io.github.qg-aramai/coremodels
REMOTE · GO.COREMODELS.IO · SCANNED SEP 20
Schema modeling in JSON, JSON-LD, and other formats with CoreModels platform.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the io.github.qg-aramai/coremodels MCP server?
io.github.qg-aramai/coremodels is a hosted endpoint at https://go.coremodels.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · go.coremodels.io
claude mcp add --transport http qg-aramai-coremodels 'https://go.coremodels.io/mcp'
{
"mcpServers": {
"qg-aramai-coremodels": {
"url": "https://go.coremodels.io/mcp"
}
}
} {
"servers": {
"qg-aramai-coremodels": {
"type": "http",
"url": "https://go.coremodels.io/mcp"
}
}
} [mcp_servers.qg-aramai-coremodels] url = "https://go.coremodels.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"qg-aramai-coremodels": {
"type": "remote",
"url": "https://go.coremodels.io/mcp",
"enabled": true
}
}
} openclaw mcp add qg-aramai-coremodels --url 'https://go.coremodels.io/mcp' --transport streamable-http
mcp_servers:
qg-aramai-coremodels:
url: "https://go.coremodels.io/mcp" {
"McpServers": {
"qg-aramai-coremodels": {
"Transport": "http",
"Url": "https://go.coremodels.io/mcp"
}
}
} assistant mcp add qg-aramai-coremodels -t streamable-http -u 'https://go.coremodels.io/mcp'
{
"mcpServers": {
"qg-aramai-coremodels": {
"type": "http",
"url": "https://go.coremodels.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 22 Aug 26 36
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: 0.87 → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: unverified → pass ▲ security
- First check of Authorization: partial security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 100 → unverified ▼ functional
- 13 Aug 26 0
- New tool “core_models_get_mixins_info” functional
- New tool “core_models_get_relation_groups_info” functional
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://go.coremodels.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=go.coremodels.io | CN=GeoTrust TLS RSA CA G1,OU=www.digicert.com,O=DigiCert Inc,C=US | 30 May 2026 | 30 Nov 2026 | RSA 2048 | SHA256-RSA | 72b62bb5bce43de2723d6302adf08e0 |
| SANs: go.coremodels.io | ||||||
| CN=GeoTrust TLS RSA CA G1,OU=www.digicert.com,O=DigiCert Inc,C=US (CA) | CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US | 2 Nov 2017 | 2 Nov 2027 | RSA 2048 | SHA256-RSA | d07782a133fc6f9a57296e131ffd179 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of go.coremodels.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| coremodels.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://go.coremodels.io/.well-known/oauth-protected-resource/mcp"
Bearer resource_metadata="https://go.coremodels.io/.well-known/oauth-protected-resource/mcp" | Header | Value |
|---|---|
| www-authenticate | Bearer resource_metadata="https://go.coremodels.io/.well-known/oauth-protected-resource/mcp" |
Protected resource metadata
| Document | https://go.coremodels.io/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://go.coremodels.io/mcp |
| Authorisation server | https://ids.schematica.io/ |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://go.coremodels.io/mcp | Auth required | 401 | |
| http (plaintext) | http://go.coremodels.io/mcp | HTTPS enforced | 301 | https://go.coremodels.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
core_models_get_mixins_info Core Models Get Mixins Info ~65
Get information about all mixins in a CoreModels project. Mixins define structured metadata used for mapping models, system integrations, and other extensions. Use get_node tool documentation to understand how mixins are attached to nodes.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
core_models_get_relation_groups_info Core Models Get Relation Groups Info ~44
Get information about relation groups for a CoreModels project. Use the relation groups to create a relation between two nodes.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
export_json_ld Export JSON-LD ~231
Export project data in JSON-LD format using a configured export profile. Use `fetch_json_ld_import_profiles` first to discover the configTypeId. At least one of exportTypes/exportElements/exportTaxonomies/exportDataTypes must be true. Tree-based mode (graphBased=false) requires exactly one nodeId; graph-based mode allows multiple or none.
| Name | Type | Req | Description |
|---|---|---|---|
| configTypeId | string | yes | JSON-LD export profile id (from fetch_json_ld_import_profiles) |
| exportDataTypes | boolean | – | – |
| exportElements | boolean | – | – |
| exportTaxonomies | boolean | – | – |
| exportTypes | boolean | – | – |
| graphBased | boolean | – | true = graph-based (no root); false = tree-based (requires exactly one nodeId) |
| graphProjectId | string | yes | – |
| includeSpace | boolean | – | – |
| nodeIds | array | – | For tree-based export, exactly one root node id; for graph-based, optional |
| spaceId | string | – | Optional space id to filter export data; empty = all spaces |
| useDefaultType | boolean | – | – |
No output schema declared.
No examples provided.
export_jsonschema Export JSON Schema ~77
Export project data as a JSON Schema string.
| Name | Type | Req | Description |
|---|---|---|---|
| configTypeId | string | – | Export profile id used for the JSON Schema export. |
| graphProjectId | string | yes | – |
| rootNodeId | string | – | Optional root node id; empty/omitted to export without a fixed root. |
| spaceId | string | – | – |
No output schema declared.
No examples provided.
export_shex Export ShEx ~91
Export project data as a ShEx (Shape Expressions) schema string.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
| includeCardinality | boolean | – | Whether to emit ShEx cardinality markers (?, *, +). Defaults to true. |
| nodeIds | array | – | Optional type node ids to export; omit to export all types (optionally scoped to a space). |
| spaceId | string | – | – |
No output schema declared.
No examples provided.
fetch_json_ld_import_profiles Fetch JSON-LD Import Profiles ~32
Fetch JSON-LD import/export profiles available for a project.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
fetch_json_schema_import_profiles Fetch JSON Schema Import Profiles ~31
Fetch JSON Schema import/export profiles available for a project.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
get_mixins_and_relation_groups Get Mixins & Relation Groups ~80
Get the project schema: all mixin definitions and all relation-group definitions. Use this once at the start of a session to discover the IDs needed by other tools (mixinId, columnId, relationGroupId). Returns compact positional arrays - see the "format" field for the layout.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
get_project_summary Get Project Summary ~107
Labels and IDs of types, elements, and taxonomies in the project. Each category is paginated independently. Pagination: - First call: omit page (defaults to 0). - Each category reports page, pageSize and hasMore. Re-request with page+1 for any category whose hasMore is true.
| Name | Type | Req | Description |
|---|---|---|---|
| graphProjectId | string | yes | – |
| page | integer | – | 0-based page index, applied independently to each category. |
| pageSize | integer | – | – |
No output schema declared.
No examples provided.
list_projects List Projects ~237
List the user's CoreModels projects as [id,name,accessLevel] (see the response "format" field). Use a returned id as graphProjectId for other tools. Pass searchTerm to filter by name (case-insensitive substring). Set includePublicProjects=true to also include public projects. Set includeAISummary=true to also return each project's saved AI-generated summary and the time it was generated (4th and 5th elements). Paged: page is 1-based; increment page up to the returned totalPages to get all results.
| Name | Type | Req | Description |
|---|---|---|---|
| includeAISummary | boolean | – | When true, each project row includes its saved AI-generated summary (markdown) and the time it was generated as 4th and 5th elements, or null if none has been generated. |
| includePublicProjects | boolean | – | When true, public projects the user is not a member of are also included. |
| page | integer | – | 1-based page number. Increment to page through results up to totalPages. |
| pageSize | integer | – | – |
| searchTerm | string | – | Optional case-insensitive substring to filter projects by name. |
No output schema declared.
No examples provided.
run_code Run Code ~240
Execute a JavaScript program that orchestrates this server's tools, and return only its result. Prefer this over many individual tool calls when a task needs several steps, looping, filtering, or combining data: intermediate results stay in the sandbox, so only what you return reaches the model. Inside the script: - listTools() -> [{name, summary}] discover available tools - getToolDoc(name) -> {name, description, parameters, required} inspect one tool's inputs - tools.<name>(args) -> parsed result call a tool (graphProjectId is injected automatically; do NOT pass it) - console.log(...) captured and returned alongside the result - return <value> JSON-serialized and returned Environment: sandboxed JavaScript, no network or filesystem, with limits on time, memory, statements and number of tool calls. Currently only read-only tools are callable from code.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | JavaScript to execute. Use tools.<name>(args), listTools(), getToolDoc(name); end with `return <value>`. |
| graphProjectId | string | yes | – |
No output schema declared.
No examples provided.
search_nodes Search Nodes ~325
Search nodes in a CoreModels project. Returns compact positional arrays; the response "format" field describes the layout. Filters (provide at least one; they combine with AND): - nodeIds: exact id lookup - nodeType: one of Element, Type, Taxonomy, Exemplar, Component, Space, Tag, Mixin - expression: partial substring match on the node label (plain text, no wildcards) - spaceIds: restrict to specific spaces Optional flags: includeRelations, includeMixins, sortAttr, sortDesc, pageSize. Pagination: - First call: omit pagingToken. - If the response has a pagingToken, more pages exist. Repeat the same call with that exact token to get the next page. - If the response has no pagingToken, this was the last page.
| Name | Type | Req | Description |
|---|---|---|---|
| expression | string | – | Partial substring match against the node label. Plain text only - no wildcards, no regex, no '*', '%', '_' or '?' characters; the literal characters are matched as-is. |
| graphProjectId | string | yes | – |
| includeMixins | boolean | – | – |
| includeRelations | boolean | – | – |
| nodeIds | array | – | – |
| nodeType | string | – | – |
| page | integer | – | 1-based page number. The response includes 'total' (the total match count) so you can compute how many pages there are. |
| pageSize | integer | – | – |
| sortAttr | string | – | – |
| sortDesc | boolean | – | – |
| spaceIds | array | – | – |
No output schema declared.
No examples provided.
validate_json Validate JSON ~136
Validate a JSON document against a project's stored JSON Schema. The schema is regenerated from the project using the supplied configTypeId (the export profile id) and rootNodeId. Provide the JSON to validate as a serialized string.
| Name | Type | Req | Description |
|---|---|---|---|
| configTypeId | string | – | Profile id used to map mixins/relations to schema keywords |
| graphProjectId | string | yes | – |
| jsonString | string | yes | The JSON document to validate, serialized as a string |
| rootNodeId | string | yes | Node id used as the root when generating the JSON Schema |
| spaceId | string | – | Optional space id to scope the schema |
No output schema declared.
No examples provided.
What is the io.github.qg-aramai/coremodels MCP server?
io.github.qg-aramai/coremodels is an MCP server listed in the public MCP registry as io.github.qg-aramai/coremodels. Schema modeling in JSON, JSON-LD, and other formats with CoreModels platform. This page covers its hosted endpoint (https://go.coremodels.io/mcp).
Is the io.github.qg-aramai/coremodels MCP server safe to use?
io.github.qg-aramai/coremodels scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.qg-aramai/coremodels MCP server expose?
io.github.qg-aramai/coremodels exposes 13 tools: export_json_ld, fetch_json_ld_import_profiles, export_jsonschema, fetch_json_schema_import_profiles, validate_json, and 8 more. Their descriptions and schemas cost roughly 1,696 tokens of context every time the server is loaded.
Does the io.github.qg-aramai/coremodels MCP server require authentication?
Yes. io.github.qg-aramai/coremodels asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.github.qg-aramai/coremodels MCP server still maintained?
io.github.qg-aramai/coremodels is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.