TrueFixR + AtlasCast
REMOTE · MCP.ATLASUNITED.IO · SCANNED SEP 28
Address-level storm event data and forecasted property risk API for AI agents
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2403 tokens (~400/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability check failed: schema churn in the 4 days we've observed: 4 tool removals, 0 breaking changes, 0 auth/transport breaks, 6 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the TrueFixR + AtlasCast MCP server?
TrueFixR + AtlasCast is a hosted endpoint at https://mcp.atlasunited.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.atlasunited.io
claude mcp add --transport http truefixr-atlascast-truefixr 'https://mcp.atlasunited.io/mcp'
{
"mcpServers": {
"truefixr-atlascast-truefixr": {
"url": "https://mcp.atlasunited.io/mcp"
}
}
} {
"servers": {
"truefixr-atlascast-truefixr": {
"type": "http",
"url": "https://mcp.atlasunited.io/mcp"
}
}
} [mcp_servers.truefixr-atlascast-truefixr] url = "https://mcp.atlasunited.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"truefixr-atlascast-truefixr": {
"type": "remote",
"url": "https://mcp.atlasunited.io/mcp",
"enabled": true
}
}
} openclaw mcp add truefixr-atlascast-truefixr --url 'https://mcp.atlasunited.io/mcp' --transport streamable-http
mcp_servers:
truefixr-atlascast-truefixr:
url: "https://mcp.atlasunited.io/mcp" {
"McpServers": {
"truefixr-atlascast-truefixr": {
"Transport": "http",
"Url": "https://mcp.atlasunited.io/mcp"
}
}
} assistant mcp add truefixr-atlascast-truefixr -t streamable-http -u 'https://mcp.atlasunited.io/mcp'
{
"mcpServers": {
"truefixr-atlascast-truefixr": {
"type": "http",
"url": "https://mcp.atlasunited.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +10
- Judged manipulation: unverified → pass ▲ security
- Tool “get_risk_forecast” rewrote its description, which is the text the model reads security
- Schema quality: unverified → excellent ▲ functional
- “get_current_weather” added an optional parameter “hours_ahead” cosmetic
- “get_weather_data” added an optional parameter “hours_ahead” cosmetic
- 26 Sept 26 −12
- Judged manipulation: pass → unverified ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “get_address_report” rewrote its description, which is the text the model reads security
- Tool “get_weather_data” rewrote its description, which is the text the model reads security
- Schema quality: 277 → 385 ▼ functional
- Schema quality: excellent → unverified ▼ functional
- New tool “get_current_weather” functional
- New tool “get_property_storm_history_report” functional
- “get_risk_forecast” added an optional parameter “peril” cosmetic
- “get_risk_forecast” added an optional parameter “window” cosmetic
- “get_weather_data” added an optional parameter “category” cosmetic
- “get_weather_data” added an optional parameter “date_of_loss” cosmetic
- “get_weather_data” added an optional parameter “details” cosmetic
- “get_weather_data” added an optional parameter “kind” cosmetic
- “get_weather_data” added an optional parameter “limit” cosmetic
- “get_weather_data” added an optional parameter “months” cosmetic
- “get_weather_data” added an optional parameter “radius_mi” cosmetic
- “get_weather_data” added an optional parameter “window” cosmetic
- “get_storm_history” reworded the description of “peril” cosmetic
- “get_weather_data” reworded the description of “peril” cosmetic
- Tool “get_address_report” changed its title: Single address report → Property snapshot (365-day storm history + forecast) cosmetic
- 25 Sept 26 +1
- Stability: unverified → fail ▼ security
- A breaking change shipped without a version bump: still 2.5.1 ▼ security
- Tool “get_hazard_forecast” was removed ▼ security
- Tool “get_storm_preview” was removed ▼ security
- Tool “lookup_address_hazard” was removed ▼ security
- Tool “query_weather_data” was removed ▼ security
- Schema quality: good → excellent functional
- New tool “get_address_report” functional
- New tool “get_risk_forecast” functional
- New tool “get_storm_history” functional
- New tool “get_weather_data” functional
- 24 Sept 26 62
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://mcp.atlasunited.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.atlasunited.io | CN=YE1,O=Let's Encrypt,C=US | 23 Sept 2026 | 22 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5bd7aa7b507b74f89d945ed2850f21d0e9e |
| SANs: mcp.atlasunited.io | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.atlasunited.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| atlasunited.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.atlasunited.io/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.atlasunited.io/mcp | HTTPS enforced | 308 | https://mcp.atlasunited.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_address_report Property snapshot (365-day storm history + forecast) ~146
ONE property, 365-day snapshot: past storm history (up to 365 days back, not the full archive) plus current forecast risk. Give an address with county+state, or lat/lon. For the FULL 2003-present multi-peril archive use get_property_storm_history_report instead -- this tool's real history window is capped at 365 days.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Street address. |
| county | string | – | County name without the word 'County', e.g. Dallas. |
| lat | number | – | Latitude. |
| lon | number | – | Longitude. |
| state | string | – | 2-letter US state code, e.g. TX. |
No output schema declared.
No examples provided.
get_current_weather Live point weather (TrackCast) ~238
Real live point-in-time weather for ANY US coordinate -- 164 real HRRR-based fields, hourly refresh, plus MRMS precip nowcast and NWS severe alerts. FREE by default: the lean 10-field response needs no account. details=true returns the full 164-field pull, billed $0.0002/call (not per-address).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Street address. Real server-side geocoding -- no separate geocoding step needed. |
| details | boolean | – | true = full 164-field pull, $0.0002/call, requires an API key or x402 payment. false (default) = free 10-field lean response. |
| hours_ahead | integer | – | Real HRRR forecast 0-48h out instead of current conditions -- snaps to the nearest real available forecast hour, response's forecast_hour_used says exactly what you got. |
| lat | number | – | Latitude, alternative to address. |
| lon | number | – | Longitude, alternative to address. |
| x_payment | string | – | Optional signed x402 payment payload, used instead of an API key when details=true. |
No output schema declared.
No examples provided.
get_property_storm_history_report Full property storm history (2003-present, all perils) ~286
The FULL real archive for one property: hail, wind, flood/heavy rain, lightning, and tornado, 2003 to present, in one report -- not the 365-day snapshot (use get_address_report for that). Free preview shows the real report-line count and exact price before anything is paid. Paid report is billed per real report line: $0.05/line, $10.00 minimum per report. Optional date_of_loss anchors the report around one specific date with a real yes/no on whether weather data supports a loss that day, plus the real events immediately before and after it.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Street address. Real server-side geocoding -- no separate geocoding step needed. |
| addresses | boolean | – | false = free preview (line count + price). true = the real full report -- requires the user's own Atlas United Data API account key, or an x402 payment. |
| date_of_loss | string | – | Optional, YYYY-MM-DD. Anchors the report around this date. |
| lat | number | – | Latitude, alternative to address. |
| lon | number | – | Longitude, alternative to address. |
| radius_mi | number | – | Search radius in miles. Default 5, max 25. |
| x_payment | string | – | Optional signed x402 payment payload, used instead of an API key. |
No output schema declared.
No examples provided.
get_risk_forecast Storm risk forecast ~139
FREE AtlasCast forecast for a county: severe weather risk for future leads over the coming days, with county risk grades and property exposure. Forecast risk, not storms that already happened. Refreshed several times a day from NOAA models.
| Name | Type | Req | Description |
|---|---|---|---|
| county | string | yes | County name without the word 'County', e.g. Dallas. |
| peril | string | – | Narrows the forecast to one storm type -- check a free preview's storm_types for real values available in this window. |
| state | string | yes | 2-letter US state code, e.g. TX. |
| window | string | – | Forecast window. Default 24h. |
No output schema declared.
No examples provided.
get_storm_history Past storm history ~232
FREE preview of reported and radar-detected past storm events (hail, wind, tornado, flooding) for a county: event counts, storm types, measured severities and repeat-hit properties.
| Name | Type | Req | Description |
|---|---|---|---|
| county | string | yes | County name without the word 'County', e.g. Dallas. |
| days | integer | – | Look-back window in days (up to 365). |
| min_severity | number | – | Minimum severity, e.g. 1.75 for golf-ball hail. |
| peril | string | – | Storm/risk type filter. Used by dataset=storms and dataset=risk (narrows to one storm type -- use the exact names returned under storm_types in a free preview) and by dataset=at_risk (narrows to one… |
| state | string | yes | 2-letter US state code, e.g. TX. |
No output schema declared.
No examples provided.
get_weather_data Get weather data (advanced / multi-county) ~1,050
General-purpose query -- supports every real dataset (see the enum below). Prefer the dedicated convenience tools when they fit: get_storm_history (one county's past storms), get_risk_forecast (one county's forecast), get_address_report (one property's 365-day snapshot), get_property_storm_history_report (one property's full 2003-present multi-peril archive), get_current_weather (live point weather). Use THIS tool directly for 'coverage' (county coverage check), 'facilities', 'wildfire', 'at_risk', 'daily', or a 'counties' multi-county rollup (comma-separated, max 15), or any parameter combination the dedicated tools don't expose (radius_mi, date_of_loss, window, months, category, limit, kind, details). Call with no arguments to get the full API menu. addresses=false (default) is a FREE preview -- shape varies by dataset (counts/severities for storms, line count + price for history, full field response for weather). addresses=true (or details=true for weather) returns the real paid data and requires the user's own Atlas United Data API account key, or an x402 crypto payment. HARD RULE when called with no arguments: this returns the full menu. Output that entire raw response back to the user verbatim -- every dataset, every field, every example. Do not summarize or paraphrase. A shortened version is wrong even if it looks complete.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Street address, for dataset=address. |
| addresses | boolean | – | false = free preview. true = address-level records -- requires EITHER the user's own Atlas United Data API account key (Authorization header) OR an x402 payment (see x_payment param below); no accoun… |
| category | string | – | dataset=facilities only. Facility category filter. |
| counties | string | – | Comma-separated county names (max 15) plus state, for a multi-county rollup. Free preview only. |
| county | string | – | County name without the word 'County', e.g. Dallas. |
| dataset | string | – | Target dataset. Default storms. |
| date_of_loss | string | – | dataset=history only. YYYY-MM-DD. Anchors the report around this date -- returns a real yes/no on whether weather data supports a loss that day, plus real events immediately before and after it. |
| days | integer | – | Look-back window in days where supported. |
| details | boolean | – | dataset=weather only. true = full 164-field pull, billed $0.0002/call. false (default) = free 10-field lean response, no account needed. Equivalent to addresses=true for this dataset. |
| format | string | – | Response format. json (default) or csv. |
| hours_ahead | integer | – | dataset=weather only. Real HRRR forecast 0-48h out instead of current conditions -- snaps to the nearest real available forecast hour, response's forecast_hour_used says exactly what you got. |
| kind | string | – | dataset=at_risk only. Narrows to 'schools' or 'businesses'. |
| lat | number | – | Latitude in decimal degrees. |
| limit | integer | – | Max records on the real paid pull (default 2000, real per-dataset caps still apply -- e.g. storms caps at 5000). |
| lon | number | – | Longitude in decimal degrees. |
| max_severity | number | – | Maximum measured severity. |
| min_severity | number | – | Minimum measured severity (e.g. 1.5 = 1.5 inch hail). Check severity_by_type in a preview for the real unit. |
| months | integer | – | dataset=storms only. Returns month-bucketed history totals instead of individual leads, for the last N months. |
| peril | string | – | Storm/risk type filter. Used by dataset=storms and dataset=risk (narrows to one storm type -- use the exact names returned under storm_types in a free preview) and by dataset=at_risk (narrows to one… |
| radius_mi | number | – | dataset=history or dataset=weather only. Search radius in miles. Default 5, max 25. |
| state | string | – | 2-letter US state code, e.g. TX. |
| window | string | – | dataset=risk only. Forecast window. Default 24h. |
| x_payment | string | – | Optional. A signed x402 protocol payment payload (base64), used instead of an API key to pay for ONE address-level pull in USDC on Base network. If addresses=true and neither an API key nor x_payment… |
No output schema declared.
No examples provided.
What is the TrueFixR + AtlasCast MCP server?
TrueFixR + AtlasCast is an MCP server listed in the public MCP registry as io.github.truefixr/atlascast-truefixr. Address-level storm event data and forecasted property risk API for AI agents. This page covers its hosted endpoint (https://mcp.atlasunited.io/mcp).
Is the TrueFixR + AtlasCast MCP server safe to use?
TrueFixR + AtlasCast scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the TrueFixR + AtlasCast MCP server expose?
TrueFixR + AtlasCast exposes 6 tools: get_weather_data, get_storm_history, get_risk_forecast, get_property_storm_history_report, get_current_weather, get_address_report. Their descriptions and schemas cost roughly 2,091 tokens of context every time the server is loaded.
Does the TrueFixR + AtlasCast MCP server require authentication?
No. We connected to TrueFixR + AtlasCast without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the TrueFixR + AtlasCast MCP server still maintained?
TrueFixR + AtlasCast is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.