# Security Mcp (remote · security-mcp.mcpize.run)

MCP server for Security

- Trust score: 20/100 (low)
- Change this week: +7
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `security-mcp.mcpize.run`: 20/100 (this document), [markdown](https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp.md), [page](https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp)

## Channel facts

- Endpoint: `https://security-mcp.mcpize.run/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 51/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
  - HTTPS check failed: the endpoint is reachable over plaintext HTTP.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 5 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add --transport http varvararatta-security-mcp https://security-mcp.mcpize.run/mcp
```

### Codex

```toml
[mcp_servers.varvararatta-security-mcp]
url = "https://security-mcp.mcpize.run/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "varvararatta-security-mcp": {
      "type": "remote",
      "url": "https://security-mcp.mcpize.run/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add varvararatta-security-mcp --url https://security-mcp.mcpize.run/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  varvararatta-security-mcp:
    url: "https://security-mcp.mcpize.run/mcp"
```

### Other

```json
{
  "mcpServers": {
    "varvararatta-security-mcp": {
      "type": "http",
      "url": "https://security-mcp.mcpize.run/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-01 (score 20, +7)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 13, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-28 (score 12, −1)

- [security regression] HTTPS: pass → fail
- [security] Transport: Transport check failed: the endpoint responded but didn't complete an MCP handshake over streamable-http.

### 2026-07-27 (score 13, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 13)

First indexed and scored.

## MCP tools (0)

No tool schema has been captured from this endpoint yet.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp#diagnostics

## Score history

- 2026-08-03: 20
- 2026-08-02: 20
- 2026-08-01: 20
- 2026-07-31: 13
- 2026-07-29: 12
- 2026-07-28: 12
- 2026-07-27: 13
- 2026-07-26: 13

## Links

- Remote endpoint: https://security-mcp.mcpize.run/mcp
- Repository: https://github.com/varvararatta/botfactory-mcp
- Changelog RSS feed: https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/varvararatta-security-mcp/security-mcp
