Security Recipes
REMOTE · SECURITY-RECIPES.AI · SCANNED SEP 28
Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 75 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability52
- AI-judged instruction clarity (fair).Partial
- Tool/resource definitions use about 3793 tokens (~50/item across 75 items; 75 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "recipes_secure_context_eval_pack" implies "eval" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 75 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Security Recipes MCP server?
Security Recipes is a hosted endpoint at https://security-recipes.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · security-recipes.ai
claude mcp add --transport http stevologic-security-recipes 'https://security-recipes.ai/mcp'
{
"mcpServers": {
"stevologic-security-recipes": {
"url": "https://security-recipes.ai/mcp"
}
}
} {
"servers": {
"stevologic-security-recipes": {
"type": "http",
"url": "https://security-recipes.ai/mcp"
}
}
} [mcp_servers.stevologic-security-recipes] url = "https://security-recipes.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"stevologic-security-recipes": {
"type": "remote",
"url": "https://security-recipes.ai/mcp",
"enabled": true
}
}
} openclaw mcp add stevologic-security-recipes --url 'https://security-recipes.ai/mcp' --transport streamable-http
mcp_servers:
stevologic-security-recipes:
url: "https://security-recipes.ai/mcp" {
"McpServers": {
"stevologic-security-recipes": {
"Transport": "http",
"Url": "https://security-recipes.ai/mcp"
}
}
} assistant mcp add stevologic-security-recipes -t streamable-http -u 'https://security-recipes.ai/mcp'
{
"mcpServers": {
"stevologic-security-recipes": {
"type": "http",
"url": "https://security-recipes.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://security-recipes.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=security-recipes.ai | CN=YE1,O=Let's Encrypt,C=US | 9 Sept 2026 | 8 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 672676e2220025b3a8f09b2e97a6b344118 |
| SANs: security-recipes.ai | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of security-recipes.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| security-recipes.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://security-recipes.ai/mcp | Verified | 200 | |
| http (plaintext) | http://security-recipes.ai/mcp | HTTPS enforced | 308 | https://security-recipes.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
recipes_a2a_agent_card_trust_profile Recipes A2A Agent Card Trust Profile ~49
Return A2A Agent Card intake profiles, trust controls, and sample decisions.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| profile_id | – | – | – |
| risk_tier | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_capability_risk_register Recipes Agent Capability Risk Register ~50
Return capability-based residual risk scores for agentic workflows.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| minimum_residual_score | – | – | – |
| risk_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_handoff_boundary_pack Recipes Agent Handoff Boundary Pack ~48
Return agent handoff boundary profiles, protocol controls, and workflow maps.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| profile_id | – | – | – |
| protocol | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_identity_ledger Recipes Agent Identity Ledger ~43
Return agent non-human identity, delegation, scope, and audit contracts.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_class | – | – | – |
| identity_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_memory_boundary_pack Recipes Agent Memory Boundary Pack ~49
Return agent memory classes, workflow profiles, TTLs, and persistence decisions.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| memory_class_id | – | – | – |
| persistent | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_skill_supply_chain_pack Recipes Agent Skill Supply Chain Pack ~55
Return agent skill provenance, permission, isolation, and supply-chain decisions.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| minimum_score | – | – | – |
| platform | – | – | – |
| risk_tier | – | – | – |
| skill_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agent_trust_fabric_pack Recipes Agent Trust Fabric Pack ~53
Return Agent Trust Fabric dimensions, workflow tiers, source evidence, and buyer proof.
| Name | Type | Req | Description |
|---|---|---|---|
| dimension_id | – | – | – |
| status | – | – | – |
| trust_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_action_runtime_pack Recipes Agentic Action Runtime Pack ~51
Return action classes, workflow action envelopes, runtime policy, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| action_class_id | – | – | – |
| decision | – | – | – |
| risk_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_aivss_risk_scoring_pack Recipes Agentic Aivss Risk Scoring Pack ~68
Return AIVSS-aligned agentic risk scores, SLAs, evidence, and hosted MCP wedges.
| Name | Type | Req | Description |
|---|---|---|---|
| minimum_score | – | – | – |
| owner | – | – | – |
| runtime_default_decision | – | – | – |
| scenario_id | – | – | – |
| severity | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_app_intake_pack Recipes Agentic App Intake Pack ~54
Return generated agentic app launch-review profiles and decisions.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| buyer_stage | – | – | – |
| decision | – | – | – |
| minimum_score | – | – | – |
| risk_tier | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_approval_receipt_pack Recipes Agentic Approval Receipt Pack ~58
Return scope-bound approval receipt profiles, workflow requirements, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| action_class | – | – | – |
| approval_profile_id | – | – | – |
| decision | – | – | – |
| risk_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_assurance_pack Recipes Agentic Assurance Pack ~39
Return enterprise assurance controls, workflow evidence, and AI/Agent BOM seed.
| Name | Type | Req | Description |
|---|---|---|---|
| control_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_catastrophic_risk_annex Recipes Agentic Catastrophic Risk Annex ~60
Return the severe-risk annex for high-impact agentic AI runtime decisions.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer_view_id | – | – | – |
| control_id | – | – | – |
| impact_domain | – | – | – |
| scenario_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_control_plane_blueprint Recipes Agentic Control Plane Blueprint ~44
Return the acquisition-ready agentic control plane architecture and buyer evidence map.
| Name | Type | Req | Description |
|---|---|---|---|
| layer_id | – | – | – |
| question_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_entitlement_review_pack Recipes Agentic Entitlement Review Pack ~63
Return expiring agent entitlement leases, access reviews, and scope evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| access_mode | – | – | – |
| entitlement_id | – | – | – |
| identity_id | – | – | – |
| namespace | – | – | – |
| risk_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_exposure_graph Recipes Agentic Exposure Graph ~77
Return risk-ranked agentic exposure paths across context, identities, MCP tools, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| identity_id | – | – | – |
| minimum_score | – | – | – |
| namespace | – | – | – |
| node_id | – | – | – |
| path_class_id | – | – | – |
| path_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_incident_response_pack Recipes Agentic Incident Response Pack ~51
Return agentic incident response classes, phases, workflow matrix, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| incident_class_id | – | – | – |
| severity | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_measurement_probe_pack Recipes Agentic Measurement Probe Pack ~59
Return measurement probes for agentic workflow traceability and readiness.
| Name | Type | Req | Description |
|---|---|---|---|
| class_id | – | – | – |
| decision | – | – | – |
| minimum_score | – | – | – |
| probe_id | – | – | – |
| status | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_posture_snapshot Recipes Agentic Posture Snapshot ~58
Return the generated enterprise posture snapshot for agentic AI and MCP operations.
| Name | Type | Req | Description |
|---|---|---|---|
| finding_id | – | – | – |
| minimum_score | – | – | – |
| posture_decision | – | – | – |
| risk_factor_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_protocol_conformance_pack Recipes Agentic Protocol Conformance Pack ~51
Return MCP/A2A protocol conformance evidence and buyer-ready drift controls.
| Name | Type | Req | Description |
|---|---|---|---|
| check_id | – | – | – |
| decision | – | – | – |
| protocol_id | – | – | – |
| source_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_readiness_scorecard Recipes Agentic Readiness Scorecard ~46
Return generated scale, pilot, gate, or block decisions for agentic workflows.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| minimum_score | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_red_team_drill_pack Recipes Agentic Red Team Drill Pack ~45
Return adversarial drills for agentic remediation workflows and MCP controls.
| Name | Type | Req | Description |
|---|---|---|---|
| attack_family | – | – | – |
| scenario_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_red_team_replay_harness Recipes Agentic Red Team Replay Harness ~59
Return replay fixtures, expected decisions, and evidence gates for red-team drills.
| Name | Type | Req | Description |
|---|---|---|---|
| attack_family | – | – | – |
| replay_id | – | – | – |
| scenario_id | – | – | – |
| severity | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_run_receipt_pack Recipes Agentic Run Receipt Pack ~51
Return agent run receipt templates for identity, context, tools, egress, approval, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| minimum_score | – | – | – |
| receipt_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_soc_detection_pack Recipes Agentic Soc Detection Pack ~54
Return SIEM-ready detections for agentic AI and MCP telemetry.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| event_class | – | – | – |
| rule_id | – | – | – |
| severity | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_source_freshness_watch Recipes Agentic Source Freshness Watch ~73
Return source-freshness and standards-drift evidence for SecurityRecipes.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| freshness_class | – | – | – |
| primary_watchlist_id | – | – | – |
| publisher_family | – | – | – |
| source_class_family | – | – | – |
| source_id | – | – | – |
| watched_source_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_standards_crosswalk Recipes Agentic Standards Crosswalk ~62
Return standards-to-evidence mappings for agentic AI, MCP, and prompt-injection guidance.
| Name | Type | Req | Description |
|---|---|---|---|
| capability_id | – | – | – |
| control_id | – | – | – |
| source_id | – | – | – |
| standard_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_system_bom Recipes Agentic System Bom ~54
Return the Agentic System BOM for workflows, agents, identities, MCP tools, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_class | – | – | – |
| component_type | – | – | – |
| namespace | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_telemetry_contract Recipes Agentic Telemetry Contract ~57
Return the OpenTelemetry-aligned agentic telemetry and redaction contract.
| Name | Type | Req | Description |
|---|---|---|---|
| check_id | – | – | – |
| decision | – | – | – |
| required_attribute | – | – | – |
| signal_class_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_agentic_threat_radar Recipes Agentic Threat Radar ~54
Return current source-backed agentic AI threat signals and product priorities.
| Name | Type | Req | Description |
|---|---|---|---|
| capability_id | – | – | – |
| horizon | – | – | – |
| minimum_score | – | – | – |
| priority | – | – | – |
| signal_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_browser_agent_boundary_pack Recipes Browser Agent Boundary Pack ~51
Return browser-agent workspace classes, task profiles, controls, and evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| risk_tier | – | – | – |
| task_profile_id | – | – | – |
| workspace_class_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_context_egress_boundary_pack Recipes Context Egress Boundary Pack ~52
Return context egress data classes, destination classes, and workflow boundary policy.
| Name | Type | Req | Description |
|---|---|---|---|
| data_class | – | – | – |
| destination_class | – | – | – |
| source_id | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_context_poisoning_guard_pack Recipes Context Poisoning Guard Pack ~61
Return context-poisoning scan results for registered secure-context sources.
| Name | Type | Req | Description |
|---|---|---|---|
| actionable_only | boolean | – | – |
| decision | – | – | – |
| limit | – | – | – |
| rule_id | – | – | – |
| severity | – | – | – |
| source_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_critical_infrastructure_secure_context_pack Recipes Critical Infrastructure Secure Context Pack ~54
Return the generated critical-infrastructure secure-context profile.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer_view_id | – | – | – |
| control_id | – | – | – |
| decision | – | – | – |
| readiness_status | – | – | – |
| sector_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_cve_catalog_info Recipes Cve Catalog Info ~31
Return the complete Medium/High/Critical CVE catalog scope, coverage, provenance, and counts.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
recipes_cve_get Recipes Cve Get ~38
Get evidence, recipe authority, and a bounded code/config/file change plan for one exact CVE.
| Name | Type | Req | Description |
|---|---|---|---|
| cve | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_cve_search Recipes Cve Search ~65
Search every in-scope Medium/High/Critical CVE; use recipes_cve_get for complete details.
| Name | Type | Req | Description |
|---|---|---|---|
| kev_only | boolean | – | – |
| limit | integer | – | – |
| published_year | – | – | – |
| query | string | yes | – |
| severity | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_design_partner_pilot_pack Recipes Design Partner Pilot Pack ~67
Return the design partner pilot motion for buyer proof and hosted MCP validation.
| Name | Type | Req | Description |
|---|---|---|---|
| metric_id | – | – | – |
| phase_id | – | – | – |
| question_id | – | – | – |
| risk_id | – | – | – |
| segment_id | – | – | – |
| status | – | – | – |
| wedge_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_enterprise_trust_center_export Recipes Enterprise Trust Center Export ~54
Return the bundled enterprise trust-center export for buyer and platform diligence.
| Name | Type | Req | Description |
|---|---|---|---|
| category | – | – | – |
| pack_id | – | – | – |
| question_id | – | – | – |
| section_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_get Recipes Get ~27
Get a full recipe record by slug or path.
| Name | Type | Req | Description |
|---|---|---|---|
| slug_or_path | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_hosted_mcp_readiness_pack Recipes Hosted Mcp Readiness Pack ~62
Return the hosted MCP readiness plan for enterprise product rollout.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer_evidence_id | – | – | – |
| control_id | – | – | – |
| gate_id | – | – | – |
| risk_id | – | – | – |
| stage_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_list Recipes List ~51
List recipes with optional metadata filtering.
| Name | Type | Req | Description |
|---|---|---|---|
| agent | – | – | – |
| facets | – | – | – |
| limit | – | – | – |
| min_quality | – | – | – |
| section | – | – | – |
| severity | – | – | – |
| tags | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_match_finding Recipes Match Finding ~68
Heuristic matcher that suggests best-fit recipes for a security finding.
| Name | Type | Req | Description |
|---|---|---|---|
| cve | – | – | – |
| ecosystem | – | – | – |
| facets | – | – | – |
| keywords | – | – | – |
| limit | integer | – | – |
| min_quality | – | – | – |
| package | – | – | – |
| rule_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_authorization_conformance_pack Recipes Mcp Authorization Conformance Pack ~52
Return MCP authorization conformance, scope-drift, and token-boundary evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| connector_id | – | – | – |
| decision | – | – | – |
| namespace | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_connector_intake_pack Recipes Mcp Connector Intake Pack ~44
Return MCP connector intake decisions, risk findings, gaps, and promotion plans.
| Name | Type | Req | Description |
|---|---|---|---|
| candidate_id | – | – | – |
| decision | – | – | – |
| namespace | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_connector_trust_pack Recipes Mcp Connector Trust Pack ~45
Return MCP connector trust tiers, controls, evidence, and workflow namespace coverage.
| Name | Type | Req | Description |
|---|---|---|---|
| connector_id | – | – | – |
| namespace | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_elicitation_boundary_pack Recipes Mcp Elicitation Boundary Pack ~55
Return MCP form-mode and URL-mode elicitation boundary evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | – | – | – |
| mode | – | – | – |
| profile_id | – | – | – |
| risk_tier | – | – | – |
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_gateway_policy Recipes Mcp Gateway Policy ~30
Return generated MCP gateway policy for scoped tool access and runtime controls.
| Name | Type | Req | Description |
|---|---|---|---|
| workflow_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_risk_coverage_pack Recipes Mcp Risk Coverage Pack ~66
Return OWASP MCP and agentic-skill risk coverage mapped to generated evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| capability_id | – | – | – |
| risk_id | – | – | – |
| risk_tier | – | – | – |
| source_id | – | – | – |
| standard_id | – | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
recipes_mcp_server_get Recipes Mcp Server Get ~32
Return one publicly documented MCP server with official setup and safety guidance.
| Name | Type | Req | Description |
|---|---|---|---|
| server_id | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
What is the Security Recipes MCP server?
Security Recipes is an MCP server listed in the public MCP registry as io.github.stevologic/security-recipes. Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner. This page covers its hosted endpoint (https://security-recipes.ai/mcp).
Is the Security Recipes MCP server safe to use?
Security Recipes scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Security Recipes MCP server expose?
Security Recipes exposes 75 tools: recipes_server_info, recipes_mcp_upstream_servers, recipes_mcp_servers_list, recipes_mcp_server_get, recipes_mcp_upstream_tools, and 70 more. Their descriptions and schemas cost roughly 3,793 tokens of context every time the server is loaded.
Does the Security Recipes MCP server require authentication?
No. We connected to Security Recipes without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Security Recipes MCP server still maintained?
Security Recipes is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.