io.github.JaviMaligno/vitamind
REMOTE · GETVITAMIND.APP · 2 COMPONENTS · SCANNED AUG 3
Know when the sun can make vitamin D where you are, for your skin type. Live UV data.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 15 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3089 tokens (~154/item across 20 items; 15 tools + 5 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · getvitamind.app
claude mcp add --transport http javimaligno-vitamind https://getvitamind.app/api/mcp/mcp
[mcp_servers.javimaligno-vitamind] url = "https://getvitamind.app/api/mcp/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"javimaligno-vitamind": {
"type": "remote",
"url": "https://getvitamind.app/api/mcp/mcp",
"enabled": true
}
}
} openclaw mcp add javimaligno-vitamind --url https://getvitamind.app/api/mcp/mcp --transport streamable-http
mcp_servers:
javimaligno-vitamind:
url: "https://getvitamind.app/api/mcp/mcp" {
"mcpServers": {
"javimaligno-vitamind": {
"type": "http",
"url": "https://getvitamind.app/api/mcp/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 0
- Tool “get_my_history” rewrote its description, which is the text the model reads security
- New tool “set_history_location” functional
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 0
- Schema quality: 2534 → 2860 ▼ functional
- New resource “Sun forecast” functional
- New tool “get_sun_forecast” functional
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 0
- Stability: unverified → 0.03 ▲ functional
- 27 Jul 26 64
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://getvitamind.app/api/mcp/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=getvitamind.app | CN=YR1,O=Let's Encrypt,C=US | 26 Jun 2026 | 24 Sept 2026 | RSA 2048 | SHA256-RSA | 50df3155f28d0219bf433b463e1e96ac2a2 |
| SANs: getvitamind.app | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of getvitamind.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| getvitamind.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:; connect-src 'self' https://*.supabase.co wss://*.supabase.co https://cdn.jsdelivr.net https://nominatim.openstreetmap.org https://va.vercel-scripts.com; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(self) |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://getvitamind.app/api/mcp/mcp | Verified | 200 | |
| http (plaintext) | http://getvitamind.app/api/mcp/mcp | HTTPS enforced | 308 | https://getvitamind.app/api/mcp/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
compare_vitamin_d_year ~229
Compare the vitamin D year of 2 to 5 places side by side in ONE call — 'Madrid vs Berlin vs Oslo, where do I actually get winter sun?'. Returns each place's months with sun, exact season span and viable days per year, plus rankedByViableDays. Use this instead of calling get_vitamin_d_year once per city: only this tool can draw the years on a shared axis.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| places | array | yes | The places to compare, 2 to 5 |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
No output schema declared.
No examples provided.
configure_sun_profile ~288
Show the user an interactive form for the four values every other tool assumes — Fitzpatrick skin type, fraction of skin exposed, age and target IU — with the minutes they need updating live. Use this when those values are unknown, when the user wants to change them, or instead of asking for them one at a time in conversation. Whatever the user picks comes back into the conversation; pass those values explicitly to the other tools afterwards.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | — | Latitude of the place being discussed, so the live estimate uses today's real UV there |
| lon | number | — | Longitude, paired with lat |
| placeName | string | — | How to label that place in the widget |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
estimate_sun_session ~327
Estimate a sun session's outcome: 'I was (or will be) out N minutes — how much vitamin D did I make?' plus 'how long before I'd burn?' for the profile. Takes a start time (defaults to the day's best hour) and session minutes; returns estimated IU (with the physiological cap), average UV and clear-sky minutes-to-sunburn. Use for any 'how much did I get / can I get in X minutes' or 'how long without burning' question.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| date | string | — | Date as YYYY-MM-DD; defaults to today |
| elevationM | number | — | Ground elevation in metres (UV rises ~8%/km); default sea level |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| minutes | number | yes | Session length in minutes |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| startTime | string | — | Local HH:MM the session starts; defaults to the day's best hour |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
get_current_status ~244
Whether RIGHT NOW is a good moment for vitamin D synthesis at a location, using live Open-Meteo UV/cloud data when reachable (clear-sky model otherwise): current UV index, minutes needed now, and when today's window opens or closes.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| elevationM | number | — | Ground elevation in metres (UV rises ~8%/km); default sea level |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
get_my_cities ~41
The signed-in user's current city and favorite cities with coordinates and timezones, ready to feed into the public tools. Requires OAuth (scope profile:read).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_my_history ~120
The signed-in user's sun history from the app's calendar: which recent days had viable sun, which they confirmed going outside, and their current streak. Covers the calendar days from `from` to `to`; records exist only for days the app was open, so a date missing from `records` means nothing was measured, not that the sun was insufficient. Requires OAuth (scope history:read). Renders as a calendar the user can tap to confirm a day.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | — | How many recent days to return; default 30 |
No output schema declared.
No examples provided.
get_my_profile ~67
The signed-in user's saved Vitamin D profile: skin type, exposed-skin default, age, target IU and their current city. Requires connecting with OAuth (scope profile:read). Call this FIRST for any personal question, then pass its values to the public tools instead of asking the user.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_sun_forecast ~309
The NEXT FEW DAYS of vitamin D sun at a location, using the live Open-Meteo forecast: per day the peak UV, average cloud cover, the synthesis window and the minutes needed, plus bestDay. Use this for any question spanning several days — 'which day this week should I go out', 'will it be better tomorrow', 'when's my next chance' — instead of calling get_vitamin_d_window once per date.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| days | integer | — | How many days ahead, 2 to 7; default 5 |
| elevationM | number | — | Ground elevation in metres (UV rises ~8%/km); default sea level |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
get_sun_times ~130
Sunrise, sunset, solar noon, civil dawn/dusk, morning AND evening golden hour, and day length (with day-over-day trend) for a location and date. Handles midnight sun and polar night. Pure sun times — for vitamin D questions use the vitamin_d tools instead.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | — | Date as YYYY-MM-DD; defaults to today |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
get_vitamin_d_window ~353
The solar vitamin D synthesis window for ONE specific day at a location, for a personal profile: when UV is strong enough (index ≥ 3), the best hour, the clear-sky minutes needed to reach the target IU, and (with atTime) the minutes at the specific hour the user plans to go out. Returns synthesisPossible=false when the sun never gets high enough that day. Only for single-day questions — for months, seasons or 'when during the year', call get_vitamin_d_year instead of calling this once per date.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| atTime | string | — | Local HH:MM the user plans to go out — adds minutesNeeded and UV at that exact time |
| date | string | — | Date as YYYY-MM-DD; defaults to today |
| elevationM | number | — | Ground elevation in metres (UV rises ~8%/km); default sea level |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
get_vitamin_d_year ~331
The WHOLE YEAR of solar vitamin D for a location in a single call. monthsWithSun lists every month with at least one viable day (season edges count as partial months, see byMonth[].viableDays); solidMonths lists months where most days work; exactViableSpan gives the exact season boundaries; summary carries per-year aggregates for comparing places. Use this for any question about months, seasons, winter/summer or 'when during the year can I…' — never probe individual dates with get_vitamin_d_window for that.
| Name | Type | Req | Description |
|---|---|---|---|
| age | number | — | Age in years (synthesis declines with age); omit for adult baseline |
| elevationM | number | — | Ground elevation in metres (UV rises ~8%/km); default sea level |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| lat | number | yes | Latitude in decimal degrees |
| lon | number | yes | Longitude in decimal degrees |
| placeName | string | — | The place's name as the user said it — used to caption the chart |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
| timezone | string | — | IANA timezone like 'Europe/Madrid'. Strongly recommended — without it all times are UTC |
No output schema declared.
No examples provided.
log_sun_session ~133
Sets a day's answer in the signed-in user's history calendar. Three values: confirmed=true (went out, the default), confirmed=false (had usable sun but stayed in), confirmed=null (clear the answer). Defaults to today. Requires OAuth (scope history:write).
| Name | Type | Req | Description |
|---|---|---|---|
| confirmed | boolean|null | — | true (default) the user went out; false they had sun but stayed in; null clears the answer |
| date | string | — | Day to set, YYYY-MM-DD; defaults to today |
| minutes | number | — | Minutes the user reports having spent in the sun (acknowledged, not stored) |
No output schema declared.
No examples provided.
search_city ~68
Find a city in the app's database by name (any of the app's six languages works) and get its coordinates, IANA timezone and elevation — feed those into the other tools.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | City name, e.g. 'Madrid', 'London', 'Nueva York' |
No output schema declared.
No examples provided.
set_history_location ~187
Records where the signed-in user was over a range of past days, so their history stops assuming. Use it when the user corrects a stretch — get_my_history marks inherited days with `locationAssumed`, and the history calendar offers those stretches for correction. Pass a cityId from search_city, or lat/lon. Changes only the location: whether they went outside that day is untouched. Requires OAuth (scope history:write).
| Name | Type | Req | Description |
|---|---|---|---|
| cityId | string | — | City id from search_city, e.g. 'builtin:londres' |
| from | string | yes | First day of the stretch, YYYY-MM-DD |
| lat | number | — | Latitude, for a place not in the database |
| lon | number | — | Longitude, paired with lat |
| to | string | yes | Last day of the stretch, YYYY-MM-DD; same as `from` for one day |
No output schema declared.
No examples provided.
update_my_profile ~175
Save the signed-in user's synthesis profile — skin type, exposed-skin fraction, age and target IU — to their account, so the app and every later call use them. Requires OAuth (scope profile:write). Only these four values are writable; favourites, cities and history are not.
| Name | Type | Req | Description |
|---|---|---|---|
| age | — | — | Age in years, or null for the adult baseline |
| exposedSkinFraction | number | — | Skin exposed: 0.10 face+hands, 0.18 face+arms, 0.25 t-shirt+shorts (default), 0.40 swimsuit |
| skinType | integer | — | Fitzpatrick skin type 1 (very fair) to 6 (very dark); default 3 |
| targetIU | number | — | Vitamin D target per session in IU; default 1000 |
No output schema declared.
No examples provided.