# GuestGraph (remote · mcp.guestgraph.io)

GuestGraph: One guest, not five strangers

- Trust score: 67/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `mcp.guestgraph.io`: 67/100 (this document), [markdown](https://verifymcp.io/servers/io-guestgraph-mental-model/mcp.md), [page](https://verifymcp.io/servers/io-guestgraph-mental-model/mcp)

## Channel facts

- Endpoint: `https://mcp.guestgraph.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 14 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 72/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2159 tokens (~154/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 88/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 56% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the GuestGraph MCP server?

GuestGraph is a hosted endpoint at https://mcp.guestgraph.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-guestgraph-mental-model 'https://mcp.guestgraph.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-guestgraph-mental-model": {
      "url": "https://mcp.guestgraph.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-guestgraph-mental-model": {
      "type": "http",
      "url": "https://mcp.guestgraph.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-guestgraph-mental-model]
url = "https://mcp.guestgraph.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-guestgraph-mental-model": {
      "type": "remote",
      "url": "https://mcp.guestgraph.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-guestgraph-mental-model --url 'https://mcp.guestgraph.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-guestgraph-mental-model:
    url: "https://mcp.guestgraph.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-guestgraph-mental-model": {
      "Transport": "http",
      "Url": "https://mcp.guestgraph.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-guestgraph-mental-model -t streamable-http -u 'https://mcp.guestgraph.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-guestgraph-mental-model": {
      "type": "http",
      "url": "https://mcp.guestgraph.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 67, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 67, +1)

- [functional] Server version: 0.30.0 → 0.31.0
- [functional] New tool “diagram”

### 2026-09-25 (score 66, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 65)

First indexed and scored.

## MCP tools (14)

### `list_types` (~71 tokens)

Every type the model's schemas declare. Use first, to learn which types exist before listing or describing one. No input. Returns `types`, each with `type`, `name`, `tagline`, `owner` (the type it nests under, or null) and `count`, the entities it holds.

Output parameters:

- `model` (object)
- `types` (array)

### `describe_schema` (~98 tokens)

One type's schema: its sections as written and its declared relations as data. Use to learn what an entity of the type may hold; for the whole vocabulary use describe_relations. Input: `type`. Returns `url`, the schema's own file, `sections`, and `relations`: owner, owns, references both ways, enums, joins and lists.

Input parameters:

- `type` (string, required): A type name from list_types, such as skill

Output parameters:

- `model` (object)
- `name` (string)
- `relations` (object)
- `sections` (array)
- `tagline` (string)
- `type` (string)
- `url` (string|null)

### `describe_relations` (~127 tokens)

What the schemas declare between types: references with form and cardinality, ownership, enums, joins, list kinds. Use for a diagram or audit; for one type's full schema use describe_schema. Optional `type` narrows every list, `direction` (declares, declared-to, both; needs `type`) one side of relations, `via` relations and enums. Returns those lists, with `forms` and `reading` explaining every term. Not paged.

Input parameters:

- `direction` (string)
- `type` (string)
- `via` (string)

Output parameters:

- `enums` (array)
- `forms` (object)
- `joins` (array)
- `lists` (array)
- `model` (object)
- `ownership` (array)
- `reading` (object)
- `relations` (array)

### `list_rules` (~83 tokens)

The rules the model is held to, from the CONVENTIONS.md its core vendors. Use to resolve a rule number that a schema or a refusal cites, such as R9. No input. Returns `tagline`, the file's `url`, and `rules`, each with `rule`, `title` and `part`; describe_rule gives one rule's text.

Output parameters:

- `model` (object)
- `rules` (array)
- `tagline` (string)
- `url` (string|null)

### `describe_rule` (~82 tokens)

One rule as written. Input: `rule`, a number from list_rules such as R9, in either case. Returns `rule`, `title`, `part`, `text` and the file's `url`. An unknown number is refused with the known ones listed.

Input parameters:

- `rule` (string, required): A rule's number from list_rules, such as R9

Output parameters:

- `model` (object)
- `part` (string|null)
- `rule` (string)
- `text` (string)
- `title` (string)
- `url` (string|null)

### `list_checks` (~84 tokens)

The checks the model's own gate runs, from the checker release this server was built with. Use to see which rules a script enforces and which are left to a reader. No input. Returns `checks`, each with `name`, `rule` and that rule's `title`, and `ranBy`. A list and no verdict: this server runs none of them.

Output parameters:

- `checks` (array)
- `model` (object)
- `ranBy` (string)

### `describe_errors` (~98 tokens)

What a refused call looks like. A tool's output schema covers its answers only, so use this once, to branch on refusals or validate them. No input. Returns `errors`, every `code` with `when` it is raised and the JSON Schema of its `details`, and `schema`, the JSON Schema of a whole refusal: `error` with `code`, `message`, `rule`, `details`, beside `model`.

Output parameters:

- `errors` (array)
- `model` (object)
- `schema` (object)

### `list_entities` (~196 tokens)

The entities of one type, by id. Use to browse a type; to find an entity by words or by name use search. Input: `type`, optional `owner` (an id) to keep one owner's entities, `limit` (default 50, at most 200) and `cursor`. Returns `entities` with `id`, `type`, `name`, `tagline`, `owner`, and `page`; follow `page.nextCursor` while `page.hasMore`.

Input parameters:

- `cursor` (string): `page.nextCursor` from the previous answer, sent with the same arguments; omit it for the first page.
- `limit` (integer): Entries per page: 50 by default, clamped to 1–200, so 0 returns one entry and 1000 returns 200.
- `owner` (string): An owner's id, to keep its entities
- `type` (string, required)

Output parameters:

- `entities` (array)
- `model` (object)
- `page` (object)
- `type` (string)

### `get_entity` (~133 tokens)

One entity as structured data: fields, sections, tables and its references both ways. Use to reason over an entity; for its page as written use fetch. Input: `id`, or `type` and `name`; an ambiguous name is refused with candidate ids. Returns `entity`. Each reference list holds at most 50 edges; `referenceCounts` gives the totals and list_references the rest.

Input parameters:

- `id` (string): The entity's id, as any answer gives it
- `name` (string): The canonical name, the entity's H1; needs type
- `type` (string)

Output parameters:

- `entity` (object)
- `model` (object)

### `list_references` (~202 tokens)

The model's edges, filtered and paged. Use to inspect one entity's relations or one kind of reference without taking whole entities. Optional `entity` (an id), `direction` (out, in, both; needs `entity`), `via`, `type` (the far end's type, or either end's without `entity`), `limit`, `cursor`. Returns `edges`, each `from`, `via`, `to`, `attrs`, and `page`.

Input parameters:

- `cursor` (string): `page.nextCursor` from the previous answer, sent with the same arguments; omit it for the first page.
- `direction` (string)
- `entity` (string)
- `limit` (integer): Entries per page: 50 by default, clamped to 1–200, so 0 returns one entry and 1000 returns 200.
- `type` (string)
- `via` (string)

Output parameters:

- `edges` (array)
- `model` (object)
- `page` (object)

### `find_evidence` (~170 tokens)

Every edge into one skill, grouped by the type of the page that drew it. Use to check a claimed skill against its evidence. Input: `skill`, an id or canonical name; optional `limit`, `cursor`. Returns `skill`, `evidence` and `page`; a profile's claim arrives via Skills.Skill with its level, an evidence row via Evidence.Skill. Attributes are verbatim.

Input parameters:

- `cursor` (string): `page.nextCursor` from the previous answer, sent with the same arguments; omit it for the first page.
- `limit` (integer): Entries per page: 50 by default, clamped to 1–200, so 0 returns one entry and 1000 returns 200.
- `skill` (string, required): The skill's id or canonical name

Output parameters:

- `evidence` (object)
- `model` (object)
- `page` (object)
- `skill` (object)

### `search` (~215 tokens)

Find entities by words, substring or exact name. `match: "words"` needs every query word's stem in name, tagline, fields, sections or cells; `"text"` (default) is a case-insensitive substring over the same; `"name"` the exact canonical name. Optional `type`, `owner`, `limit`, `cursor`. Returns `results` with `id`, `title`, `type`, `matched`, `words` in words mode, and `page`: name matches first, then a listing.

Input parameters:

- `cursor` (string): `page.nextCursor` from the previous answer, sent with the same arguments; omit it for the first page.
- `limit` (integer): Entries per page: 50 by default, clamped to 1–200, so 0 returns one entry and 1000 returns 200.
- `match` (string)
- `owner` (string): An owner's id, to keep its entities
- `query` (string, required)
- `type` (string)

Output parameters:

- `match` (string)
- `model` (object)
- `page` (object)
- `query` (string)
- `results` (array)
- `words` (array)

### `fetch` (~87 tokens)

One entity's page as written. Use to quote or display the source; for structured fields and references use get_entity. Input: `id`, from search, list_entities or any reference. Returns `id`, `title`, `type`, `url` and `text`, the Markdown source. Takes no name: search with match "name" finds the id.

Input parameters:

- `id` (string, required)

Output parameters:

- `id` (string)
- `model` (object)
- `text` (string)
- `title` (string)
- `type` (string)
- `url` (string|null)

### `diagram` (~173 tokens)

A picture of the model as Mermaid, from its edges or its schemas. Use to show connections; for edges as data use list_references. Input: `shape`; `id`, `domain` or `type` narrow it. Returns `mermaid`, `nodes`, `links`, `title`, `edges`, `omitted`, schema's `everyType`. A process draws each gate's failure dashed, to a phase or one Stop node, outside `nodes`. At most 50 nodes.

Input parameters:

- `domain` (string): A domain's id, to draw its concepts
- `id` (string): The process to draw, or the entity at the middle of a neighborhood
- `shape` (string, required)
- `type` (string): A type, to draw its schema and the types it is declared with

Output parameters:

- `edges` (integer)
- `everyType` (array)
- `links` (array)
- `mermaid` (string)
- `model` (object)
- `nodes` (array)
- `omitted` (integer)
- `shape` (string)
- `title` (string|null)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-guestgraph-mental-model/mcp#diagnostics

## Score history

- 2026-09-28: 67
- 2026-09-27: 67
- 2026-09-26: 66
- 2026-09-25: 66
- 2026-09-24: 65

## Common questions

### What is the GuestGraph MCP server?

GuestGraph is an MCP server listed in the public MCP registry as io.guestgraph/mental-model. GuestGraph: One guest, not five strangers. This page covers its hosted endpoint (https://mcp.guestgraph.io/mcp).

### Is the GuestGraph MCP server safe to use?

GuestGraph scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the GuestGraph MCP server expose?

GuestGraph exposes 14 tools: list_types, describe_schema, describe_relations, list_rules, describe_rule, and 9 more. Their descriptions and schemas cost roughly 1,819 tokens of context every time the server is loaded.

### Does the GuestGraph MCP server require authentication?

No. We connected to GuestGraph without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the GuestGraph MCP server still maintained?

GuestGraph is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.guestgraph.io/mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-guestgraph-mental-model/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-guestgraph-mental-model/mcp.json
- HTML version of this page: https://verifymcp.io/servers/io-guestgraph-mental-model/mcp
