io.github.OV3RK177/kairos-signal
REMOTE · KAIROSSIGNAL.COM · SCANNED SEP 28
Provenance-first DePIN telemetry: 331 live networks + 129 Bittensor subnets, 10,508 series.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability67
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1633 tokens (~148/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management86
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 1 breaking changes, 0 auth/transport breaks, 0 additions. See how to fix → Fail
Tool Coverage93
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 79% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.OV3RK177/kairos-signal MCP server?
io.github.OV3RK177/kairos-signal is a hosted endpoint at https://kairossignal.com/mcp/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · kairossignal.com
claude mcp add --transport http ov3rk177-kairos-signal 'https://kairossignal.com/mcp/'
{
"mcpServers": {
"ov3rk177-kairos-signal": {
"url": "https://kairossignal.com/mcp/"
}
}
} {
"servers": {
"ov3rk177-kairos-signal": {
"type": "http",
"url": "https://kairossignal.com/mcp/"
}
}
} [mcp_servers.ov3rk177-kairos-signal] url = "https://kairossignal.com/mcp/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ov3rk177-kairos-signal": {
"type": "remote",
"url": "https://kairossignal.com/mcp/",
"enabled": true
}
}
} openclaw mcp add ov3rk177-kairos-signal --url 'https://kairossignal.com/mcp/' --transport streamable-http
mcp_servers:
ov3rk177-kairos-signal:
url: "https://kairossignal.com/mcp/" {
"McpServers": {
"ov3rk177-kairos-signal": {
"Transport": "http",
"Url": "https://kairossignal.com/mcp/"
}
}
} assistant mcp add ov3rk177-kairos-signal -t streamable-http -u 'https://kairossignal.com/mcp/'
{
"mcpServers": {
"ov3rk177-kairos-signal": {
"type": "http",
"url": "https://kairossignal.com/mcp/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “register_agent” rewrote its description, which is the text the model reads security
- 26 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “register_agent” rewrote its description, which is the text the model reads security
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 23 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 22 Sept 26 +4
- HTTPS: fail → pass ▲ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “register_agent” rewrote its description, which is the text the model reads security
- 21 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://kairossignal.com/mcp/
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=kairossignal.com | CN=YE1,O=Let's Encrypt,C=US | 16 Sept 2026 | 15 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6c98679358e732d548881a5825fb1544d12 |
| SANs: *.kairossignal.com, kairossignal.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of kairossignal.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| kairossignal.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://kairossignal.com/mcp/ | Verified | 200 | |
| http (plaintext) | http://kairossignal.com/mcp/ | HTTPS enforced | 308 | https://kairossignal.com/mcp/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_balance ~33
Check your remaining credit balance. Use after purchases to see remaining credits.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | Your API key |
No output schema declared.
No examples provided.
fetch_dataset ~115
Query records from a dataset with limit/offset. Free tier: 10 records per query. For depin_onchain, raw archived observations, including rejected rows, are retained. observation_quality reports limited PKT airdrop checks; not_checked means not validated. This read-time annotation is not covered by original proof hashes.
| Name | Type | Req | Description |
|---|---|---|---|
| dataset | string | yes | Dataset name (e.g., depin_onchain) |
| limit | integer | – | Max records (max 10 for free tier) |
| offset | integer | – | Record offset |
No output schema declared.
No examples provided.
get_data_dictionary ~76
ONBOARDING SPEC: freshness, history depth, coverage and endpoints per feed (depin_onchain, depin_daily, health_profiles, signal_ledger, market_ticks, zk_footprints). Machine-legible; answers 'how stale is this and how far back does it go' for every feed. Free, no key.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_derivation_ledger ~105
DERIVATION TRUTH: raw upstream payloads, SHA-256-pinned, with the exact collector code hash for each fetch. Replay any published value: fetch the verify_url yourself, run the pinned code, compare. Answers 'a hash proves a footprint, not the derivation' — divergence from origin is mechanically detectable. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | – | Optional: filter to one symbol (e.g. AKT). Omit for the coverage list. |
No output schema declared.
No examples provided.
get_stats ~15
Get aggregate statistics from the databases
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_datasets ~40
List all available datasets with record counts. Free to browse — market ticks, DePIN network stats, technical indicators, US county atlas, ZK footprints.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_products ~113
Browse purchasable products with prices in credits ($1 = 1 credit). DePIN supply-telemetry, provenance, derivation-replay, history, grades and the intel bundle are BUYABLE NOW from $0.49. Signal-feed tiers, DAG-manifold tiers and mcp_unlimited are priced but NOT yet purchasable: their entitlement is not wired into the serving API, so purchase_data refuses them with 503 not_yet_deliverable rather than charging you for nothing. Call after register_agent.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
purchase_data ~230
Buy a product with your credits; the data ships inline in the response. Deliverable today: the whole depin_* family plus depin_intel_bundle — call list_products for the live prices rather than trusting a figure restated here, which is how a price in a second place drifts from the first. The signal_*, dag_* and mcp_unlimited keys are priced but return 503 not_yet_deliverable — they are deliberately blocked, not broken, because nothing grants their entitlement yet. Credits buy DATA; they do not change your access tier. Use api_key from register_agent.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | Your API key from register_agent |
| idempotency_key | string | – | Optional. Any stable string unique to THIS intended purchase (e.g. a uuid). If a network error makes you retry the same call, re-send the SAME idempotency_key: the retry returns the same receipt and… |
| product_key | string | yes | Product key to purchase (e.g. dag_pro, mcp_unlimited) |
No output schema declared.
No examples provided.
register_agent ~196
START HERE. One call: get an API key instantly (no card, no human, no Stripe, ~5 seconds) plus $5 free credits, no card (first 3 keys per IP per 30 days). Past that per-IP limit a key is still created, at $0, and the response says so — it is never a silent zero. Works immediately: query live DePIN telemetry (504 symbols, every value carries a verify_url you can check yourself), GPU inference, DAG manifold. Try get_data_dictionary first if you want the coverage spec, or GET https://kairossignal.com/try with zero setup. Nothing to cancel; credits just sit there until you spend them. Then list_products to see what $0.49+ buys.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_name | string | yes | Your agent name |
| string | – | OPTIONAL contact email (for delivery and topup notifications). Omit to register anonymously. |
No output schema declared.
No examples provided.
topup_credits ~266
Add credits. Card (one call): {"method": "stripe", "amount": N} where N is $20 or $99 — returns a Stripe checkout_url already bound to your api_key, and credits post automatically once Stripe confirms payment at $1 = 1 credit. No human step and no wallet needed. USDC on Base ({"method": "usdc"}) is also accepted but requires more work: verify your sender first via POST /v1/credits/crypto/challenge and /verify with X-API-Key, sign the returned challenge with your own EOA, then pass the verified from_address and send only after a successful quote — credit requires finalized Base evidence. Instructions: https://kairossignal.com/docs/crypto.html
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount in USD to add. Fixed packs only: 20 or 99. Any other value returns the available packs instead of a link. |
| api_key | string | yes | Your API key |
| from_address | string | – | Required for USDC: your EOA address already verified to this API account through the wallet challenge flow. |
| method | string | yes | Payment method |
| tx_hash | string | – | Legacy optional field; a transaction hash does not replace from_address or verify payment. |
No output schema declared.
No examples provided.
verify_footprint ~134
Retained Merkle-membership check for one depin_onchain observation: stamp_day (YYYYMMDD), leaf_index (0-based row in /attestations/batch_<day>.tsv), expected_row_sha256. verified=true ONLY when the row at that index hashes to expected_row_sha256 AND its inclusion path reaches that day's manifest merkle_root. Says nothing about Bitcoin status or upstream accuracy. Other datasets: unsupported (no retained proof).
| Name | Type | Req | Description |
|---|---|---|---|
| dataset | string | yes | – |
| expected_row_sha256 | string | yes | – |
| leaf_index | integer | yes | – |
| stamp_day | string | yes | – |
No output schema declared.
No examples provided.
What is the io.github.OV3RK177/kairos-signal MCP server?
io.github.OV3RK177/kairos-signal is an MCP server listed in the public MCP registry as io.github.OV3RK177/kairos-signal. Provenance-first DePIN telemetry: 331 live networks + 129 Bittensor subnets, 10,508 series. This page covers its hosted endpoint (https://kairossignal.com/mcp/).
Is the io.github.OV3RK177/kairos-signal MCP server safe to use?
io.github.OV3RK177/kairos-signal scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.OV3RK177/kairos-signal MCP server expose?
io.github.OV3RK177/kairos-signal exposes 11 tools: register_agent, list_products, purchase_data, topup_credits, check_balance, and 6 more. Their descriptions and schemas cost roughly 1,323 tokens of context every time the server is loaded.
Does the io.github.OV3RK177/kairos-signal MCP server require authentication?
No. We connected to io.github.OV3RK177/kairos-signal without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.OV3RK177/kairos-signal MCP server still maintained?
io.github.OV3RK177/kairos-signal is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.