The Cracks Index
REMOTE · API.FYNQO.APP · SCANNED SEP 20
Read-only MCP server for The Cracks Index: ranks countries and regions on social-safety strength
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2239 tokens (~149/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the The Cracks Index MCP server?
The Cracks Index is a hosted endpoint at https://api.fynqo.app/mcp/cracks/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.fynqo.app
claude mcp add --transport http johanvd75-byte-cracks-index 'https://api.fynqo.app/mcp/cracks/'
{
"mcpServers": {
"johanvd75-byte-cracks-index": {
"url": "https://api.fynqo.app/mcp/cracks/"
}
}
} {
"servers": {
"johanvd75-byte-cracks-index": {
"type": "http",
"url": "https://api.fynqo.app/mcp/cracks/"
}
}
} [mcp_servers.johanvd75-byte-cracks-index] url = "https://api.fynqo.app/mcp/cracks/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"johanvd75-byte-cracks-index": {
"type": "remote",
"url": "https://api.fynqo.app/mcp/cracks/",
"enabled": true
}
}
} openclaw mcp add johanvd75-byte-cracks-index --url 'https://api.fynqo.app/mcp/cracks/' --transport streamable-http
mcp_servers:
johanvd75-byte-cracks-index:
url: "https://api.fynqo.app/mcp/cracks/" {
"McpServers": {
"johanvd75-byte-cracks-index": {
"Transport": "http",
"Url": "https://api.fynqo.app/mcp/cracks/"
}
}
} assistant mcp add johanvd75-byte-cracks-index -t streamable-http -u 'https://api.fynqo.app/mcp/cracks/'
{
"mcpServers": {
"johanvd75-byte-cracks-index": {
"type": "http",
"url": "https://api.fynqo.app/mcp/cracks/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 15 Sept 26 +1
- DNSSEC: fail → pass ▲ security
- 9 Sept 26 0
- Server version: 1.29.1 → 1.30.0 functional
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- Server version: 1.29.0 → 1.29.1 functional
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- The server no longer declares the “experimental” capability functional
- 5 Aug 26 0
- DNSSEC: unverified → fail ▼ security
- Authorization: unverified → partial ▲ security
- TLS certificate: unverified → pass ▲ security
- HSTS header: unverified → pass ▲ security
- Transport: fail → pass ▲ security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://api.fynqo.app/mcp/cracks/
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.fynqo.app | CN=YE1,O=Let's Encrypt,C=US | 26 Aug 2026 | 24 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 527b8da4ca098cf96ccce7f1552c3e1c7ba |
| SANs: api.fynqo.app | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of api.fynqo.app. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| fynqo.app. | present | 2371 | 13 | Verified |
| api.fynqo.app. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' https://us.i.posthog.com https://us-assets.i.posthog.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://api.fynqo.app https://us.i.posthog.com; frame-ancestors 'none'; base-uri 'self'; object-src 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=(), payment=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.fynqo.app/mcp/cracks/ | Verified | 200 | |
| http (plaintext) | http://api.fynqo.app/mcp/cracks/ | HTTPS enforced | 301 | https://api.fynqo.app/mcp/cracks/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
area_statistics Where an area sits statistically ~162
Return where one area sits statistically within its own level. Places an area against its peer group (all areas at the same level in the latest snapshot): its percentile, the distance from its composite score to the level median, best and worst, and the handful of areas nearest to it by score. Useful for answering "is this area typical, or an outlier?". Read-only, area-level aggregates only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| area | string | yes | An ISO-3166 alpha-3 country code (e.g. 'NLD') or an area code of an EU NUTS-2 region or Dutch municipality (e.g. 'NL32', 'GM0363'). Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
compare_countries Compare countries ~84
Compare the composite score and rank of several countries. ``iso3_list`` is a list of ISO-3166 alpha-3 country codes.
| Name | Type | Req | Description |
|---|---|---|---|
| iso3_list | array | yes | List of ISO-3166 alpha-3 country codes to compare side by side, e.g. ['NLD', 'DEU', 'FRA']. Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
compare_gemeenten Compare Dutch municipalities on the social domain ~158
Compare the social-domain profile of several Dutch municipalities. Given two to six CBS GM-codes, returns a side-by-side comparison of their four v1 social-domain indicators plus composite score and rank. Useful for an agent answering "how does municipality A compare to B on the social domain". Read-only, no personal data. wmo_pressure and youth_care_load are context only — shown but never scored. CBS aggregates describe an area, not its quality. Netherlands-only.
| Name | Type | Req | Description |
|---|---|---|---|
| region_codes | string | yes | Two to six CBS GM-codes of Dutch municipalities, comma-separated, e.g. 'GM0363,GM0599,GM0518'. Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
country_detail Country detail ~52
Return one country's score, rank and per-indicator breakdown.
| Name | Type | Req | Description |
|---|---|---|---|
| iso3 | string | yes | ISO-3166 alpha-3 country code, e.g. 'NLD' for the Netherlands. Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
country_fix Country: highest-impact fix ~94
Return the single highest-impact improvement for one country. The Cracks Index names, alongside each country's score, the one change most associated with the fastest improvement, turning a ranking into a constructive, actionable signal. Read-only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| iso3 | string | yes | ISO-3166 alpha-3 country code, e.g. 'NLD' for the Netherlands. Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
gemeente_social_profile Dutch municipality: social-domain profile ~191
Return the Dutch social-domain profile for one municipality. Given a CBS GM-code, returns that municipality's four v1 social-domain indicators — social-assistance receipt, modelled homelessness, Wmo use and youth-care use — each with its raw value, source and whether it was measured or modelled. The composite score and rank are included for context, alongside the v0-equivalent score. Read-only, no personal data. wmo_pressure and youth_care_load are context only — never folded into the score. CBS aggregates describe an area, not its quality. Netherlands-only: the deeper municipal layer exists for Dutch municipalities.
| Name | Type | Req | Description |
|---|---|---|---|
| region_code | string | yes | CBS GM-code of a Dutch municipality, e.g. 'GM0363' (Amsterdam) or 'GM0599' (Rotterdam). Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
get_cracks_index Country ranking ~21
Return the full country ranking for the latest published snapshot.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_regions List regions and municipalities ~270
List sub-national areas in the Cracks Index, ranked within their level. The index covers sub-national areas as well as countries: EU regions (NUTS-2) and Dutch municipalities. This tool returns those areas with their composite score and rank. Parameters ---------- level : optional Filter by area level: ``nuts2`` (EU regions) or ``gemeente`` (Dutch municipalities). Omit to return all sub-national areas. country_iso3 : optional ISO-3166 alpha-3 country code to restrict the list to one country's areas (e.g. ``NLD``). limit : optional Maximum number of areas to return (1-1000, default 200). Read-only, no personal data. Ranks are within the area's own level.
| Name | Type | Req | Description |
|---|---|---|---|
| country_iso3 | – | – | Optional ISO-3166 alpha-3 country code to restrict the result to one country's areas, e.g. 'NLD'. |
| level | – | – | Filter by area level: 'nuts2' for EU NUTS-2 regions or 'municipality' for Dutch municipalities. Omit to include all levels. |
| limit | integer | – | Maximum number of areas to return (default 200). |
Structured output declared, but exposes no named fields.
No examples provided.
improvement_guidance Improvement guidance ~231
Return constructive improvement guidance for one area. Given an area identifier — an ISO-3166 alpha-3 country code, an EU NUTS-2 region code or a Dutch municipality CBS GM-code — returns that area's highest-impact improvement lever from the Cracks Index, together with Fynqo's approach to earlier, joined-up coordination and a link to the public "claim your score" page where an organisation can request a deeper local report. Read-only, no personal data. The lever is framed as "the change most associated with improvement". It is general, aggregated guidance, not policy, medical, legal or financial advice, and carries no promise of a guaranteed score gain (sales-engine §3.4, §5).
| Name | Type | Req | Description |
|---|---|---|---|
| area | string | yes | An ISO-3166 alpha-3 country code (e.g. 'NLD') or an area code of an EU NUTS-2 region or Dutch municipality (e.g. 'NL32', 'GM0363'). Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
indicator_correlations Indicator correlations ~146
Return pairwise correlations between the six indicators across areas. Computes the Pearson correlation coefficient between every pair of the six Cracks Index indicators, using each area's direction-corrected normalised score. Adds a short plain-language note naming the strongest relationship. A coefficient near +1 means areas that do well on one indicator tend to do well on the other; near -1 means the opposite. Read-only, area-level aggregates only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| level | string | – | Area level to correlate over: 'country', 'nuts2' (EU regions) or 'gemeente' (Dutch municipalities). Defaults to 'country'. |
Structured output declared, but exposes no named fields.
No examples provided.
indicator_ranking Rank areas by one indicator ~207
Rank all areas by a single chosen indicator. Returns every area's value for one indicator, ordered best-first by the direction-corrected ``normalized_score`` (a higher normalised score always means fewer cracks on that indicator). The raw value and unit are included so the figure can be quoted directly. Read-only, area-level aggregates only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| indicator_key | string | yes | One of the six Cracks Index indicators: 'problem_debt', 'eviction_rate', 'mh_treatment_gap', 'youth_care_unmet', 'food_insecurity' or 'material_deprivation'. See the 'methodology' tool for definition… |
| level | string | – | Area level to rank: 'country', 'nuts2' (EU regions) or 'gemeente' (Dutch municipalities). Defaults to 'country'. |
| limit | integer | – | Maximum number of areas to return (1-500, default 200). |
Structured output declared, but exposes no named fields.
No examples provided.
methodology Methodology and sources ~20
Return the index methodology: indicators, weights, direction, sources.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
region_detail Region detail ~146
Return one sub-national area: score, rank, indicator breakdown and fix. Given a region code (an EU NUTS-2 code or a Dutch municipality CBS GM-code), returns that area's composite score, its rank within its own level (regions rank against regions, municipalities against municipalities), the per-indicator breakdown and the single highest-impact improvement for the area. Read-only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| region_code | string | yes | Area code of an EU NUTS-2 region or Dutch municipality, e.g. 'NL32' (Noord-Holland) or 'GM0363' (Amsterdam). Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
score_trends Score history over time ~166
Return one area's composite-score history across every snapshot. Given an area identifier — an ISO-3166 alpha-3 country code, an EU NUTS-2 region code or a Dutch municipality CBS GM-code — walks every published Cracks Index snapshot and returns that area's composite score and rank at each point in time, plus the net change from the first to the most recent snapshot. Read-only, area-level aggregates only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| area | string | yes | An ISO-3166 alpha-3 country code (e.g. 'NLD') or an area code of an EU NUTS-2 region or Dutch municipality (e.g. 'NL32', 'GM0363'). Case-insensitive. |
Structured output declared, but exposes no named fields.
No examples provided.
top_movers Biggest risers and fallers ~170
Return the biggest risers and fallers between the two latest snapshots. Compares every area's composite score in the most recent snapshot against the snapshot before it and returns the areas that improved most (``improvers`` — score fell) and worsened most (``decliners`` — score rose). Needs at least two snapshots; returns an explanatory empty payload otherwise. Read-only, area-level aggregates only, no personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| level | string | – | Area level to rank movers within: 'country', 'nuts2' (EU regions) or 'gemeente' (Dutch municipalities). Defaults to 'country'. |
| limit | integer | – | How many risers and how many fallers to return each (1-50, default 5). |
Structured output declared, but exposes no named fields.
No examples provided.
What is the The Cracks Index MCP server?
The Cracks Index is an MCP server listed in the public MCP registry as io.github.johanvd75-byte/cracks-index. Read-only MCP server for The Cracks Index: ranks countries and regions on social-safety strength. This page covers its hosted endpoint (https://api.fynqo.app/mcp/cracks/).
Is the The Cracks Index MCP server safe to use?
The Cracks Index scores 89 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the The Cracks Index MCP server expose?
The Cracks Index exposes 15 tools: get_cracks_index, compare_countries, country_detail, country_fix, get_regions, and 10 more. Their descriptions and schemas cost roughly 2,118 tokens of context every time the server is loaded.
Does the The Cracks Index MCP server require authentication?
No. We connected to The Cracks Index without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the The Cracks Index MCP server still maintained?
The Cracks Index is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.