io.github.theluckystrike/currency-converter-ecb-rates-daily-keyless
REMOTE · MCP.ZOVO.ONE · 2 COMPONENTS · SCANNED SEP 20
Convert currencies on the daily European Central Bank reference rates. No API key, no signup.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability86
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1376 tokens (~114/item across 12 items; 10 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management37
- Stability observed for 11 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 90% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 10 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server?
io.github.theluckystrike/currency-converter-ecb-rates-daily… is a hosted endpoint at https://mcp.zovo.one/mcp/currency, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.zovo.one
claude mcp add --transport http theluckystrike-currency-converter-ecb-rates-dail 'https://mcp.zovo.one/mcp/currency'
{
"mcpServers": {
"theluckystrike-currency-converter-ecb-rates-dail": {
"url": "https://mcp.zovo.one/mcp/currency"
}
}
} {
"servers": {
"theluckystrike-currency-converter-ecb-rates-dail": {
"type": "http",
"url": "https://mcp.zovo.one/mcp/currency"
}
}
} [mcp_servers.theluckystrike-currency-converter-ecb-rates-dail] url = "https://mcp.zovo.one/mcp/currency"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"theluckystrike-currency-converter-ecb-rates-dail": {
"type": "remote",
"url": "https://mcp.zovo.one/mcp/currency",
"enabled": true
}
}
} openclaw mcp add theluckystrike-currency-converter-ecb-rates-dail --url 'https://mcp.zovo.one/mcp/currency' --transport streamable-http
mcp_servers:
theluckystrike-currency-converter-ecb-rates-dail:
url: "https://mcp.zovo.one/mcp/currency" {
"McpServers": {
"theluckystrike-currency-converter-ecb-rates-dail": {
"Transport": "http",
"Url": "https://mcp.zovo.one/mcp/currency"
}
}
} assistant mcp add theluckystrike-currency-converter-ecb-rates-dail -t streamable-http -u 'https://mcp.zovo.one/mcp/currency'
{
"mcpServers": {
"theluckystrike-currency-converter-ecb-rates-dail": {
"type": "http",
"url": "https://mcp.zovo.one/mcp/currency"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +58
- Authorization: unverified → fail ▼ security
- Transport: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- Tool “convert_many” rewrote its description, which is the text the model reads security
- Endpoint reachability: behind authorisation → reachable ▲ functional
- MCP protocol: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Schema quality: unverified → 100 ▲ functional
- Stability: unverified → 0.30 ▲ functional
- Server version: 0.21.0 → 0.22.0 functional
- 17 Sept 26 −57
- Endpoint reachability: reachable → behind authorisation ▼ security
- Authorization: fail → unverified ▼ security
- Stability: 0.23 → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Schema quality: 100 → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
- Tool “license_activate” rewrote its description, which is the text the model reads security
- New prompt “upgrade_to_pro” functional
- New resource “pricing” functional
- 10 Sept 26 0
- Tool “license_activate” rewrote its description, which is the text the model reads security
- Tool “currencies_list” rewrote its description, which is the text the model reads security
- Tool “convert_many” rewrote its description, which is the text the model reads security
- Tool “cache_status” rewrote its description, which is the text the model reads security
- Tool “rates_latest” rewrote its description, which is the text the model reads security
- Tool “license_status” rewrote its description, which is the text the model reads security
- Stability: unverified → 0.03 ▲ functional
- “license_activate” reworded the description of “key” cosmetic
- 9 Sept 26 +43
- Transport: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- First check of Judged manipulation: pass security
- Authorization: Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. security
- MCP protocol: unverified → pass ▲ functional
- Schema quality: unverified → 100 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 90 functional
- First check of Schema quality: excellent functional
- First check of Destructive annotations: pass functional
- First check of Schema quality: fail functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.zovo.one/mcp/currency
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=zovo.one | CN=WE1,O=Google Trust Services,C=US | 2 Sept 2026 | 1 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | ef74739bd6e575bb13db69661e215324 |
| SANs: zovo.one, mcp.zovo.one, *.mcp.zovo.one | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.zovo.one. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| one. | present | 64939 | 8 | Verified |
| zovo.one. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="mcp.zovo.one", error="invalid_token"
Bearer realm="mcp.zovo.one", error="invalid_token" | Header | Value |
|---|---|
| strict-transport-security | max-age=15552000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.zovo.one/mcp/currency | Verified | 200 | |
| http (plaintext) | http://mcp.zovo.one/mcp/currency | HTTPS enforced | 301 | https://mcp.zovo.one/mcp/currency |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cache_status Rate cache status ~54
Report the ECB rate cache here: which dates are held, how old they are and when they refresh. Reads only. Check it before trusting a rate after time offline; a cache that no longer parses is quarantined and named.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
convert Convert an amount ~244
Call this tool to convert an amount between any two ECB-quoted currencies, today or on a past date. Returns the converted amount, the cross rate to 6 decimals, the rounding applied and the rate date used.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount in major units of the from currency, e.g. 100 or 12.34 |
| date | string | – | ISO date YYYY-MM-DD. Omit for the latest published rate. A weekend or TARGET holiday falls back to the last rate published on or before it, and the answer says so. A date older than the free 90-day w… |
| from | string | yes | Currency the amount is in. Cross rates go through the euro, the only pair the ECB publishes |
| to | string | – | Currency to convert into; defaults to the shared business profile's default_currency, so you are never asked what currency you invoice in. The result is rounded once, at the end, to this currency's o… |
No output schema declared.
No examples provided.
convert_many Convert one amount into several currencies ~86
Convert one amount into many currencies off the SAME ECB rate date, each rounded to its own minor units. For several lines at once (mixed-currency invoice lines), call it once per line: every line then shares one rate date. Unknown targets are listed, never failed.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | – |
| from | string | yes | – |
| to | array | yes | Target currencies |
No output schema declared.
No examples provided.
currencies_list Currencies the ECB quotes ~48
Every currency in the ECB daily set with its rate against the euro and its decimal places. This is the whole domain: a code not on this list cannot be converted, quoted or historised here.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
fx_rates_for FX rates in the shape expense-tracker wants ~160
Call this tool when a rebill or an invoice spans more than one currency, instead of asking the user for rates. Returns the fx_rates object expense_to_invoice takes, plus the rate date to write on the invoice.
| Name | Type | Req | Description |
|---|---|---|---|
| currencies | array | yes | The other currencies present, e.g. ["EUR", "GBP"]. Direction: each returned rate means 1 unit of that key = X units of the target, so {"EUR": 1.08} is 1 EUR = 1.08 of the target. The target needs no… |
| target | string | – | The currency the invoice will be issued in; defaults to the shared business profile's default_currency. Pass it on as target_currency alongside the fx_rates object |
No output schema declared.
No examples provided.
license_activate Activate license ~76
Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | License key from checkout, MCPL1.<payload>.<signature> |
No output schema declared.
No examples provided.
license_status License status ~55
Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
rate_history Rate history for a pair ~213
Call this tool for the ECB rate of one currency pair across a window. Returns one row per published day plus the min, max, average and the change. A window wider than the free 90 days is shortened, not refused.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Trailing window in calendar days, default 30. Only TARGET business days carry a rate, so 30 days holds about 21 rows. Free reads up to 90 days back; Pro reads the whole series back to 1999-01-04 |
| from | string | yes | Base currency of the pair |
| from_date | string | – | ISO date, inclusive. Overrides days. Free is limited to the last 90 days |
| max_rows | integer | – | Cap the table, default 200. min/max/avg still cover the whole window |
| to | string | yes | Quote currency of the pair. Each row is 1 from = X to |
| to_date | string | – | ISO date, inclusive, default today |
No output schema declared.
No examples provided.
rate_on Rate on a given date ~231
Call this tool for the ECB rate of one pair on one date. Returns both directions and the rate date, so a reciprocal is never reported as the published figure. A date beyond the free window is shortened, never refused.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | ISO date YYYY-MM-DD. If the ECB published nothing that day - every weekend, 1 January, Good Friday, Easter Monday, 1 May, 25 and 26 December - the last rate published on or before it is returned and… |
| from | string | yes | Base currency. The ECB quotes every currency per 1 euro, so "the ECB rate for USD" is from EUR to USD, not the other way round; invert only if the user asked for the inverse |
| to | string | yes | Quote currency. The rate returned is 1 from = X to |
No output schema declared.
No examples provided.
rates_latest Latest ECB reference rates ~138
Call this tool for the latest ECB daily reference rates against any base: 1.0812 for USD means 1 base = 1.0812 USD. Crosses go through the euro. Returns the ECB rate date and the cache age.
| Name | Type | Req | Description |
|---|---|---|---|
| base | string | – | Base currency; defaults to the shared business profile's default_currency, else EUR. A rate of 1.0812 for USD means 1 base = 1.0812 USD. Cross rates go through the euro, the only pair the ECB publish… |
| quotes | array | – | Only these currencies, at most 200. Omit for all of them |
No output schema declared.
No examples provided.
What is the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server?
io.github.theluckystrike/currency-converter-ecb-rates-daily… is an MCP server listed in the public MCP registry as io.github.theluckystrike/currency-converter-ecb-rates-daily…. Convert currencies on the daily European Central Bank reference rates. No API key, no signup. This page covers its hosted endpoint (https://mcp.zovo.one/mcp/currency).
Is the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server safe to use?
io.github.theluckystrike/currency-converter-ecb-rates-daily… scores 84 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server expose?
io.github.theluckystrike/currency-converter-ecb-rates-daily… exposes 10 tools: rates_latest, convert, convert_many, fx_rates_for, rate_history, and 5 more. Their descriptions and schemas cost roughly 1,305 tokens of context every time the server is loaded.
Does the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server require authentication?
Yes. io.github.theluckystrike/currency-converter-ecb-rates-daily… asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.github.theluckystrike/currency-converter-ecb-rates-daily… MCP server still maintained?
io.github.theluckystrike/currency-converter-ecb-rates-daily… is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.