Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

HillSignal

REMOTE · WWW.HILLSIGNAL.COM · SCANNED SEP 30

Federal contracts, SAM notices, congressional trades, PAC money, insider trades, bills, EOs, themes.

+10 this week 83 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security80
Transport & Reachability100
Schema Quality & AI Usability71
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3864 tokens (~161/item across 24 items; 24 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
  • Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 24 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the HillSignal MCP server?

HillSignal is a hosted endpoint at https://www.hillsignal.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · www.hillsignal.com

# add to Claude Code
claude mcp add --transport http com-hillsignal-hillsignalapp 'https://www.hillsignal.com/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-hillsignal-hillsignalapp": {
      "url": "https://www.hillsignal.com/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-hillsignal-hillsignalapp": {
      "type": "http",
      "url": "https://www.hillsignal.com/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-hillsignal-hillsignalapp]
url = "https://www.hillsignal.com/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-hillsignal-hillsignalapp": {
      "type": "remote",
      "url": "https://www.hillsignal.com/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-hillsignal-hillsignalapp --url 'https://www.hillsignal.com/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-hillsignal-hillsignalapp:
    url: "https://www.hillsignal.com/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-hillsignal-hillsignalapp": {
      "Transport": "http",
      "Url": "https://www.hillsignal.com/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-hillsignal-hillsignalapp -t streamable-http -u 'https://www.hillsignal.com/api/mcp'
// mcp.json
{
  "mcpServers": {
    "com-hillsignal-hillsignalapp": {
      "type": "http",
      "url": "https://www.hillsignal.com/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +7
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 +1
    • Tool “foreign_agents” rewrote its description, which is the text the model reads security
  • 23 Sept 26 0
    • Tool “foreign_agents” rewrote its description, which is the text the model reads security
  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 0
    • Tool “foreign_agents” rewrote its description, which is the text the model reads security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 30 Sept 2026 · Probed https://www.hillsignal.com/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=www.hillsignal.com CN=YR2,O=Let's Encrypt,C=US 25 Sept 2026 24 Dec 2026 RSA 2048 SHA256-RSA 581b1cb05e089a394a7b596fd3f6636d738
SANs: www.hillsignal.com
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of www.hillsignal.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
hillsignal.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
x-content-type-options nosniff
x-frame-options DENY
referrer-policy origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://www.hillsignal.com/api/mcp Verified 200
http (plaintext) http://www.hillsignal.com/api/mcp HTTPS enforced 308 https://www.hillsignal.com/api/mcp
MCP tools · 24 exposed · ~3,634 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
award_totals ~217

Aggregate every matching federal award (same filters as search_awards) into totals per recipient, per resolved ticker, or per awarding agency: award count, total dollars, share, first and last award, largest award. Use this for "who won the most from the Navy this year" and similar questions; it counts all matches, not a page.

NameTypeReqDescription
agencystring–Awarding agency or sub-agency (partial)
group_bystring–recipient (default) | ticker | agency
keywordstring–Word in the award description
limitnumber–Top groups to return, 1-50 (default 25)
min_amountnumber–Minimum award amount in USD
recipientstring–Recipient or parent name (partial)
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
tickerstring–Resolved ticker
untilstring–ISO date; only rows on or before this date

No output schema declared.

No examples provided.

congressional_trades ~166

Stock trades disclosed by members of Congress (House and Senate Periodic Transaction Reports), by member name, ticker, transaction type or date. Returns one row per transaction with the disclosed amount range and the filing PDF. limit caps the FILINGS read, not the trades returned, and filings_matching is how many exist: when truncated is set, far more trades exist than are shown and returned_trades must never be quoted as a total.

NameTypeReqDescription
limitnumber–Max rows, 1-25 (default 10)
politicianstring–Member name (partial)
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
tickerstring–Ticker traded
transaction_typestring–purchase | sale

No output schema declared.

No examples provided.

data_coverage ~49

Row counts and the latest dated row for every dataset behind these tools, plus entity-resolution coverage. Call it when an answer depends on how complete the data is, or before saying something does not exist.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

executive_orders ~84

Executive orders, proclamations and memoranda with affected sectors and tickers.

NameTypeReqDescription
limitnumber–Max rows, 1-25 (default 10)
querystring–Words in the title or summary
sectorstring–Sector label
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date

No output schema declared.

No examples provided.

foreign_agents ~497

Who is paid to represent a foreign government or party inside the United States, and HOW MUCH, from the Justice Department's FARA register and the contracts filed with it. Pass top="contracts" for the biggest deals — the largest contract prices, who pays whom, and who owns the client in the filer's own sworn words. Pass country= to LIST THAT COUNTRY'S AGENTS BY NAME: registered_agents is the full current roster, each with its foreign principal, registration number and dates, plus former_agents and the counts. Answer "how many agents does Israel have and who are they" from that roster. Pass bill= for the foreign interests that lobbied a bill, or nothing for the country leaderboard. A country response also carries also_in_lobbying_data, the minority of those agents that additionally file under the Lobbying Disclosure Act, split into DIRECT, where the lobbying client IS the foreign principal and bills are named, and SHARED_FIRM, where one firm holds a foreign registration and separate domestic clients — context, never a claim about those clients. That subset is never the roster. Countries are spelled as the register spells them. A country roster also carries the MONEY per agent: agreed_price is the contract price from the agreement exhibit filed at registration, always with the rate it is stated at, and reported_receipts is what the agent later reported actually receiving, as a floor rather than earnings. Both are null where no figure could be proved. Each agent may also carry foreign_principal_owned_by — the filer's sworn words on who owns the foreign principal, which is how a US-registered company names its foreign parent.

NameTypeReqDescription
billstring–Bill number, e.g. HR1234 — returns foreign principals that lobbied it
countrystring–Country as the register spells it, e.g. "ISRAEL", "SAUDI ARABIA", "KOREA, SOUTH"
limitnumber–Max rows, 1-100 (default 20)
ratestring–With top=contracts: the rate to rank, "month" (default) or "year", "quarter", "hour", "one-time". Rates are never mixed or converted.
topstring–Pass "contracts" to rank the BIGGEST foreign-agent contract prices on file — who is paid the most, by whom. Combine with country= to narrow it.

No output schema declared.

No examples provided.

form_d_raises ~140

SEC Form D private placements by issuer name, resolved ticker, date or minimum amount. No minimum size is applied: pass min_amount to impose one. A null offering_amount means the filer stated no offering size, which Form D permits, and is not a raise of zero.

NameTypeReqDescription
limitnumber–Max rows, 1-25 (default 10)
min_amountnumber–Minimum offering amount USD
querystring–Issuer name (partial)
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
tickerstring–Resolved public parent ticker

No output schema declared.

No examples provided.

get_entity ~104

One company in the federal record: contracts won, PACs, patents, private raises, members of Congress who hold board seats there, insider trades, and its connections graph. Look up by ticker, entity_id, or a name (resolved exactly).

NameTypeReqDescription
entity_idstring–HillSignal entity id (hs:entity:...)
namestring–Company name; resolved by exact match
tickerstring–Stock ticker, e.g. LMT

No output schema declared.

No examples provided.

get_politician ~91

A member of Congress: committees, board seats and other positions from annual Financial Disclosures (with resolved tickers), recent stock trades, and top PAC contributors from FEC data. Look up by name or bioguide_id; ambiguous names return candidates.

NameTypeReqDescription
bioguide_idstring–Bioguide id, e.g. P000197
namestring–Member name

No output schema declared.

No examples provided.

get_theme ~63

One theme in full: the setup, the dated chronology with each beat linked to its source record, why it matters, what to watch, and the evidence.

NameTypeReqDescription
theme_idstringyesTheme id from list_themes (with or without hs:theme: prefix)

No output schema declared.

No examples provided.

insider_trades ~113

SEC Form 4 insider transactions by ticker or insider name; filter to buys or sells, minimum value, date.

NameTypeReqDescription
insiderstring–Insider name (partial)
limitnumber–Max rows, 1-25 (default 10)
min_valuenumber–Minimum total value USD
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
tickerstring–Ticker
typestring–buy | sell

No output schema declared.

No examples provided.

institutional_holders ~60

Largest institutional holders of a ticker from 13F-HR filings HillSignal has ingested, latest position per institution.

NameTypeReqDescription
limitnumber–Max rows, 1-25 (default 10)
tickerstringyesTicker

No output schema declared.

No examples provided.

latest_events ~110

The newest events across every source (awards, trades, filings, bills, orders, themes), with provenance. Optional filters by category, ticker or source id.

NameTypeReqDescription
categoriesstring–Comma-separated categories, e.g. contract,trade,filing
limitnumber–Max events, 1-25 (default 20)
sourcesstring–Comma-separated source ids from /api/wire
tickersstring–Comma-separated tickers

No output schema declared.

No examples provided.

list_themes ~35

The themes the government is currently funding across bills, contracts, solicitations and filings, each with a permanent page and a verdict.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

lobbying ~203

Senate LDA lobbying disclosures: what a company spent lobbying, which firms it hired, which issues it worked, which agencies it contacted, which bills it named, and how many of its lobbyists previously held government posts. Or pass bill= for everyone who lobbied a given bill. This is the intent layer — super PAC money says who a company is FOR, lobbying says what it WANTS. Answers "what is Coinbase lobbying on", "who lobbied HR1234", "which agencies does Lockheed contact".

NameTypeReqDescription
billstring–Bill number, e.g. HR1234 or S.567 — returns everyone who lobbied it
companystring–Company name; resolved by exact match
limitnumber–Max rows, 1-50 (default 20)
since_yearnumber–Only filings from this year onward
tickerstring–Issuer ticker, e.g. COIN

No output schema declared.

No examples provided.

money_trail ~248

How much a person or organization gave, through which entities, to which committees, and what those committees did with it. Answers "how much did Elon Musk give to Trump", "who did Timothy Mellon fund", "where did Uline's money go". Returns donor_identity (the resolved person or organization, every employer spelling folded into one, with lifetime totals), given_via (the LLCs, trusts and partnerships the cheques were actually written under — how the money reached the committee), the recipient committees, and each super PAC's independent spending for and against candidates. Names go in as written ("Elon Musk"); the FEC form ("MUSK, ELON") is handled. Ambiguous names return matched_as; narrow with employer.

NameTypeReqDescription
cyclenumber–Two-year election cycle, e.g. 2024 or 2026; omit for current and previous
employerstring–Narrow to receipts whose employer field contains this (e.g. "Tesla")
limitnumber–Max recipient committees, 1-25 (default 10)
namestringyesDonor: a person ("Ken Griffin") or organization ("Uline")

No output schema declared.

No examples provided.

outside_money ~138

Outside money on a candidate: every super PAC and other filer spending independently to support or oppose them, with totals, from FEC Schedule E. Answers "who is backing Trump", "which groups are attacking this senator", "how much outside money is in the Ohio Senate race". Candidate names go in as written.

NameTypeReqDescription
candidatestringyesCandidate name, e.g. "Donald Trump", "Ossoff"
cyclenumber–Two-year election cycle, e.g. 2024 or 2026; omit for all
limitnumber–Max committees per side, 1-50 (default 15)

No output schema declared.

No examples provided.

pac_lookup ~122

Corporate and trade-association PACs linked to a public company (by ticker) or found by committee name, with the candidates they fund. Answers "does Lockheed have a PAC and who does it give to", "which politicians take money from Pfizer's PAC". For super PACs and mega-donors use super_pacs and money_trail instead.

NameTypeReqDescription
committee_namestring–PAC or sponsor name (partial)
limitnumber–Max rows, 1-25 (default 10)
tickerstring–Issuer ticker

No output schema declared.

No examples provided.

pac_totals ~163

Which PACs give the most: contributors to tracked candidates ranked by total dollars (FEC Schedule A), by election cycle, with donor-processing conduits like ActBlue and WinRed separated out. mode=disbursers ranks committees by their own reported disbursements instead. Use for "which PACs donate the most to Congress" questions; for super PACs use super_pacs.

NameTypeReqDescription
cyclenumber–Two-year election cycle, e.g. 2026 or 2024; omit for all
limitnumber–Top rows, 1-50 (default 10)
modestring–contributors (default) | disbursers
querystring–Filter contributor or committee name (partial)

No output schema declared.

No examples provided.

resolve_entity ~80

Map an organization name (a contract recipient, a subsidiary, a PAC sponsor, a Form D issuer) to its public-company ticker. Exact normalized match against SEC legal names, aliases and the Exhibit 21 subsidiary map; returns the method and a confidence, or the reason for a miss. Never guesses.

NameTypeReqDescription
namestringyesOrganization name as written

No output schema declared.

No examples provided.

search_awards ~237

Search federal contract awards (USAspending, $10M+) by recipient, ticker, awarding agency, keyword, date range or minimum amount. Returns total_matching and pages with offset (up to 50 per call), sorted by date or amount. For "who won the most" questions use award_totals instead, which counts every match.

NameTypeReqDescription
agencystring–Awarding agency or sub-agency (partial), e.g. "Navy"
keywordstring–Word in the award description or NAICS description
limitnumber–Max rows, 1-50 (default 25)
min_amountnumber–Minimum award amount in USD
offsetnumber–Row offset for paging (default 0)
recipientstring–Recipient or parent name (partial)
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
sortstring–date (default) | amount
tickerstring–Resolved ticker
untilstring–ISO date; only rows on or before this date

No output schema declared.

No examples provided.

search_bills ~148

Full-text search over bills, contract awards and other government events with their analysed sector and ticker exposure. Filter by bill number, ticker, sector, date or event type.

NameTypeReqDescription
bill_numberstring–e.g. HR1234 or S567
event_typestring–Comma-separated event types
limitnumber–Max rows, 1-25 (default 10)
querystring–Search words
sectorstring–Sector label, e.g. Defense
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date
tickerstring–Ticker named in the analysis

No output schema declared.

No examples provided.

search_opportunities ~155

Search SAM.gov notices: Sources Sought and Pre-solicitations (the earliest public signal of a purchase), solicitations and combined synopses. Filter by keyword, NAICS, agency, notice type, date.

NameTypeReqDescription
agencystring–Department or organization (partial)
keywordstring–Word in the notice title
limitnumber–Max rows, 1-25 (default 10)
naicsstring–NAICS code or prefix, e.g. 3364
notice_typestring–sources_sought | presolicitation | solicitation | combined
sincestring–ISO date (YYYY-MM-DD); only rows on or after this date

No output schema declared.

No examples provided.

super_pacs ~373

Which super PACs are pulling the strings: the largest by money raised, spent or on hand for a cycle, from the FEC's own committee totals. With query or committee_id, one committee's profile: its top donors, what it spent for and against which candidates, and the vendors it paid for campaign work. With shared_vendors, the media buyers and consultancies working for more than one committee. With public_companies, listed companies ranked by the political money they give, resolved to tickers. A committee profile also names the public companies behind its money. Answers "biggest super PACs this cycle", "who funds MAGA Inc", "what is America PAC spending on", "which firms work for both sides", "which public companies give the most".

NameTypeReqDescription
committee_idstring–FEC committee id, e.g. C00879510
cyclenumber–Two-year election cycle (default: current)
limitnumber–Max rows, 1-25 (default 10)
min_committeesnumber–With shared_vendors: minimum committees sharing a vendor (default 2)
public_companiesboolean–Return publicly traded companies ranked by political money given, resolved to tickers
querystring–Committee name (partial), e.g. "America PAC"
shared_vendorsboolean–Return vendors paid by two or more committees instead of a committee ranking
sortstring–receipts (default) | independent_expenditures | disbursements | cash_on_hand
tickerstring–With public_companies: one issuer, e.g. COIN
typesstring–"all" to include every PAC type; default super PACs and hybrids only

No output schema declared.

No examples provided.

track_record ~38

Every forward call HillSignal made since May 2025, verified against SPY 30 days later, with the inclusion rules and the miss rate.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the HillSignal MCP server?

HillSignal is an MCP server listed in the public MCP registry as com.hillsignal/hillsignalapp. Federal contracts, SAM notices, congressional trades, PAC money, insider trades, bills, EOs, themes. This page covers its hosted endpoint (https://www.hillsignal.com/api/mcp).

Is the HillSignal MCP server safe to use?

HillSignal scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the HillSignal MCP server expose?

HillSignal exposes 24 tools: resolve_entity, get_entity, search_awards, award_totals, search_opportunities, and 19 more. Their descriptions and schemas cost roughly 3,634 tokens of context every time the server is loaded.

Does the HillSignal MCP server require authentication?

No. We connected to HillSignal without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the HillSignal MCP server still maintained?

HillSignal is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.