AurelianFlo
REMOTE · API.AURELIANFLO.COM · SCANNED SEP 22
Remote MCP server for OFAC screening, EDD memos, exposure forecasts, queues, and reports.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability79
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1701 tokens (~154/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 96% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the AurelianFlo MCP server?
AurelianFlo is a hosted endpoint at https://api.aurelianflo.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.aurelianflo.com
claude mcp add --transport http com-aurelianflo-core 'https://api.aurelianflo.com/mcp'
{
"mcpServers": {
"com-aurelianflo-core": {
"url": "https://api.aurelianflo.com/mcp"
}
}
} {
"servers": {
"com-aurelianflo-core": {
"type": "http",
"url": "https://api.aurelianflo.com/mcp"
}
}
} [mcp_servers.com-aurelianflo-core] url = "https://api.aurelianflo.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-aurelianflo-core": {
"type": "remote",
"url": "https://api.aurelianflo.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-aurelianflo-core --url 'https://api.aurelianflo.com/mcp' --transport streamable-http
mcp_servers:
com-aurelianflo-core:
url: "https://api.aurelianflo.com/mcp" {
"McpServers": {
"com-aurelianflo-core": {
"Transport": "http",
"Url": "https://api.aurelianflo.com/mcp"
}
}
} assistant mcp add com-aurelianflo-core -t streamable-http -u 'https://api.aurelianflo.com/mcp'
{
"mcpServers": {
"com-aurelianflo-core": {
"type": "http",
"url": "https://api.aurelianflo.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://api.aurelianflo.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.aurelianflo.com | CN=YR2,O=Let's Encrypt,C=US | 13 Aug 2026 | 11 Nov 2026 | RSA 2048 | SHA256-RSA | 53c816d4494443cf01c5546a17d108094fd |
| SANs: api.aurelianflo.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.aurelianflo.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| aurelianflo.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.aurelianflo.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.aurelianflo.com/mcp | HTTPS enforced | 308 | https://api.aurelianflo.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compliance_edd_report EDD Report ~286
Build a paid enhanced due diligence memo for a wallet set using exact-match OFAC screening, sanctions evidence, and follow-up actions, returning structured JSON or an inline PDF/DOCX artifact. Use this for case handoff; use wallet_ofac_batch for screening-only results or report_pdf_generate/report_docx_generate only when the report payload already exists.
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | Crypto wallet addresses to screen for OFAC sanctions exposure and include in the enhanced due diligence memo. |
| artifact_only | boolean | – | When output_format is pdf or docx, return a compact artifact-first response without the full memo payload. |
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| case_name | string | – | Optional case or review title shown in the memo. |
| jurisdiction | string | – | Optional jurisdiction or operating region for the case. |
| output_format | string | yes | Select json for the structured memo payload or pdf|docx for a generated artifact. |
| reference_id | string | – | Optional internal case or review reference. |
| requested_by | string | – | Optional requester, owner, or reviewing team. |
| review_reason | string | – | Optional reason the EDD memo is being prepared. |
| subject_name | string | yes | Human-readable subject or counterparty name for the memo. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
compliance_exposure_forecast Compliance Exposure Forecast ~240
Forecast future OFAC wallet exposure for a wallet set using stored OFAC snapshot diffs when available, listedOn backfill when honest, or an explicit caller prior; returns current exact-match baseline, metadata-weighted per-wallet risk, and report-shaped output. Use this when current screening is not enough; use wallet_ofac_batch for current hit status only.
| Name | Type | Req | Description |
|---|---|---|---|
| address_metadata | array | – | Optional per-address business metadata used to weight exposure hazard. |
| addresses | array | yes | Wallet addresses to forecast for future OFAC exact-match exposure. |
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| horizon_days | integer | – | Forecast horizon in days. |
| iterations | integer | – | Forecast trial count. |
| priors | object | – | Explicit prior assumptions used only when overriding OFAC history cadence. |
| summary_focus | string | – | Optional summary emphasis or focus area. |
| target | object | – | Target event for the forecast probability. |
| tier_weights | object | – | Relationship tier weight overrides. |
| title | string | – | Optional report title. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
compliance_queue_optimize Compliance Review Queue Optimizer ~227
Optimize a compliance review queue using current OFAC exact matches, future exposure probabilities, exposure value, relationship tier, recency, and reviewer capacity. Use this when review_items and review_budget are known; use compliance_exposure_forecast for probability-only analysis or compliance_edd_report for a case memo.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| horizon_days | integer | – | Forecast horizon in days. |
| iterations | integer | – | Forecast trial count. |
| objective | string | – | Optimization objective. |
| priors | object | – | Explicit prior assumptions used only when overriding OFAC history cadence. |
| review_budget | integer | yes | Number of items a reviewer can handle in the next review window. |
| review_items | array | yes | Wallet review items with per-address metadata required for queue optimization. |
| summary_focus | string | – | Optional summary emphasis or focus area. |
| tier_weights | object | – | Relationship tier weight overrides. |
| title | string | – | Optional report title. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
queue_saved_list Saved Queue Status ~100
Free read-only saved queue status utility for agents asking whether AurelianFlo can list prior compliance_queue_optimize results. AurelianFlo does not persist saved queues server-side; rerun compliance_queue_optimize with the original review_items to recreate a queue.
| Name | Type | Req | Description |
|---|---|---|---|
| case_reference | string | – | Optional client-side case reference to echo in the status response. |
| limit | integer | – | Maximum saved queue records to list if server-side queue persistence becomes configured. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
report_docx_generate Report DOCX Generate ~156
Return an inline DOCX artifact from supplied report_meta, tables, metrics, and summary content; this read-only renderer does not persist hosted files. Use this only when a structured report payload already exists; use report_pdf_generate for fixed-layout output or compliance_edd_report to build the memo first.
| Name | Type | Req | Description |
|---|---|---|---|
| executive_summary | array | – | Optional executive summary bullets. |
| export_artifacts | object | – | Optional prior export metadata carried alongside the report payload. |
| headline_metrics | array | – | Optional headline metrics rendered near the top of the report. |
| report_meta | object | yes | – |
| result | object | – | Optional raw result payload attached for audit or downstream use. |
| tables | object | yes | Named tables rendered into the report artifact. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
report_pdf_generate Report PDF Generate ~155
Return an inline PDF artifact from supplied report_meta, tables, metrics, and summary content; this read-only renderer does not persist hosted files. Use this only when a structured report payload already exists; use report_docx_generate for editable Word output or compliance_edd_report to build the memo first.
| Name | Type | Req | Description |
|---|---|---|---|
| executive_summary | array | – | Optional executive summary bullets. |
| export_artifacts | object | – | Optional prior export metadata carried alongside the report payload. |
| headline_metrics | array | – | Optional headline metrics rendered near the top of the report. |
| report_meta | object | yes | – |
| result | object | – | Optional raw result payload attached for audit or downstream use. |
| tables | object | yes | Named tables rendered into the report artifact. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
report_saved_retrieve Saved Report Retrieval Status ~108
Free read-only past report retrieval status utility for agents asking about previously generated reports. AurelianFlo returns report artifacts inline as artifact.contentBase64 and does not persist hosted report files server-side.
| Name | Type | Req | Description |
|---|---|---|---|
| file_name | string | – | Optional file name from a prior artifact response. |
| report_id | string | – | Optional client-side report or case identifier to echo in the retrieval status response. |
| settlement_tx | string | – | Optional x402 settlement transaction hash associated with a prior paid report call. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
server_capabilities Server Capabilities ~43
Free first-call capability and connection check for AurelianFlo; use it before paid tools to inspect OFAC screening workflows, access modes, and x402 payment requirements.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
wallet_ofac_batch Batch Wallet Screen ~128
Screen 1-100 crypto wallet addresses against OFAC SDN digital currency designations before payout, onboarding, or treasury movement, returning per-wallet results plus a batch-level proceed-or-pause decision. Use this instead of wallet_ofac_screen for multiple addresses; use compliance_edd_report when a formal memo is needed.
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | Crypto wallet addresses to screen against OFAC SDN digital currency address designations. |
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
wallet_ofac_report OFAC Wallet Screen Report ~134
Run a paid OFAC screening report for one crypto wallet and return structured JSON or an inline PDF/DOCX artifact. Use wallet_ofac_screen for a quick single-address status check, or wallet_ofac_batch for multiple addresses.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Crypto wallet address to screen against OFAC SDN digital currency address designations. |
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| output_format | string | yes | Select json for the structured report payload or pdf|docx for a generated artifact. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
wallet_ofac_screen OFAC Wallet Screen ~124
Screen one crypto wallet address against OFAC SDN digital currency designations and return exact hits, sanctioned entity metadata, asset coverage, and a manual-review signal. Use this for one-off status checks; use wallet_ofac_report for PDF/DOCX output or wallet_ofac_batch for multiple addresses.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Crypto wallet address to screen against OFAC SDN digital currency address designations. |
| asset | string | – | Optional asset or network ticker filter such as ETH, USDC, XBT, TRX, ARB, or BSC. |
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | – | Inline generated file artifact. The service does not persist a hosted download URL. |
| artifact_summary | object | – | Delivery and rendering metadata for an inline generated artifact. |
| artifacts | object | – | Artifact rendering hints keyed by format. |
| data | object | – | Primary structured result payload for the tool. |
| error | string | – | Machine-readable error code or message when the tool fails. |
| message | string | – | Human-readable error or status message. |
| output | object | – | Nested renderer output when a workflow bundles an artifact render. |
| report | – | – | Report-shaped payload when available; null for status-only retrieval responses. |
| source | – | – | Source label, route, dataset, or execution metadata for the result. |
| success | boolean | – | Whether the tool completed successfully. |
No examples provided.
What is the AurelianFlo MCP server?
AurelianFlo is an MCP server listed in the public MCP registry as com.aurelianflo/core. Remote MCP server for OFAC screening, EDD memos, exposure forecasts, queues, and reports. This page covers its hosted endpoint (https://api.aurelianflo.com/mcp).
Is the AurelianFlo MCP server safe to use?
AurelianFlo scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the AurelianFlo MCP server expose?
AurelianFlo exposes 11 tools: server_capabilities, queue_saved_list, report_saved_retrieve, wallet_ofac_report, wallet_ofac_screen, and 6 more. Their descriptions and schemas cost roughly 1,701 tokens of context every time the server is loaded.
Does the AurelianFlo MCP server require authentication?
No. We connected to AurelianFlo without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the AurelianFlo MCP server still maintained?
AurelianFlo is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.