Medicare Coverage
REMOTE · GATEWAY.PIPEWORX.IO · SCANNED AUG 3
MCP server for medicare-coverage
Available components
Recent critical change
Authorization (2 Aug 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (forget). See how to fix → View diagnostics → Fail
- HTTPS check failed: the endpoint is reachable over plaintext HTTP. See how to fix → View diagnostics → Fail
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 12695 tokens (~222/item across 57 items; 57 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Tools include usage examples.Pass
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 66% of tool parameters carry a description.Partial
- Structured output schemas are declared (46% of tools); any adoption earns full credit.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · gateway.pipeworx.io
claude mcp add --transport http pipeworx-io-medicare-coverage https://gateway.pipeworx.io/medicare-coverage/mcp
[mcp_servers.pipeworx-io-medicare-coverage] url = "https://gateway.pipeworx.io/medicare-coverage/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pipeworx-io-medicare-coverage": {
"type": "remote",
"url": "https://gateway.pipeworx.io/medicare-coverage/mcp",
"enabled": true
}
}
} openclaw mcp add pipeworx-io-medicare-coverage --url https://gateway.pipeworx.io/medicare-coverage/mcp --transport streamable-http
mcp_servers:
pipeworx-io-medicare-coverage:
url: "https://gateway.pipeworx.io/medicare-coverage/mcp" {
"mcpServers": {
"pipeworx-io-medicare-coverage": {
"type": "http",
"url": "https://gateway.pipeworx.io/medicare-coverage/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 0
- Authorization: fail → unverified ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “deep_research” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx_grounded” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx_beta” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx” rewrote its description, which is the text the model reads security
- 2 Aug 26 +1
- Authorization: unverified → fail ▼ critical
- The server rewrote its instructions, which are the text every model session reads security
- Tool “ask_pipeworx_beta” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx_grounded” rewrote its description, which is the text the model reads security
- Tool “deep_research” rewrote its description, which is the text the model reads security
- Tool “medicare_coverage_timeline” rewrote its description, which is the text the model reads security
- “medicare_coverage_timeline” reworded the description of “document_id” cosmetic
- “medicare_coverage_timeline” reworded the description of “version” cosmetic
- 1 Aug 26 0
- Authorization: fail → unverified ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “ask_pipeworx” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx_beta” rewrote its description, which is the text the model reads security
- Tool “ask_pipeworx_grounded” rewrote its description, which is the text the model reads security
- Tool “deep_research” rewrote its description, which is the text the model reads security
- 31 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- Tool coverage: 96% → 65% ▼ functional
- Schema quality: 276 → 218 ▲ functional
- Tool coverage: 21% → 46% ▲ functional
- Stability: unverified → 0.03 ▲ functional
- 29 Jul 26 57
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://gateway.pipeworx.io/medicare-coverage/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=pipeworx.io | CN=WE1,O=Google Trust Services,C=US | 20 Jul 2026 | 18 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 8b854960bb5cdb890e68540cbf9f08a8 |
| SANs: pipeworx.io, gateway.pipeworx.io, *.gateway.pipeworx.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of gateway.pipeworx.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| pipeworx.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://gateway.pipeworx.io/medicare-coverage/mcp | Verified | 200 | |
| http (plaintext) | http://gateway.pipeworx.io/medicare-coverage/mcp | Served over HTTP | 200 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
recent_alerts Recent Alerts ~204
Pull fired events from your subscription feed. Returns the most recent alerts the evaluator has written to your persisted feed — each carries source, citation_uri (pipeworx:// when available), and the raw event payload. Filter by type (e.g. "sec_8k") and/or since (ISO timestamp). Set mark_read:true to flag returned events read so the next call only shows newer ones. Polls work fine; the same feed is also at GET registry.pipeworx.io/alerts.json for scripts and dashboards.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max events to return (1-200, default 50). |
| mark_read | boolean | — | Flag the returned events read in the same call (default false). |
| since | string | — | Optional ISO timestamp — return events fired_at >= this time. |
| type | string | — | Optional — filter to one subscription type. |
| unread_only | boolean | — | Return only events where read_at is null (default false). |
No output schema declared.
No examples provided.
recent_changes Recent Changes ~320
"What's new with X" / "latest on Y" / "what happened to Z this week / month / quarter" / "updates on Acme" / "news on Tesla recently" / "what's happening with Apple" — change feed for a company in the last N days/weeks/months in ONE parallel call. Fans out to SEC EDGAR (filings since `since`), GDELT→GNews fallback (news mentions in window — GDELT preferred, GNews when rate-limited or 5xx), USPTO (patents granted; PatentsView API sunset May 2025 so this soft-fails until reactivated). `since` accepts ISO date ("2026-04-01") or relative shorthand ("7d", "30d", "3m", "1y"). Returns structured changes[] grouped by source + total_changes count + pipeworx:// citation URIs. Use entity_profile instead when you want the static profile (filings + fundamentals + LEI + patents) regardless of window.
| Name | Type | Req | Description |
|---|---|---|---|
| since | string | yes | Window start — ISO date ("2026-04-01") or relative ("7d", "30d", "3m", "1y"). Use "30d" or "1m" for typical monitoring. |
| type | string | yes | Entity type. Only "company" supported today. |
| value | string | yes | Ticker (e.g., "AAPL") or zero-padded CIK (e.g., "0000320193"). |
No output schema declared.
No examples provided.
remember Remember ~144
Save data the agent will need to reuse later — across this conversation or across sessions. Use when you discover something worth carrying forward (a resolved ticker, a target address, a user preference, a research subject) so you don't have to look it up again. Stored as a key-value pair scoped by your identifier. Authenticated users get persistent memory; anonymous sessions retain memory for 24 hours. Pair with recall to retrieve later, forget to delete.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | Memory key (e.g., "subject_property", "target_ticker", "user_preference") |
| value | string | yes | Value to store (any text — findings, addresses, preferences, notes) |
No output schema declared.
No examples provided.
resolve_entity Resolve Entity ~253
"What's the ticker for…" / "find the CIK for…" / "what's the RxCUI for…" / "look up the ID for…" / "what is X's official identifier" — resolve a user-spoken NAME to the canonical/official identifier other tools require as input. Use FIRST whenever you have a name but need an ID. SUPPORTED TYPES: "company" (returns ticker + 10-digit CIK + company_name from SEC EDGAR + pipeworx://edgar/company/{cik} citation URI; accepts ticker, CIK, or company name as input — auto-disambiguated), "drug" (returns RxCUI + ingredient + brand from RxNorm + pipeworx://rxnorm/{rxcui} citation; accepts brand or generic name). Each call cascades through several lookup endpoints internally — using resolve_entity replaces 2-3 manual lookups.
| Name | Type | Req | Description |
|---|---|---|---|
| type | string | yes | Entity type: "company" or "drug". |
| value | string | yes | For company: ticker (AAPL), CIK (0000320193), or name. For drug: brand or generic name (e.g., "ozempic", "metformin"). |
No output schema declared.
No examples provided.
scan_competitor_ai_presence Scan Competitor AI Presence ~225
Compare AI visibility across multiple entities side-by-side. Probes each entity (your brand + N competitors) with ai_visibility_check, ranks by score, surfaces which is most/least recognized. Useful for competitive AI-marketing audits: "does Claude know about us as well as our competitors?". Returns ranked list with score, confidence, signal density per entity.
| Name | Type | Req | Description |
|---|---|---|---|
| _apiKey | string | — | Optional Anthropic API key — only if "anthropic" is in models. Passed to api.anthropic.com per probe. |
| context | string | — | Optional shared context applied to every probe (e.g. "B2B SaaS", "Boston restaurant"). Disambiguates common names. |
| entities | array | yes | Array of 2-8 entities to compare (brand/business/product names). First entry treated as the "subject" for narrative; rest are competitors. |
| models | array | — | Which models to probe. Supported: "workers-ai" (free default), "anthropic" (requires _apiKey). Omit for just workers-ai. |
No output schema declared.
No examples provided.
scan_dependency Scan Dependency ~254
Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.
| Name | Type | Req | Description |
|---|---|---|---|
| package | string | yes | npm package name. Scoped packages (e.g. "@types/node") are accepted. |
| version | string | — | Specific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted. |
No output schema declared.
No examples provided.
search_within Search Within a Source ~238
Semantic search INSIDE a fetched record. Pass the text you already pulled (e.g. a SEC 10-K body, an article, a long tool result) plus a natural-language query; get back the top-N passages with character offsets and similarity scores. Use when the record is too big to cram into the prompt — search_within saves context, returns only the passages that matter, and every passage carries an offset so the agent can verify a verbatim quote. Pairs with ask_pipeworx_grounded: fetch with the gateway, ground over the relevant passages instead of the whole document. BGE-base-en embeddings + cosine over 500-char overlapping windows; cap is 200K chars (longer inputs are truncated and flagged).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | — | Max passages to return (1-20, default 5). |
| query | string | yes | Natural-language query — what passages do you want? E.g. "supply-chain risk", "fiscal year 2024 revenue", "drug interactions with warfarin". |
| text | string | yes | The document text to search inside (max ~200K chars). |
No output schema declared.
No examples provided.
subscribe Subscribe to Alerts ~449
Create a proactive monitoring subscription to a live-data event stream. Returns the new subscription id. Requires a Pipeworx OAuth account (anonymous + BYO cannot persist subscriptions). Supported types: "sec_8k" (8-K filings matching ticker + item codes — e.g. items:["5.02"] = officer change), "polymarket_edge" (Polymarket↔Kalshi cross-venue mispricings — params:{topic:"fed"}), "fred_series" (new FRED observations — params:{series_id:"UNRATE"}). Delivery channels: feed (always on — pull via recent_alerts or GET registry.pipeworx.io/alerts.json), and optionally email (set delivery:{email:"[email protected]"}) or sms (delivery:{sms:"+15551234567"} — phone must be verified at /account first; 10/day cap).
| Name | Type | Req | Description |
|---|---|---|---|
| delivery | object | — | Optional delivery channels in addition to the always-on persistent feed. {email:"[email protected]"} sends a templated alert per fired event. {sms:"+15551234567"} sends an SMS per event — must match the veri… |
| params | object | yes | Type-specific filter. sec_8k: {ticker:"AAPL", items?:["5.02","1.01"]}. polymarket_edge: {topic:"fed", min_spread_bps?:500}. fred_series: {series_id:"UNRATE"}. patent_grant: {applicant:"Apple Inc."}.… |
| type | string | yes | Subscription type. |
No output schema declared.
No examples provided.
suggest_questions What Can I Ask Pipeworx? ~240
What can I ask Pipeworx? / what is Pipeworx good for? / what can you do? / give me ideas / show me examples / getting started / what data do you have? — the onboarding entry point for an agent that just connected and wants to know what is worth asking. Returns category-bucketed example questions (company financials, drugs & clinical trials, economics, real estate, prediction markets, weather, government & patents, science & academia, news) — each with the exact tool + argument shape that answers it, drawn from the live catalog of thousands of tools. Call with no arguments for the full spread, or pass `topic` (e.g. "finance", "pharma", "betting") to focus. Use this FIRST when you do not yet know what Pipeworx can do for you, or to learn how to call the meta-tools (ask_pipeworx, entity_profile, compare_entities, etc.).
| Name | Type | Req | Description |
|---|---|---|---|
| topic | string | — | Optional focus area: finance | pharma | economics | real-estate | betting | weather | government | science | news. Omit for a cross-category spread. |
No output schema declared.
No examples provided.
unsubscribe Unsubscribe from Alerts ~60
Cancel a subscription by id. Ownership is enforced — you can only cancel your own subscriptions. The row is deactivated (not deleted) so its historical events stay available via recent_alerts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Subscription id (uuid) returned by subscribe. |
No output schema declared.
No examples provided.
validate_claim Validate Claim ~306
"Is it true that…" / "fact check" / "verify the claim that…" / "did X really…" / "was Y actually…" / "confirm or refute" / "true or false" — natural-language claim verification against authoritative sources. Use whenever the agent needs to check whether something a user said is factually correct. Company-financial claims (revenue, net income, cash for public US companies) verify via the structured SEC EDGAR + XBRL fast path with exact percent-delta math; ANY OTHER factual claim (macro statistics, rates, prices, drug data, records) automatically falls through to the grounded pipeline — routed to the right live source, answered with verbatim evidence, then judged. Returns a verdict (confirmed / approximately_correct / refuted / inconclusive / unsupported), the grounded or structured actual value with pipeworx:// citation, and reasoning. Replaces 4–6 sequential calls (NL parsing → entity resolution → data lookup → comparison).
| Name | Type | Req | Description |
|---|---|---|---|
| claim | string | yes | Natural-language factual claim, e.g., "Apple's FY2024 revenue was $400 billion" or "Microsoft made about $100B in profit last year". |
| tolerance_pct | number | — | Max percent deviation still graded approximately_correct (0.5–50). Overrides the tolerance implied by the claim wording — set 1–2 for hallucination detection where any material error must be refuted.… |
No output schema declared.
No examples provided.