io.github.omarkeshk/council-ai
REMOTE · MCP.COUNCIL-AI.APP · SCANNED SEP 20
Multi-LLM council: 25+ frontier models in parallel, consensus scoring, verdict-first code review.
Available components
Recent critical change
Authorization (9 Aug 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (library_delete). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2128 tokens (~212/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety88
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "council_query" implies "send" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.omarkeshk/council-ai MCP server?
io.github.omarkeshk/council-ai is a hosted endpoint at https://mcp.council-ai.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.council-ai.app
claude mcp add --transport http omarkeshk-council-ai 'https://mcp.council-ai.app/mcp'
{
"mcpServers": {
"omarkeshk-council-ai": {
"url": "https://mcp.council-ai.app/mcp"
}
}
} {
"servers": {
"omarkeshk-council-ai": {
"type": "http",
"url": "https://mcp.council-ai.app/mcp"
}
}
} [mcp_servers.omarkeshk-council-ai] url = "https://mcp.council-ai.app/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"omarkeshk-council-ai": {
"type": "remote",
"url": "https://mcp.council-ai.app/mcp",
"enabled": true
}
}
} openclaw mcp add omarkeshk-council-ai --url 'https://mcp.council-ai.app/mcp' --transport streamable-http
mcp_servers:
omarkeshk-council-ai:
url: "https://mcp.council-ai.app/mcp" {
"McpServers": {
"omarkeshk-council-ai": {
"Transport": "http",
"Url": "https://mcp.council-ai.app/mcp"
}
}
} assistant mcp add omarkeshk-council-ai -t streamable-http -u 'https://mcp.council-ai.app/mcp'
{
"mcpServers": {
"omarkeshk-council-ai": {
"type": "http",
"url": "https://mcp.council-ai.app/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 19 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 18 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 17 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 16 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 15 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 14 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 13 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.council-ai.app/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.council-ai.app | CN=WE1,O=Google Trust Services,C=US | 7 Sept 2026 | 6 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 3b2709b9897565d70ee6502e779acc05 |
| SANs: mcp.council-ai.app | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.council-ai.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| council-ai.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.council-ai.app/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.council-ai.app/mcp | HTTPS enforced | 301 | https://mcp.council-ai.app/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
council_models Council Models ~61
List the AI models available to the current user. Returns ID, provider, tier, context window, and capability flags (web search, vision, streaming). Use the IDs returned here as the `models` array argument to council_query / council_query_with_rag.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| models | array | yes | Models available to this user, across all providers. |
| userPlan | string | yes | The user's current subscription plan. |
No examples provided.
council_query Council Query ~622
Send a prompt to a council of frontier AI models across 9 labs (Anthropic, OpenAI, Google, xAI, DeepSeek, Qwen, Mistral, Moonshot, z.ai). Returns each model's independent response plus a moderator-synthesized consensus answer with an agreement score and the key point of disagreement, when one exists. Use when a single-model answer might hallucinate or when verification across labs matters (research, contracts, architecture, legal, medical, code review). Adaptive-cost pattern: for a quick check, call with 2-3 models; if consensusScore comes back low (or keyDisagreement matters to the decision), escalate by re-running with more models — easy questions stay cheap, disputed ones get more compute. TIMEOUTS: a full council can run for minutes. If your MCP client has a fixed tool-call timeout, set async=true — you get a queryId back immediately and fetch the finished result with council_result. Call council_models first to pick specific model IDs, and council_usage to check remaining budget. Bills against the user's Council AI monthly budget.
| Name | Type | Req | Description |
|---|---|---|---|
| async | boolean | – | When true, return {queryId, status:"running"} immediately instead of waiting for the council. Fetch the finished result with council_result. Use whenever your MCP client enforces a fixed tool-call ti… |
| mode | string | – | Cross-model visibility. 'independent' (default): all models answer in parallel, blind to each other — best for unbiased comparison; the synthesis reconciles them. 'sequential': models answer one at a… |
| models | array | – | Model IDs to include (2-10). Defaults to a cross-lab flagship council. Use council_models to list available IDs. Example: ["claude-fable-5.1", "gpt-5.6-sol", "gemini-3.8-flash"] |
| prompt | string | yes | The question or task to send to the council. Include all needed context — every query is stateless. Example: "Is optimistic locking or a distributed lock the better fit for this checkout flow? [paste… |
| synthesisDirective | string | – | Optional instructions for the moderator that synthesizes the council's answers. The council models never see this — it only shapes the synthesis. Use for special modes, e.g. devil's advocate: "Argue… |
| synthesize | boolean | – | When true (default), include the moderator synthesis + consensus score. Set false to get only the raw per-model responses (faster, cheaper). |
| Name | Type | Req | Description |
|---|---|---|---|
| agreementType | – | – | Agreement classification from the moderator's analysis. Null when synthesize=false. |
| budgetPercentUsed | number|null | – | The user's monthly Council budget consumption after this query, as a percentage (0-100+). Use it to decide whether another query is affordable. Council never reports budget in dollar amounts — always… |
| consensusScore | number|null | – | Cross-model agreement score on the 0-100 scale. Null when synthesize=false; absent while an async query is still running. |
| consensusUnavailable | boolean | – | True when the moderator's agreement verdict could not be parsed, so this run has no consensus score at all. Do not substitute a number — report agreement as unknown. |
| droppedModelIds | array | – | Requested model IDs that were skipped (unknown or retired). Call council_models for current IDs. |
| durationMs | number | – | Wall-clock duration of the council run (fan-out + synthesis), in milliseconds. |
| errors | array | – | Per-model failures, if any. The synthesis covers the models that responded. |
| keyDisagreement | string|null | – | The main point the models disagreed on, when one was identified. Often more decision-relevant than the consensus itself — inspect it before acting on a low consensusScore. Null on high agreement or w… |
| modelMapping | object | – | Anonymous reviewer label (M1..Mn) to model name mapping used during synthesis. |
| perModelResponses | object | – | Each model's independent response, keyed by model name. Absent while an async query is still running. |
| queryId | string | – | Server-side ID of this council query. With async=true, pass it to council_result. |
| status | string | – | Only present on async queries: "running" means poll council_result with the queryId. |
| synthesis | string | – | Moderator-synthesized consensus answer across all models. Empty when synthesize=false; absent while an async query is still running. |
| synthesisError | string|null | – | Set when moderator synthesis failed and the response degraded to raw per-model output. |
| timedOutModelIds | array | – | Council members that failed by exceeding the per-model timeout. On a synchronous run (90s per model) this is recoverable: re-run the same query with async=true, which allows 300s. Slow reasoning mode… |
| totalTokens | object | – | Aggregate token usage for this query across the whole council. |
| wasSyncRun | boolean | – | True when this ran synchronously — the path with the tight per-model timeout. |
No examples provided.
council_query_with_rag Council Query with RAG ~295
Like council_query, but first retrieves the most relevant passages from the user's personal Council RAG library (uploaded PDFs, Word docs, contracts, research papers, codebases) and injects them into every model's prompt. Use when the question is about content the user has uploaded — contract review, research synthesis across a paper library, code review against an architecture doc, etc. Ultra-tier only.
| Name | Type | Req | Description |
|---|---|---|---|
| async | boolean | – | When true, retrieval runs immediately (sources are returned right away) but the council itself runs in the background — fetch the finished answer with council_result. Use when your MCP client enforce… |
| library_query | string | – | Optional retrieval-specific query. If omitted, the main prompt is used as the retrieval query. Set this when the user's prompt has unrelated framing but the concrete documents to retrieve are describ… |
| models | array | – | Model IDs to include. Defaults to the user's preferred council. |
| project_id | string | – | Restrict retrieval to a specific Council project workspace. |
| prompt | string | yes | The question or task to send to the council. Example: "Review this NDA draft against our standard playbook terms." |
| retrieval_limit | number | – | Number of chunks to retrieve. Default: 8. |
| synthesize | boolean | – | When true (default), include the moderator synthesis + consensus score. |
| Name | Type | Req | Description |
|---|---|---|---|
| consensusScore | number|null | – | Cross-model agreement score on the 0-100 scale. Null when synthesize=false; absent while an async query is still running. |
| perModelResponses | object | – | Each model's independent response, keyed by model name. Absent while an async query is still running. |
| queryId | string | – | Present on async queries — pass it to council_result. |
| ragSkipped | boolean | – | True when retrieval found nothing and the query fell through to a plain council_query. |
| retrievedChunks | array | yes | Library chunks that were injected into every model's prompt. Empty when the library had no relevant content. |
| status | string | – | Only present on async queries: "running" means poll council_result with the queryId. |
| synthesis | string | – | Moderator-synthesized consensus answer, grounded in the retrieved library chunks. Absent while an async query is still running. |
No examples provided.
council_result Council Result ~97
Fetch the result of a council_query started with async=true. Returns status "running" while the council is still working (wait 30-60 seconds and call again), the full synthesis + per-model responses once complete, or status "failed" with the error. Polling is free — the council run itself was already billed by council_query.
| Name | Type | Req | Description |
|---|---|---|---|
| queryId | string | yes | The queryId returned by council_query when called with async=true. |
| Name | Type | Req | Description |
|---|---|---|---|
| agreementType | – | – | Agreement classification from the moderator's analysis. |
| budgetPercentUsed | number|null | – | Monthly Council budget consumption, as a percentage (0-100+). Never dollars. |
| consensusScore | number|null | – | Cross-model agreement score, 0-100. Null when the query ran with synthesize=false. |
| droppedModelIds | array | – | Requested model IDs that were skipped (unknown or retired). |
| durationMs | number|null | – | Wall-clock duration of the council run, in milliseconds. |
| elapsedMs | number|null | – | Time since the query started, while running. |
| error | string | – | Failure reason when status is "failed". |
| errors | array | – | Per-model failures, if any. The synthesis covers the models that responded. |
| keyDisagreement | string|null | – | The main point the models disagreed on, when one was identified. |
| modelMapping | object | – | Anonymous label (M1..Mn) to model ID mapping. |
| perModelResponses | object | – | Each model's independent response, keyed by anonymous label (M1..Mn). |
| queryId | string | yes | The polled query ID. |
| status | string | yes | running → poll again in 30-60s. complete → full result below. failed → see error. |
| synthesis | string | – | Moderator-synthesized consensus answer. Present when status is "complete". |
| synthesisError | string|null | – | Set when moderator synthesis failed and the response degraded to raw per-model output. |
| totalTokens | object | – | Aggregate token usage across the whole council. |
No examples provided.
council_review Council Code Review ~362
Multi-model code review. Sends a unified diff (or code snippet) to multiple frontier AI models from different labs in parallel, each acting as an independent reviewer with an explicit verdict + findings contract. Returns a verdict-first synthesis: overall SHIP/NO-SHIP, consensus score, confirmed findings (flagged by 2+ models), then dissents (single-model findings with reasoning), then each reviewer's verdict. Diffs are capped at 14,000 characters — split larger changes by file or hunk and call once per chunk. Bills against the user's Council AI monthly budget like any council query.
| Name | Type | Req | Description |
|---|---|---|---|
| async | boolean | – | When true, return {queryId, status:"running"} immediately and fetch the finished review with council_result. Use when your MCP client enforces a fixed tool-call timeout, or with 4+ reviewers — async… |
| context | string | – | What the change is supposed to do: intent, constraints, related files or invariants reviewers cannot see from the diff alone. Improves signal, reduces false positives. |
| diff | string | yes | The unified diff (git diff output) or code snippet to review. Max 14,000 characters — if your diff is larger, split it by file or hunk and review each part separately. Example: the output of `git dif… |
| focus | string | – | Review focus: "bugs" (correctness), "security", "performance", "architecture", or "all" (default — full review, bugs prioritized). |
| models | array | – | Model IDs to include as reviewers (2-10). Defaults to the user's preferred council. Use council_models to list available IDs. |
| Name | Type | Req | Description |
|---|---|---|---|
| consensusScore | number|null | – | Cross-reviewer agreement score on the 0-100 scale. Absent while an async review is still running. |
| errors | array | – | Per-reviewer failures, if any. |
| focus | string | yes | The review focus this synthesis was produced under. |
| modelMapping | object | – | Anonymous reviewer label (M1..Mn) to model name mapping — how dissents are attributed. |
| perModelResponses | object | – | Each reviewer model's raw independent review, keyed by model name. Absent while an async review is still running. |
| queryId | string | – | Server-side ID of this review query. With async=true, pass it to council_result. |
| status | string | – | Only present on async reviews: "running" means poll council_result with the queryId. |
| synthesis | string | – | Verdict-first moderator synthesis: ## Council Verdict (SHIP/NO-SHIP), ## Confirmed Findings (2+ reviewers agree), ## Dissents, ## Reviewer Verdicts. Absent while an async review is still running. |
No examples provided.
council_usage Council Usage ~70
Return the user's current monthly cost-budget consumption (current spend, budget cap, percentage used, days until reset). Use to decide whether to warn the user before invoking another council_query, or to suggest using cheaper models. Per Council's rule: never show dollar amounts to the user in the response — use percentages.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| percentUsed | number | – | Percentage of the monthly budget consumed, 0-100+. |
| periodEndsAt | string | – | When the current monthly budget cycle resets, ISO 8601. |
| status | string | – | Budget status: ok, warning, or exceeded. |
No examples provided.
library_delete Library Delete ~122
Permanently delete a document from the user's Council RAG library — the record, every indexed chunk, AND the stored file are removed. This cannot be undone; re-adding the document requires uploading it again. Get document IDs from library_list. Use when the user asks to remove a document or when the 200-document library cap blocks an upload. Confirm with the user before deleting anything they did not explicitly name. No model call, no budget consumption.
| Name | Type | Req | Description |
|---|---|---|---|
| documentId | string | yes | ID of the document to delete, as returned by library_list or library_upload. |
| Name | Type | Req | Description |
|---|---|---|---|
| deletedChunks | number | yes | Number of indexed chunks that were deleted along with the document. |
| success | boolean | yes | True when the document and all its data were removed. |
No examples provided.
library_list Library List ~47
List the documents in the user's Council RAG library. Returns id, filename, source type, ingestion status, chunk count, and upload date for each document. No retrieval, no budget consumption.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| documents | array | yes | Every document in the user's library, newest first. Empty when the library has no documents. |
No examples provided.
library_search Library Search ~155
Semantic search over the user's Council RAG library (uploaded PDFs, Word docs, contracts, research papers, codebases). Returns top-K chunks with source filename and page number. No model call, no budget consumption. Use to find direct quotes, check what the library contains, or scope a follow-up council_query_with_rag call.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Number of chunks to return, 1-20. Default: 8. |
| project_id | string | – | Restrict retrieval to a specific Council project workspace ID. Omit to search the whole library. |
| query | string | yes | Semantic retrieval query — describe the content you want, not keywords. Example: "termination and notice-period clauses in the vendor agreement" |
| Name | Type | Req | Description |
|---|---|---|---|
| hits | array | yes | Top-K matching chunks, most relevant first. Empty when nothing matches. |
No examples provided.
library_upload Library Upload ~297
Upload a document into the user's Council RAG library so future council_query_with_rag and library_search calls can retrieve it. Accepts PDF, Word (docx), text, and markdown files as base64 — images are not supported. Max 10MB per file via MCP (the web library at https://council-ai.app/settings?tab=library takes up to 50MB); libraries hold up to 200 documents. Ingestion (chunking + embedding) runs in the background: the returned document starts in "pending" status — check library_list for it to reach "ready" before querying against it. No model call, no budget consumption.
| Name | Type | Req | Description |
|---|---|---|---|
| contentBase64 | string | yes | The file's raw bytes, base64-encoded (standard alphabet, no data: URI prefix). For a plain-text or markdown document, base64-encode the UTF-8 text. |
| filename | string | yes | Original filename including extension — the extension drives type detection. Example: "vendor-contract-2026.pdf". |
| mimeType | string | – | MIME type, e.g. "application/pdf". Optional — the backend verifies the real type from the file's magic bytes regardless. |
| projectId | string | – | Council project workspace to file the document under. Omit for the general library. |
| tags | array | – | Free-form tags to attach to the document, e.g. ["contracts", "2026"]. |
| Name | Type | Req | Description |
|---|---|---|---|
| document | object | yes | The created document record, in "pending" status until background ingestion completes. |
No examples provided.
What is the io.github.omarkeshk/council-ai MCP server?
io.github.omarkeshk/council-ai is an MCP server listed in the public MCP registry as io.github.omarkeshk/council-ai. Multi-LLM council: 25+ frontier models in parallel, consensus scoring, verdict-first code review. This page covers its hosted endpoint (https://mcp.council-ai.app/mcp).
Is the io.github.omarkeshk/council-ai MCP server safe to use?
io.github.omarkeshk/council-ai scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.omarkeshk/council-ai MCP server expose?
io.github.omarkeshk/council-ai exposes 10 tools: council_query, council_result, council_query_with_rag, council_review, library_search, and 5 more. Their descriptions and schemas cost roughly 2,128 tokens of context every time the server is loaded.
Does the io.github.omarkeshk/council-ai MCP server require authentication?
No. We connected to io.github.omarkeshk/council-ai without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.omarkeshk/council-ai MCP server still maintained?
io.github.omarkeshk/council-ai is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.