AimRank
REMOTE · APP.AIMRANK.IO · SCANNED OCT 1
Read public pairwise-preference rankings and their statistical quality evidence. No API key.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability80
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2755 tokens (~119/item across 23 items; 21 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management73
- Stability observed for 22 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the AimRank MCP server?
AimRank is a hosted endpoint at https://app.aimrank.io/mcp/public, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · app.aimrank.io
claude mcp add --transport http io-aimrank-aimrank 'https://app.aimrank.io/mcp/public'
{
"mcpServers": {
"io-aimrank-aimrank": {
"url": "https://app.aimrank.io/mcp/public"
}
}
} {
"servers": {
"io-aimrank-aimrank": {
"type": "http",
"url": "https://app.aimrank.io/mcp/public"
}
}
} [mcp_servers.io-aimrank-aimrank] url = "https://app.aimrank.io/mcp/public"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-aimrank-aimrank": {
"type": "remote",
"url": "https://app.aimrank.io/mcp/public",
"enabled": true
}
}
} openclaw mcp add io-aimrank-aimrank --url 'https://app.aimrank.io/mcp/public' --transport streamable-http
mcp_servers:
io-aimrank-aimrank:
url: "https://app.aimrank.io/mcp/public" {
"McpServers": {
"io-aimrank-aimrank": {
"Transport": "http",
"Url": "https://app.aimrank.io/mcp/public"
}
}
} assistant mcp add io-aimrank-aimrank -t streamable-http -u 'https://app.aimrank.io/mcp/public'
{
"mcpServers": {
"io-aimrank-aimrank": {
"type": "http",
"url": "https://app.aimrank.io/mcp/public"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 30 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 1 Oct 2026 · Probed https://app.aimrank.io/mcp/public
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=app.aimrank.io | CN=YE2,O=Let's Encrypt,C=US | 7 Sept 2026 | 6 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 518a1191a86ebe3dbed9fb40c5297c9a368 |
| SANs: app.aimrank.io | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of app.aimrank.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| aimrank.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://browser.sentry-cdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https://api.stripe.com https://*.sentry.io https://*.ingest.sentry.io https://*.amazonaws.com https://datasets-server.huggingface.co; frame-src 'self' https://js.stripe.com https://hooks.stripe.com; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self' https://hooks.stripe.com; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), payment=(self "https://js.stripe.com"), usb=(), accelerometer=(), fullscreen=(self), interest-cohort=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://app.aimrank.io/mcp/public | Verified | 200 | |
| http (plaintext) | http://app.aimrank.io/mcp/public | HTTPS enforced | 308 | https://app.aimrank.io/mcp/public |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
aimrank_create_share_card ~147
Return share-ready URLs + embed snippets for a ranking. Formats: "all" (default — everything), "twitter", "linkedin", "embed_leaderboard", "embed_vote", "badge_markdown", "qr_code", "data_card". Pass these to a human to paste into a tweet, blog, Notion page, or Slack message. The OG image renders automatically when the public_url is unfurled by Twitter / LinkedIn / Slack. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| format | string | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_discover_public_rankings ~150
Browse public rankings — agent equivalent of surfing aimrank.io. Filters: category, media_type ("text" | "image" | "audio" | "video"), sort ("trending" | "recent" | "most_votes" | "random"), limit 1-50. Each result embeds share assets so the agent can hand any ranking back to the user as a clickable link without a follow-up call. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| category | – | – | – |
| limit | integer | – | – |
| media_type | – | – | – |
| sort | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_explain ~131
iCOMPLY contract: explain a prediction in features + narrative. Returns the Glicko-2 μ/φ inputs for both entities + a deterministic narrative. No LLM-synthesised rationale — these are the actual numbers the math uses, which is exactly what an Annex IV auditor needs to trace. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| entity_a_id | string | yes | – |
| entity_b_id | string | yes | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_find_similar_domains ~190
Find public domains most similar to a query or a known domain. Use ``query`` for free-text search ("pharma evaluation") OR ``domain_id`` to find domains similar to one you already know. Exactly one must be provided. TF-IDF + cosine similarity over name + description + category + declared constitution + objectives text. Cheap (no embedding API calls), 5-minute in-process cache. Only public domains are searched / returned. Score in [0, 1] — typical "useful match" threshold is ≥0.15; "near duplicate" is ≥0.5. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| domain_id | – | – | – |
| limit | integer | – | – |
| min_score | number | – | – |
| query | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_agreement ~121
Inter-annotator agreement — Layer 5. Returns Cohen's κ (n=2 raters), Fleiss' κ, Krippendorff's α, Scott's π + Landis-Koch interpretation, plus the multi-rater coverage report. `min_raters` overrides the ranking's configured min_raters_per_pair. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| min_raters | – | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_ceiling ~103
Pairwise-κ ceiling from qualification attempts. The upper bound any judge / RM can credibly hit on this domain — used to pin the L3 pilot refund clause (refund if κ < ceiling - 5pp). api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| min_overlapping_items | integer | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_crowd_bt ~120
CrowdBT — joint fit of entity scores + per-annotator reliability η. Surfaces noisy / anti-correlated raters explicitly. Methodology audit, not a live engine. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| max_iterations | integer | – | – |
| min_votes_per_annotator | integer | – | – |
| min_votes_per_entity | integer | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_daily_pair ~103
Fetch today's Daily Pair — the trending matchup chosen at 00:00 UTC. Pairs with the `vote_of_the_day` agent template. Returns the challenge + a fresh matchup. If the cron hasn't run yet, falls back via ok=False so the agent can use `aimrank_get_matchup` instead. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_data_card ~106
Auto data card — Layer 7. Provenance + IAA + coverage + per-annotator quality + transitivity + qualification stats in one synthesized markdown audit artefact. Format: 'markdown' (default) or 'json' for structured summary. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| format | string | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_domain ~56
Get domain details including entity pool and competition list. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| domain_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_leaderboard ~67
Get the top N entities of a ranking sorted by rating. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| limit | integer | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_matchup ~84
Get the next pair of entities to evaluate. Strategies: adaptive (default), swiss, balanced, random, uncertainty, explore, information_gain. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| ranking_id | string | yes | – |
| strategy | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_plackett_luce ~169
Plackett-Luce listwise ranking aggregation — OFFLINE AUDIT ONLY. Reported post-hoc; it NEVER writes ratings, and setting it as a ranking's algorithm returns 400. AimRank has 6 rating engines plus 2 offline aggregators (this and CrowdBT) — never describe it as an 8th rating algorithm. Generalises Bradley-Terry to ranked lists. On pairwise data, collapses to BT MLE — useful as a second-opinion aggregator. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| max_iterations | integer | – | – |
| min_appearances_per_entity | integer | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_get_ranking ~61
Fetch a ranking's metadata + top 25 entities sorted by rating. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_healthcheck ~23
iCOMPLY contract: liveness + DB-connectivity probe.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_list_competitions ~61
List all competitions (open voting + brackets) in a domain. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| domain_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_list_domain_entities ~59
List all entities in a domain's pool sorted by rating. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| domain_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_list_public_judges ~152
Browse public judge-prompt artifacts shared by other users. Filter by ``category`` (free-text), ``domain_id``, or both. Sort options: ``fork_count`` (default — most-forked first), ``recent``, ``faithfulness``. Returns artifact summaries WITHOUT the full prompt text — call `aimrank_fork_judge_prompt` or the REST GET to retrieve the full prompt before using it. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| category | – | – | – |
| domain_id | – | – | – |
| limit | integer | – | – |
| sort | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_predict ~121
iCOMPLY contract: pairwise prediction with provenance fields. Returns the engine's predicted winner + probability shaped so iCOMPLY's Annex IV section-4 generator can ingest the response directly. See [iCOMPLY_INTEGRATION_STRATEGY.md] for the contract. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| entity_a_id | string | yes | – |
| entity_b_id | string | yes | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_predict_matchup_winner ~128
Predict the winner of a matchup BEFORE a vote is cast. Uses Glicko-2 win probability under the same formula matchmaking uses internally. Pairs with aimrank_submit_vote for the "Claude predicts, you vote, we compare" demo. Does not record a vote — read-only. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| entity_a_id | string | yes | – |
| entity_b_id | string | yes | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
aimrank_search_entities ~69
Find entities by name substring within a ranking. api_key is optional on the public endpoint; on /mcp/mcp a missing key is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| limit | integer | – | – |
| query | string | yes | – |
| ranking_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | object | yes | – |
No examples provided.
What is the AimRank MCP server?
AimRank is an MCP server listed in the public MCP registry as io.aimrank/aimrank. Read public pairwise-preference rankings and their statistical quality evidence. No API key. This page covers its hosted endpoint (https://app.aimrank.io/mcp/public).
Is the AimRank MCP server safe to use?
AimRank scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the AimRank MCP server expose?
AimRank exposes 21 tools: aimrank_get_daily_pair, aimrank_get_ranking, aimrank_get_leaderboard, aimrank_get_matchup, aimrank_search_entities, and 16 more. Their descriptions and schemas cost roughly 2,221 tokens of context every time the server is loaded.
Does the AimRank MCP server require authentication?
No. We connected to AimRank without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the AimRank MCP server still maintained?
AimRank is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.