Car Handshake
REMOTE · MCP.CARHANDSHAKE.COM · SCANNED AUG 18
Find and compare live vehicle inventory from participating US dealers and contact them with consent.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (schedule_test_drive). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability79
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1946 tokens (~149/item across 13 items; 10 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage87
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 54% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.carhandshake.com
claude mcp add --transport http com-carhandshake-inventory https://mcp.carhandshake.com/mcp
[mcp_servers.com-carhandshake-inventory] url = "https://mcp.carhandshake.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-carhandshake-inventory": {
"type": "remote",
"url": "https://mcp.carhandshake.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-carhandshake-inventory --url https://mcp.carhandshake.com/mcp --transport streamable-http
mcp_servers:
com-carhandshake-inventory:
url: "https://mcp.carhandshake.com/mcp" {
"mcpServers": {
"com-carhandshake-inventory": {
"type": "http",
"url": "https://mcp.carhandshake.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 17 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Aug 26 +7
- Schema quality: unverified → good ▲ functional
- 14 Aug 26 −6
- Schema quality: good → unverified ▼ functional
- “shop_vehicles” reworded the description of “radius_miles” cosmetic
- 13 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
- 11 Aug 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 18 Aug 2026 · Probed https://mcp.carhandshake.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.carhandshake.com | CN=Amazon RSA 2048 M04,O=Amazon,C=US | 14 Jul 2026 | 27 Jan 2027 | RSA 2048 | SHA256-RSA | ba841d4955fb412ea165bddbda51fb9 |
| SANs: mcp.carhandshake.com | ||||||
| CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 773124f2a952e3ed18a58bdb85d1bc0ce5f27 |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
DNSSEC insecure
Validation of mcp.carhandshake.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| carhandshake.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.carhandshake.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.carhandshake.com/mcp | HTTPS enforced | 301 | https://mcp.carhandshake.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
compare_vehicles Compare two to four live listings ~70
Only for explicit comparison: after exactly one shop_vehicles call, pass 2-4 distinct returned listing IDs. Never search or shop again.
| Name | Type | Req | Description |
|---|---|---|---|
| listing_ids | array | yes | 2-4 exact IDs returned by shop_vehicles. |
| priorities | array | – | Shopper priorities, up to eight. |
| Name | Type | Req | Description |
|---|---|---|---|
| compared | integer | yes | – |
| missing_listing_ids | array | yes | – |
| recommendation | object | yes | – |
| vehicles | array | yes | – |
No examples provided.
fetch Fetch one live vehicle listing for citation ~34
Citation only after search; never shopping/detail. Fetch one exact ID.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Exact listing ID returned by search. |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| metadata | object | – | – |
| text | string | yes | – |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
find_dealerships Find participating US dealerships ~92
Use this once to resolve participating dealerships by name/place with IDs, addresses, and listing counts. For named-dealer inventory, pass an exact returned dealer_id to one shop_vehicles call. For rooftop contacts or sales/service hours, call get_dealership once.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| location | string | – | Place or postal text exactly as supplied. |
| query | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| dealerships | array | yes | – |
| interpreted_location | object|null | yes | – |
| next_action | string | yes | – |
| total | integer | yes | – |
No examples provided.
get_dealership Get dealership locations, hours, and contacts ~52
Use this with one exact dealer_id from find_dealerships or get_vehicle to return every public rooftop, phone, website, capability, and named sales/service schedule.
| Name | Type | Req | Description |
|---|---|---|---|
| dealer_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_card_url | string|null | yes | – |
| dealer_id | string | yes | – |
| domain | string | yes | – |
| locations | array | yes | – |
| name | string | yes | – |
| vehicle_count | integer | yes | – |
No examples provided.
get_vehicle Get one live listing by stable ID ~34
For full detail, pass exact shop_vehicles listing_id; returns dealer.dealer_id.
| Name | Type | Req | Description |
|---|---|---|---|
| listing_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| battery_kwh | number|null | – | – |
| body | string|null | – | – |
| charge_port | string|null | – | – |
| city_mpg | integer|null | – | – |
| condition | string|null | – | – |
| dc_fast_charge | boolean|null | – | – |
| dealer | object | yes | – |
| description | string|null | – | – |
| displacement_cc | number|null | – | – |
| distance_miles | number|null | – | – |
| driveline | string|null | – | – |
| electric_range_miles | number|null | – | – |
| engine | string|null | – | – |
| exterior_color | string|null | – | – |
| features | array | – | – |
| fuel | string|null | – | – |
| highway_mpg | integer|null | – | – |
| interior_color | string|null | – | – |
| listing_id | string | yes | – |
| listing_url | string|null | – | – |
| listing_url_source | string|null | – | – |
| location | object | yes | – |
| make | string | yes | – |
| mileage | integer|null | – | – |
| model | string | yes | – |
| motor_power_hp | number|null | – | – |
| msrp | integer|null | – | – |
| photos | array | – | – |
| price | integer|null | – | – |
| primary_photo_url | string|null | – | – |
| status | string | yes | – |
| stock | string|null | – | – |
| transmission | string|null | – | – |
| trim | string|null | – | – |
| updated_at | string | – | – |
| vehicle_type | string | yes | – |
| vin | string | – | – |
| year | integer | yes | – |
No examples provided.
request_trade_in_appraisal Request a trade-in appraisal ~233
With explicit consent and confirmation, request dealer trade-in appraisal for this listing.
| Name | Type | Req | Description |
|---|---|---|---|
| allowed_channels | array | yes | Accepted channels. |
| consent_granted_at | string | yes | Consent time, RFC 3339 with timezone. |
| consent_text | string | yes | Exact accepted words; never fabricate consent. |
| dry_run | boolean | – | Validate only; no dealer contact. |
| string | – | Email; email or phone required. | |
| first_name | string | yes | First name. |
| idempotency_key | string | yes | Unique retry key. |
| last_name | string | yes | Last name. |
| listing_id | string | yes | Exact listing_id from prior read. |
| message | string | – | Optional dealer note. |
| phone | string | – | E.164 phone; email or phone required. |
| preferred_contact | string | – | – |
| trade_in_condition | string | – | – |
| trade_in_make | string | yes | – |
| trade_in_mileage | integer | – | – |
| trade_in_model | string | yes | – |
| trade_in_trim | string | – | – |
| trade_in_year | integer | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| lead_id | string | yes | – |
| status | string | yes | – |
No examples provided.
schedule_test_drive Request a test drive ~185
With explicit consent and confirmation, request dealer test-drive follow-up for this listing.
| Name | Type | Req | Description |
|---|---|---|---|
| allowed_channels | array | yes | Accepted channels. |
| appointment_at | string | – | – |
| consent_granted_at | string | yes | Consent time, RFC 3339 with timezone. |
| consent_text | string | yes | Exact accepted words; never fabricate consent. |
| dry_run | boolean | – | Validate only; no dealer contact. |
| string | – | Email; email or phone required. | |
| first_name | string | yes | First name. |
| idempotency_key | string | yes | Unique retry key. |
| last_name | string | yes | Last name. |
| listing_id | string | yes | Exact listing_id from prior read. |
| message | string | – | Optional dealer note. |
| phone | string | – | E.164 phone; email or phone required. |
| preferred_contact | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| lead_id | string | yes | – |
| status | string | yes | – |
No examples provided.
search Search live vehicle listings for citations ~37
Citation only; never shopping/detail/compare. Search once, then fetch exact IDs.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Vehicle-shopping query, verbatim. |
| Name | Type | Req | Description |
|---|---|---|---|
| next_action | string | yes | – |
| results | array | yes | – |
No examples provided.
shop_vehicles Shop connected US dealership inventory ~558
Use for live US cars, SUVs, trucks, EVs, motorcycles, RVs, or trailers by place (near me/close by), budget, mileage, make/model, condition, body, fuel, features, named dealer, or live-listing recommendation. Call once; never retry/refine/broaden. Geographic fallback is final; filters stay exact. Use returned facts; browse only if asked. Named-dealer stock: find_dealerships once, then shop. Not for repair/reliability/facts, MSRP/non-US, named-source, web-only, or no-app. Pass request verbatim; never ask for ZIP.
| Name | Type | Req | Description |
|---|---|---|---|
| bodies | array | – | – |
| charge_ports | array | – | – |
| conditions | array | – | New, used, or certified pre-owned (cpo). |
| cursor | string | – | – |
| dc_fast_charge | boolean | – | – |
| dealer_ids | array | – | – |
| displacement_cc_max | integer | – | – |
| displacement_cc_min | integer | – | – |
| drivelines | array | – | – |
| electric_range_max | number | – | – |
| electric_range_min | number | – | – |
| exterior_colors | array | – | – |
| features | array | – | Features: third_row, awd_4wd, tow_package, apple_carplay, android_auto, adaptive_cruise, leather, heated_seats, ev_range_200_plus. Unknown names are disclosed, not hard-filtered. |
| fuels | array | – | – |
| interior_colors | array | – | – |
| limit | integer | – | – |
| location_text | string | – | Free-text city/place/state/postal exactly as the shopper supplied; never ask for a ZIP code. |
| makes | array | – | – |
| mileage_max | integer | – | – |
| models | array | – | – |
| nationwide | boolean | – | – |
| price_max | integer | – | – |
| price_min | integer | – | – |
| radius_miles | number | – | Search radius around the resolved location. If nothing matches, the search widens automatically — double this radius, then statewide, then national — keeping every vehicle filter exact, and reports t… |
| request | string | yes | The shopper's natural-language request, verbatim. |
| sort_by | string | – | Result order; default relevance. |
| sort_direction | string | – | – |
| statuses | array | – | Omit unless status is explicit; omission searches both available and intransit. |
| transmissions | array | – | – |
| trims | array | – | – |
| vehicle_types | array | – | Vehicle categories, including motorcycles, RVs, and trailers. |
| year_max | integer | – | – |
| year_min | integer | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| applied_filters | object | yes | – |
| coverage | object | yes | – |
| fallback | object | yes | – |
| freshness | object | yes | – |
| interpreted_request | object | yes | – |
| matches | array | yes | – |
| next_action | string | yes | – |
| next_cursor | string|null | yes | – |
| suggested_relaxations | array | yes | – |
| total | integer | yes | – |
| total_relation | string | yes | – |
No examples provided.
submit_vehicle_inquiry Send a vehicle inquiry ~178
With explicit consent and confirmation, send this listing's dealer the shopper's question.
| Name | Type | Req | Description |
|---|---|---|---|
| allowed_channels | array | yes | Accepted channels. |
| consent_granted_at | string | yes | Consent time, RFC 3339 with timezone. |
| consent_text | string | yes | Exact accepted words; never fabricate consent. |
| dry_run | boolean | – | Validate only; no dealer contact. |
| string | – | Email; email or phone required. | |
| first_name | string | yes | First name. |
| idempotency_key | string | yes | Unique retry key. |
| last_name | string | yes | Last name. |
| listing_id | string | yes | Exact listing_id from prior read. |
| message | string | yes | Optional dealer note. |
| phone | string | – | E.164 phone; email or phone required. |
| preferred_contact | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| lead_id | string | yes | – |
| status | string | yes | – |
No examples provided.