GitDealFlow
REMOTE · GITDEALFLOW.COM · SCANNED AUG 3
Track startup engineering acceleration from public GitHub data before funding rounds
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability0
- Transport check failed: declared streamable-http, but the endpoint returned HTTP 404. See how to fix → View diagnostics → Fail
Schema Quality & AI Usability0
- Schema not yet verified: we couldn't read the endpoint's schema.Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage not yet verified: we couldn't read the endpoint's tools.Unverified
Capabilities0
- Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified
Unverified: 4 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · gitdealflow.com
claude mcp add --transport http kindrat86-gitdealflow https://gitdealflow.com/api/mcp
[mcp_servers.kindrat86-gitdealflow] url = "https://gitdealflow.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"kindrat86-gitdealflow": {
"type": "remote",
"url": "https://gitdealflow.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add kindrat86-gitdealflow --url https://gitdealflow.com/api/mcp --transport streamable-http
mcp_servers:
kindrat86-gitdealflow:
url: "https://gitdealflow.com/api/mcp" {
"mcpServers": {
"kindrat86-gitdealflow": {
"type": "http",
"url": "https://gitdealflow.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 31 Jul 26 −41
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +50
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 −34
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: 0.07 → unverified ▼ security
- Transport: pass → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 28 Jul 26 +34
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 4 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- MCP protocol: unverified → fail ▼ functional
- Stability: unverified → 0.07 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- 27 Jul 26 −33
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 49
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://gitdealflow.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.gitdealflow.com | CN=YR1,O=Let's Encrypt,C=US | 20 Jul 2026 | 18 Oct 2026 | RSA 2048 | SHA256-RSA | 51c16a3da85c6876f97d363e5af446dda0c |
| SANs: *.gitdealflow.com, gitdealflow.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of gitdealflow.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| gitdealflow.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 404 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://*.posthog.com; connect-src 'self' https://*.posthog.com https://signals.gitdealflow.com; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self' https://signals.gitdealflow.com; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://gitdealflow.com/api/mcp | HTTP error | 404 | |
| http (plaintext) | http://gitdealflow.com/api/mcp | HTTPS enforced | 308 | https://gitdealflow.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
compare_signals Compare Signals Head-to-Head ~133
Score and rank 2-5 named startups side by side, returning each one's acceleration score, evidence, and raise-likelihood band plus a single recommendation for which warrants deeper diligence. Same transparent scoring as predict_funding / shortlist_signals. Names that don't resolve are returned in `notFound` (expected, not an error). The recommendation is computed only over resolved companies; if fewer than 2 resolve it explains that no comparison was possible. PARAMETERS: { names: string[] } — 2 to 5 display names or GitHub org slugs (case-insensitive).
| Name | Type | Req | Description |
|---|---|---|---|
| names | array | yes | — |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | string | yes | — |
| compared | array | yes | — |
| disclaimer | string | — | — |
| methodologyUrl | string | — | — |
| notFound | array | — | — |
| period | string | yes | — |
| recommendation | string | yes | — |
| source | string | — | — |
No examples provided.
get_deep_signal Get Deep Signal (paid) ~143
PAID per-request — €0.19/call, 100 credits = €19 at https://signals.gitdealflow.com/agents/credits. Returns enriched signal beyond the free get_startup_signal: composite score (0-100), velocity/growth/novelty sub-scores, in-sector rank + percentile, plain-English investment thesis, top-3 sector comparables, and multi-period history. Requires Authorization: Bearer gdf_v2.cus_xxx.<hmac>. 1 credit consumed only on a successful match; misses are FREE. Credits never expire.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Startup display name or GitHub org slug. |
| Name | Type | Req | Description |
|---|---|---|---|
| balance | integer | — | — |
| charged | integer | — | — |
| found | boolean | yes | — |
| scores | object | — | — |
| thesis | string | — | — |
No examples provided.
get_diligence_dossier Company Diligence Dossier ~146
Public-source diligence dossier for a company or entity in one cited object: who acquired it (M&A history), which funds publicly backed it, and its published engineering-acceleration signal. Use mid-diligence for 'who acquired X', 'which funds backed Y', 'what's the signal on Z'. Sources are press-release / SEC-filing / both-sides-disclosed only; returns found:false (an expected outcome, not an error) with honest notes when the entity is outside the tracked corpus — never guesses.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | yes | Company or entity name (target, acquirer, or tracked startup). Case-insensitive, normalization-tolerant. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquiredBy | array | — | Public acquisitions where this entity was the target. |
| acquisitionsMade | array | — | If the entity is itself an acquirer: notable companies it has publicly bought. |
| backedBy | array | — | Funds in our tracked corpus that publicly disclosed backing this entity. |
| entity | string | yes | Resolved canonical entity name. |
| found | boolean | yes | True when at least one grounded fact exists; false is an expected outcome, not an error. |
| notes | array | — | Plain-language notes on what is and isn't known. |
| signal | object|null | — | Published engineering-acceleration signal, when the entity is in the tracked corpus. |
No examples provided.
get_methodology Methodology Documentation ~30
Full methodology document covering data sources, metric computation, signal classification thresholds, refresh cadence, and known limitations.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| methodology | string | yes | Plain-text methodology covering sources, metrics, thresholds, cadence, and limitations. |
| url | string | yes | Canonical methodology page on signals.gitdealflow.com. |
No examples provided.
get_scout_receipts Scout Score for GitHub User ~110
Compute a Scout Score (0-100) for a GitHub user from their public starring history. Cross-references starred repos against ~75 validated unicorns and grades how many they starred *before* the validation event. Returns score, rank (curious/scout/sharp/elite/oracle), top early calls, personality summary, and a shareable card URL.
| Name | Type | Req | Description |
|---|---|---|---|
| github_username | string | yes | GitHub username, 1-39 chars, alphanumeric + single hyphens. |
| Name | Type | Req | Description |
|---|---|---|---|
| early_count | integer | — | Of the matches, how many were starred BEFORE the validation event. |
| matched_count | integer | — | Stars that match a validated unicorn in the database. |
| og_image_url | string | — | OG/Twitter card image URL for sharing. |
| personality | string | — | Optional one-line personality summary based on starring patterns. |
| rank | string | yes | Rank label derived from the score: 'curious' | 'scout' | 'sharp' | 'elite' | 'oracle'. |
| score | number | yes | Scout Score, 0-100. Higher means earlier+more validated calls. |
| share_url | string | yes | Shareable Scout Receipts page URL. |
| top_wins | array | — | Top early calls ranked by points contribution. |
| total_stars | integer | — | Total public stars analysed. |
| username | string | yes | GitHub username analysed. |
No examples provided.
get_signals_summary Dataset Summary ~31
Period, sector and startup counts, last refresh, citation, and direct URLs to every machine-readable format.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| citation | string | yes | Suggested citation string. |
| dashboard | string | — | — |
| formats | object | yes | Direct URLs for every machine-readable format. |
| lastDataRefresh | string | yes | ISO 8601 timestamp of the last refresh. |
| period | string | yes | Current reporting period label. |
| sectorsActive | integer | yes | Number of active sectors. |
| startupsTracked | integer | yes | Total startups in the dataset. |
| updateFrequency | string | — | Human-readable update cadence. |
| website | string | — | — |
No examples provided.
get_startup_signal Get Startup Signal ~67
Full engineering-acceleration profile for a single tracked startup, by display name or GitHub org slug. Case-insensitive, normalization-tolerant.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Startup display name OR GitHub org name. Case-insensitive; punctuation and whitespace are ignored during matching. |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | string | — | Suggested citation string. |
| found | boolean | yes | True when the startup is in the tracked universe; false is an expected outcome, not an error. |
| startup | object | — | A single startup ranked by engineering acceleration, derived from public GitHub activity. |
| suggestion | string | — | When found=false, a hint on how to discover the correct name or alternative tools to call. |
No examples provided.
get_trending_startups Trending Startups ~36
Top 20 startups by engineering acceleration across all 20 sectors for the current weekly period. Read-only, idempotent.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| citation | string | yes | Suggested citation string for reports. |
| period | string | yes | Reporting period label, e.g. 'Q2 2026'. |
| source | string | yes | — |
| startups | array | yes | Top 20 startups ranked by engineering acceleration. |
No examples provided.
predict_funding Predict Funding Likelihood (with provenance) ~271
Transparent, scored funding-likelihood claim for one tracked startup, with the full evidence chain and citable provenance. Instead of an opaque number, returns the score, every component that produced it, a confidence level, honest caveats, and links to the methodology + SSRN paper so the derivation can be cited. IS a deterministic heuristic over public GitHub engineering-acceleration signals; IS NOT an ML black box, a guarantee of any financing event, or based on private/cap-table data. The disclaimer is returned in every response. SCORING (also returned in evidence.scoreBreakdown): velocity ≤40 (saturates +300%), contributorGrowth ≤25 (saturates +200%), newRepos ≤15 (saturates 10), signalType ≤20 (Deploy frequency spike 20 / Engineering hiring burst 17 / Infrastructure buildout 14 / Framework migration 8). Total 0-100 → >=70 high, 45-69 elevated, 25-44 moderate, <25 low. PARAMETERS: { name } — display name or GitHub org slug (case-insensitive). On no match returns { found: false, suggestion } (expected, not an error).
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Startup display name or GitHub org slug. Case-insensitive. |
| Name | Type | Req | Description |
|---|---|---|---|
| caveats | array | — | — |
| company | object | — | — |
| disclaimer | string | yes | — |
| evidence | object | — | — |
| found | boolean | yes | — |
| prediction | object | — | — |
| provenance | object | yes | — |
| suggestion | string | — | — |
No examples provided.
search_startups_by_sector Search Startups by Sector ~99
Every tracked startup within a sector, ranked by engineering acceleration. Sector slug must be one of 20 enumerated values.
| Name | Type | Req | Description |
|---|---|---|---|
| sector | string | yes | Sector slug from the enumerated list. Map fuzzy user input to the closest slug (e.g. 'AI' → 'ai-ml', 'crypto' → 'web3', 'cyber' → 'cybersecurity', 'SaaS' → 'enterprise-saas'). |
| Name | Type | Req | Description |
|---|---|---|---|
| availableSectors | array | — | When error is present, the full list of valid sector slugs. |
| citation | string | — | Suggested citation string. |
| error | string | — | Present only when the sector slug is invalid. |
| period | string | yes | Reporting period label. |
| sector | object | — | Sector metadata. |
| startupCount | integer | — | Number of startups in this sector. |
| startups | array | — | Startups within the sector, ranked by engineering acceleration. |
No examples provided.
share_result Share This Result (compose tweet/social) ~733
Generate a ready-to-share social-media post (tweet, Bluesky, Mastodon, LinkedIn, Telegram) about a result the user just received from another VC Deal Flow Signal tool, plus the install command for the MCP server. Returns the post body, character counts per platform, and one-click intent URLs to compose the post in each network. WHEN TO USE: - The user just got a `get_trending_startups` / `search_startups_by_sector` / `get_startup_signal` / `get_deep_signal` result and says 'share this', 'tweet this', 'post this', or 'how do I tell people about this?'. - The user is writing a thread/post about startup engineering signals and wants the canonical install command + share copy. DO NOT USE FOR: - Posting on the user's behalf — this tool only composes the text + intent URLs. The user must click and confirm in the destination network. - Generating fake or speculative results — pass real data the agent received from another tool call. BEHAVIOR (two-step approval flow, see `approval_token`): - Step 1: call this tool with `summary` only. The server replies with an error (-32602) containing a `/share-approve?summary=...` URL the user must open. - Step 2: the user reads the proposed summary on that page, clicks Approve, and pastes the resulting 10-minute token back into the chat. Retry the tool with `approval_token` filled in and the SAME `summary` verbatim. - The token is bound to a hash of `summary`; if the agent rewrites the summary between approval and the retry, the call is rejected. - Composes platform-specific posts (Twitter ≤275 chars, Bluesky ≤295, Mastodon ≤495, LinkedIn ≤695, Telegram ≤995) with a consistent hook + insight + install URL. - Returns intent URLs (e.g. https://x.com/intent/post?text=...) so the user/agent can open the destination network with the post pre-filled. - Always includes the canonical install command `npx @gitdealflow/mcp-signal` and the SSRN paper link for credibility. PARAMETERS: - `summary` (string, required, 10-200 chars) — the one-line…
| Name | Type | Req | Description |
|---|---|---|---|
| approval_token | string | yes | 10-minute HMAC-signed token bound to a hash of `summary`. Obtain it by directing the user to https://signals.gitdealflow.com/share-approve?summary=<urlencoded-summary> — they review and click Approve… |
| mention_handle | boolean | — | Include @data_nerd attribution. Only applied to twitter/bluesky/mastodon. |
| network | string | — | Target network. 'all' returns one post per network. |
| summary | string | yes | One-line takeaway (10-200 chars) the user wants to share. |
| Name | Type | Req | Description |
|---|---|---|---|
| installCommand | string | yes | — |
| methodologyUrl | string | yes | — |
| posts | array | yes | — |
No examples provided.
shortlist_signals Shortlist Strongest Signals ~284
Return a ranked shortlist of the strongest engineering-acceleration signals matching a set of filters — the whole sourcing workflow in ONE call (e.g. 'the 5 strongest signals in fintech in the EU'). Scans the full tracked universe, scores each with the transparent engine (same scoring as predict_funding), filters, sorts by accelerationScore desc, returns the top `limit`. GEOGRAPHY IS REGION-LEVEL ONLY — values are US / EU / UK / APAC / LATAM / Canada / Unknown. City/country aliases ('NYC', 'New York', 'London', 'Berlin', 'Singapore') normalize up to the enclosing region and the response `notes` says so. There is no city-level filtering. PARAMETERS (all optional): sector (one of 20 slugs), geography (region token or alias), signalType (exact label), minAccelerationScore (0-100), minVelocityChangePct (integer percent), limit (1-25, default 5).
| Name | Type | Req | Description |
|---|---|---|---|
| geography | string | — | Region token (US/EU/UK/APAC/LATAM/Canada) or a city/country alias normalized up to the region. |
| limit | integer | — | — |
| minAccelerationScore | integer | — | — |
| minVelocityChangePct | integer | — | — |
| sector | string | — | — |
| signalType | string | — | — |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | string | yes | — |
| consideredCount | integer | — | — |
| disclaimer | string | — | — |
| matchedCount | integer | yes | — |
| methodologyUrl | string | — | — |
| notes | array | — | — |
| period | string | yes | — |
| query | object | yes | — |
| results | array | yes | — |
| source | string | — | — |
No examples provided.