# Security Recipes (remote · security-recipes.ai)

Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

- Trust score: 70/100 (medium)
- Change this week: +1
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `security-recipes.ai`: 70/100 (this document), [markdown](https://verifymcp.io/servers/stevologic-security-recipes/security-recipes.md), [page](https://verifymcp.io/servers/stevologic-security-recipes/security-recipes)

## Channel facts

- Endpoint: `https://security-recipes.ai/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 75 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 52/100
  - AI-judged instruction clarity (fair).
  - Tool/resource definitions use about 3793 tokens (~50/item across 75 items; 75 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "recipes_secure_context_eval_pack" implies "eval" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 75 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Security Recipes MCP server?

Security Recipes is a hosted endpoint at https://security-recipes.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http stevologic-security-recipes 'https://security-recipes.ai/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "stevologic-security-recipes": {
      "url": "https://security-recipes.ai/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "stevologic-security-recipes": {
      "type": "http",
      "url": "https://security-recipes.ai/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.stevologic-security-recipes]
url = "https://security-recipes.ai/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "stevologic-security-recipes": {
      "type": "remote",
      "url": "https://security-recipes.ai/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add stevologic-security-recipes --url 'https://security-recipes.ai/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  stevologic-security-recipes:
    url: "https://security-recipes.ai/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "stevologic-security-recipes": {
      "Transport": "http",
      "Url": "https://security-recipes.ai/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add stevologic-security-recipes -t streamable-http -u 'https://security-recipes.ai/mcp'
```

### Other

```json
{
  "mcpServers": {
    "stevologic-security-recipes": {
      "type": "http",
      "url": "https://security-recipes.ai/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 70, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 70, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-21 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-19 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (75)

### `recipes_server_info` (~18 tokens)

Recipes Server Info

Return MCP server metadata and source-index configuration.

### `recipes_mcp_upstream_servers` (~24 tokens)

Recipes Mcp Upstream Servers

List optional upstream MCP servers configured for this Security Recipes server.

### `recipes_mcp_servers_list` (~40 tokens)

Recipes Mcp Servers List

Search the bundled catalog of publicly documented MCP servers and ecosystems.

Input parameters:

- `availability`
- `limit` (integer)
- `query`

### `recipes_mcp_server_get` (~32 tokens)

Recipes Mcp Server Get

Return one publicly documented MCP server with official setup and safety guidance.

Input parameters:

- `server_id` (string, required)

### `recipes_mcp_upstream_tools` (~35 tokens)

Recipes Mcp Upstream Tools

List tools exposed by a configured upstream MCP server and show local allow decisions.

Input parameters:

- `server_id` (string, required)

### `recipes_mcp_upstream_call` (~46 tokens)

Recipes Mcp Upstream Call

Call an allowed read-only tool on a configured upstream MCP server.

Input parameters:

- `arguments`
- `server_id` (string, required)
- `tool_name` (string, required)

### `recipes_mcp_upstream_context` (~46 tokens)

Recipes Mcp Upstream Context

Collect bounded context from configured upstream MCP servers for a remediation query.

Input parameters:

- `max_chars` (integer)
- `query` (string, required)
- `server_ids`

### `recipes_refresh` (~25 tokens)

Recipes Refresh

Refresh the in-memory copy of recipes-index.json.

Input parameters:

- `force` (boolean)

### `recipes_search` (~55 tokens)

Recipes Search

Full-text search over security-recipes documents.

Input parameters:

- `agent`
- `facets`
- `limit`
- `min_quality`
- `query` (string, required)
- `section`
- `tags`

### `recipes_list` (~51 tokens)

Recipes List

List recipes with optional metadata filtering.

Input parameters:

- `agent`
- `facets`
- `limit`
- `min_quality`
- `section`
- `severity`
- `tags`

### `recipes_get` (~27 tokens)

Recipes Get

Get a full recipe record by slug or path.

Input parameters:

- `slug_or_path` (string, required)

### `recipes_playbooks_list` (~41 tokens)

Recipes Playbooks List

List concise remediation playbook records, optionally filtered by query or category.

Input parameters:

- `category`
- `limit` (integer)
- `query`

### `recipes_playbook_get` (~33 tokens)

Recipes Playbook Get

Get one complete remediation workflow, evidence, output, and Python contract.

Input parameters:

- `playbook_id` (string, required)

### `recipes_playbook_plan` (~41 tokens)

Recipes Playbook Plan

Build a deterministic, read-only phase, gate, and evidence checklist for a finding.

Input parameters:

- `finding`
- `playbook_id` (string, required)

### `recipes_cve_catalog_info` (~31 tokens)

Recipes Cve Catalog Info

Return the complete Medium/High/Critical CVE catalog scope, coverage, provenance, and counts.

### `recipes_cve_search` (~65 tokens)

Recipes Cve Search

Search every in-scope Medium/High/Critical CVE; use recipes_cve_get for complete details.

Input parameters:

- `kev_only` (boolean)
- `limit` (integer)
- `published_year`
- `query` (string, required)
- `severity`

### `recipes_cve_get` (~38 tokens)

Recipes Cve Get

Get evidence, recipe authority, and a bounded code/config/file change plan for one exact CVE.

Input parameters:

- `cve` (string, required)

### `recipes_quality_report` (~38 tokens)

Recipes Quality Report

Summarize recipe quality tiers and list recipes missing world-class signals.

Input parameters:

- `facet`
- `limit`
- `tier`

### `recipes_workflow_control_plane` (~31 tokens)

Recipes Workflow Control Plane

Return workflow control-plane policy for agents, reviewers, and MCP gateways.

Input parameters:

- `workflow_id`

### `recipes_mcp_gateway_policy` (~30 tokens)

Recipes Mcp Gateway Policy

Return generated MCP gateway policy for scoped tool access and runtime controls.

Input parameters:

- `workflow_id`

### `recipes_agentic_assurance_pack` (~39 tokens)

Recipes Agentic Assurance Pack

Return enterprise assurance controls, workflow evidence, and AI/Agent BOM seed.

Input parameters:

- `control_id`
- `workflow_id`

### `recipes_agent_identity_ledger` (~43 tokens)

Recipes Agent Identity Ledger

Return agent non-human identity, delegation, scope, and audit contracts.

Input parameters:

- `agent_class`
- `identity_id`
- `workflow_id`

### `recipes_agentic_entitlement_review_pack` (~63 tokens)

Recipes Agentic Entitlement Review Pack

Return expiring agent entitlement leases, access reviews, and scope evidence.

Input parameters:

- `access_mode`
- `entitlement_id`
- `identity_id`
- `namespace`
- `risk_tier`
- `workflow_id`

### `recipes_agentic_approval_receipt_pack` (~58 tokens)

Recipes Agentic Approval Receipt Pack

Return scope-bound approval receipt profiles, workflow requirements, and evidence.

Input parameters:

- `action_class`
- `approval_profile_id`
- `decision`
- `risk_tier`
- `workflow_id`

### `recipes_mcp_connector_trust_pack` (~45 tokens)

Recipes Mcp Connector Trust Pack

Return MCP connector trust tiers, controls, evidence, and workflow namespace coverage.

Input parameters:

- `connector_id`
- `namespace`
- `workflow_id`

### `recipes_mcp_connector_intake_pack` (~44 tokens)

Recipes Mcp Connector Intake Pack

Return MCP connector intake decisions, risk findings, gaps, and promotion plans.

Input parameters:

- `candidate_id`
- `decision`
- `namespace`

### `recipes_mcp_stdio_launch_boundary_pack` (~44 tokens)

Recipes Mcp Stdio Launch Boundary Pack

Return MCP STDIO launch boundaries, profiles, decisions, and evidence.

Input parameters:

- `decision`
- `launch_id`
- `profile_id`

### `recipes_mcp_authorization_conformance_pack` (~52 tokens)

Recipes Mcp Authorization Conformance Pack

Return MCP authorization conformance, scope-drift, and token-boundary evidence.

Input parameters:

- `connector_id`
- `decision`
- `namespace`
- `workflow_id`

### `recipes_mcp_elicitation_boundary_pack` (~55 tokens)

Recipes Mcp Elicitation Boundary Pack

Return MCP form-mode and URL-mode elicitation boundary evidence.

Input parameters:

- `decision`
- `mode`
- `profile_id`
- `risk_tier`
- `workflow_id`

### `recipes_mcp_tool_risk_contract` (~56 tokens)

Recipes Mcp Tool Risk Contract

Return MCP tool annotation, trust, and session-combination risk evidence.

Input parameters:

- `connector_id`
- `decision`
- `namespace`
- `risk_tier`
- `workflow_id`

### `recipes_mcp_tool_surface_drift_pack` (~56 tokens)

Recipes Mcp Tool Surface Drift Pack

Return pinned MCP tool descriptions, schemas, annotations, and drift evidence.

Input parameters:

- `decision`
- `namespace`
- `source_kind`
- `surface_id`
- `tool_name`

### `recipes_agentic_red_team_drill_pack` (~45 tokens)

Recipes Agentic Red Team Drill Pack

Return adversarial drills for agentic remediation workflows and MCP controls.

Input parameters:

- `attack_family`
- `scenario_id`
- `workflow_id`

### `recipes_agentic_red_team_replay_harness` (~59 tokens)

Recipes Agentic Red Team Replay Harness

Return replay fixtures, expected decisions, and evidence gates for red-team drills.

Input parameters:

- `attack_family`
- `replay_id`
- `scenario_id`
- `severity`
- `workflow_id`

### `recipes_agentic_readiness_scorecard` (~46 tokens)

Recipes Agentic Readiness Scorecard

Return generated scale, pilot, gate, or block decisions for agentic workflows.

Input parameters:

- `decision`
- `minimum_score`
- `workflow_id`

### `recipes_agent_capability_risk_register` (~50 tokens)

Recipes Agent Capability Risk Register

Return capability-based residual risk scores for agentic workflows.

Input parameters:

- `decision`
- `minimum_residual_score`
- `risk_tier`
- `workflow_id`

### `recipes_agent_memory_boundary_pack` (~49 tokens)

Recipes Agent Memory Boundary Pack

Return agent memory classes, workflow profiles, TTLs, and persistence decisions.

Input parameters:

- `decision`
- `memory_class_id`
- `persistent`
- `workflow_id`

### `recipes_agent_skill_supply_chain_pack` (~55 tokens)

Recipes Agent Skill Supply Chain Pack

Return agent skill provenance, permission, isolation, and supply-chain decisions.

Input parameters:

- `decision`
- `minimum_score`
- `platform`
- `risk_tier`
- `skill_id`

### `recipes_agent_handoff_boundary_pack` (~48 tokens)

Recipes Agent Handoff Boundary Pack

Return agent handoff boundary profiles, protocol controls, and workflow maps.

Input parameters:

- `decision`
- `profile_id`
- `protocol`
- `workflow_id`

### `recipes_a2a_agent_card_trust_profile` (~49 tokens)

Recipes A2A Agent Card Trust Profile

Return A2A Agent Card intake profiles, trust controls, and sample decisions.

Input parameters:

- `decision`
- `profile_id`
- `risk_tier`

### `recipes_agentic_system_bom` (~54 tokens)

Recipes Agentic System Bom

Return the Agentic System BOM for workflows, agents, identities, MCP tools, and evidence.

Input parameters:

- `agent_class`
- `component_type`
- `namespace`
- `workflow_id`

### `recipes_agentic_run_receipt_pack` (~51 tokens)

Recipes Agentic Run Receipt Pack

Return agent run receipt templates for identity, context, tools, egress, approval, and evidence.

Input parameters:

- `minimum_score`
- `receipt_id`
- `workflow_id`

### `recipes_secure_context_trust_pack` (~51 tokens)

Recipes Secure Context Trust Pack

Return context provenance, retrieval policy, source hashes, and workflow context packages.

Input parameters:

- `decision`
- `source_id`
- `trust_tier`
- `workflow_id`

### `recipes_secure_context_attestation_pack` (~57 tokens)

Recipes Secure Context Attestation Pack

Return secure-context attestation subjects, verification policy, and recertification state.

Input parameters:

- `artifact_id`
- `source_id`
- `status`
- `subject_type`
- `workflow_id`

### `recipes_secure_context_lineage_ledger` (~58 tokens)

Recipes Secure Context Lineage Ledger

Return context lineage, reuse policy, stage requirements, hashes, and workflow envelopes.

Input parameters:

- `decision`
- `reuse_class`
- `source_id`
- `stage_id`
- `workflow_id`

### `recipes_secure_context_eval_pack` (~60 tokens)

Recipes Secure Context Eval Pack

Return scenario-backed secure-context evals for retrieval, attestation, egress, and handoffs.

Input parameters:

- `decision`
- `minimum_score`
- `scenario_id`
- `scenario_type`
- `workflow_id`

### `recipes_context_poisoning_guard_pack` (~61 tokens)

Recipes Context Poisoning Guard Pack

Return context-poisoning scan results for registered secure-context sources.

Input parameters:

- `actionable_only` (boolean)
- `decision`
- `limit`
- `rule_id`
- `severity`
- `source_id`

### `recipes_context_egress_boundary_pack` (~52 tokens)

Recipes Context Egress Boundary Pack

Return context egress data classes, destination classes, and workflow boundary policy.

Input parameters:

- `data_class`
- `destination_class`
- `source_id`
- `workflow_id`

### `recipes_agentic_threat_radar` (~54 tokens)

Recipes Agentic Threat Radar

Return current source-backed agentic AI threat signals and product priorities.

Input parameters:

- `capability_id`
- `horizon`
- `minimum_score`
- `priority`
- `signal_id`

### `recipes_agentic_standards_crosswalk` (~62 tokens)

Recipes Agentic Standards Crosswalk

Return standards-to-evidence mappings for agentic AI, MCP, and prompt-injection guidance.

Input parameters:

- `capability_id`
- `control_id`
- `source_id`
- `standard_id`
- `status`

### `recipes_agentic_source_freshness_watch` (~73 tokens)

Recipes Agentic Source Freshness Watch

Return source-freshness and standards-drift evidence for SecurityRecipes.

Input parameters:

- `decision`
- `freshness_class`
- `primary_watchlist_id`
- `publisher_family`
- `source_class_family`
- `source_id`
- `watched_source_id`

### `recipes_mcp_risk_coverage_pack` (~66 tokens)

Recipes Mcp Risk Coverage Pack

Return OWASP MCP and agentic-skill risk coverage mapped to generated evidence.

Input parameters:

- `capability_id`
- `risk_id`
- `risk_tier`
- `source_id`
- `standard_id`
- `status`

### `recipes_agentic_protocol_conformance_pack` (~51 tokens)

Recipes Agentic Protocol Conformance Pack

Return MCP/A2A protocol conformance evidence and buyer-ready drift controls.

Input parameters:

- `check_id`
- `decision`
- `protocol_id`
- `source_id`

### `recipes_agentic_control_plane_blueprint` (~44 tokens)

Recipes Agentic Control Plane Blueprint

Return the acquisition-ready agentic control plane architecture and buyer evidence map.

Input parameters:

- `layer_id`
- `question_id`
- `status`

### `recipes_agentic_exposure_graph` (~77 tokens)

Recipes Agentic Exposure Graph

Return risk-ranked agentic exposure paths across context, identities, MCP tools, and evidence.

Input parameters:

- `decision`
- `identity_id`
- `minimum_score`
- `namespace`
- `node_id`
- `path_class_id`
- `path_id`
- `workflow_id`

### `recipes_agentic_posture_snapshot` (~58 tokens)

Recipes Agentic Posture Snapshot

Return the generated enterprise posture snapshot for agentic AI and MCP operations.

Input parameters:

- `finding_id`
- `minimum_score`
- `posture_decision`
- `risk_factor_id`
- `workflow_id`

### `recipes_agentic_aivss_risk_scoring_pack` (~68 tokens)

Recipes Agentic Aivss Risk Scoring Pack

Return AIVSS-aligned agentic risk scores, SLAs, evidence, and hosted MCP wedges.

Input parameters:

- `minimum_score`
- `owner`
- `runtime_default_decision`
- `scenario_id`
- `severity`

### `recipes_agentic_app_intake_pack` (~54 tokens)

Recipes Agentic App Intake Pack

Return generated agentic app launch-review profiles and decisions.

Input parameters:

- `app_id`
- `buyer_stage`
- `decision`
- `minimum_score`
- `risk_tier`

### `recipes_model_provider_routing_pack` (~61 tokens)

Recipes Model Provider Routing Pack

Return model-provider route profiles, workflow mappings, and required evidence.

Input parameters:

- `decision`
- `model_id`
- `provider_id`
- `risk_tier`
- `route_id`
- `workflow_id`

### `recipes_agentic_catastrophic_risk_annex` (~60 tokens)

Recipes Agentic Catastrophic Risk Annex

Return the severe-risk annex for high-impact agentic AI runtime decisions.

Input parameters:

- `buyer_view_id`
- `control_id`
- `impact_domain`
- `scenario_id`
- `status`

### `recipes_critical_infrastructure_secure_context_pack` (~54 tokens)

Recipes Critical Infrastructure Secure Context Pack

Return the generated critical-infrastructure secure-context profile.

Input parameters:

- `buyer_view_id`
- `control_id`
- `decision`
- `readiness_status`
- `sector_id`

### `recipes_agentic_incident_response_pack` (~51 tokens)

Recipes Agentic Incident Response Pack

Return agentic incident response classes, phases, workflow matrix, and evidence.

Input parameters:

- `decision`
- `incident_class_id`
- `severity`
- `workflow_id`

### `recipes_agentic_action_runtime_pack` (~51 tokens)

Recipes Agentic Action Runtime Pack

Return action classes, workflow action envelopes, runtime policy, and evidence.

Input parameters:

- `action_class_id`
- `decision`
- `risk_tier`
- `workflow_id`

### `recipes_agent_trust_fabric_pack` (~53 tokens)

Recipes Agent Trust Fabric Pack

Return Agent Trust Fabric dimensions, workflow tiers, source evidence, and buyer proof.

Input parameters:

- `dimension_id`
- `status`
- `trust_tier`
- `workflow_id`

### `recipes_browser_agent_boundary_pack` (~51 tokens)

Recipes Browser Agent Boundary Pack

Return browser-agent workspace classes, task profiles, controls, and evidence.

Input parameters:

- `decision`
- `risk_tier`
- `task_profile_id`
- `workspace_class_id`

### `recipes_agentic_measurement_probe_pack` (~59 tokens)

Recipes Agentic Measurement Probe Pack

Return measurement probes for agentic workflow traceability and readiness.

Input parameters:

- `class_id`
- `decision`
- `minimum_score`
- `probe_id`
- `status`
- `workflow_id`

### `recipes_agentic_telemetry_contract` (~57 tokens)

Recipes Agentic Telemetry Contract

Return the OpenTelemetry-aligned agentic telemetry and redaction contract.

Input parameters:

- `check_id`
- `decision`
- `required_attribute`
- `signal_class_id`
- `workflow_id`

### `recipes_agentic_soc_detection_pack` (~54 tokens)

Recipes Agentic Soc Detection Pack

Return SIEM-ready detections for agentic AI and MCP telemetry.

Input parameters:

- `decision`
- `event_class`
- `rule_id`
- `severity`
- `workflow_id`

### `recipes_enterprise_trust_center_export` (~54 tokens)

Recipes Enterprise Trust Center Export

Return the bundled enterprise trust-center export for buyer and platform diligence.

Input parameters:

- `category`
- `pack_id`
- `question_id`
- `section_id`
- `status`

### `recipes_secure_context_value_model` (~61 tokens)

Recipes Secure Context Value Model

Return the secure context value model for buyer, ROI, and acquisition diligence.

Input parameters:

- `driver_id`
- `question_id`
- `scenario_id`
- `segment_id`
- `status`
- `wedge_id`

### `recipes_design_partner_pilot_pack` (~67 tokens)

Recipes Design Partner Pilot Pack

Return the design partner pilot motion for buyer proof and hosted MCP validation.

Input parameters:

- `metric_id`
- `phase_id`
- `question_id`
- `risk_id`
- `segment_id`
- `status`
- `wedge_id`

### `recipes_secure_context_buyer_diligence_brief` (~64 tokens)

Recipes Secure Context Buyer Diligence Brief

Return buyer and acquirer diligence evidence for the secure context layer.

Input parameters:

- `bet_id`
- `buyer_id`
- `objection_id`
- `question_id`
- `source_id`
- `status`

### `recipes_secure_context_customer_proof_pack` (~60 tokens)

Recipes Secure Context Customer Proof Pack

Return the customer proof contract for design partner and acquisition evidence.

Input parameters:

- `claim_id`
- `event_id`
- `gate_id`
- `metric_id`
- `risk_id`
- `status`

### `recipes_secure_context_evidence_contract` (~52 tokens)

Recipes Secure Context Evidence Contract

Return the secure context evidence API and release contract.

Input parameters:

- `artifact_id`
- `channel_id`
- `endpoint_id`
- `object_type_id`
- `status`

### `recipes_hosted_mcp_readiness_pack` (~62 tokens)

Recipes Hosted Mcp Readiness Pack

Return the hosted MCP readiness plan for enterprise product rollout.

Input parameters:

- `buyer_evidence_id`
- `control_id`
- `gate_id`
- `risk_id`
- `stage_id`
- `status`

### `recipes_match_finding` (~68 tokens)

Recipes Match Finding

Heuristic matcher that suggests best-fit recipes for a security finding.

Input parameters:

- `cve`
- `ecosystem`
- `facets`
- `keywords`
- `limit` (integer)
- `min_quality`
- `package`
- `rule_id`

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/stevologic-security-recipes/security-recipes#diagnostics

## Score history

- 2026-09-28: 70
- 2026-09-27: 70
- 2026-09-26: 70
- 2026-09-25: 70
- 2026-09-24: 70
- 2026-09-23: 69
- 2026-09-22: 69
- 2026-09-21: 69
- 2026-09-20: 68
- 2026-09-19: 68
- 2026-09-18: 67
- 2026-09-17: 67
- 2026-09-16: 66
- 2026-09-15: 66
- 2026-09-14: 65
- 2026-09-13: 65
- 2026-09-12: 64
- 2026-09-11: 64
- 2026-09-10: 63
- 2026-09-09: 63
- 2026-09-08: 62
- 2026-09-07: 62
- 2026-09-06: 62
- 2026-09-05: 61
- 2026-09-04: 61
- 2026-09-03: 60
- 2026-09-02: 60
- 2026-09-01: 59
- 2026-08-31: 23
- 2026-08-30: 58

## Common questions

### What is the Security Recipes MCP server?

Security Recipes is an MCP server listed in the public MCP registry as io.github.stevologic/security-recipes. Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner. This page covers its hosted endpoint (https://security-recipes.ai/mcp).

### Is the Security Recipes MCP server safe to use?

Security Recipes scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Security Recipes MCP server expose?

Security Recipes exposes 75 tools: recipes_server_info, recipes_mcp_upstream_servers, recipes_mcp_servers_list, recipes_mcp_server_get, recipes_mcp_upstream_tools, and 70 more. Their descriptions and schemas cost roughly 3,793 tokens of context every time the server is loaded.

### Does the Security Recipes MCP server require authentication?

No. We connected to Security Recipes without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Security Recipes MCP server still maintained?

Security Recipes is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://security-recipes.ai/mcp
- Repository: https://github.com/stevologic/security-recipes.ai
- Website: https://security-recipes.ai/
- Changelog RSS feed: https://verifymcp.io/servers/stevologic-security-recipes/security-recipes.xml
- Changelog JSON feed: https://verifymcp.io/servers/stevologic-security-recipes/security-recipes.json
- HTML version of this page: https://verifymcp.io/servers/stevologic-security-recipes/security-recipes
