app.agendaforge/agendaforge
REMOTE · MCP.AGENDAFORGE.APP · SCANNED SEP 22
Event management for organizers: events, sessions, speakers, agendas, forms, approval-gated writes.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security81
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 401, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability47
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (poor).Fail
- Context-footprint check failed: tool/resource definitions use about 9464 tokens (~169/item across 56 items; 55 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management88
- Stability check failed: schema churn in the 27 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 5 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- Manipulation check failed: an AI judge found 1 of 57 captured unit(s) of tool text manipulative, the first being "server instructions". See how to fix → Fail
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the app.agendaforge/agendaforge MCP server?
app.agendaforge/agendaforge is a hosted endpoint at https://mcp.agendaforge.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.agendaforge.app
claude mcp add --transport http app-agendaforge-agendaforge 'https://mcp.agendaforge.app/mcp'
{
"mcpServers": {
"app-agendaforge-agendaforge": {
"url": "https://mcp.agendaforge.app/mcp"
}
}
} {
"servers": {
"app-agendaforge-agendaforge": {
"type": "http",
"url": "https://mcp.agendaforge.app/mcp"
}
}
} [mcp_servers.app-agendaforge-agendaforge] url = "https://mcp.agendaforge.app/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"app-agendaforge-agendaforge": {
"type": "remote",
"url": "https://mcp.agendaforge.app/mcp",
"enabled": true
}
}
} openclaw mcp add app-agendaforge-agendaforge --url 'https://mcp.agendaforge.app/mcp' --transport streamable-http
mcp_servers:
app-agendaforge-agendaforge:
url: "https://mcp.agendaforge.app/mcp" {
"McpServers": {
"app-agendaforge-agendaforge": {
"Transport": "http",
"Url": "https://mcp.agendaforge.app/mcp"
}
}
} assistant mcp add app-agendaforge-agendaforge -t streamable-http -u 'https://mcp.agendaforge.app/mcp'
{
"mcpServers": {
"app-agendaforge-agendaforge": {
"type": "http",
"url": "https://mcp.agendaforge.app/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 84 to 88.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 78 to 81.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 71 to 74.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 64 to 68.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 58 to 61.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 48 to 51.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 41 to 44.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 34 to 38.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.agendaforge.app/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=agendaforge.app | CN=WE1,O=Google Trust Services,C=US | 25 Aug 2026 | 23 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | f75d3a9c6d5ed5e13490b2d00ce3069 |
| SANs: agendaforge.app, mcp.agendaforge.app, *.mcp.agendaforge.app | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.agendaforge.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| agendaforge.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.agendaforge.app/.well-known/oauth-protected-resource/mcp"
Bearer resource_metadata="https://mcp.agendaforge.app/.well-known/oauth-protected-resource/mcp" Protected resource metadata
| Document | https://mcp.agendaforge.app/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.agendaforge.app/mcp |
| Authorisation server | https://vigilant-gale-70.authkit.app |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.agendaforge.app/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.agendaforge.app/mcp | Inconclusive | 401 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
update_contact ~452
Update a contact's profile fields, tags, or custom fields. Depending on the organization's settings, this either executes immediately or files a proposal for approval; the response status field says which happened.
| Name | Type | Req | Description |
|---|---|---|---|
| bio | string | – | New biography. |
| company | string | – | New company. |
| contactId | string | yes | The contact id to update. |
| customFields | object | – | Key→value map of custom fields. Only include keys you want to add or change; existing custom fields are preserved (send a key with value null to remove it). You may key each entry by the field's disp… |
| eventId | string | yes | Event id, as returned by list_events. |
| expertiseAreas | array | – | Replacement list of the contact's areas of expertise. |
| firstName | string | – | New first name. |
| jobTitle | string | – | New job title. |
| lastName | string | – | New last name. |
| location | string | – | New location. |
| org | string | – | Organization slug. Only needed when you belong to multiple organizations; must be one returned by list_my_orgs. |
| phone | string | – | New phone number. |
| rating | number | – | A numeric rating/score for the contact. |
| request_id | string | yes | Client-generated unique id for this write (e.g. a UUID). Retries with the same request_id return the original executed or proposed outcome instead of creating a duplicate. Never reuse a request_id fo… |
| socialLinks | object | – | The contact's social profile links. |
| status | string | – | The contact's status. 'archived' hides them; this is reversible. |
| tags | array | – | Replacement list of free-text tags for the contact. |
| type | string | – | The contact's type/category. |
| website | string | – | New personal website URL. |
No output schema declared.
No examples provided.
update_form ~183
Conversationally edit a DRAFT form by instruction. Active forms are refused. Depending on the organization's settings, this either executes immediately or files a proposal for approval; the response status field says which happened.
| Name | Type | Req | Description |
|---|---|---|---|
| eventId | string | yes | Event id, as returned by list_events. |
| formId | string | yes | The draft form id to edit. |
| instruction | string | yes | The natural-language edit instruction (e.g. 'rename the title', 'add a phone field'). |
| org | string | – | Organization slug. Only needed when you belong to multiple organizations; must be one returned by list_my_orgs. |
| request_id | string | yes | Client-generated unique id for this write (e.g. a UUID). Retries with the same request_id return the original executed or proposed outcome instead of creating a duplicate. Never reuse a request_id fo… |
No output schema declared.
No examples provided.
update_form_pipeline ~168
Replace a form's submission pipeline stages (add, remove, rename, reorder). Depending on the organization's settings, this either executes immediately or files a proposal for approval; the response status field says which happened.
| Name | Type | Req | Description |
|---|---|---|---|
| eventId | string | yes | Event id, as returned by list_events. |
| formId | string | yes | The form id. |
| org | string | – | Organization slug. Only needed when you belong to multiple organizations; must be one returned by list_my_orgs. |
| request_id | string | yes | Client-generated unique id for this write (e.g. a UUID). Retries with the same request_id return the original executed or proposed outcome instead of creating a duplicate. Never reuse a request_id fo… |
| statuses | array | yes | The full replacement pipeline stages array. |
No output schema declared.
No examples provided.
update_session ~567
Update a session's content, taxonomy, schedule, or custom fields. Depending on the organization's settings, this either executes immediately or files a proposal for approval; the response status field says which happened.
| Name | Type | Req | Description |
|---|---|---|---|
| customFields | object | – | Key→value map of custom fields. Only include keys you want to add or change; existing custom fields are preserved (send a key with value null to remove it). You may key each entry by the field's disp… |
| description | string | – | New session description. |
| duration | number | – | New duration in minutes (recomputes end time if scheduled). |
| endTime | string | – | New end time as an ISO 8601 string. |
| eventId | string | yes | Event id, as returned by list_events. |
| format | string | – | The format's exact NAME as returned by get_field_options (not free text). |
| isPublic | boolean | – | Whether the session is public. |
| isTentative | boolean | – | Whether the session is tentative. |
| language | string | – | The language's exact NAME as returned by get_field_options (not free text). |
| level | string | – | The level's exact NAME as returned by get_field_options (not free text). |
| maxAttendees | number | – | New maximum attendee capacity. |
| org | string | – | Organization slug. Only needed when you belong to multiple organizations; must be one returned by list_my_orgs. |
| request_id | string | yes | Client-generated unique id for this write (e.g. a UUID). Retries with the same request_id return the original executed or proposed outcome instead of creating a duplicate. Never reuse a request_id fo… |
| room | string | – | The room's exact NAME as returned by get_field_options (not free text). |
| sessionId | string | yes | The session id to update. |
| startTime | string | – | New start time as an ISO 8601 string. |
| status | string | – | The status's exact NAME as returned by get_field_options (not free text). |
| tags | array | – | Replacement list of PREDEFINED tag names for the session. Each must exactly match a tag from get_field_options — tags are not free text. |
| title | string | – | New session title. |
| track | string | – | The track's exact NAME as returned by get_field_options (not free text). |
| type | string | – | New session type. |
No output schema declared.
No examples provided.
update_sponsor ~318
Update a sponsor's details or custom fields. Depending on the organization's settings, this either executes immediately or files a proposal for approval; the response status field says which happened.
| Name | Type | Req | Description |
|---|---|---|---|
| customFields | object | – | Key→value map of custom fields. Only include keys you want to add or change; existing custom fields are preserved (send a key with value null to remove it). You may key each entry by the field's disp… |
| description | string | – | New sponsor description. |
| eventId | string | yes | Event id, as returned by list_events. |
| hasBooth | boolean | – | Whether the sponsor has a booth. |
| name | string | – | New sponsor name. |
| org | string | – | Organization slug. Only needed when you belong to multiple organizations; must be one returned by list_my_orgs. |
| request_id | string | yes | Client-generated unique id for this write (e.g. a UUID). Retries with the same request_id return the original executed or proposed outcome instead of creating a duplicate. Never reuse a request_id fo… |
| sponsorId | string | yes | The sponsor id to update. |
| website | string | – | New sponsor website URL. |
No output schema declared.
No examples provided.
What is the app.agendaforge/agendaforge MCP server?
app.agendaforge/agendaforge is an MCP server listed in the public MCP registry as app.agendaforge/agendaforge. Event management for organizers: events, sessions, speakers, agendas, forms, approval-gated writes. This page covers its hosted endpoint (https://mcp.agendaforge.app/mcp).
Is the app.agendaforge/agendaforge MCP server safe to use?
app.agendaforge/agendaforge scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the app.agendaforge/agendaforge MCP server expose?
app.agendaforge/agendaforge exposes 55 tools: list_my_orgs, list_events, get_event, list_sessions, get_session, and 50 more. Their descriptions and schemas cost roughly 9,327 tokens of context every time the server is loaded.
Does the app.agendaforge/agendaforge MCP server require authentication?
Yes. app.agendaforge/agendaforge asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the app.agendaforge/agendaforge MCP server still maintained?
app.agendaforge/agendaforge is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.