# Blackbook Protocol Advisor (remote · theblackbook.pro)

Purchaser-gated MCP for Vault, HMRC TRS, 95/5 equity, and Companies House PSC.

- Trust score: 82/100 (high trust)
- Change this week: +2
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-01

## Components

- remote · `theblackbook.pro`: 82/100 (this document), [markdown](https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook.md), [page](https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook)

## Channel facts

- Endpoint: `https://theblackbook.pro`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.3`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-01.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (confirm_and_submit).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 83/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 4571 tokens (~147/item across 31 items; 25 tools + 6 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 25 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 27 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Blackbook Protocol Advisor MCP server?

Blackbook Protocol Advisor is a hosted endpoint at https://theblackbook.pro/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http koynlabs-blackbook-advisor 'https://theblackbook.pro/'
```

### Cursor

```json
{
  "mcpServers": {
    "koynlabs-blackbook-advisor": {
      "url": "https://theblackbook.pro/"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "koynlabs-blackbook-advisor": {
      "type": "http",
      "url": "https://theblackbook.pro/"
    }
  }
}
```

### Codex

```toml
[mcp_servers.koynlabs-blackbook-advisor]
url = "https://theblackbook.pro/"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "koynlabs-blackbook-advisor": {
      "type": "remote",
      "url": "https://theblackbook.pro/",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add koynlabs-blackbook-advisor --url 'https://theblackbook.pro/' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  koynlabs-blackbook-advisor:
    url: "https://theblackbook.pro/"
```

### Netclaw

```json
{
  "McpServers": {
    "koynlabs-blackbook-advisor": {
      "Transport": "http",
      "Url": "https://theblackbook.pro/"
    }
  }
}
```

### Vellum

```bash
assistant mcp add koynlabs-blackbook-advisor -t streamable-http -u 'https://theblackbook.pro/'
```

### Other

```json
{
  "mcpServers": {
    "koynlabs-blackbook-advisor": {
      "type": "http",
      "url": "https://theblackbook.pro/"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 82, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 82, +1)

No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-25 (score 81, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-23 (score 80, +1)

No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-21 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 78, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 77, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (25)

### `search_book` (~91 tokens)

Search Protocol book

REQUIRED before substantive Protocol answers. Search approved Blackbook Protocol passages and return cited excerpts. Prefer Protocol vocabulary from hits over generic UK legal advice. Returns ranked results plus the educational boundary.

Input parameters:

- `limit` (integer): Maximum number of cited excerpts to return. Default 5. Example: 5
- `query` (string, required): Search text using Protocol terms. Example: 95/5 equity split Vault PSC trustees

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `results` (array): Ranked corpus hits with citation and excerpt

### `get_module_playbook` (~91 tokens)

Get module playbook

REQUIRED when coaching setup. Return the ordered Protocol checklist for a module. For 95/5 / share transfer into the Trust use equity_95_5 (not a freestyle solicitor checklist). Modules: vault, trs, equity_95_5, psc, banking, ip, philosophy, legacy, property.

Input parameters:

- `module` (string, required): Protocol module id. Example: equity_95_5

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `id` (string): Module id that was requested
- `steps` (array): Ordered coaching steps
- `summary` (string): One-paragraph module purpose
- `title` (string): Human title for the module

### `list_skills` (~71 tokens)

List workflow skills

List Protocol Architect workflow skills (Vault, TRS, 95/5, PSC, portal co-pilot). Call when the Owner asks how to set something up; then get_skill for the matching workflow.

Input parameters:

- `query` (string): Optional text to filter skill names or descriptions. Example: psc

Output parameters:

- `skills` (array): Discoverable skills with name, description, and skill:// URI

### `get_skill` (~79 tokens)

Get workflow skill

Load a Protocol workflow skill as markdown. Names: establish-vault-trust, register-trust-trs, implement-95-5-equity-split, update-psc-companies-house, run-portal-copilot.

Input parameters:

- `name` (string, required): Skill name from list_skills. Example: implement-95-5-equity-split

Output parameters:

- `description` (string): Skill summary from frontmatter
- `markdown` (string): Full SKILL.md contents
- `name` (string): Skill name
- `uri` (string): skill:// URI for this workflow

### `list_modules` (~36 tokens)

List Protocol modules

List available Protocol advisor modules in coaching order.

Input parameters:

- `query` (string): Optional text to filter module id or title. Example: vault

Output parameters:

- `modules` (array): Protocol modules with id and title

### `get_hmrc_guidance` (~78 tokens)

Get HMRC guidance

Retrieve approved GOV.UK/HMRC trust and inheritance-tax guidance by topic. Returns a title, official URL, and short summary. Not a live scrape of GOV.UK.

Input parameters:

- `jurisdiction` (string): Jurisdiction filter. Example: UK
- `topic` (string, required): Guidance topic. Example: trs or inheritance tax

Output parameters:

- `guidance` (object): Approved GOV.UK title, URL, and summary
- `jurisdiction` (string): Jurisdiction used
- `topic` (string): Topic that was requested

### `get_companies_house_guidance` (~55 tokens)

Get Companies House guidance

Retrieve approved Companies House / PSC / WebFiling guidance. PSC filings name individuals (trustees), never the Trust itself.

Input parameters:

- `topic` (string, required): Guidance topic. Example: psc or webfiling

Output parameters:

- `guidance` (object): Approved GOV.UK title, URL, and summary
- `topic` (string): Topic that was requested

### `run_trust_intake` (~294 tokens)

Run trust intake

Validate a structured trust setup intake and return missing facts, Protocol warnings, and next modules. Call before drafting forms or opening portals.

Input parameters:

- `assetValue` (string): Optional indicative value of those assets. Example: 100000 GBP
- `assets` (string, required): Assets intended for the Trust. Example: 95 ordinary shares in Example Ltd
- `companyName` (string): Engine (limited company) name. Example: Example Ltd
- `companyNumber` (string): Companies House number. Example: 12345678
- `deadlines` (string): Known filing or lender deadlines. Example: TRS within 90 days of the deed
- `existingArrangements` (string): Existing companies, trusts, or wills that affect setup. Example: Sole shareholder of Example Ltd
- `jurisdiction` (string, required): Governing law of the trust. Example: England and Wales
- `objective` (string, required): Why the Owner is setting up the Vault. Example: Family wealth planning
- `parties` (string, required): Trustees and beneficiaries in Protocol terms. Example: Alex Example (Lead Trustee); Class: children
- `questions` (string): Owner questions the Architect should address. Example: Can the Trust be named as PSC?
- `settlor` (string, required): Person settling the Trust. Example: Alex Example
- `trustName` (string): Vault / settlement name. Example: Example Family Settlement 2026

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `missing` (array): Required fields that are still blank
- `nextModules` (array): Suggested next Protocol modules
- `ok` (boolean): True when required intake fields are present
- `warnings` (array): Protocol cautions such as settlor-as-beneficiary or 90/5

### `draft_form_answers` (~78 tokens)

Draft form answers

Draft preparation notes for TRS, IHT100, IHT400, and related professional-review questions from a completed intake. Label as a Protocol guide for solicitor execution.

Input parameters:

- `formFamily` (string): Form family to draft against. Example: TRS
- `intake` (object, required): Structured Owner facts for Protocol coaching and portal field mapping

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `prepare_portal_fill` (~98 tokens)

Prepare portal fill

Map intake facts to a fill_fields payload for TRS or Companies House PSC. Secrets (auth code) are listed but never filled. Call after Owner login; align labels with list_fillable_fields. Never maps the Trust as a PSC organisation.

Input parameters:

- `formFamily` (string): Portal family to map. Example: COMPANIES_HOUSE_PSC
- `intake` (object, required): Structured Owner facts for Protocol coaching and portal field mapping

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `generate_review_bundle` (~60 tokens)

Generate review bundle

Generate a cited professional-review bundle from a completed intake for the Owner to take to a solicitor or CTA.

Input parameters:

- `format` (string): Bundle format. Example: markdown
- `intake` (object, required): Structured Owner facts for Protocol coaching and portal field mapping

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `list_risk_flags` (~55 tokens)

List risk flags

Return legal, tax, and practical red flags detected from customer facts (settlor-as-beneficiary, lender consent, offshore, time pressure).

Input parameters:

- `intake` (object, required): Structured Owner facts for Protocol coaching and portal field mapping

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `flags` (array): Detected flags with code, label, and detail

### `list_implementation_modes` (~60 tokens)

List implementation modes

List Owner choices: self_serve (own browser + guidance) vs assisted (Browserbase live view + optional fill). Ask before starting co-pilot.

Input parameters:

- `preferred` (string): Optional Owner preference if already stated. Example: self_serve

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `defaultAsk` (string): Question to ask the Owner before choosing a path
- `modes` (array): self_serve and assisted options with recommended tools

### `get_self_serve_portal` (~76 tokens)

Get self-serve portal

Self-serve path: return the official portal URL plus Protocol checklist for the Owner’s own browser. Present portalUrl as a clickable markdown link (MCP cannot launch local browsers). Do not start Browserbase.

Input parameters:

- `portalId` (string, required): Allowlisted official portal. Example: trs for HMRC Trust Registration Service

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement
- `mode` (string): Always self_serve
- `openInstruction` (string): How the client should present portalUrl
- `portalId` (string): Portal that was requested
- `portalUrl` (string): Official HTTPS URL to present as a markdown link

### `start_browser_session` (~78 tokens)

Start browser session

ASSISTED mode only. Start a fresh ephemeral Browserbase (or mock) co-pilot session. Returns liveViewUrl — no purchaser email. If Owner prefers their own browser, use get_self_serve_portal instead.

Input parameters:

- `reason` (string): Why assisted mode is needed. Example: Owner asked for live TRS fill help

Output parameters:

- `id` (string): Session id for later portal tools
- `liveViewUrl` (string): URL the Owner opens to see and control the remote browser
- `mode` (string): mock or browserbase
- `portalAuthenticated` (boolean): False on a fresh session until Owner signs in via live view

### `open_portal` (~106 tokens)

Open official portal

Navigate the assisted session to an allowlisted portal: trs, trs_manage, companies_house_webfiling, or companies_house_psc.

Input parameters:

- `portalId` (string, required): Allowlisted official portal. Example: trs for HMRC Trust Registration Service
- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `explain_current_screen` (~82 tokens)

Explain current screen

Summarise the current portal page: URL, text excerpt, fillable fields, Protocol hint, signedInLikely.

Input parameters:

- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `list_fillable_fields` (~84 tokens)

List fillable fields

Inventory visible non-secret form controls (label/name/type) on the current portal page. Use to align prepare_portal_fill keys.

Input parameters:

- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `fill_fields` (~114 tokens)

Fill non-secret fields

Fill non-secret form fields (label/placeholder/name). Never passwords, OTPs, or Companies House auth codes.

Input parameters:

- `fields` (object, required): Map of visible field label, placeholder, or name to a non-secret value. Example: {"Trust name":"Example Family Settlement 2026"}
- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `request_user_action` (~106 tokens)

Request owner action

Pause for Owner login, CAPTCHA, 2FA, or review in the Browserbase live view. Never ask the Owner to paste passwords into chat.

Input parameters:

- `action` (string, required): Why the Owner must use the live view. Example: login
- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `wait_for_user_ready` (~136 tokens)

Wait for owner ready

After request_user_action(login|2fa), poll until the page leaves the sign-in surface (or timeout). Then continue fill.

Input parameters:

- `pollMs` (integer): Polling interval in milliseconds. Default 3000. Example: 3000
- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789
- `timeoutMs` (integer): How long to wait for sign-in in milliseconds. Default 90000. Example: 90000

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `prepare_submit_confirmation` (~83 tokens)

Prepare submit confirmation

Create a one-time confirmation token required before confirm_and_submit. Show the token to the human Owner; do not submit without it.

Input parameters:

- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `confirm_and_submit` (~114 tokens)

Confirm and submit

Submit the current portal form only after the human provides a valid one-time confirmationToken from prepare_submit_confirmation. This can file on a government portal.

Input parameters:

- `confirmationToken` (string, required): One-time token the Owner typed from prepare_submit_confirmation. Example: 7K2Q9M
- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `end_browser_session` (~82 tokens)

End browser session

Tear down the assisted browser session. No credentials are persisted. Safe to call more than once for the same id after expiry.

Input parameters:

- `sessionId` (string, required): Ephemeral co-pilot session id returned by start_browser_session. Example: 8f3c2a1b-4d5e-6789-abcd-ef0123456789

Output parameters:

- `boundary` (string): Educational / non-advice boundary when the tool includes one

### `get_legal_boundary` (~49 tokens)

Get legal boundary

Return the mandatory educational / non-advice boundary statement. Call when the Owner asks if this is legal advice.

Input parameters:

- `audience` (string): Who will read the boundary line. Example: owner

Output parameters:

- `boundary` (string): Mandatory educational / non-advice boundary statement

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook#diagnostics

## Score history

- 2026-10-01: 82
- 2026-09-30: 82
- 2026-09-29: 82
- 2026-09-28: 82
- 2026-09-27: 82
- 2026-09-26: 81
- 2026-09-25: 81
- 2026-09-24: 80
- 2026-09-23: 80
- 2026-09-22: 79
- 2026-09-21: 79
- 2026-09-20: 78
- 2026-09-19: 78
- 2026-09-18: 78
- 2026-09-17: 77
- 2026-09-16: 77
- 2026-09-15: 76
- 2026-09-14: 76
- 2026-09-13: 75
- 2026-09-12: 75
- 2026-09-11: 74
- 2026-09-10: 74
- 2026-09-09: 73
- 2026-09-08: 73
- 2026-09-07: 72
- 2026-09-06: 72
- 2026-09-05: 71
- 2026-09-04: 71
- 2026-09-03: 71
- 2026-09-02: 70

## Common questions

### What is the Blackbook Protocol Advisor MCP server?

Blackbook Protocol Advisor is an MCP server listed in the public MCP registry as io.github.koynlabs/blackbook-advisor. Purchaser-gated MCP for Vault, HMRC TRS, 95/5 equity, and Companies House PSC. This page covers its hosted endpoint (https://theblackbook.pro).

### Is the Blackbook Protocol Advisor MCP server safe to use?

Blackbook Protocol Advisor scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Blackbook Protocol Advisor MCP server expose?

Blackbook Protocol Advisor exposes 25 tools: search_book, get_module_playbook, list_skills, get_skill, list_modules, and 20 more. Their descriptions and schemas cost roughly 2,256 tokens of context every time the server is loaded.

### Does the Blackbook Protocol Advisor MCP server require authentication?

No. We connected to Blackbook Protocol Advisor without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Blackbook Protocol Advisor MCP server still maintained?

Blackbook Protocol Advisor is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://theblackbook.pro/
- Repository: https://github.com/koynlabs/mcp-blackbook
- Website: https://theblackbook.pro/
- Changelog RSS feed: https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook.xml
- Changelog JSON feed: https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook.json
- HTML version of this page: https://verifymcp.io/servers/koynlabs-blackbook-advisor/theblackbook
