Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

it.elsas/security-intel

REMOTE · ELSAS.IT · SCANNED AUG 3

Daily Ed25519-signed security intelligence for AI-agent stacks; CVEs & advisories, paid via x402.

Available components

−41 this week 23 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security57
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema not yet verified: we couldn't read the endpoint's schema.Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage not yet verified: we couldn't read the endpoint's tools.Unverified
Capabilities0
  • Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified

Unverified: 4 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · elsas.it

# add to Claude Code
claude mcp add --transport http it-elsas-security-intel https://elsas.it/mcp
# ~/.codex/config.toml
[mcp_servers.it-elsas-security-intel]
url = "https://elsas.it/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "it-elsas-security-intel": {
      "type": "remote",
      "url": "https://elsas.it/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add it-elsas-security-intel --url https://elsas.it/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  it-elsas-security-intel:
    url: "https://elsas.it/mcp"
// mcp.json
{
  "mcpServers": {
    "it-elsas-security-intel": {
      "type": "http",
      "url": "https://elsas.it/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Aug 26 −42
    • Endpoint reachability: unreachable → not serving MCP security
    • HSTS header: unverified → fail security
    • TLS certificate: unverified → pass security
    • Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. security
    • Transport: Transport check failed: declared streamable-http, but the endpoint returned HTTP 404. security
  • 1 Aug 26 0
    • Endpoint reachability: reachable → unreachable security
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1
    • TLS certificate: unverified → pass security
    • HSTS header: unverified → pass security
    • Transport: fail → pass security
    • Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
    • Endpoint reachability: unreachable → reachable functional
    • Tool coverage: unverified → 100 functional
    • Schema quality: unverified → 100 functional
    • MCP protocol: unverified → pass functional
    • Stability: unverified → 0.07 functional
  • 28 Jul 26 0
    • Endpoint reachability: reachable → unreachable security
    • TLS certificate: pass → unverified security
    • HSTS header: pass → unverified security
    • Transport: pass → fail security
    • Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
    • Tool coverage: 100 → unverified functional
    • Capabilities: pass → unverified functional
    • Schema quality: 100 → unverified functional
  • 27 Jul 26 +61
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 3

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://elsas.it/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=elsas.it CN=YE1,O=Let's Encrypt,C=US 1 Aug 2026 30 Oct 2026 ECDSA 256 ECDSA-SHA384 6f75aa203ad65b7ec4cda8a921b5a2bc99b
SANs: elsas.it
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of elsas.it. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
it. present 51765 13 Verified
elsas.it. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 404
Header Value
content-security-policy default-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; upgrade-insecure-requests
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://elsas.it/mcp HTTP error 404
http (plaintext) http://elsas.it/mcp HTTPS enforced 308 https://elsas.it/mcp
MCP tools — 11 exposed · ~2,041 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
check_affected ~565

Check your installed packages against recent security advisories. Pay-per-value: $0 when nothing affects your versions (status all_clear/verify is always free), otherwise priced per confirmed match via x402 — you only pay when you learn you are actually exposed. Zero-friction input: paste your dependency file straight into `lockfile` — no need to hand-extract package/version. Auto-detected formats: package-lock.json, yarn.lock, requirements.txt (== pins), poetry.lock, Pipfile.lock, go.mod, go.sum, Cargo.lock, and CycloneDX / SPDX JSON SBOMs. Or pass an explicit `components` list of {package, version, ecosystem?} (you may pass both — they are merged). Built for agents that poll on their own clock: pass `since` (a cursor) to match ONLY advisories first published after your last check, so a repeated poll is free until something NEW hits you — and you pay at most once per new exposure. The returned `cursor` is interchangeable with get_since's cursor; store it and pass it back next time. Use `min_severity` to ignore (and not pay for) matches below your threshold. Returns advisories that affect (or may affect) your versions, each with the primary-source URL so you can verify independently. Trust-safe: when a version range cannot be parsed, or an advisory is product-level (no version data), it is reported as "verify" rather than silently cleared. Pair with the signed report for an auditable trail.

NameTypeReqDescription
componentsoptional list of {package, version, ecosystem?}.
lockfileoptional raw lockfile or SBOM text — parsed server-side into components (exact pinned versions only). Auto-detected; combine with `components` if you like. Practical size limit ~1MB; for…
lockfile_typeoptional hint/filename to force the parser (e.g. "go.mod", "requirements.txt", "cyclonedx") when auto-detect is ambiguous.
min_severityoptional floor — one of low|medium|moderate|high|critical. Matches below it are dropped (and not charged for).
previewbooleanif true, return only the shape (counts + max severity) used to quote a price — no advisory bodies. The gateway uses this; you do not need to set it.
sinceoptional cursor — only match advisories first published after it. Omit on the first call; pass the returned `cursor` thereafter.

Structured output declared, but exposes no named fields.

No examples provided.

check_cve ~125

Normalized, SIGNED verdict for a single CVE: CVSS (v3.1/v4.0, authoritative from NVD with OSV fallback), CISA-KEV exploitation status, and EPSS probability. PAID ($0.01 USDC via x402). Deterministic JSON; the response carries an Ed25519 SSHSIG signature (`_signature`) you can verify offline — unlike unsigned CVE APIs.

NameTypeReqDescription
cvestringyesa CVE id, e.g. "CVE-2021-44228".

Structured output declared, but exposes no named fields.

No examples provided.

check_package ~121

SIGNED vulnerability verdict for one package version (OSV.dev) with a CISA-KEV flag per matching advisory. PAID ($0.002 USDC via x402). Deterministic JSON + Ed25519 signature.

NameTypeReqDescription
ecosystemOSV ecosystem (npm, PyPI, Go, crates.io, …). Inferred-as-given; pass it for precise matching.
namestringyespackage name (e.g. "lodash", "requests").
versionexact version to test against advisory ranges (recommended).

Structured output declared, but exposes no named fields.

No examples provided.

get_items ~206

Full bodies for items you discovered via `get_since` (PAID — pay-per-value, priced per delivered item via x402; $0 if none of the ids are found). `get_since` gives you a free index (id, title, severity, …) so you can decide what matters to you; `get_items` returns the actionable payload — affected ranges, primary sources, assessment and remediation — only for the ids you ask for. Each item carries the `report_id` of the signed report it was first published in: fetch that report via `get_sample_report(run_id=report_id)` to verify the Ed25519 signature yourself.

NameTypeReqDescription
idsarrayyesitem ids (from get_since's index) to retrieve.
previewbooleanif true, return only the shape (count + max severity) used to quote a price — no bodies. The gateway uses this; you do not need to set it.

Structured output declared, but exposes no named fields.

No examples provided.

get_sample_report ~136

FREE preview — yesterday's full report, identical in format and signing to the paid `get_today`. Call this first to see exactly what you get before paying: real curated security items, severities, recommendations, and an Ed25519 signature you can verify (https://elsas.it/docs#verify). The only difference from get_today is freshness (this is the previous day's report).

NameTypeReqDescription
run_idOptional specific report id (from `list_available`). Defaults to the most recent report that is not today's paid one.
stackOptional comma-separated filter (same stacks as get_today).

Structured output declared, but exposes no named fields.

No examples provided.

get_since ~180

Delta feed for agents that poll on their own clock: what's new since you last checked. Free. Pass the `cursor` from your previous call (omit on first call); poll as often as you like. Returns a lightweight index of new items — id, title, item_type, CVE id, severity, the signed report_id each was published in, and published_at — plus a new `cursor` and `count`. count == 0 means nothing new since you last looked. To get the full bodies (affected ranges, sources, assessment, remediation) for what's new, call the paid get_today (or check_affected to test your own deps). Optional `stack` filters by relevant_for tags (same as get_today). Returns: {cursor, count, index}.

NameTypeReqDescription
cursor
stack

Structured output declared, but exposes no named fields.

No examples provided.

get_today ~198

Today's full curated security report for the MCP / AI-agent ecosystem (PAID — $0.10 USDC, charged automatically via x402 on Base; no account needed). Returns the latest signed, independently cross-validated digest of security incidents, advisories (CVE/GHSA/OSV/KEV) and notable changes affecting MCP servers, agents and their dependencies — each item with severity, why it matters, and a recommended action. Every report is Ed25519-signed; verify it yourself (see https://elsas.it/docs#verify). Try it free first with `get_sample_report` (yesterday's report, identical format).

NameTypeReqDescription
stackOptional comma-separated filter, e.g. "devops,security", to return only relevant items. Stacks: devops, coding, qa, finance, healthcare, legal, content, security, knowledge.

Structured output declared, but exposes no named fields.

No examples provided.

is_exploited ~137

Fast boolean: is this CVE known-exploited? SIGNED. `exploited` is driven by CISA-KEV (authoritative evidence of in-the-wild exploitation). EPSS (predictive probability) is included as a secondary signal but does NOT set the boolean — we report observed exploitation, not a forecast. PAID ($0.001 USDC via x402). Args: cve — e.g. "CVE-2024-3094". Returns: signed {exploited, kev, epss, basis, _signature}.

NameTypeReqDescription
cvestringyes

Structured output declared, but exposes no named fields.

No examples provided.

list_available ~57

List available validated reports. Cheap to call, returns no full bodies. Only shows reports that passed validation (signed, TL;DR, no AUTO-CORRECTED). The current (newest) report is excluded — it's the paid product.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultarrayyes

No examples provided.

scan_dependencies ~197

Bulk OSV scan of a whole lockfile/SBOM — every dependency checked against OSV.dev, KEV-flagged. SIGNED. PAID pay-per-value: billed per vulnerability HIT (dynamic x402, $0 when the whole tree is clean, capped at $0.10). Unlike `check_affected` (matches your deps against elsas's curated CURRENT advisory set), this runs a FULL OSV scan of the entire dependency graph.

NameTypeReqDescription
lockfilestringyesraw lockfile/SBOM text — package-lock.json, yarn.lock, requirements.txt, poetry.lock, Pipfile.lock, go.mod/go.sum, Cargo.lock, CycloneDX/SPDX JSON (auto-detected, ~1MB cap).
lockfile_typeoptional parser hint/filename.
previewbooleangateway-internal — returns only {affected, max_severity} for pricing.

Structured output declared, but exposes no named fields.

No examples provided.

search_cves ~119

SIGNED keyword search over the NVD CVE corpus, each result enriched with a CISA-KEV flag. PAID ($0.01 USDC via x402). Deterministic JSON + Ed25519 signature.

NameTypeReqDescription
keywordstringyesfree-text (matched by NVD keywordSearch), e.g. "langchain rce".
limitintegermax results (1–50, default 20).
sinceoptional ISO date (YYYY-MM-DD); only CVEs published on/after it.

Structured output declared, but exposes no named fields.

No examples provided.