Enpitech
REMOTE · MCP.ENPITECH.DEV · SCANNED OCT 1
AgentReady website scans for AI agents, AI Hub search, newsletter and contact, from Enpitech.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (email_agentready_report). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability39
- 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1989 tokens (~180/item across 11 items; 8 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage83
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 42% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the Enpitech MCP server?
Enpitech is a hosted endpoint at https://mcp.enpitech.dev/mcp-app, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.enpitech.dev
claude mcp add --transport http enpitech-enpitech 'https://mcp.enpitech.dev/mcp-app'
{
"mcpServers": {
"enpitech-enpitech": {
"url": "https://mcp.enpitech.dev/mcp-app"
}
}
} {
"servers": {
"enpitech-enpitech": {
"type": "http",
"url": "https://mcp.enpitech.dev/mcp-app"
}
}
} [mcp_servers.enpitech-enpitech] url = "https://mcp.enpitech.dev/mcp-app"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"enpitech-enpitech": {
"type": "remote",
"url": "https://mcp.enpitech.dev/mcp-app",
"enabled": true
}
}
} openclaw mcp add enpitech-enpitech --url 'https://mcp.enpitech.dev/mcp-app' --transport streamable-http
mcp_servers:
enpitech-enpitech:
url: "https://mcp.enpitech.dev/mcp-app" {
"McpServers": {
"enpitech-enpitech": {
"Transport": "http",
"Url": "https://mcp.enpitech.dev/mcp-app"
}
}
} assistant mcp add enpitech-enpitech -t streamable-http -u 'https://mcp.enpitech.dev/mcp-app'
{
"mcpServers": {
"enpitech-enpitech": {
"type": "http",
"url": "https://mcp.enpitech.dev/mcp-app"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- Tool “agent_ready” now declares an output schema ▲ functional
- Tool “agentready_scan” now declares an output schema ▲ functional
- Tool “ai_hub_search” now declares an output schema ▲ functional
- Tool “contact_form” now declares an output schema ▲ functional
- Tool “email_agentready_report” now declares an output schema ▲ functional
- Tool “newsletter” now declares an output schema ▲ functional
- Tool “submit_contact” now declares an output schema ▲ functional
- Tool “subscribe_newsletter” now declares an output schema ▲ functional
- First check of Tool coverage: 100 functional
- 26 Sept 26 56
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 1 Oct 2026 · Probed https://mcp.enpitech.dev/mcp-app
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.enpitech.dev | CN=YE2,O=Let's Encrypt,C=US | 26 Sept 2026 | 25 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 62623d6517cd7c46f499a68704706e0dc9b |
| SANs: mcp.enpitech.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.enpitech.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| enpitech.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.enpitech.dev/mcp-app | Verified | 200 | |
| http (plaintext) | http://mcp.enpitech.dev/mcp-app | HTTPS enforced | 301 | https://mcp.enpitech.dev/mcp-app |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
agent_ready Check Agent Readiness ~267
Opens Enpitech's AgentReady scanner as a view in the conversation. Inside the view the scanner fetches the site's public pages and runs 21 checks across five weighted categories (Discovery & Access, Readable for Agents, Structured Data, Actions & MCP, Trust & Safety), then shows a 0-100 agent-readiness score, the per-category breakdown, and the fixes ranked by the points each would recover. Use it when the user asks how ready a website is for AI agents, their own or any site they name: how readable, accessible or usable it is to AI, to agents or to AI crawlers; whether ChatGPT or Claude can read or use it; how to show up in AI answers; or for an audit of llms.txt, robots.txt, schema.org markup or MCP support. url is optional: with no URL the scanner opens with an empty input for the user to fill in. This tool returns only the URL it was opened with; the scan runs inside the view, via agentready_scan.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | – | The site to scan, as the user gave it. A bare hostname like stripe.com is fine; the scanner normalizes it. Omit when the user has not named a site, and they will be asked for one. |
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The site the scanner opened with, or an empty string when the user will type one in the view. |
No examples provided.
agentready_scan Get AgentReady Results ~246
Runs the AgentReady scan on one site and returns the raw result, with no view. It fetches the site's public pages and runs 21 checks across five weighted categories (Discovery & Access, Readable for Agents, Structured Data, Actions & MCP, Trust & Safety), returning a 0-100 agent-readiness score, the per-category breakdown of every check, and the top fixes ranked by the points each would recover. When bot protection blocks too many checks the result carries limited: true and the headline score is not meaningful, though the per-check breakdown still is. When the scan does not run it returns ok: false with an errorType of invalid, unreachable, timeout or ratelimited. agent_ready runs this same scan and presents it as a visual report, so this tool fits the cases a view does not: the result is wanted as data, or several sites are being compared at once. The AgentReady view also calls this tool to run its own scan. Read-only: it fetches only public pages of the site named in the call and changes nothing on it.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The site to scan. A bare hostname like stripe.com works. |
| Name | Type | Req | Description |
|---|---|---|---|
| categories | array | yes | The five weighted categories and their 21 checks. |
| cleanUrl | string | yes | Hostname and path scanned, e.g. stripe.com. |
| limited | boolean | yes | True when bot protection blocked so much that the headline score is not meaningful; the per-check breakdown still is. |
| ok | boolean | yes | – |
| projectedScore | number | yes | The score the site would reach with the top fixes applied. |
| protection | – | yes | Bot protection on the homepage, or null when there is none. |
| scannedAt | number | yes | When the scan finished, Unix milliseconds. |
| scannedUrl | string | yes | The absolute URL that was fetched. |
| score | number | yes | Agent-readiness score, 0-100. |
| topFixes | array | yes | Fixes ranked by the points each would recover. |
| unverifiedCount | number | yes | Checks that could not be verified, e.g. behind bot protection. |
No examples provided.
ai_hub_search Search the AI Hub ~271
Searches the Enpitech AI Hub, Enpitech's curated catalog of Claude Code skills, MCP servers and AI tools, and agentic workflows for frontend teams, each one used by Enpitech engineers in production. Use it when the user wants a skill, MCP server, AI tool or workflow for a frontend task (code review, Figma to code, testing, context files, generative UI and so on), or asks what the AI Hub has. Returns matching items with a one-line take, an overview, the install command when there is one, and a link to the item's page on enpitech.dev. Read-only: it searches a published catalog and sends nothing anywhere.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Limit results to one part of the catalog: skills (Claude Code and Agent Skills), tools (MCP servers and AI tooling) or workflows (agentic workflows and prompts). Omit to search all three. |
| limit | integer | – | How many results to return, 1-20 (default 8). |
| query | string | – | What to look for, in plain words: a task, a technology or a name, e.g. "code review", "Figma to React", "MCP servers for React". Omit to list the catalog in order. |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| query | string | yes | The search terms, or empty when listing. |
| results | array | yes | Best matches first. |
| total | number | yes | How many catalog items matched in all. |
No examples provided.
contact_form Open Contact Form ~367
Opens Enpitech's contact form as a view in the conversation, where the user types their own name, email and message, plus an optional phone number and company, and submits it. Use it when the user wants to get in touch with Enpitech about frontend engineering work: frontend is the bottleneck their releases wait on; AI-generated frontend code their team cannot safely merge; senior React engineers embedded in a product team; AI features, an MCP app, or an agent-ready interface built into their product; private training for their team on AI-assisted frontend delivery or Claude Code; hosting, sponsoring or speaking at a frontend meetup. It opens a form and answers no questions. The tool itself sends nothing: it returns the contact surface the form opened on, and the enquiry is sent by submit_contact when the user submits.
| Name | Type | Req | Description |
|---|---|---|---|
| origin | string | – | Which contact surface to open the form in, inferred from the conversation. Omit when unsure; it defaults to general. general = the user wants senior React engineers embedded in their team, a web prod… |
| Name | Type | Req | Description |
|---|---|---|---|
| origin | string | yes | The contact surface the form opened on. |
No examples provided.
email_agentready_report Email AgentReady Report ~173
Emails the full 21-point AgentReady report for a site that has already been scanned, and stores the submitted name, email, phone and company as a sales lead in Enpitech's CRM under the agent-ready origin. The AgentReady view calls this tool when the user fills in the report form on the results page; it is not offered to the model. The scan is re-run server-side before the report is rendered, so the emailed report reflects the site at send time. Returns success with an emailed flag, which is false when the lead was stored but the email did not go out.
| Name | Type | Req | Description |
|---|---|---|---|
| companyName | string | – | – |
| string | yes | – | |
| name | string | yes | – |
| phone | string | – | – |
| score | string | – | – |
| url | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| emailed | boolean | – | False when the request was stored but the email did not go out; the view then offers a PDF instead. |
| success | boolean | yes | True when the request was stored. |
No examples provided.
newsletter Open Newsletter Signup ~85
Opens a signup form for the Enpitech newsletter, about frontend, AI and how teams ship, as a view in the conversation. The user types their own email and subscribes there. Use it when the user asks to subscribe to, join or get the Enpitech newsletter. It opens a form and subscribes no one: the subscription happens only when the user submits the form.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
submit_contact Send Enquiry ~335
Sends a contact enquiry to Enpitech, storing the submitted name, email, message and optional phone and company as a sales lead in Enpitech's CRM, tagged with the origin surface. The contact form view calls this tool when the user submits the form; it can also be called directly once the user has given those details in the conversation. Every field carries a value the user actually supplied; contact_form opens the same form as a view for the user to fill in when a detail is missing.
| Name | Type | Req | Description |
|---|---|---|---|
| companyName | – | – | – |
| string | yes | – | |
| message | string | yes | – |
| name | string | yes | – |
| origin | string | – | Which contact surface to open the form in, inferred from the conversation. Omit when unsure; it defaults to general. general = the user wants senior React engineers embedded in their team, a web prod… |
| phone | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| success | boolean | yes | True when the enquiry was sent. |
No examples provided.
subscribe_newsletter Subscribe to Newsletter ~99
Subscribes the email address the user typed into the newsletter signup view to the Enpitech newsletter, managed in Mailchimp. The newsletter view calls this tool when the user submits the form; it is not offered to the model. Returns success with a status of subscribed, or pending when a confirmation email was sent first. Every newsletter email carries an unsubscribe link.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address the user typed into the signup form. |
| Name | Type | Req | Description |
|---|---|---|---|
| status | string | – | subscribed, or pending when a confirmation email was sent first. |
| success | boolean | yes | True when the signup went through. |
No examples provided.
What is the Enpitech MCP server?
Enpitech is an MCP server listed in the public MCP registry as io.github.enpitech/enpitech. AgentReady website scans for AI agents, AI Hub search, newsletter and contact, from Enpitech. This page covers its hosted endpoint (https://mcp.enpitech.dev/mcp-app).
Is the Enpitech MCP server safe to use?
Enpitech scores 59 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Enpitech MCP server expose?
Enpitech exposes 8 tools: contact_form, submit_contact, agent_ready, email_agentready_report, agentready_scan, and 3 more. Their descriptions and schemas cost roughly 1,843 tokens of context every time the server is loaded.
Does the Enpitech MCP server require authentication?
No. We connected to Enpitech without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Enpitech MCP server still maintained?
Enpitech is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.