Duck Tax
REMOTE · DUCKTAX.COM · SCANNED SEP 28
Check micro-entity company accounts: raw figures in, validated balance sheet and deadlines out.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 20 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability74
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3012 tokens (~150/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
- Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 98% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_filing" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Duck Tax MCP server?
Duck Tax is a hosted endpoint at https://ducktax.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · ducktax.com
claude mcp add --transport http com-ducktax-ducktax 'https://ducktax.com/api/mcp'
{
"mcpServers": {
"com-ducktax-ducktax": {
"url": "https://ducktax.com/api/mcp"
}
}
} {
"servers": {
"com-ducktax-ducktax": {
"type": "http",
"url": "https://ducktax.com/api/mcp"
}
}
} [mcp_servers.com-ducktax-ducktax] url = "https://ducktax.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-ducktax-ducktax": {
"type": "remote",
"url": "https://ducktax.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-ducktax-ducktax --url 'https://ducktax.com/api/mcp' --transport streamable-http
mcp_servers:
com-ducktax-ducktax:
url: "https://ducktax.com/api/mcp" {
"McpServers": {
"com-ducktax-ducktax": {
"Transport": "http",
"Url": "https://ducktax.com/api/mcp"
}
}
} assistant mcp add com-ducktax-ducktax -t streamable-http -u 'https://ducktax.com/api/mcp'
{
"mcpServers": {
"com-ducktax-ducktax": {
"type": "http",
"url": "https://ducktax.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- 16 Sept 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://ducktax.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=ducktax.com | CN=YR1,O=Let's Encrypt,C=US | 9 Aug 2026 | 7 Nov 2026 | RSA 2048 | SHA256-RSA | 6003029d8a9f8f613490af3a13ec9ace8ea |
| SANs: ducktax.com, www.ducktax.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of ducktax.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| ducktax.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ducktax.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://ducktax.com/api/mcp | HTTPS enforced | 308 | https://ducktax.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
categorise_transactions ~141
Categorise bank-statement transaction descriptions into the fixed vocabulary this product maps to balance sheet lines (sales, software, owner-in, …). Send description strings only, never amounts or dates. Sum the amounts per returned category yourself, then call totals_to_figures. One statement import is one quota unit; previously seen descriptions are answered from a shared cache free.
| Name | Type | Req | Description |
|---|---|---|---|
| descriptions | array | yes | The raw description strings, one per transaction. |
| tradingType | string | yes | What the company does, to resolve ambiguous merchants. One of: software, consulting, creative, retail, construction, property, hospitality, other. lookup_company suggests one from the SIC codes. |
No output schema declared.
No examples provided.
check_accounts ~241
Derive a small-company balance sheet (micro-entity, in UK terms) from raw figures and validate it. Returns the derived sheet for the current and prior year, the figures the authority would reject (negatives where it wants a positive, share capital left at nil), and whether they are complete enough to hand to a filing product. It does NOT check that the sheet balances and cannot: retained earnings is derived as the balancing figure, so both sides always agree. Do not tell anybody their sheet was checked for internal consistency. Free and instant: call it after every change to the figures. All money in major units (pounds not pence, dollars not cents). Pass lastFiledAs from lookup_company and it also warns when figures showing activity are about to be filed dormant again.
| Name | Type | Req | Description |
|---|---|---|---|
| figures | object | yes | The figures behind a small-company balance sheet. ALL amounts in major units. |
| jurisdiction | string | yes | ISO country code. GB is the only jurisdiction with full support. |
| lastFiledAs | string | – | What the last accounts were filed as, straight from lookup_company's company.lastAccountsType. Pass it through; do not guess it. |
No output schema declared.
No examples provided.
check_filing_extension ~324
Whether a company can still apply to its registrar for more time to file, how many days are left to apply, and what being late costs if that window is missed. This is usually the most useful thing to tell somebody who has just found a deadline: applying is free, takes about 15 minutes, and has to be done BEFORE the deadline it extends, so the option expires on the same day the penalty starts. Returns nextAction first. It PREPARES an application and can never submit one: the application is made by a director on the registrar’s own service, which this tool links to. It does not file accounts. Give a company number to read the deadline off the register (quota-charged, cached results free), or give the dates yourself and it costs nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| alreadyExtended | boolean | yes | True if this deadline has been extended once already. Do not guess it, ask. |
| companyNumber | string | – | Read the deadline and period end off the register. Omit if you supply the dates. |
| filing | string | yes | Which deadline. Only accounts can be extended; ask about the other and it says so. |
| filingDeadline | string | – | The normal filing deadline, if you already have it. Skips the register request. |
| jurisdiction | string | yes | ISO country code. Register access exists for GB and AU. |
| periodEnd | string | – | The accounting reference date. Bounds how much extra time could be granted. |
| today | string | – | Defaults to the server's date. Supply it to test a boundary. |
No output schema declared.
No examples provided.
delete_filing ~48
Delete one saved filing by id, permanently. Confirm with the person before calling this; there is no undo and no trash.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | The id from list_saved_filings. |
No output schema declared.
No examples provided.
dormant_figures ~85
The complete set of figures for a dormant company: share capital, the matching cash, and zeros everywhere else. The register says when the last accounts were filed dormant, and for those companies this collapses the whole form to one call. Amounts in major units.
| Name | Type | Req | Description |
|---|---|---|---|
| shareCapital | number | yes | Issued share capital in major units. 1 is the overwhelmingly common figure. |
No output schema declared.
No examples provided.
draft_extension_reason ~240
Turn a short factual account of what went wrong into the reason text for an application for more time to file accounts, framed in the terms the registrar actually applies. It uses only the facts you give it: it will not invent circumstances, and where something is missing it leaves a bracketed placeholder rather than filling it in. The person must check every sentence before using it, because they are certifying it to the registrar. Ask them what happened, do not supply it yourself. This tool does not submit the application and does not file accounts. Quota-charged as an explanation; identical input is answered from cache free.
| Name | Type | Req | Description |
|---|---|---|---|
| circumstances | string | yes | What actually happened, in the person's own words, with dates. Facts only. If you do not have this, ask them for it rather than writing it. |
| expectedReadyBy | string | – | When they expect the accounts to be ready, if they have said. Never estimate it. |
| jurisdiction | string | yes | ISO country code. Register access exists for GB and AU. |
| whyItStoppedTheAccounts | string | – | How the event stopped the accounts being prepared, if they have said. |
No output schema declared.
No examples provided.
explain_accounts ~114
A plain-English reading of a set of figures, written for a director who is not an accountant: what the derived balance sheet says about the company and anything that needs attention before filing. Only the derived sheet is sent to the model, no company name or number. Quota-charged; identical figures are answered from cache free.
| Name | Type | Req | Description |
|---|---|---|---|
| figures | object | yes | The figures behind a small-company balance sheet. ALL amounts in major units. |
| jurisdiction | string | yes | ISO country code. Register access exists for GB and AU. |
No output schema declared.
No examples provided.
get_prior_year_figures ~94
Read last year's figures out of the company's last filed accounts at Companies House, ready to drop into the *Prior fields of check_accounts or save_filing. Saves typing seven numbers from a PDF and gets the comparatives exactly as filed. GB only, and only when the last accounts were filed digitally. Quota-charged; cached results are free.
| Name | Type | Req | Description |
|---|---|---|---|
| companyNumber | string | yes | The GB company number. |
No output schema declared.
No examples provided.
late_filing_penalty ~78
What missing a Companies House accounts deadline costs. Given the due date, returns days remaining or overdue, the penalty band already incurred, and what the next band costs, the number that makes someone act today. UK private companies only.
| Name | Type | Req | Description |
|---|---|---|---|
| accountsDue | string | yes | The accounts due date, from lookup_company or a Companies House letter. |
No output schema declared.
No examples provided.
list_jurisdictions ~59
The countries this server knows about and what it can actually do in each: which have a real accounts engine, which registers can be searched or looked up, the currency, and the identifiers each jurisdiction files under. Call this first when unsure.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_saved_filings ~51
The user's saved filings, most recently touched first, with every figure in major units. This is the same list the website dashboard shows. Start here when asked about "my accounts" or "my company".
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_tracked_companies ~53
Every company this user gets deadline reminders about, including the ones implied by their saved filings. Shows the next accounts deadline and days remaining where a register record is already cached. Free: this never contacts a register.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lookup_company ~140
Look a company up on its public register (Companies House for GB, ABN Lookup for AU) by its registered number. Returns the full public record: name, status, registered office, officers, SIC codes, accounting period, plus both filing deadlines with days remaining and the late-filing penalty already incurred if overdue. Rate limited and quota-charged; cached results are free. Find the number first with search_companies.
| Name | Type | Req | Description |
|---|---|---|---|
| companyNumber | string | yes | The register identifier: GB company number (e.g. 15379140) or AU ABN. |
| jurisdiction | string | yes | ISO country code. Register access exists for GB and AU. |
No output schema declared.
No examples provided.
sample_accounts ~56
A real worked example: nil turnover, a director loan, a near-empty bank account, the simplest accounts the UK regime permits. Use it to demonstrate check_accounts or as a template for a first-year company. Amounts in major units.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
save_filing ~224
Save a set of figures to the user's account, or update a saved one by passing its id from list_saved_filings. Figures in major units. The filing is saved even when validation finds problems, because a work in progress is worth keeping, and the problems come back in the response so you can raise them.
| Name | Type | Req | Description |
|---|---|---|---|
| categoryTotals | object | – | Where the figures came from, when a bank statement fed them: signed major-unit totals per category code from categorise_transactions. |
| figures | object | yes | The figures behind a small-company balance sheet. ALL amounts in major units. |
| id | integer | – | Omit to create. Pass an id from list_saved_filings to update that filing. |
| identifiers | object | – | Register identifiers, e.g. {"companyNumber": "15379140"}. Tax references (UTR, EIN, TFN) are never stored and are silently dropped. |
| jurisdiction | string | yes | – |
| label | string | – | A name for the filing, e.g. "SparkGames year to 31 Dec 2025". |
No output schema declared.
No examples provided.
search_companies ~88
Find a company by name on its public register and get back its registered number, status and address. This is how you reach lookup_company when the person only knows the name. Free of the daily quota; lightly rate limited.
| Name | Type | Req | Description |
|---|---|---|---|
| jurisdiction | string | yes | ISO country code. Register access exists for GB and AU. |
| query | string | yes | The company name, as someone would say it. |
No output schema declared.
No examples provided.
server_status ~59
What this deployment can actually do right now: which integrations are configured, whether your token is valid, and how much of each daily quota you have left. Call it when a tool refuses and you want to know whether the feature is off or used up.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
totals_to_figures ~104
Turn categorised bank-statement totals into balance sheet figures, applying the rules that stop an import lying: only income categories reach turnover, only expense categories reach operating costs, and the owner topping up the account is never sales. Totals are signed major units per category code; get codes from categorise_transactions.
| Name | Type | Req | Description |
|---|---|---|---|
| totals | object | yes | Signed totals per category code, major units, e.g. {"sales": 60000, "software": -1200}. |
No output schema declared.
No examples provided.
track_company_deadlines ~289
Watch a company by its register number and get reminded before its filing deadlines. Which channels are actually available depends on the server: the reply reports what will really be sent, and it can be nothing at all, so read it rather than assuming. No saved filing is needed: this is for the deadline itself, which matters months before any figures exist. Reminders go out on a ladder of days before the deadline (default 90, 60, 30, 14, 7, 1), and each one states the company, the deadline, the date, the days remaining and the penalty for missing it. Calling this again updates the settings and un-mutes a company that was untracked.
| Name | Type | Req | Description |
|---|---|---|---|
| companyNumber | string | yes | The register identifier: GB company number (e.g. 15379140) or AU ABN. |
| boolean | yes | Send reminders to the account email address. | |
| jurisdiction | string | yes | ISO country code. Deadline reminders exist where the register publishes deadlines. |
| push | boolean | yes | Send reminders as web push to signed-in browsers. |
| remindDaysBefore | array | – | Days before the deadline to warn, e.g. [60, 14, 1]. Omit to use this server’s default ladder. Only the tightest rung that applies is ever sent, so a long ladder does not mean a burst of messages. |
No output schema declared.
No examples provided.
untrack_company_deadlines ~99
Stop sending deadline reminders about a company. This mutes rather than forgets, which is the only thing that holds: a company implied by a saved filing would otherwise be re-added by the next scan. track_company_deadlines un-mutes it again.
| Name | Type | Req | Description |
|---|---|---|---|
| companyNumber | string | yes | The register identifier, as in track_company_deadlines. |
| jurisdiction | string | yes | ISO country code. Deadline reminders exist where the register publishes deadlines. |
No output schema declared.
No examples provided.
What is the Duck Tax MCP server?
Duck Tax is an MCP server listed in the public MCP registry as com.ducktax/ducktax. Check micro-entity company accounts: raw figures in, validated balance sheet and deadlines out. This page covers its hosted endpoint (https://ducktax.com/api/mcp).
Is the Duck Tax MCP server safe to use?
Duck Tax scores 69 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Duck Tax MCP server expose?
Duck Tax exposes 20 tools: check_accounts, dormant_figures, totals_to_figures, late_filing_penalty, list_jurisdictions, and 15 more. Their descriptions and schemas cost roughly 2,587 tokens of context every time the server is loaded.
Does the Duck Tax MCP server require authentication?
No. We connected to Duck Tax without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Duck Tax MCP server still maintained?
Duck Tax is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.