Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

nittim

REMOTE · NITTIM.COM · SCANNED SEP 20

Production-safety audits for AI-generated code, with a fix for every finding.

Available components

+4 this week 86 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security97
Transport & Reachability100
Schema Quality & AI Usability77
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4193 tokens (~279/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
  • Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the nittim MCP server?

nittim is a hosted endpoint at https://nittim.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · nittim.com

# add to Claude Code
claude mcp add --transport http com-nittim-nittim 'https://nittim.com/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-nittim-nittim": {
      "url": "https://nittim.com/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-nittim-nittim": {
      "type": "http",
      "url": "https://nittim.com/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-nittim-nittim]
url = "https://nittim.com/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-nittim-nittim": {
      "type": "remote",
      "url": "https://nittim.com/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-nittim-nittim --url 'https://nittim.com/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-nittim-nittim:
    url: "https://nittim.com/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-nittim-nittim": {
      "Transport": "http",
      "Url": "https://nittim.com/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-nittim-nittim -t streamable-http -u 'https://nittim.com/api/mcp'
// mcp.json
{
  "mcpServers": {
    "com-nittim-nittim": {
      "type": "http",
      "url": "https://nittim.com/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 +2
    • The server rewrote its instructions, which are the text every model session reads security
    • Server version: 0.2.0+d9c5763 → 0.2.0+93bf872 functional
  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 13 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 +1
    • The server rewrote its instructions, which are the text every model session reads security
    • Server version: 0.2.0+70e80bb → 0.2.0+d9c5763 functional
  • 9 Sept 26 +1
    • The server rewrote its instructions, which are the text every model session reads security
    • Stability: unverified → 0.03 functional
    • Server version: 0.2.0+d5518e3 → 0.2.0+70e80bb functional
  • 8 Sept 26 79

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://nittim.com/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=nittim.com CN=YR1,O=Let's Encrypt,C=US 11 Aug 2026 9 Nov 2026 RSA 2048 SHA256-RSA 553f6b2648dda288651b71cf0588f58a8c9
SANs: nittim.com
CN=YR1,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA a20253f15f2691c05dc1ce13b9bcca4e
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of nittim.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
nittim.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://nittim.com/.well-known/oauth-protected-resource/api/mcp"

Bearer resource_metadata="https://nittim.com/.well-known/oauth-protected-resource/api/mcp"
Header Value
strict-transport-security max-age=31536000; includeSubDomains
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()

Protected resource metadata

Document https://nittim.com/.well-known/oauth-protected-resource/api/mcp
Retrieved Yes
Resource https://nittim.com/api/mcp
Authorisation server https://xsmbdmgcuhpxzfrzdiwv.supabase.co/auth/v1

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://nittim.com/api/mcp Verified 200
http (plaintext) http://nittim.com/api/mcp HTTPS enforced 308 https://nittim.com/api/mcp
MCP tools · 15 exposed · ~3,451 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
audit_repo ~428

Paid nittim AI audit of a GitHub repository: one structured pass over the highest-signal source; the only tool here that returns scores and a verdict. Answers with the audit's id, not the report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.DELIVERED AS A BATCH: the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours.

NameTypeReqDescription
authorizationstringHUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.
confirmedCostobjectCOST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.
deployedUrlstringOptional URL of this repository's live deployment, for an origin the account owner actually operates. When set, the audit adds one bounded, READ-ONLY fetch pass against it and reports drift between t…
fullScanbooleanTrue buys the wider Full Audit tier: every eligible source file, priced by pass count.
githubTokenstringOptional read-only GitHub token. Without one, only public repos are reachable.
payInsteadbooleanTrue pays credits now instead of queuing for the daily free-audit budget to reopen, skipping the covered (Audit) entitlement even when it would otherwise be free.
repoUrlstringyesGitHub repository URL or owner/repo. A private repo needs a githubToken.

No output schema declared.

No examples provided.

audit_source ~431

Paid nittim AI audit of source files you post, for a project with no GitHub remote. Send SOURCE files, not build output — no node_modules or dist. On nittim's own key this answers with the audit's id; the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. On your own key (BYOK Pro) the report comes back in this call instead. Costs 5.14 credits (a paid+subscribed org's included allowance, an unspent Audit, then prepaid credits), always saved as a PRIVATE report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

NameTypeReqDescription
authorizationstringHUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.
confirmedCostobjectCOST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.
filesarrayyesSource files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.
fullScanbooleanTrue buys the wider Full Audit tier over the files you post, priced by pass count.
namestringyesA display label for this project, e.g. 'my-abacus-app'. Sanitized before use.
uploadGrantstringOptional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.

No output schema declared.

No examples provided.

describe_protocol ~104

How this server works, in full: how a paid call quotes and charges, the two audit tiers, the Nittim Loop and its reward rules and caps, and dispute guidance. Free, no key, no charge, no side effects — it reads static text and calls no model. `section` picks one page; omitted, it returns all of them.

NameTypeReqDescription
sectionstringWhich page: money, tiers, loop, disputes, or all (the default).

No output schema declared.

No examples provided.

dispute_finding ~233

NEEDS A KEY: mint one at https://nittim.com/keys. Records that a finding from a prior audit is wrong (stance:'dispute') or genuinely real (stance:'confirm'), backed by evidence from the repo. Free. A SIGNAL for owner triage — it never changes the audit's scores, verdict or stored report on its own. The finding is identified by its findingKey (from the digest), or by its exact dimension and title.

NameTypeReqDescription
auditIdstringyesThe audit UUID, from its report link.
dimensionstringThe finding's dimension, e.g. 'security' — required if findingKey is omitted.
evidenceobjectyesWhat you can see in the repo that supports your stance.
findingKeystringThe finding's stable key from the digest, if you have it (preferred over dimension+title).
stancestringyes'dispute' = this finding is wrong. 'confirm' = this finding is genuinely real.
titlestringThe finding's exact title — required if findingKey is omitted.

No output schema declared.

No examples provided.

estimate_audit ~244

Price an audit before buying one: give a GitHub repository URL, or a manifest of paths and byte sizes — no file content, nothing uploaded — and get the tier (Audit or Full Audit), the pass count and the exact price. No account or key is needed: it never charges, runs no audit, calls no model and stores nothing. Signed in it also returns your credit balance and whether an unspent Audit covers the run; a guest quote omits both. `fullScan: true` prices Full Audit.

NameTypeReqDescription
filesarrayA manifest of paths and sizes only, in place of `repoUrl` — the same set you would post. Over the cap the answer names it and how to trim. Send one or the other.
fullScanbooleanPrice Full Audit (every eligible file, or a refusal with the reason when the selection is too large) instead of the default Audit.
githubTokenstringOptional GitHub personal access token (read-only) for a private repo.
repoUrlstringGitHub repository URL or owner/repo. Mutually exclusive with `files` — send one.

No output schema declared.

No examples provided.

get_audit ~102

Retrieve a nittim audit by its UUID, at any stage: the finished markdown digest (verdict, scores, top findings) plus its report link, or — no error, nothing charged — that it is still running, or why it failed and what happened to the charge. Free. Reading needs the key of the account that owns the audit.

NameTypeReqDescription
idstringyesThe UUID of the saved audit, from the /report/{id} URL.

No output schema declared.

No examples provided.

get_loop ~101

Returns the current text of nittim's free, tool-agnostic self-review checklist — the same content served at https://nittim.com/selfcheck.md. Reviews a codebase against the public shape of nittim's 13-category Priority Framework, plus a 14th on what the code gives away, and states the procedure for running it as a loop. No arguments. No key, no account and no charge — nothing here is sent anywhere.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

judge_output ~374

Run a cross-vendor judge model over any text you post: code, a document, another model's output, anything. Returns findings + rationale ONLY — never a score, never a pass/fail verdict. Costs 5.03 credits. The judge always comes from a different vendor family than whatever produced the content, and the answer says which one ran. `modelUnderTest` names that family. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

NameTypeReqDescription
authorizationstringHUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.
confirmedCostobjectCOST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.
contentstringyesThe text to judge — code, a document, another model's output. Up to ~100KB.
contextstringOptional — background the judge should know, e.g. what this content is for.
criteriastringOptional — what to judge it against, e.g. 'correctness and security'.
modelUnderTeststringOptional — which vendor family produced `content`, if it is itself a model's output. The judge that runs is always a different family than this names. Use 'unspecified' for anything that is not model…

No output schema declared.

No examples provided.

list_modules ~70

List every audit module nittim can run: the two deterministic scanners (secret scan + OSV dependency CVE check) and the LLM-reasoned checks. Returns each module's key, tier, and a plain-English description of what it checks. Each module's key identifies it for running individually.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

mint_key ~120

For a client that cannot sign in over OAuth: a short, one-time link to https://nittim.com/keys/claim/<token>. Opening it, signed in, mints a real nittim API key and shows it once — the key itself is NEVER returned by this tool or by any other MCP result. The link expires in a few minutes and works exactly once. Free.

NameTypeReqDescription
keyNamestringOptional display name for the key that will be minted, e.g. 'my-cursor-key'. Defaults to 'API key'.

No output schema declared.

No examples provided.

preview_upload ~151

NEEDS A KEY: mint one at https://nittim.com/keys. Send the paths and sizes of the files you would post — no content leaves your machine to ask this — and get back the list, the byte count, and a link for the account owner to approve it. Free. The approval covers that file list and no other, and a paid audit's own confirmation already covers the file list beside the price, so approving ahead of time is optional.

NameTypeReqDescription
filesarrayyesPaths and sizes only — the same set you would post. Never file content.
namestringyesA display label for this project, e.g. 'my-abacus-app'. Sanitized before use.

No output schema declared.

No examples provided.

report_loop ~441

NEEDS A KEY: mint one at https://nittim.com/keys. Records anonymised counts from a Nittim Loop the developer has finished and agreed to send: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean. Counts only — never a title, file path or snippet. Nothing is charged, and an eligible report can earn a credit reward (rules and caps: see describe_protocol). Reporting the same repo again updates the existing record; the reply says which happened. Results appear at https://nittim.com/loop.

NameTypeReqDescription
client_namestringYour own name — omit to read it from the MCP connection instead.
client_versionstringYour own version string, if you have one.
convergencestringOptional: 'converged' (two consecutive clean passes) or 'cap_reached' (stopped for any other reason). Omit if unsure — the read from `passes` is derived either way.
first_wave_lensesintegerOptional, with mode 'one_shot' only: how many lenses ran in parallel on pass 1.
modestringOptional: 'one_shot' (every lens sweeps the whole tree first, then one fix wave, then a short convergence loop) or 'serial' (one lens or area per pass, fixing between passes).
passesarrayyesOne entry per pass you actually ran, in order.
repo_hashstringyessha256 of the repository's canonical identity (the lowercased 'owner/repo', or a stable local fingerprint) — never the repo name itself. nittim never sees the name.
repo_size_bucketstringyesA rough size bucket for the repo you looped over.
sweptbooleanOptional: was the CLASS swept — a guard, lint rule or exhaustiveness check that makes a new instance loud — rather than only the instances a pass named? Never derived, never changes the reward. On a…

No output schema declared.

No examples provided.

run_module ~310

Run ONE nittim audit module against a GitHub repository, never producing scores or a verdict. The two deterministic modules (secret-scan, dependency-cve) return scanner evidence directly, free, with nothing to confirm. Deep-tier modules make one focused model call, cost 5.03 credits each and follow the protocol below. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

NameTypeReqDescription
authorizationstringHUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.
confirmedCostobjectCOST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.
githubTokenstringOptional read-only GitHub token. Without one, only public repos are reachable.
moduleKeystringyesThe module's key, e.g. 'secret-scan', 'dependency-cve', 'security', 'privacy', 'gdpr'.
repoUrlstringyesGitHub repository URL or owner/repo. A private repo needs a githubToken.

No output schema declared.

No examples provided.

scan_source ~173

Free nittim look: committed secrets and known CVEs over posted source files. No account, no key, no nittim credits. Hard evidence only: never scores, never a production verdict. Send SOURCE files, not build output (no node_modules, no dist, no binaries).

NameTypeReqDescription
filesarrayyesSource files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.
namestringyesA display label for this project, e.g. 'my-abacus-app'. Sanitized before use.
uploadGrantstringOptional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.

No output schema declared.

No examples provided.

verify_fix ~169

NEEDS A KEY: mint one at https://nittim.com/keys. Re-checks ONE finding from a finished audit against the repository's current code, or a commit named in the call, and answers fixed, still present, or undetermined — with the reason. It reads only the file that finding cites. Free, capped per day, and it moves no score or verdict: the report keeps recording what was true of the commit it ran on.

NameTypeReqDescription
auditIdstringyesThe audit UUID, from its report link.
findingKeystringyesThe finding's stable key, as printed beside it in the report's findings list.
refstringA commit SHA or branch to check instead of the repository's current HEAD. Must be the audited commit or newer.

No output schema declared.

No examples provided.

Common questions

What is the nittim MCP server?

nittim is an MCP server listed in the public MCP registry as com.nittim/nittim. Production-safety audits for AI-generated code, with a fix for every finding. This page covers its hosted endpoint (https://nittim.com/api/mcp).

Is the nittim MCP server safe to use?

nittim scores 86 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the nittim MCP server expose?

nittim exposes 15 tools: audit_repo, audit_source, scan_source, estimate_audit, get_audit, and 10 more. Their descriptions and schemas cost roughly 3,451 tokens of context every time the server is loaded.

Does the nittim MCP server require authentication?

Yes. nittim asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the nittim MCP server still maintained?

nittim is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.