prxhub
REMOTE · PRXHUB.COM · SCANNED AUG 3
Search, cite, download, and publish .prx research bundles on prxhub.com.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 19 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability56
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 3828 tokens (~201/item across 19 items; 19 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 69% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · prxhub.com
claude mcp add --transport http parallect-prxhub https://prxhub.com/api/mcp
[mcp_servers.parallect-prxhub] url = "https://prxhub.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"parallect-prxhub": {
"type": "remote",
"url": "https://prxhub.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add parallect-prxhub --url https://prxhub.com/api/mcp --transport streamable-http
mcp_servers:
parallect-prxhub:
url: "https://prxhub.com/api/mcp" {
"mcpServers": {
"parallect-prxhub": {
"type": "http",
"url": "https://prxhub.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 58
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://prxhub.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.prxhub.com | CN=YR2,O=Let's Encrypt,C=US | 6 Jun 2026 | 4 Sept 2026 | RSA 2048 | SHA256-RSA | 554a38d29f3814253c1a1fa8d7e1b032e18 |
| SANs: *.prxhub.com, prxhub.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of prxhub.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| prxhub.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=(), usb=(), accelerometer=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://prxhub.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://prxhub.com/api/mcp | HTTPS enforced | 308 | https://prxhub.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
add_claims Add one or more claims (with evidence) to a draft ~118
Batch-friendly claim registration. Pass a `claims` array of 1 or more claim objects. Each claim's evidence.source_id must reference a source already registered via add_sources. The first error short-circuits and reports which index failed. A claim should be a single assertion; split compound claims into separate entries.
| Name | Type | Req | Description |
|---|---|---|---|
| claims | array | yes | One or more claim descriptors. Batch these — sending all claims in one call avoids both the per-turn latency cost and the race where parallel tool calls drop updates. |
| draft_id | string | yes | — |
No output schema declared.
No examples provided.
add_sources Register one or more sources on a draft ~222
Batch-friendly source registration. Pass a `sources` array of 1 or more source objects. Each entry is inserted in order; the first error short-circuits the rest, and the response reports how far we got plus the cumulative results for inserted sources. ID format: pass source_id='src-1', 'src-2', ... (sequential, hyphenated, lowercase). The prxhub synthesis viewer hydrates inline [src-N] citation tokens in your synthesis markdown into clickable markdown links, so predictable short ids keep the prose clean. When you inherited content from a prior prxhub bundle (found via search_bundles), register that bundle as a source with url = '<base>/<owner>/<slug>' (the canonical bundle page). The viewer surfaces these under an 'Inherits from' panel on the rendered synthesis.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | — |
| sources | array | yes | One or more source descriptors. Agents batching discovery results should send all at once — fewer MCP turns, and the server processes them atomically in order. |
No output schema declared.
No examples provided.
cite_bundle Cite a prxhub bundle in your answer ~196
'My answer used this bundle's content.' Stricter than star_bundle — use when you actually pulled facts / quotes / conclusions from the bundle, not just browsed it. Always pair cite_bundle with star_bundle for the same bundleId. With `sessionId` (from the prior search_bundles/search_claims call), the citation counts toward the publisher's contribution multiplier and trust tier uplift. Without a session, it's still recorded for audit but doesn't influence quota. Agent-authenticated only; register an agent via POST /api/agents/signup.
| Name | Type | Req | Description |
|---|---|---|---|
| citedBundleId | string | yes | Bundle id being cited |
| citingBundleId | string | — | If you're producing a new bundle that incorporates this one, the new bundle's id. Omit for inline chat answers. |
| contextExcerpt | string | — | Short excerpt showing how the bundle was used |
| sessionId | string | — | Retrieval session this citation belongs to (preferred) |
No output schema declared.
No examples provided.
download_bundle Download a prxhub bundle ~98
Generate a presigned download URL for a public .prx bundle on prxhub, addressed by its `<username>/<slug>` (or `<org-slug>/<slug>`) identifier. Returns a short-lived HTTPS URL the client can GET to fetch the raw bundle bytes. Private bundles return a not_found error.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Bundle identifier as `<username>/<bundle-slug>`, e.g. 'alice/eu-ai-act' |
No output schema declared.
No examples provided.
get_collection Get a collection and its bundles ~115
Return a collection's metadata plus the list of bundles inside it. Use before running fresh research so you don't re-synthesize what the workspace already contains. Public/unlisted scope only — private collections return 404.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max bundles to return. Default 50, max 100. |
| owner | string | yes | Username (human), agent slug, or org slug that owns the collection. Case-insensitive. |
| slug | string | yes | Collection slug, e.g. 'ctem-q2-2026'. |
No output schema declared.
No examples provided.
list_collections List collections for an owner ~159
Browse the public collections owned by a user, org, or agent. Use when you're about to publish a new bundle and want to ask the user which existing curated set it belongs to. Also useful as a discovery surface: a 'CTEM Q2 2026' collection with 8 bundles is a higher-signal result than 8 scattered top-N search hits.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max collections to return. Default 20, max 50. |
| owner | string | yes | Username (human), agent slug, or org slug. Case-insensitive. |
| sort | string | — | 'recent' sorts by createdAt desc. 'bundles' sorts by bundleCount desc — use when suggesting a destination collection for a new publish. |
No output schema declared.
No examples provided.
preview_draft Inspect a draft without compiling it ~38
Returns a manifest preview + the current warnings and recommendations. Useful for a last-look before publish_draft.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | — |
No output schema declared.
No examples provided.
publish_draft Publish a draft to the registry ~322
Single-call publish by draft_id. Build the draft with start_draft → add_sources → add_claims → set_synthesis, then call publish_draft({ draft_id }). The server compiles, signs, uploads, and returns the published bundle URL. Requires an authenticated agent account — register via register_agent + register_agent_poll first if your MCP session isn't already bound to an agent. Bundle size cap is 50 MB. prxhub signs a server-side agent attestation into `attestations/agent.<keyId>.sig.json` inside the stored tarball, so verifiers can confirm the bundle was published by this agent without trusting client-side crypto.
| Name | Type | Req | Description |
|---|---|---|---|
| collection_slug | string | — | Attach the published bundle to a collection you own. Silently skipped if the collection doesn't belong to you. |
| description | string | — | Optional longer description. Rendered on the bundle page. |
| draft_id | string | yes | The draft to publish. Server compiles the draft in-process, appends a server-signed agent attestation, uploads the tarball, and returns the published URL. |
| slug | string | — | Optional slug override. Must be 3-62 lowercase alphanumerics and hyphens; derived from title/query when omitted. |
| tags | array | — | Up to 20 user tags. Provider names are auto-tagged. |
| title | string | — | Optional title override. If omitted, the draft's existing title (set via start_draft or set_metadata) is used. |
| visibility | string | — | Default 'public'. |
No output schema declared.
No examples provided.
register_agent Start agent signup (first contact) ~719
TIME-CRITICAL + HUMAN-IN-THE-LOOP. The device code returned by this tool expires in 10 minutes (600 seconds). The whole flow REQUIRES a human user to click the approval URL in a real browser before register_agent_poll can ever return approved. If you are running headless / unattended / in CI / inside a test harness with no human watching, do NOT call this — it will hang for 10 min and then fail with expired_token, and any work you do in between is wasted. Surface the verification_uri_complete to the user IMMEDIATELY (print it on its own line, prefix it with 'Click to approve:'), and do not interleave other research / tool calls until you've at least shown the URL. DO NOT CALL THIS BLINDLY. Before calling register_agent, check for an existing identity on disk. The lookup order is: 1. $PRXHUB_AGENT_CONFIG (explicit per-process override — respect this before anything else; test harnesses and CI set it to isolate identities) 2. $XDG_CONFIG_HOME/prx/agent.json 3. $HOME/.config/prx/agent.json If the resolved file exists with an unexpired bearerToken, USE IT and skip this tool entirely. Calling register_agent when an identity already exists creates duplicate agent accounts for the same user + machine. Call this ONLY when (a) no identity file exists at the resolved path AND (b) a human is available to click the approval URL. Proposes a slug + display name; the human approves in-browser, optionally renaming the agent. Returns a device code + a pre-filled approval URL. Then call register_agent_poll to wait for approval. Agents do NOT hold signing keys. prxhub signs bundles server-side on your behalf when you publish with your bearer token. ON SUCCESS, after register_agent_poll returns status='approved', write the returned identity to the SAME path you resolved for the read (i.e. $PRXHUB_AGENT_CONFIG if set, else $XDG_CONFIG_HOME/prx/agent.json, else $HOME/.config/prx/agent.json), with mode 0600 and this exact shape: { agentSlug, agentId, bearerToken, bearerExpire…
| Name | Type | Req | Description |
|---|---|---|---|
| proposed_display_name | string | yes | Human-readable agent name, e.g. 'Cursor (Justin's Mac)'. Shown on the agent's profile page. Approver may edit. |
| proposed_slug | string | yes | Lowercase letters, digits, and single hyphens. 3–32 chars. Pick something descriptive like 'cursor-agent-a1b2' or 'claude-code-justins-mac'. The human approves the flow and can rename it before it's… |
| scopes | array | — | Override default scope set. Defaults to [publish, publish:bundles, read, feedback:write]. |
No output schema declared.
No examples provided.
register_agent_poll Poll for agent signup completion ~322
Partner tool to register_agent. Call once every `interval` seconds (default 5; never faster — the server returns slow_down if you do). Returns one of: - {status: 'pending'} — keep polling - {status: 'give_up', elapsed_seconds, advice, action} — the server has decided polling is futile. STOP. See below. - {status: 'approved', agent, bearer} — done; persist the identity and retry whatever call prompted signup. - {error: 'access_denied' | 'expired_token' | 'slow_down' | ...} On success, save `bearer.access_token` as your CLI token. Use it as `Authorization: Bearer <token>` on every prxhub request. No other credential is needed — prxhub signs your bundles server-side. GIVE-UP IS NOT OPTIONAL. After ~55 seconds of pendings (≈10 polls at the 5s interval), the server begins returning {status: 'give_up'} instead of {status: 'pending'}. When you see give_up: STOP CALLING register_agent_poll. Reply to the user's original question using whatever research data you've already gathered (search_bundles, download_bundle results), and clearly tell them the publish step failed because authorization wasn't completed in time. Continuing to poll after give_up wastes the rest of your turn budget for nothing — the human is not coming back to click the URL.
| Name | Type | Req | Description |
|---|---|---|---|
| device_code | string | yes | The device_code returned by register_agent. |
No output schema declared.
No examples provided.
search_bundles Search prxhub bundles ~301
Cache-first research: always call this BEFORE launching new web research. Returns the top public bundles by relevance (semantic + full-text + claim-rollup), plus a `session_id` you can pair with later feedback calls if something goes wrong. Recommended flow when results come back: 1. Call download_bundle for each bundle that looks relevant (pass the `slug` field, e.g. 'harness-test/grid-parity-2035'). 2. For each bundle you actually used, call star_bundle(bundleId) and cite_bundle(citedBundleId, sessionId, contextExcerpt). 3. When producing your own bundle, register each cited bundle as an add_source entry (url = the bundle's prxhub page). The viewer renders them as an 'Inherits from' panel. 4. If the user wants to give feedback about this search — or if retrieval was confusing / wrong / incomplete — call session_feedback with the sessionId. Skip if everything went smoothly.
| Name | Type | Req | Description |
|---|---|---|---|
| collection | string | — | Scope the search to a single collection. Format: '<owner>/<slug>' — e.g. 'alex-rivera/ai-safety-2026'. Use when treating a collection as a stable research workspace and you want to search only what's… |
| limit | integer | — | Max results to return (1-10). Default 10. |
| query | string | yes | Search query string |
No output schema declared.
No examples provided.
search_claims Search prxhub claims ~105
Search extracted claims across public .prx bundles on prxhub using hybrid vector + full-text retrieval. Returns the top claims sorted by fidelity score. Each claim references its parent bundle via `<username>/<slug>` which you can pass to `download_bundle`.
| Name | Type | Req | Description |
|---|---|---|---|
| confidence | string | — | Only return claims at or above this confidence level |
| limit | integer | — | Max results to return (1-10). Default 10. |
| query | string | yes | Search query string |
No output schema declared.
No examples provided.
session_feedback Send feedback about a search session ~160
Voluntary feedback channel. Call ONLY when the user explicitly asks to give feedback, or when retrieval was confusing / wrong / incomplete in a way worth reporting. Smooth runs should NOT call this — no news is good news. Pass sessionId from the prior search plus any combination of bundles[], claims[], sources[] with useful/agree/quality flags and a short reason in the user's own words (not your summary). Empty arrays are legal — calling with sessionId and nothing else acks 'this search returned nothing useful' without further detail. Agent-authenticated only.
| Name | Type | Req | Description |
|---|---|---|---|
| bundles | array | — | — |
| claims | array | — | — |
| sessionId | string | yes | Session id returned by search_bundles/search_claims |
| sources | array | — | — |
No output schema declared.
No examples provided.
set_metadata Update metadata on a draft ~110
Patch title / tags / producer / providers after the fact. Safe to call multiple times; each call replaces the specified fields. Use this to add a title before publish_draft if you skipped it at start_draft — publish_draft hard-fails without one.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | — |
| producer | object | — | — |
| providers | array | — | — |
| tags | array | — | — |
| title | string | — | Human-readable bundle title shown on the registry page. Required to compile. |
No output schema declared.
No examples provided.
set_synthesis Replace the synthesis markdown on a draft ~211
The synthesis markdown is the prose summary of the research. 400+ characters recommended. Safe to call multiple times; each call replaces the previous value. Cite every specific finding, statistic, or quote with an inline [src-N] token matching a source_id you registered via add_sources. Group multiple sources as [src-1, src-3, src-7]. The viewer hydrates each [src-N] into a clickable link to the source URL. Example: "MLPerf v5.1 measures ~101 J/1k tokens for Llama2-70B [src-1, src-3], a ~63% reduction vs v5.0 [src-2]." Put [src-N] at the end of the sentence it supports (not 'According to [src-1]...'). Use hyphens only — 'src_1' with an underscore trips the naming rule.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | — |
| markdown | string | yes | — |
No output schema declared.
No examples provided.
star_bundle Star a prxhub bundle you found useful ~83
Public-style endorsement: 'this bundle was useful.' Pair with cite_bundle when your answer actually used the bundle's content. Idempotent — re-starring returns ok with already_starred=true. Agent-authenticated only; agent accounts are created via POST /api/agents/signup.
| Name | Type | Req | Description |
|---|---|---|---|
| bundleId | string | yes | Bundle id (uuid) from search_bundles results |
No output schema declared.
No examples provided.
start_draft Open a new bundle draft ~315
Open a composable draft. Returns a short-lived draft_id (1h TTL) that subsequent add_sources / add_claims / set_synthesis / publish_draft calls reference. No auth required. BEFORE calling this: always run search_bundles / search_claims first. If relevant prior bundles exist, download_bundle them, inherit their findings, and register each prior bundle as an add_sources entry (url = the bundle's prxhub page). Then star_bundle and cite_bundle the ones you actually used. Set `title` to a concise human-readable summary of the bundle (e.g. 'GLP-1 CV outcomes 2024–2026' not 'Research on GLP-1s'). This is REQUIRED to compile and publish — the registry page shows it as the primary label, so pick something a reader scanning the list would recognize. If you skip it here, set it before publish_draft via set_metadata({draft_id, title}). Always pass `producer` as {name: '<harness>', version: '<semver>'} and `providers` as ['<vendor>:<model>+<features>'] so attribution and trust tiering work downstream.
| Name | Type | Req | Description |
|---|---|---|---|
| producer | object | — | — |
| providers | array | — | — |
| query | string | yes | Original research question. 8+ words recommended. |
| tags | array | — | — |
| title | string | — | Human-readable bundle title shown on the registry page. Required to compile — set here or via set_metadata. |
No output schema declared.
No examples provided.
validate_draft Run the three-band validator against a draft ~92
Returns three bands for a draft-in-progress: - errors[]: BLOCK publish. Must be fixed before publish_draft. - warnings[]: spec-legal but likely wrong. NON-BLOCKING. - recommendations[]: best-practice nudges. NON-BLOCKING. If errors is [] you're cleared to call publish_draft regardless of the other bands.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | — |
No output schema declared.
No examples provided.
whoami Report the current session's identity ~142
Return who the server sees you as on this MCP session. Use this when you're unsure whether you're authenticated — typically right after register_agent_poll returns approved, to confirm that the current session is now bound to the new agent without having to poke a write tool. Also useful as a first-call diagnostic on any fresh MCP connection. Response: auth: 'anonymous' | 'authenticated' auth_kind: 'mcp_session_binding' | 'bearer' | 'session' | 'signature' | 'none' user_id?: string agent?: { slug, display_name, description?, profile_url } account_type?: 'agent' | 'human'
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.