# Zambo (remote · zambo.dev)

Trust Layer for AI work. Give your AI hands. Every run returns a verifiable receipt. No key needed.

- Trust score: 71/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `zambo.dev`: 71/100 (this document), [markdown](https://verifymcp.io/servers/dev-zambo-zambo/zambo.md), [page](https://verifymcp.io/servers/dev-zambo-zambo/zambo)

## Channel facts

- Endpoint: `https://zambo.dev/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `4.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (zambo_universal).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 94/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 2037 tokens (~101/item across 20 items; 13 tools + 7 resources), lean.
  - Tools include usage examples.
- **Stability & Change Management**: 7/100
  - Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Zambo MCP server?

Zambo is a hosted endpoint at https://zambo.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http dev-zambo-zambo 'https://zambo.dev/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "dev-zambo-zambo": {
      "url": "https://zambo.dev/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "dev-zambo-zambo": {
      "type": "http",
      "url": "https://zambo.dev/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.dev-zambo-zambo]
url = "https://zambo.dev/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-zambo-zambo": {
      "type": "remote",
      "url": "https://zambo.dev/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add dev-zambo-zambo --url 'https://zambo.dev/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  dev-zambo-zambo:
    url: "https://zambo.dev/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "dev-zambo-zambo": {
      "Transport": "http",
      "Url": "https://zambo.dev/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add dev-zambo-zambo -t streamable-http -u 'https://zambo.dev/mcp'
```

### Other

```json
{
  "mcpServers": {
    "dev-zambo-zambo": {
      "type": "http",
      "url": "https://zambo.dev/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 71, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 71, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-26 (score 70)

First indexed and scored.

## MCP tools (13)

### `zambo_universal` (~392 tokens)

Zambo Universal

Universal Zambo entry point for routing natural-language requests across supported Zambo tools through one MCP connection. Covers strategy, code audits, lead generation, wallet intelligence, provenance certificates, swarm coordination, and live market data. Returns a route, execution state, downstream tool results when available, and receipt information.

Input parameters:

- `_session_id` (string): Stable ID generated by the host AI once per conversation and reused on every Zambo call. Enables a shared working trail across multi-step tasks.
- `context` (object): Optional extra context. Supported keys: repo_url, goal, trade, city, wallet, domain. Example: { "repo_url": "https://github.com/owner/repo" }
- `email` (string): Optional email, only with the user's consent. Namespaces Pass access and a compact working trail so the same user can continue across AI clients without restarting.
- `format` (string): Response format. Default: json.
- `mode` (string): Collaboration mode. execute routes and performs the request; continue uses the current session trail; verify checks whether the current session has completed a request. Default: execute.
- `need` (string, required): Natural language description of what you need. Any length. Also accepts: message, query, prompt, input, goal, text. Example: 'How do I protect my AI agent from prompt injection?'
- `remember` (string): Optional explicit fact to persist in this stable session. It is returned by mode:'verify'; only use after the user asks you to remember it or clearly consents.
- `session_code` (string): Optional ZAMBO-XXXX handoff code from Telegram /export. Loads that saved conversation into this request so another AI can continue immediately.
- `session_id` (string): Alias for _session_id. Use one stable ID for the whole conversation so Zambo and the host AI do not repeat completed steps.

Output parameters:

- `executed` (boolean)
- `executed_tools` (array)
- `grounding` (string)
- `observed_status` (string)
- `ok` (boolean)
- `planned_tools` (array)
- `result` (string)
- `result_status` (string)
- `run_id` (string)
- `sources` (array)
- `understood` (string)
- `verify` (object)

### `new_session` (~38 tokens)

NEW Session

Starts fresh session context and returns a new session_id. Reuse that ID on subsequent calls for continuity; changing or omitting it starts clean context.

Output parameters:

- `instructions` (string)
- `session_id` (string)
- `status` (string)

### `journal_log` (~200 tokens)

Journal LOG

Log an action performed outside Zambo into an append-only job timeline. Zambo records the report and does not claim it ran or observed the action.

Input parameters:

- `completed_at` (string): RFC 3339 completion timestamp.
- `duration_ms` (number): Reported duration in milliseconds.
- `executor_identity` (string, required): Agent, client, or local executor that reported the action.
- `external_executor` (string): External server or executor name when relevant.
- `inputs` (object): Optional local input object. It is redacted and hashed, then discarded.
- `job_id` (string, required): Stable job or session identifier shared by the agent.
- `metadata` (object): Optional redacted display metadata.
- `redacted_inputs_hash` (string): Hash of redacted inputs. Raw inputs are never stored.
- `started_at` (string): RFC 3339 start timestamp.
- `tool_name` (string, required): Tool or action name reported by the agent.

Output parameters:

- `result` (string)

### `live_price` (~167 tokens)

Live Price

Real-time cryptocurrency price lookup for supported coins. Uses CoinGecko first, Coinbase as a secondary no-key provider, then the most recent cached verified value with its age if both live providers are unavailable. Returns live USD price, 24-hour percentage change, and market capitalization when verified.

Input parameters:

- `coin` (string): Alias for symbol. Accepts the same coin ticker or name, for example BTC.
- `symbol` (string): Coin ticker or name — BTC, ETH, SOL, DOGE, BNB, XRP, MATIC, AVAX, ADA, LINK, DOT, UNI, ATOM, NEAR, APT, OP, ARB, SUI, PEPE, WIF, BONK, TON, TRX, LTC, SHIB. Case-insensitive.

Output parameters:

- `result` (string)

### `leadsignal` (~93 tokens)

Leadsignal

AI lead generation for contractors and local service businesses. Accepts a trade type and city. Returns qualified local leads with available contact information.

Input parameters:

- `city` (string, required): City and optional state. Example: 'Chicago', 'Denver CO', 'Austin Texas'
- `trade` (string, required): The trade or service type. Example: 'plumber', 'HVAC', 'electrician', 'roofer', 'general contractor'

Output parameters:

- `city` (string)
- `count` (number)
- `leads` (array)
- `trade` (string)

### `provibe_audit` (~141 tokens)

Provibe Audit

AI code audit for a public GitHub repository. Returns a Provibe score from 0 to 100, security vulnerabilities, a dead-code map, and an execution plan for addressing the findings.

Input parameters:

- `email` (string): Zambo Pass email for full audit (optional — without it you get the free teaser: score + top 3 issues). Get pass: https://zambo.dev/#zambo-pass
- `repo_url` (string, required): Public GitHub repository URL. Example: https://github.com/owner/my-saas
- `vibe_context` (string): Optional context: language, framework, specific concerns, or what the project does

Output parameters:

- `dead_code` (array)
- `execution_plan` (string)
- `provibe_score` (number)
- `vulnerabilities` (array)

### `ghost_audit_site` (~113 tokens)

Ghost Audit Site

Achilles 10-stage audit for a website. Returns SEO gaps, AI discoverability issues, conversion leaks, brand-presence gaps, competitor intelligence, a score from 0 to 100, stage findings, an audit ID, a live stream URL, and a report URL.

Input parameters:

- `email` (string): Optional email tied to an active Zambo Pass or Day Pass for unlimited audits.
- `url` (string, required): Full website URL to audit (e.g., https://yoursite.com). Include https://.

Output parameters:

- `audit_id` (string)
- `download_url` (string)
- `stages` (array)
- `status` (string)
- `stream_url` (string)

### `ghost_audit_status` (~56 tokens)

Ghost Audit Status

Status report for a Ghost Audit identified by audit_id. Returns whether the audit is running or complete, along with elapsed-time information and report availability.

Input parameters:

- `audit_id` (string, required): The audit_id returned by ghost_audit_site

Output parameters:

- `audit_id` (string)
- `ready` (boolean)
- `status` (string)

### `ghost_audit_report` (~55 tokens)

Ghost Audit Report

Full markdown report for a completed Ghost Audit. Returns the Achilles 10-stage score, severity-ranked findings, stage analysis, and recommended fixes.

Input parameters:

- `audit_id` (string, required): The audit_id returned by ghost_audit_site

Output parameters:

- `audit_id` (string)
- `report` (string)
- `status` (string)

### `credithunt` (~128 tokens)

Credithunt

Live verified index of AI and cloud startup credit programs. Accepts an optional technology stack and stage. Returns matching programs, eligibility details, current links, and available credit information.

Input parameters:

- `min_value` (number): Minimum credit value in USD to filter by (optional). Example: 5000
- `stack` (array): Your tech stack for matched recommendations. Example: ["openai","vercel","aws"]. Leave empty to get all programs.
- `stage` (string): Your stage: solo (1 person), early (2–10), growth (10+). Default: solo.

Output parameters:

- `count` (number)
- `matched` (array)
- `programs` (array)

### `prompt_shield` (~175 tokens)

Prompt Shield

Detection and analysis of prompt injection, jailbreak, and policy-bypass attempts. Returns an injection risk score, a safe/review/block recommendation, attack indicators, and a safe rewritten version when available.

Input parameters:

- `certificate` (boolean): If true, freeze this scan as a permanent public certificate and return certificate_url (optional)
- `context` (string): Describe your app for better contextual analysis (optional)
- `email` (string): Zambo Pass email for unlimited calls (optional)
- `mode` (string): 'fast' = pattern scan only (default), 'deep' = pattern + Groq semantic analysis
- `prompt` (string, required): The user input or prompt to validate for injection/jailbreak (max 16K chars)
- `system` (string): Your system prompt — also scanned for prompt leak attempts (optional)

Output parameters:

- `safe` (boolean)
- `sanitized` (string)
- `threats` (array)

### `day_pass_activate` (~91 tokens)

DAY Pass Activate

Agent-native access activation endpoint. Accepts an optional payment envelope or existing access key and returns a payment challenge or verified activation result. Activation results include receipt URL, run ID, access key, expiration, usage guidance, and a spend receipt. Activation occurs only after a verified transfer.

Input parameters:

- `x_payment` (string): Base64 JSON x402 payment envelope signed from the live challenge, sent as X-Payment.

Output parameters:

- `access_key` (string)
- `activated` (boolean)
- `already_active` (boolean)
- `expires_at` (string)
- `how_to_use` (object)
- `x711_credits` (number)

### `capability_search` (~123 tokens)

Capability Search

Search across the supported Zambo tool catalog for a use case. Returns relevant tools with relevance scores, descriptions, taglines, and callable API endpoints.

Input parameters:

- `keyword` (string): Natural-language alias for q.
- `q` (string): Search keyword or phrase. Also accepts the natural aliases query, keyword, or search. Example: 'code audit', 'prompt injection defense', 'wallet scoring', 'lead generation', 'trust verification'
- `query` (string): Alias for q. Use q when possible.
- `search` (string): Natural-language alias for q.

Output parameters:

- `count` (number)
- `matched` (array)
- `tools` (array)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/dev-zambo-zambo/zambo#diagnostics

## Score history

- 2026-09-28: 71
- 2026-09-27: 71
- 2026-09-26: 70

## Common questions

### What is the Zambo MCP server?

Zambo is an MCP server listed in the public MCP registry as dev.zambo/zambo. Trust Layer for AI work. Give your AI hands. Every run returns a verifiable receipt. No key needed. This page covers its hosted endpoint (https://zambo.dev/mcp).

### Is the Zambo MCP server safe to use?

Zambo scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Zambo MCP server expose?

Zambo exposes 13 tools: zambo_universal, new_session, journal_log, live_price, leadsignal, and 8 more. Their descriptions and schemas cost roughly 1,772 tokens of context every time the server is loaded.

### Does the Zambo MCP server require authentication?

No. We connected to Zambo without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Zambo MCP server still maintained?

Zambo is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://zambo.dev/mcp
- Repository: https://gitlab.com/rambozambodotdev/zambo
- Website: https://zambo.dev/
- Changelog RSS feed: https://verifymcp.io/servers/dev-zambo-zambo/zambo.xml
- Changelog JSON feed: https://verifymcp.io/servers/dev-zambo-zambo/zambo.json
- HTML version of this page: https://verifymcp.io/servers/dev-zambo-zambo/zambo
