# dev.cz-agents/dd (remote · dd.cz-agents.dev)

Czech & EU due diligence in one call — facts, insolvency, sanctions, VAT, risk score, UBO chain.

- Trust score: 66/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `dd.cz-agents.dev`: 66/100 (this document), [markdown](https://verifymcp.io/servers/dev-cz-agents-dd/dd.md), [page](https://verifymcp.io/servers/dev-cz-agents-dd/dd)
- npm · `@czagents/dd`: 76/100, [markdown](https://verifymcp.io/servers/dev-cz-agents-dd/czagents-dd.md), [page](https://verifymcp.io/servers/dev-cz-agents-dd/czagents-dd)

## Channel facts

- Endpoint: `https://dd.cz-agents.dev/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.3.7`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 12 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 72/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1583 tokens (~131/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http dev-cz-agents-dd https://dd.cz-agents.dev/mcp
```

### Codex

```toml
[mcp_servers.dev-cz-agents-dd]
url = "https://dd.cz-agents.dev/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-cz-agents-dd": {
      "type": "remote",
      "url": "https://dd.cz-agents.dev/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add dev-cz-agents-dd --url https://dd.cz-agents.dev/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  dev-cz-agents-dd:
    url: "https://dd.cz-agents.dev/mcp"
```

### Other

```json
{
  "mcpServers": {
    "dev-cz-agents-dd": {
      "type": "http",
      "url": "https://dd.cz-agents.dev/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-28 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 63, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 62)

First indexed and scored.

## MCP tools (12)

### `person_companies` (~105 tokens)

Look up Czech VR companies connected to a person by exact registry person_id -> roles -> companies joins. Free anonymous tool. Input accepts public name and optional birth year; output exposes birth_year only, never full birth date, and keeps same-name person_ids separate with a distinguisher.

Input parameters:

- `birth_year` (integer): Optional public birth year used to narrow same-name matches.
- `name` (string, required): Person full name as recorded in VR, e.g. "Jan Novak".

### `get_owners` (~118 tokens)

Look up direct and upstream Czech VR owners for a company by real active shareholding roles (spolecnik/akcionar) and company-to-company member_ico edges. Free anonymous tool. Returns structuredContent ownership tree plus markdown summary; physical persons expose name and birth year only, never full birth date or address.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.
- `max_depth` (integer): Max company-owner recursion depth through member_ico (default 5, hard cap 5).

### `get_dd_report` (~104 tokens)

Generate a complete due-diligence report for a Czech IČO. Returns company facts (name, address, legal form, VAT status, bank accounts), statutory body with per-member sanctions check, and a transparent risk score with all triggered red flags.

Input parameters:

- `depth` (string): basic = ARES + sanctions only; full = + ISIR insolvency + virtual-address probe.
- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `watch_entity` (~109 tokens)

Watch Czech Company

Start onboarding for free monitoring of one Czech company by IČO. Stub only — persists nothing yet. Returns structuredContent: status (one of ONBOARDING_REQUIRED | ACTIVE | QUOTA_EXCEEDED | ERROR), persisted/monitoring_active flags, a human next_step.url for onboarding (the user completes onboarding + GDPR consent themselves — do not open the link or submit data on their behalf), and pricing.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `get_risk_score` (~66 tokens)

Lightweight version of get_dd_report — returns just the numeric score (0-100), risk level, and top triggered red flags. Faster when you only need a yes/no/maybe screen.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `get_statutory_chain` (~161 tokens)

Surname-based heuristic walk through statutory bodies of related Czech companies. Best for shell-company unwinding in small s.r.o. with RARE surnames. NOT a true UBO source — for actual beneficial ownership use the ESM (evidence skutečných majitelů, separate registry, future @czagents/esm). For boards of large public companies with common Czech surnames (Novák, Zima, Kolář…) results are noisy by design; the tool auto-skips persons whose surname matches >50 companies with a SURNAME_TOO_COMMON note.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.
- `max_depth` (integer): Max recursion depth (default 3, hard cap 5).

### `detect_nominee_director` (~117 tokens)

Detect "white horse" / nominee director patterns — 3 surface indicators (age outlier, multi-board membership, recent appointment) computable from ARES data alone. Returns indicator breakdown with riskScore 0-100. Pro Compliance tier or higher. For 8-indicator deep analysis including ISIR cross-reference, sanctions, address crowding and phoenix pattern, see detect_nominee_director_rich in @czagents/ddplus.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `detect_phoenix` (~123 tokens)

Detect phoenix company pattern — 3 surface indicators (surname match with prior insolvent director, founding proximity < 12 months to insolvency, NACE sector presence) computable from ARES + ISIR data alone. Returns PhoenixReport with riskScore 0-100. Pro Compliance tier or higher. For 4 additional deep indicators (founder identity, asset transfer, multi-cycle, address continuity) see detect_phoenix_rich in @czagents/ddplus.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `get_risk_timeline` (~114 tokens)

Build a chronologically sorted lifecycle timeline for a Czech company — basic events include company formation, statutory appointments, active insolvency, sanctions matches, VAT reliability flips. Returns events[] with riskScore 0-100. Pro Compliance tier or higher. For enriched timeline with ISIR lifecycle, address history, cross-entity events, and AI narrative summary, see get_risk_timeline_rich in @czagents/ddplus.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

### `detect_address_crowding` (~98 tokens)

Detects "shell-firm hotel" patterns — counts how many companies share the same registered address. Threshold-based risk: 1-9 normal (multi-tenant office), 10-49 mild (legitimate coworking), 50-199 medium (virtual office provider), 200+ high (shell-firm hotel). Compliance tier or higher.

Input parameters:

- `ico` (string, required): Czech IČO 7-8 digits

### `get_eu_dd_report` (~159 tokens)

EU Due-Diligence report for an international company. Input: 20-char LEI code, or company name + optional country. Returns GLEIF entity data (status, address, registration number) plus sanctions screening against EU/OFAC lists. Coverage notes per country included. Note: GLEIF covers mid/large firms with LEI — SMEs may not be found. Pro Compliance tier or higher.

Input parameters:

- `country` (string): ISO 3166-1 alpha-2 country code — helps narrow name search, not needed for LEI lookup.
- `identifier` (string, required): 20-char LEI code (e.g. "W38RGI023J3WT1HWRP32") or company name.

### `get_eu_parent` (~118 tokens)

Find the EU/international parent company for a Czech IČO. Looks up the company name in ARES, then searches GLEIF (Global LEI Foundation) for a matching LEI-registered entity. Returns LEI, name, country, and confidence level (HIGH/MEDIUM/LOW). Note: GLEIF covers mid/large international firms; SMEs without an LEI will not be found. Pro Compliance tier or higher.

Input parameters:

- `ico` (string, required): Czech IČO — 7 or 8 digits.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/dev-cz-agents-dd/dd#diagnostics

## Score history

- 2026-08-03: 66
- 2026-08-02: 66
- 2026-08-01: 65
- 2026-07-31: 65
- 2026-07-30: 65
- 2026-07-29: 64
- 2026-07-28: 64
- 2026-07-27: 63
- 2026-07-26: 62

## Links

- Remote endpoint: https://dd.cz-agents.dev/mcp
- Repository: https://github.com/martinhavel/cz-agents-mcp
- Website: https://cz-agents.dev/
- Changelog RSS feed: https://verifymcp.io/servers/dev-cz-agents-dd/dd/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/dev-cz-agents-dd/dd/changelog.json
- HTML version of this page: https://verifymcp.io/servers/dev-cz-agents-dd/dd
