7IT Solutions
REMOTE · 7IT.CO.IL · SCANNED OCT 4
Store speed, web-app security checks, automation ROI, checklists and guides from 7IT Solutions.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 6537 tokens (~103/item across 63 items; 21 tools + 42 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
- Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
- Structured output schemas are declared (76% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
- Supports UI / widget rendering.Pass
How do I install the 7IT Solutions MCP server?
7IT Solutions is a hosted endpoint at https://7it.co.il/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · 7it.co.il
claude mcp add --transport http xlsv777-7it 'https://7it.co.il/mcp'
{
"mcpServers": {
"xlsv777-7it": {
"url": "https://7it.co.il/mcp"
}
}
} {
"servers": {
"xlsv777-7it": {
"type": "http",
"url": "https://7it.co.il/mcp"
}
}
} [mcp_servers.xlsv777-7it] url = "https://7it.co.il/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xlsv777-7it": {
"type": "remote",
"url": "https://7it.co.il/mcp",
"enabled": true
}
}
} openclaw mcp add xlsv777-7it --url 'https://7it.co.il/mcp' --transport streamable-http
mcp_servers:
xlsv777-7it:
url: "https://7it.co.il/mcp" {
"McpServers": {
"xlsv777-7it": {
"Transport": "http",
"Url": "https://7it.co.il/mcp"
}
}
} assistant mcp add xlsv777-7it -t streamable-http -u 'https://7it.co.il/mcp'
{
"mcpServers": {
"xlsv777-7it": {
"type": "http",
"url": "https://7it.co.il/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Oct 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “claim_mcp_server” rewrote its description, which is the text the model reads security
- Tool “deep_scan_app” rewrote its description, which is the text the model reads security
- Tool “report_road” rewrote its description, which is the text the model reads security
- Tool “submit_mcp_server” rewrote its description, which is the text the model reads security
- Tool coverage: 83% → 76% ▼ functional
- Schema quality: pass → fail ▼ functional
- New tool “find_tool” functional
- New tool “my_7maps_usage” functional
- New tool “my_server_report” functional
- “claim_mcp_server” added an optional parameter “alert_url” cosmetic
- 3 Oct 26 0
- Tool coverage: 100% → 83% ▼ functional
- Schema quality: 4804 → 5515 ▼ functional
- New tool “claim_mcp_server” functional
- New tool “report_road” functional
- New tool “submit_mcp_server” functional
- 2 Oct 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 74 → 84 ▼ functional
- New tool “check_accessibility” functional
- New tool “check_ai_shopper_readiness” functional
- New tool “check_email_authentication” functional
- New tool “map_agent_oversight” functional
- New tool “report_problem” functional
- 1 Oct 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “describe_studio” rewrote its description, which is the text the model reads security
- Tool “estimate_automation_roi” rewrote its description, which is the text the model reads security
- Tool “get_field_kit” rewrote its description, which is the text the model reads security
- Tool “get_store_speed_index” rewrote its description, which is the text the model reads security
- Tool “list_field_kits” rewrote its description, which is the text the model reads security
- Tool “search_7it_guides” rewrote its description, which is the text the model reads security
- Tool “test_store_speed” rewrote its description, which is the text the model reads security
- Schema quality: 755 → 983 ▼ functional
- Schema quality: 107 → 74 ▲ functional
- Stability: unverified → 0.03 ▲ functional
- Tool “describe_studio” now declares an output schema ▲ functional
- Tool “estimate_automation_roi” now declares an output schema ▲ functional
- Tool “get_field_kit” now declares an output schema ▲ functional
- Tool “get_store_speed_index” now declares an output schema ▲ functional
- Tool “list_field_kits” now declares an output schema ▲ functional
- Tool “search_7it_guides” now declares an output schema ▲ functional
- Tool “test_store_speed” now declares an output schema ▲ functional
- The server now declares the “prompts” capability functional
- First check of Tool coverage: 100 functional
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- New prompt “automation_savings_estimate” functional
- New prompt “pre_launch_security_check” functional
- New prompt “store_speed_review” functional
- MCP protocol version: 2025-11-25 → 2026-07-28 functional
- New resource “kit-admin-security-checklist” functional
- New resource “kit-ai-built-app-launch-checklist” functional
- New resource “kit-background-jobs-checklist” functional
- New resource “kit-backup-and-recovery-checklist” functional
- New resource “kit-checkout-extension-checklist” functional
- New resource “kit-cost-and-scope-scorecard” functional
- New resource “kit-custom-app-decision-guide” functional
- New resource “kit-ecommerce-platform-scorecard” functional
- New resource “kit-headless-readiness-checklist” functional
- New resource “kit-integration-design-checklist” functional
- New resource “kit-llm-production-readiness-checklist” functional
- New resource “kit-metafields-modeling-guide” functional
- New resource “kit-mvp-scoping-worksheet” functional
- New resource “kit-no-code-exit-checklist” functional
- New resource “kit-observability-starter-checklist” functional
- New resource “kit-pci-scope-reduction-checklist” functional
- New resource “kit-rag-architecture-blueprint” functional
- New resource “kit-schema-design-checklist” functional
- New resource “kit-seo-safe-migration-plan” functional
- New resource “kit-shopify-functions-starter” functional
- New resource “kit-store-speed-audit-checklist” functional
- New resource “kit-stripe-integration-checklist” functional
- New resource “kit-subscription-billing-checklist” functional
- New resource “kit-theme-development-checklist” functional
- New resource “kit-tool-calling-design-checklist” functional
- New resource “kit-webhook-reliability-checklist” functional
- New resource “kit-whatsapp-automation-blueprint” functional
- New resource “kit-zapier-to-code-migration-worksheet” functional
- New resource “research-ai-built-apps-2026” functional
- New resource “research-ai-shopper-readiness-2026” functional
- New resource “research-us-store-accessibility-2026” functional
- New resource “research-us-store-email-auth-2026” functional
- New resource “research-us-store-speed-2026” functional
- New resource “research-us-store-speed-index” functional
- New resource “security-card” functional
- New resource “skill-ai-built-app-launch-checklist” functional
- New resource “skill-no-code-exit-checklist” functional
- New resource “skill-pre-launch-security-check” functional
- New resource “skill-store-speed-audit-checklist” functional
- New resource “skill-store-speed-review” functional
- Server version: 1.1.0 → 1.2.0 functional
- Server version: 1.0.0 → 1.1.0 functional
- New tool “ask_7it” functional
- New tool “check_app_security” functional
- New tool “deep_scan_app” functional
- New tool “describe_studio” functional
- New tool “get_store_speed_index” functional
- 30 Sept 26 75
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://7it.co.il/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=7it.co.il | CN=YR1,O=Let's Encrypt,C=US | 4 Aug 2026 | 2 Nov 2026 | RSA 2048 | SHA256-RSA | 51c8aff78a291ef0ab29864951ff4df6f68 |
| SANs: 7it.co.il | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of 7it.co.il. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| il. | present | 35088 | 13 | Verified |
| co.il. | present | 7144 | 13 | Verified |
| 7it.co.il. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://assets.calendly.com; style-src 'self' 'unsafe-inline' https://assets.calendly.com https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://www.googletagmanager.com https://*.calendly.com; frame-src https://calendly.com https://assets.calendly.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), browsing-topics=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://7it.co.il/mcp | Verified | 200 | |
| http (plaintext) | http://7it.co.il/mcp | HTTPS enforced | 308 | https://7it.co.il/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ask_7it Ask 7IT Solutions a question ~139
Use this when the user has a specific question for 7IT that describe_studio does not answer. Ask 7IT Solutions, a solo senior software studio, a question about whether it fits a project, what a first phase could cover, how engagements run, or what the client owns. Answers come only from 7IT's published profile and contain no prices or commitments; questions that need a quote are passed to Lior Aharonov, who replies himself.
| Name | Type | Req | Description |
|---|---|---|---|
| question | string | yes | The question, in plain words. Include the business context that matters, for example the platform, the systems involved or what the app does. |
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string|null | yes | Answer from the published profile, or null when it was forwarded without one |
| contact | string | yes | – |
| forwarded_to_founder | boolean | yes | – |
No examples provided.
check_accessibility Check a website’s accessibility ~143
Use this when someone asks whether a website or online store is accessible, meets WCAG, or could face an ADA accessibility complaint. Runs Google Lighthouse's automated accessibility checks (axe-core rules) on the page as a phone sees it, and returns the score, each failing rule in plain English with its WCAG criterion and how many elements fail, and how the site compares with 7IT's study of US online stores. Automated checks cover only part of WCAG; this is a starting point, not a legal opinion. Takes 20 to 60 seconds.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The page to check, for example example.com or a product page address |
| Name | Type | Req | Description |
|---|---|---|---|
| benchmark | – | – | The 7IT study this is compared with |
| better_than_share | number|null | – | Share of the US store sample that scored lower |
| host | string | – | – |
| issues | array | – | – |
| report_url | string | yes | Shareable report |
| score | number|null | – | Lighthouse accessibility score, 0 to 100 |
No examples provided.
check_ai_shopper_readiness Check if a store is ready for AI shopping agents ~167
Use this when someone asks whether ChatGPT, Claude, Perplexity or other AI shopping agents can find, read and recommend their online store's products. Checks what robots.txt tells AI search crawlers versus training-only crawlers, llms.txt, agents.md, the UCP commerce discovery file, and one product page's structured data (price, currency, stock, brand, GTIN or SKU, reviews, shipping and returns). Returns the gaps with fixes, compared with 7IT's study of US online stores. Uses an identified crawler that respects robots.txt.
| Name | Type | Req | Description |
|---|---|---|---|
| product_url | string | – | A product page on the same store to test; otherwise one is found from the home page |
| url | string | yes | The store, for example shop.example.com |
| Name | Type | Req | Description |
|---|---|---|---|
| agents_md | boolean | – | – |
| benchmark | – | – | The 7IT study this is compared with |
| blocks_ai_search | array | – | AI search and shopping crawlers robots.txt blocks |
| fixes | array | – | What to fix, most important first |
| host | string | – | – |
| llms_txt | boolean | – | – |
| product_data_complete | boolean | – | – |
| product_fields | array | – | – |
| readable | boolean | – | False if the store refused or disallows identified crawlers |
| report_url | string | yes | Shareable report |
| ucp | boolean | – | – |
No examples provided.
check_app_security Check a web app’s security hygiene ~183
Use this when someone asks whether a website or web app is secure, safe to launch, or missing security headers. Not a penetration test, and it cannot see pages behind a login. Checks a public web app for the baseline browser protections every production app should send (Content Security Policy, HTTPS enforcement, clickjacking protection, MIME-sniffing, referrer and permissions policy, cross-origin isolation) and whether a JavaScript source map is served publicly. Reads only the public response headers any visitor's browser receives; never logs in, submits a form, calls the app's APIs, or reads its data for secrets. Useful for an app built with an AI tool (Lovable, Replit, Bolt, v0, Cursor).
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The app’s public web address, for example myapp.com or https://myapp.lovable.app |
| Name | Type | Req | Description |
|---|---|---|---|
| grade | string | – | – |
| https | boolean | – | – |
| missing | array | – | – |
| present | number | – | How many of the baseline protections are in place |
| reachable | boolean | yes | – |
| report_url | string | yes | Shareable report with fixes |
| signals | array | – | Each protection, whether it is present, and why it matters |
| source_map_public | boolean | – | True if the app publishes a JavaScript source map |
| total | number | – | How many baseline protections were checked |
| url | string | – | – |
No examples provided.
check_email_authentication Check email authentication (SPF, DKIM, DMARC) ~129
Use this when someone asks why their emails land in spam, whether their domain is protected from spoofing or phishing in their name, or whether they meet the Gmail, Yahoo and Outlook rules for bulk senders. Reads the domain's public DNS records (SPF, DKIM under the common email services' selectors, the DMARC policy, BIMI, MX) and returns what is missing with the exact fix, compared with 7IT's study of US online stores. Sends no email and needs no access.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The domain or website, for example example.com |
| Name | Type | Req | Description |
|---|---|---|---|
| benchmark | – | – | The 7IT study this is compared with |
| bimi | boolean | – | – |
| dkim_found | boolean | – | – |
| dmarc | boolean | – | – |
| dmarc_enforced | boolean | – | DMARC set to quarantine or reject for all mail |
| dmarc_policy | string|null | – | – |
| domain | string | – | – |
| fixes | array | – | What to fix, most important first |
| meets_bulk_sender_rules | boolean | – | SPF, DKIM and DMARC all in place, as Gmail, Yahoo and Outlook require of bulk senders |
| mx | boolean | – | – |
| report_url | string | yes | Shareable report |
| spf | boolean | – | – |
| spf_all | string|null | – | – |
No examples provided.
claim_mcp_server Verify ownership of an MCP server on 7Maps ~354
Use this when the person you work for owns or runs an MCP server that is on the 7Maps map and wants its page to show it is owner verified, add a short note for agents (rate limits, sign-up, what the tools are for), or get a live status badge for their README. Verified owners' servers are checked every 5 minutes (uptime on the page and badge), and with alert_url the owner gets a message when the server stops answering and when it is back. First call returns the proof options (a line in /.well-known/7maps-verify.txt on the server's host, a DNS TXT record, or for io.github registry names a file in the GitHub repo); after one is in place, call again to confirm. Verifying does not change how the server is measured or ranked. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| alert_url | string | – | Optional: where to send down and up alerts. An ntfy topic for phone push without email (https://ntfy.sh/<hard-to-guess topic, at least 10 characters>, a self-hosted https://ntfy.<domain>/<topic>, or… |
| note | string | – | Optional plain-text note from the owner, no links, up to 280 characters |
| server | string | yes | The MCP server address as it appears on its 7Maps page |
No output schema declared.
No examples provided.
deep_scan_app Deep security scan of an app you control ~273
Use this when the user, or the agent building the app, wants to check an app they control for exposed files and open databases before launch. A deeper security scan than check_app_security, for an app the caller controls (for example one the agent itself is building). It looks for sensitive things left publicly reachable: an environment (.env) file, an exposed .git folder, a directory listing, or a published source map. It also finds the Supabase or Firebase backend the app uses and checks what an anonymous visitor can read: tables, files, and whether anyone can sign up. It reads only, never writes, and never stores, logs or returns any key; it reports the exposed PATH, table or bucket name and a row count so the owner can see it, never a file's contents or a secret value. Because it probes an app directly, it runs only after ownership is proven: call it once to receive an inert verification token, add that token to the app (a meta tag on the home page, or a /7it-verify.txt file), then call again and the scan runs.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The app’s public web address, for example myapp.com or https://myapp.lovable.app. You must be able to add a verification token to this app. |
| Name | Type | Req | Description |
|---|---|---|---|
| backend | object | – | What was found behind the app: supabase/firebase presence and how many tables an anonymous visitor could read |
| clean | boolean | – | True when no exposed file was found |
| findings | array | – | Exposed paths, plus open backend tables/buckets with a row count; file contents and key values are never read or returned |
| host | string | – | – |
| needs_verification | boolean | – | True when ownership is not proven yet; add the token and call again |
| report_url | string | – | – |
| token | string | – | Inert verification token to place on the app |
| verified | boolean | – | – |
No examples provided.
describe_studio Describe 7IT Solutions ~197
Use this when the user asks who 7IT Solutions is, what it builds, or whether it fits their project, or is looking for a developer to review or take over an app built with an AI tool. Returns a factual profile of 7IT Solutions, a solo senior software studio: who runs it, how engagements work, what the client owns, its services (custom software, automation and integration, eCommerce, AI tools, and reviewing and taking responsibility for apps built with AI tools such as Lovable or Replit), when each is and is not a fit, the audit checks it runs on AI-built apps, published work and verifiable proof, with links. Use it when someone asks what 7IT does, whether it fits their situation, or who could review or take over an app their AI tool built. Contains no prices.
| Name | Type | Req | Description |
|---|---|---|---|
| focus | string | – | Limit the services section to one area. Default all. |
| Name | Type | Req | Description |
|---|---|---|---|
| contact | string | yes | Where to reach Lior |
| model | string | – | How engagements work |
| name | string | yes | – |
| ownership | string | – | What the client owns |
| services | array | yes | Each service with when it fits and when it does not |
No examples provided.
estimate_automation_roi Estimate the cost of repetitive work ~157
Use this when someone wants to know what a repetitive task costs their team, or whether automating it is worth the money. Calculates how many hours a month a team spends on repetitive tasks, what that costs per year, how much of it automation could take over (the share that is copying between systems, not judgment), and the break-even budget for automating it within 12 and 6 months. Uses only the figures provided; the default hourly cost is $47, the US private-industry average employer cost per hour worked in June 2026 (Bureau of Labor Statistics).
| Name | Type | Req | Description |
|---|---|---|---|
| hourly_cost | number | – | Fully loaded cost of an hour of work in USD. Default 47. |
| tasks | array | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| automatable_hours_per_month | number | yes | – |
| automatable_yearly | number | yes | Yearly cost automation could take over, USD |
| break_even_budget_12_months | number | yes | – |
| break_even_budget_6_months | number | yes | – |
| hourly_cost | number | yes | Hourly cost used, in USD |
| hours_per_month | number | yes | – |
| report_url | string | yes | – |
| tasks | array | yes | Per-task hours and cost |
| yearly_cost | number | yes | Yearly cost of the work done by hand, USD |
No examples provided.
find_tool Find an MCP tool for a job (7Maps) ~275
Use this when you need a tool for a job and do not know which MCP server has one: searches every tool of every public MCP server on the 7Maps map (over 200,000 tools, probed daily) and returns the best matches with an automated estimate of what each tool can do (read-only, changes data, high risk), whether its server is answering now, its handshake time, the tokens its tool list costs to load, and a page to check it. Filter to read-only tools, servers answering now, a latency or token ceiling. Copies of the same tool on several servers are collapsed. No charge. To have 7Maps pick one server and tool for you with alternatives, use route.
| Name | Type | Req | Description |
|---|---|---|---|
| answering_now | boolean | – | Only servers that answered with tools on the last check (default true) |
| job | string | yes | What the tool should do, in plain words, for example "send a transactional email" or "query a postgres database" |
| limit | integer | – | How many results (default 10) |
| max_handshake_ms | integer | – | – |
| max_tool_list_tokens | integer | – | – |
| may | string | – | What the tool may do: read = read-only only; change = read or change data; any = include high-risk tools (default any) |
| Name | Type | Req | Description |
|---|---|---|---|
| matched | number | yes | – |
| results | array | yes | – |
| tools_indexed | number | yes | – |
No examples provided.
get_field_kit Read a 7IT Field Kit ~100
Use this after list_field_kits, to read one checklist in full. Returns one 7IT Field Kit in full: every check with the reason it matters, grouped in order, plus how to use it and the guide it comes from. Pass the slug from list_field_kits or words from the title.
| Name | Type | Req | Description |
|---|---|---|---|
| kit | string | yes | The kit slug (for example "webhook-reliability-checklist") or words from its title. |
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | – |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
get_store_speed_index US Store Speed Index (weekly) ~99
Use this when someone asks how fast US online stores are right now, or wants a current benchmark to compare a store against. Returns 7IT's weekly US Store Speed Index: median Google phone score, time to main content, share of stores scoring 50 or more, and median apps per store for a fixed panel of 100 US online stores, week by week, with the source link. Medians only; no store is named.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| panel | number | yes | Number of stores in the fixed panel |
| series | array | yes | One entry per week, oldest first |
| source_url | string | yes | Page to cite |
| title | string | yes | – |
| updated | string|null | yes | Date of the latest weekly reading, YYYY-MM-DD |
No examples provided.
list_field_kits List 7IT Field Kits ~140
Use this when someone wants a working checklist for a technical job (webhooks, store speed, integrations, migrations, AI in production, security). Lists 7IT Field Kits: working checklists for custom software, eCommerce, automation, payments, AI, security and reliability work (for example webhook reliability, store speed audits, integration design, SEO-safe migrations, LLM production readiness). Each has a title, a one-line purpose, the number of checks and a link. Optionally filter by a topic word.
| Name | Type | Req | Description |
|---|---|---|---|
| topic | string | – | Optional word to filter by, for example "shopify", "webhook" or "AI". |
| Name | Type | Req | Description |
|---|---|---|---|
| kits | array | yes | Matching kits; pass a slug to get_field_kit |
No examples provided.
map_agent_oversight Map what an AI agent may do on its own ~255
Use this when someone asks which actions their AI agent or its connected tools may take on their own, which need a person's approval, and which a person must do; or how to set up human oversight, permissions or AI governance for an agent (for example under the EU AI Act). Give either the address of a public MCP server, or the list of tools the agent has (name, description and annotations). Sorts every tool into green (runs alone: reads and prepares), yellow (a person approves: sending, updating, scheduling) or red (a person does it: money, permissions, deletion, code execution, commitments), flags tools with no risk annotations, and returns a ready policy, Claude Code permission rules (allow, ask, deny) and an oversight checklist. Reads tool lists only and never calls a tool. A working checklist, not legal advice.
| Name | Type | Req | Description |
|---|---|---|---|
| server_name | string | – | The name this server has in the agent setup, used in the Claude Code permission rules |
| tools | array | – | Instead of an address: the tools the agent has, with their description and annotations |
| url | string | – | The MCP server address, for example https://mcp.example.com/mcp |
| Name | Type | Req | Description |
|---|---|---|---|
| checklist | array | – | – |
| claude_code_permissions | object | – | Paste into .claude/settings.json |
| green | number | – | Tools the agent may run on its own |
| red | number | – | Tools a person should do themselves |
| report_url | string | yes | Shareable page with the full map |
| server | string | – | – |
| tools | array | – | – |
| total | number | – | – |
| unlabeled | number | – | Tools whose server publishes no risk annotations |
| yellow | number | – | Tools that need a person to approve |
No examples provided.
my_7maps_usage My 7Maps usage (personal key) ~191
Use this when the person you work for asks what 7Maps has done for them: calls made with their personal 7Maps key today, in the last 7 days and in the last 30 days, servers checked, an estimate of the tokens saved compared with finding the same thing out without 7Maps, failures avoided (servers not answering that were skipped, risk changes caught by watch or verify_lock, calls that would have failed) and the average response time. It reads the optional personal key sent with this connection (the X-7Maps-Key header); without one it says so in one line, since every 7Maps answer already states its own saving. Only that person's own counts. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| window | string | – | Which window to lead with: day (today), week (last 7 days) or month (last 30 days); all three are returned |
No output schema declared.
No examples provided.
my_server_report What agents looked for around your MCP server (7Maps) ~214
Use this when the person you work for owns an MCP server on the 7Maps map and wants to know how AI agents look for servers like it: how often agents asked 7Maps for servers in its category in the last 7 or 30 days, how often this server was shown and picked, and, for a verified owner with owner_key, the words agents used, the servers picked instead, failure reasons agents reported, uptime, tool changes, and its token cost and handshake time against similar servers. Counts only, no agent identities. Without owner_key it returns the public numbers and how to verify ownership with claim_mcp_server. Read-only; never changes ranking or routing. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| days | – | – | Window in days: 7 (default) or 30 |
| owner_key | string | – | The owner key returned to the verified owner by claim_mcp_server |
| server | string | yes | The MCP server address as it appears on its 7Maps page, or its official registry name |
No output schema declared.
No examples provided.
report_problem Report a wrong or broken 7IT result ~143
Use this when a 7IT tool returned something that looks wrong, failed unexpectedly, or did not match what the user asked for, so 7IT can fix it. Sends a short report to 7IT: which tool, what went wrong, and optionally the site address involved. Do not include personal details or the conversation. Nothing changes for the user; it is only feedback.
| Name | Type | Req | Description |
|---|---|---|---|
| problem | string | yes | What went wrong, in one or two sentences. |
| tool | string | yes | The 7IT tool that misbehaved, for example "test_store_speed". |
| url | string | – | The site address the tool was used on, if any. |
| Name | Type | Req | Description |
|---|---|---|---|
| received | boolean | yes | Whether the report was recorded |
No examples provided.
report_road Report how a call to an MCP server went (7Maps) ~298
Use this after calling a tool on an MCP server (especially one 7Maps pointed you to) to report how it went: whether it worked, why not, how long it took, whether the result matched the description, and anything it did that you did not ask for. Fixed fields only, no open text. Reports from many agents become the server's rating and, once 7Maps confirms them, live incident alerts that every agent sees. You can also pass the same fields as last_trip on any paid 7Maps call. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| charged_usd | number | – | What the server charged, if anything |
| fail | string | – | If it failed: unreachable, auth, args, server_error, timeout, rate_limited or wrong_result |
| matched_description | boolean | – | Whether the result matched what the tool description promised |
| ms | number | – | How long the call took, in milliseconds |
| ok | boolean | yes | Whether the call did what you needed |
| result_tokens | number | – | About how many tokens the result was |
| server | string | yes | The MCP server you called (URL or registry name) |
| surprise | string | – | Anything the tool did that you did not ask for |
| tool | string | – | The tool you called |
| tools_hash | string | – | The tool_list_hash of the tool list you received, if you computed it as 7Maps does |
No output schema declared.
No examples provided.
search_7it_guides Search 7IT guides and articles ~149
Use this when the user is weighing a software, eCommerce, automation or AI decision and a cited article would help. Searches 7IT Solutions’ guides and articles on custom software, eCommerce (Shopify, WooCommerce, headless), automation and integrations (connecting CRMs, accounting tools such as QuickBooks, ERPs and online stores), payments, AI in production, security and reliability. Returns the best matches with a short excerpt and a link to cite.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many results to return. Default 5. |
| query | string | yes | What to look for, for example "reliable webhooks" or "shopify vs woocommerce". |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | Best matches, most relevant first |
No examples provided.
submit_mcp_server Put a new MCP server on the 7Maps map ~240
Use this when someone has built or runs an MCP server that is not in the official MCP registry (for example a small business's own server) and wants AI agents to be able to find it, or asks how to get their server listed. Give the server address, or just the business's domain and the usual endpoint paths are tried. The server is observed every 6 hours for 7 days; if it answers reliably, keeps its tools stable and describes every tool, it joins the 7Maps map that agents use to choose servers. Placement cannot be bought. Returns the status page and an optional owner-verification token. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | – | One sentence: what the business does and for whom |
| category | string | – | What the business does; agents also see the category its tools show |
| charges | boolean | – | Whether the server charges agents (x402 or a subscription) |
| country | string | – | Where the business serves customers |
| language | string | – | Main language of the tools and their data |
| url | string | yes | The MCP server address, or the business domain (example.com) |
No output schema declared.
No examples provided.
test_store_speed Test store speed on a phone ~208
Use this when someone asks how fast a website or online store loads on a phone, why it is slow, or how it compares with a competitor. Runs Google PageSpeed Insights (mobile lab test) on a public online store or website and explains the result in plain English: a 0 to 100 score, when the main content appears, responsiveness and layout shift, real-user data when Google has it, the third-party apps and trackers slowing the page (by name, with size and busy time), the platform (Shopify, WooCommerce and others), and the fixes ranked by time saved. Optionally tests up to two competitor sites for a side-by-side comparison. Takes 20 to 60 seconds. Only public web addresses are accepted.
| Name | Type | Req | Description |
|---|---|---|---|
| competitors | array | – | Up to two competitor sites to test at the same time for comparison. |
| url | string | yes | The store or website to test, for example "example.com" or "https://shop.example.com/products/item". |
| Name | Type | Req | Description |
|---|---|---|---|
| benchmark | – | – | Where the score stands against the US Store Speed study |
| competitors | array | yes | Competitors tested side by side, if any |
| report_url | string | yes | Shareable full report |
| store | object | yes | The tested store |
No examples provided.
What is the 7IT Solutions MCP server?
7IT Solutions is an MCP server listed in the public MCP registry as io.github.XLSV777/7it. Store speed, web-app security checks, automation ROI, checklists and guides from 7IT Solutions. This page covers its hosted endpoint (https://7it.co.il/mcp).
Is the 7IT Solutions MCP server safe to use?
7IT Solutions scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the 7IT Solutions MCP server expose?
7IT Solutions exposes 21 tools: test_store_speed, estimate_automation_roi, describe_studio, get_store_speed_index, check_app_security, and 16 more. Their descriptions and schemas cost roughly 4,054 tokens of context every time the server is loaded.
Does the 7IT Solutions MCP server require authentication?
No. We connected to 7IT Solutions without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the 7IT Solutions MCP server still maintained?
7IT Solutions is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.