonance scores each turn with its own text, emotions, and styles… |
| filename | string | – | Original filename including extension (e.g. call.wav). Helps decoding when audio_base64 is used. |
| model | string | – | oruk-resonance (full local pipeline: transcription, emotion, style, affect, analysis) or oruk-fourier (parallel transcript and native 15-label emotion, with the shared 16-label style model). Resonanc… |
No output schema declared.
No examples provided.
What is the oruk Speech MCP server?
oruk Speech is an MCP server listed in the public MCP registry as ai.oruk/speech. Hosted speech-to-text + speech emotion/tone analysis for agents. No install; trial keys built in. This page covers its hosted endpoint (https://oruk.ai/mcp).
Is the oruk Speech MCP server safe to use?
oruk Speech scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the oruk Speech MCP server expose?
oruk Speech exposes 7 tools: oruk_analyze_speech, oruk_transcribe_audio, oruk_analyze_tone, oruk_check_usage, oruk_create_trial_key, and 2 more. Their descriptions and schemas cost roughly 1,769 tokens of context every time the server is loaded.
Does the oruk Speech MCP server require authentication?
No. We connected to oruk Speech without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the oruk Speech MCP server still maintained?
oruk Speech is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.