# it.elsas/security-intel (remote · elsas.it)

Daily Ed25519-signed security intelligence for AI-agent stacks; CVEs & advisories, paid via x402.

- Trust score: 23/100 (low)
- Change this week: −41
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `elsas.it`: 23/100 (this document), [markdown](https://verifymcp.io/servers/it-elsas-security-intel/elsas.md), [page](https://verifymcp.io/servers/it-elsas-security-intel/elsas)

## Channel facts

- Endpoint: `https://elsas.it/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport check failed: declared streamable-http, but the endpoint returned HTTP 404.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 4 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add --transport http it-elsas-security-intel https://elsas.it/mcp
```

### Codex

```toml
[mcp_servers.it-elsas-security-intel]
url = "https://elsas.it/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "it-elsas-security-intel": {
      "type": "remote",
      "url": "https://elsas.it/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add it-elsas-security-intel --url https://elsas.it/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  it-elsas-security-intel:
    url: "https://elsas.it/mcp"
```

### Other

```json
{
  "mcpServers": {
    "it-elsas-security-intel": {
      "type": "http",
      "url": "https://elsas.it/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 23, −42)

- [security regression] Endpoint reachability: unreachable → not serving MCP
- [security regression] HSTS header: unverified → fail
- [security improvement] TLS certificate: unverified → pass
- [security] Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
- [security] Transport: Transport check failed: declared streamable-http, but the endpoint returned HTTP 404.

### 2026-08-01 (score 65, 0)

- [security regression] Endpoint reachability: reachable → unreachable

### 2026-07-31 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 65, +1)

- [security improvement] TLS certificate: unverified → pass
- [security improvement] HSTS header: unverified → pass
- [security improvement] Transport: fail → pass
- [security] Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
- [functional improvement] Endpoint reachability: unreachable → reachable
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Schema quality: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Stability: unverified → 0.07

### 2026-07-28 (score 64, 0)

- [security regression] Endpoint reachability: reachable → unreachable
- [security regression] TLS certificate: pass → unverified
- [security regression] HSTS header: pass → unverified
- [security regression] Transport: pass → fail
- [security] Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Capabilities: pass → unverified
- [functional regression] Schema quality: 100 → unverified

### 2026-07-27 (score 64, +61)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 3)

First indexed and scored.

## MCP tools (11)

### `get_today` (~198 tokens)

Today's full curated security report for the MCP / AI-agent ecosystem
(PAID — $0.10 USDC, charged automatically via x402 on Base; no account needed).

Returns the latest signed, independently cross-validated digest of security
incidents, advisories (CVE/GHSA/OSV/KEV) and notable changes affecting MCP
servers, agents and their dependencies — each item with severity, why it
matters, and a recommended action. Every report is Ed25519-signed; verify it
yourself (see https://elsas.it/docs#verify). Try it free first with
\`get_sample_report` (yesterday's report, identical format).

Input parameters:

- `stack`: Optional comma-separated filter, e.g. "devops,security", to return    only relevant items. Stacks: devops, coding, qa, finance,    healthcare, legal, content, security, knowledge.

### `get_sample_report` (~136 tokens)

FREE preview — yesterday's full report, identical in format and signing to
the paid `get_today`. Call this first to see exactly what you get before
paying: real curated security items, severities, recommendations, and an
Ed25519 signature you can verify (https://elsas.it/docs#verify). The only
difference from get_today is freshness (this is the previous day's report).

Input parameters:

- `run_id`: Optional specific report id (from `list_available`). Defaults to     the most recent report that is not today's paid one.
- `stack`: Optional comma-separated filter (same stacks as get_today).

### `list_available` (~57 tokens)

List available validated reports. Cheap to call, returns no full bodies.
Only shows reports that passed validation (signed, TL;DR, no AUTO-CORRECTED).
The current (newest) report is excluded — it's the paid product.

Output parameters:

- `result` (array)

### `check_affected` (~565 tokens)

Check your installed packages against recent security advisories.

Pay-per-value: $0 when nothing affects your versions (status all_clear/verify is
always free), otherwise priced per confirmed match via x402 — you only pay when
you learn you are actually exposed.

Zero-friction input: paste your dependency file straight into `lockfile` — no need
to hand-extract package/version. Auto-detected formats: package-lock.json,
yarn.lock, requirements.txt (== pins), poetry.lock, Pipfile.lock, go.mod, go.sum,
Cargo.lock, and CycloneDX / SPDX JSON SBOMs. Or pass an explicit `components` list
of {package, version, ecosystem?} (you may pass both — they are merged).

Built for agents that poll on their own clock: pass `since` (a cursor) to match
ONLY advisories first published after your last check, so a repeated poll is free
until something NEW hits you — and you pay at most once per new exposure. The
returned `cursor` is interchangeable with get_since's cursor; store it and pass it
back next time. Use `min_severity` to ignore (and not pay for) matches below your
threshold.

Returns advisories that affect (or may affect) your versions, each with the
primary-source URL so you can verify independently. Trust-safe: when a version
range cannot be parsed, or an advisory is product-level (no version data), it is
reported as "verify" rather than silently cleared. Pair with the signed report for
an auditable trail.

Input parameters:

- `components`: optional list of {package, version, ecosystem?}.
- `lockfile`: optional raw lockfile or SBOM text — parsed server-side into       components (exact pinned versions only). Auto-detected; combine with       `components` if you like. Practical size limit ~1MB; for…
- `lockfile_type`: optional hint/filename to force the parser (e.g. "go.mod",            "requirements.txt", "cyclonedx") when auto-detect is ambiguous.
- `min_severity`: optional floor — one of low|medium|moderate|high|critical.           Matches below it are dropped (and not charged for).
- `preview` (boolean): if true, return only the shape (counts + max severity) used to      quote a price — no advisory bodies. The gateway uses this; you do      not need to set it.
- `since`: optional cursor — only match advisories first published after it.    Omit on the first call; pass the returned `cursor` thereafter.

### `get_since` (~180 tokens)

Delta feed for agents that poll on their own clock: what's new since you
last checked. Free. Pass the `cursor` from your previous call (omit on first
call); poll as often as you like.

Returns a lightweight index of new items — id, title, item_type, CVE id,
severity, the signed report_id each was published in, and published_at — plus
a new `cursor` and `count`. count == 0 means nothing new since you last looked.

To get the full bodies (affected ranges, sources, assessment, remediation) for
what's new, call the paid get_today (or check_affected to test your own deps).
Optional `stack` filters by relevant_for tags (same as get_today).

Returns: {cursor, count, index}.

Input parameters:

- `cursor`
- `stack`

### `get_items` (~206 tokens)

Full bodies for items you discovered via `get_since` (PAID — pay-per-value,
priced per delivered item via x402; $0 if none of the ids are found).

\`get_since` gives you a free index (id, title, severity, …) so you can decide
what matters to you; `get_items` returns the actionable payload — affected
ranges, primary sources, assessment and remediation — only for the ids you ask
for. Each item carries the `report_id` of the signed report it was first
published in: fetch that report via `get_sample_report(run_id=report_id)` to
verify the Ed25519 signature yourself.

Input parameters:

- `ids` (array, required): item ids (from get_since's index) to retrieve.
- `preview` (boolean): if true, return only the shape (count + max severity) used to quote      a price — no bodies. The gateway uses this; you do not need to set it.

### `check_cve` (~125 tokens)

Normalized, SIGNED verdict for a single CVE: CVSS (v3.1/v4.0, authoritative
from NVD with OSV fallback), CISA-KEV exploitation status, and EPSS probability.

PAID ($0.01 USDC via x402). Deterministic JSON; the response carries an Ed25519
SSHSIG signature (`_signature`) you can verify offline — unlike unsigned CVE APIs.

Input parameters:

- `cve` (string, required): a CVE id, e.g. "CVE-2021-44228".

### `is_exploited` (~137 tokens)

Fast boolean: is this CVE known-exploited? SIGNED.

\`exploited` is driven by CISA-KEV (authoritative evidence of in-the-wild
exploitation). EPSS (predictive probability) is included as a secondary signal
but does NOT set the boolean — we report observed exploitation, not a forecast.

PAID ($0.001 USDC via x402). Args: cve — e.g. "CVE-2024-3094".
Returns: signed {exploited, kev, epss, basis, _signature}.

Input parameters:

- `cve` (string, required)

### `check_package` (~121 tokens)

SIGNED vulnerability verdict for one package version (OSV.dev) with a CISA-KEV
flag per matching advisory.

PAID ($0.002 USDC via x402). Deterministic JSON + Ed25519 signature.

Input parameters:

- `ecosystem`: OSV ecosystem (npm, PyPI, Go, crates.io, …). Inferred-as-given;        pass it for precise matching.
- `name` (string, required): package name (e.g. "lodash", "requests").
- `version`: exact version to test against advisory ranges (recommended).

### `search_cves` (~119 tokens)

SIGNED keyword search over the NVD CVE corpus, each result enriched with a
CISA-KEV flag.

PAID ($0.01 USDC via x402). Deterministic JSON + Ed25519 signature.

Input parameters:

- `keyword` (string, required): free-text (matched by NVD keywordSearch), e.g. "langchain rce".
- `limit` (integer): max results (1–50, default 20).
- `since`: optional ISO date (YYYY-MM-DD); only CVEs published on/after it.

### `scan_dependencies` (~197 tokens)

Bulk OSV scan of a whole lockfile/SBOM — every dependency checked against
OSV.dev, KEV-flagged. SIGNED. PAID pay-per-value: billed per vulnerability HIT
(dynamic x402, $0 when the whole tree is clean, capped at $0.10).

Unlike `check_affected` (matches your deps against elsas's curated CURRENT
advisory set), this runs a FULL OSV scan of the entire dependency graph.

Input parameters:

- `lockfile` (string, required): raw lockfile/SBOM text — package-lock.json, yarn.lock,       requirements.txt, poetry.lock, Pipfile.lock, go.mod/go.sum,       Cargo.lock, CycloneDX/SPDX JSON (auto-detected, ~1MB cap).
- `lockfile_type`: optional parser hint/filename.
- `preview` (boolean): gateway-internal — returns only {affected, max_severity} for pricing.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/it-elsas-security-intel/elsas#diagnostics

## Score history

- 2026-08-03: 23
- 2026-08-02: 23
- 2026-08-01: 65
- 2026-07-31: 65
- 2026-07-30: 65
- 2026-07-29: 65
- 2026-07-28: 64
- 2026-07-27: 64
- 2026-07-26: 3

## Links

- Remote endpoint: https://elsas.it/mcp
- Repository: https://github.com/romans-repos/elsas-verify
- Website: https://elsas.it/
- Changelog RSS feed: https://verifymcp.io/servers/it-elsas-security-intel/elsas/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/it-elsas-security-intel/elsas/changelog.json
- HTML version of this page: https://verifymcp.io/servers/it-elsas-security-intel/elsas
