7Maps
REMOTE · 7IT.CO.IL · SCANNED OCT 7
MCP server map (software, not geography): status, estimated tool risk, changes, tool search.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4067 tokens (~271/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
- Structured output schemas are declared (13% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the 7Maps MCP server?
7Maps is a hosted endpoint at https://7it.co.il/7maps/mcp?via=registry, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · 7it.co.il
claude mcp add --transport http xlsv777-7maps 'https://7it.co.il/7maps/mcp?via=registry'
{
"mcpServers": {
"xlsv777-7maps": {
"url": "https://7it.co.il/7maps/mcp?via=registry"
}
}
} {
"servers": {
"xlsv777-7maps": {
"type": "http",
"url": "https://7it.co.il/7maps/mcp?via=registry"
}
}
} [mcp_servers.xlsv777-7maps] url = "https://7it.co.il/7maps/mcp?via=registry"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xlsv777-7maps": {
"type": "remote",
"url": "https://7it.co.il/7maps/mcp?via=registry",
"enabled": true
}
}
} openclaw mcp add xlsv777-7maps --url 'https://7it.co.il/7maps/mcp?via=registry' --transport streamable-http
mcp_servers:
xlsv777-7maps:
url: "https://7it.co.il/7maps/mcp?via=registry" {
"McpServers": {
"xlsv777-7maps": {
"Transport": "http",
"Url": "https://7it.co.il/7maps/mcp?via=registry"
}
}
} assistant mcp add xlsv777-7maps -t streamable-http -u 'https://7it.co.il/7maps/mcp?via=registry'
{
"mcpServers": {
"xlsv777-7maps": {
"type": "http",
"url": "https://7it.co.il/7maps/mcp?via=registry"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 7 Oct 26 +1
- Tool “claim_mcp_server” rewrote its description, which is the text the model reads security
- “claim_mcp_server” added an optional parameter “owner_secret” cosmetic
- “claim_mcp_server” added an optional parameter “recover” cosmetic
- “claim_mcp_server” added an optional parameter “recover_check” cosmetic
- “my_server_report” reworded the description of “owner_key” cosmetic
- 4 Oct 26 +1
- Tool “my_7maps_usage” rewrote its description, which is the text the model reads security
- 3 Oct 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “road_conditions” rewrote its description, which is the text the model reads security
- Tool “submit_mcp_server” rewrote its description, which is the text the model reads security
- Tool “claim_mcp_server” rewrote its description, which is the text the model reads security
- Tool “report_road” rewrote its description, which is the text the model reads security
- Schema quality: 2809 → 3819 ▼ functional
- Tool coverage: 8% → 13% ▲ functional
- Stability: unverified → 0.03 ▲ functional
- New tool “find_tool” functional
- New tool “my_server_report” functional
- New tool “my_7maps_usage” functional
- “claim_mcp_server” added an optional parameter “alert_url” cosmetic
- “road_conditions” reworded the description of “last_trip” cosmetic
- “route” reworded the description of “last_trip” cosmetic
- “tool_card” reworded the description of “last_trip” cosmetic
- “verify_lock” reworded the description of “last_trip” cosmetic
- “watch” reworded the description of “last_trip” cosmetic
- “changes_since” reworded the description of “last_trip” cosmetic
- “preflight” reworded the description of “last_trip” cosmetic
- 2 Oct 26 72
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://7it.co.il/7maps/mcp?via=registry
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=7it.co.il | CN=YR2,O=Let's Encrypt,C=US | 6 Oct 2026 | 4 Jan 2027 | RSA 2048 | SHA256-RSA | 69b6336517d20c648cb978e944fae24d84a |
| SANs: 7it.co.il | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of 7it.co.il. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| il. | present | 35088 | 13 | Verified |
| co.il. | present | 7144 | 13 | Verified |
| 7it.co.il. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://assets.calendly.com https://app.lemonsqueezy.com; style-src 'self' 'unsafe-inline' https://assets.calendly.com https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://www.googletagmanager.com https://*.calendly.com; frame-src https://calendly.com https://assets.calendly.com https://7it.lemonsqueezy.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), browsing-topics=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://7it.co.il/7maps/mcp?via=registry | Verified | 200 | |
| http (plaintext) | http://7it.co.il/7maps/mcp?via=registry | HTTPS enforced | 308 | https://7it.co.il/7maps/mcp?via=registry |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
about_7maps What 7Maps is (no charge) ~147
Use this when deciding whether to use 7Maps, or when asked what it is: what the map covers right now, what each 7Maps tool answers, what a call costs, and how it saves an agent tokens, time and failed calls compared with connecting to MCP servers blind. Includes a live worked example on a real server from the map (changes daily), and, if you name a server, a quote of what 7Maps would save you on it (tokens and time) before you pay. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| server | string | – | A server you are considering: get a quote of the tokens and time 7Maps would save on it, before paying |
No output schema declared.
No examples provided.
changes_since What changed on my MCP servers (7Maps) ~201
Use this to check all the MCP servers you depend on in one call instead of one by one: give up to 50 servers and the date of your last check, and get only what changed since then (outages, recoveries, tools added, removed or changed, risk increases, silent changes). Most answers are "nothing changed". Paid per call (see list_paid_tools). Reads the map only.
| Name | Type | Req | Description |
|---|---|---|---|
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| servers | array | yes | Server URLs or official registry names |
| since | string | yes | Date of your last check (YYYY-MM-DD); up to 30 days back |
No output schema declared.
No examples provided.
claim_mcp_server Verify ownership of an MCP server on 7Maps ~488
Use this when the person you work for owns or runs an MCP server that is on the 7Maps map and wants its page to show it is owner verified, add a short note for agents (rate limits, sign-up, what the tools are for), or get a live status badge for their README. Verified owners' servers are checked every 5 minutes (uptime on the page and badge), and with alert_url the owner gets a message when the server stops answering and when it is back. First call returns the proof options (a line in /.well-known/7maps-verify.txt on the server's host, a DNS TXT record, or for io.github registry names a file in the GitHub repo); after one is in place, call again to confirm. The first verification returns an owner secret, shown once: keep it, because later changes to an already verified server (note, alerts) need it as owner_secret. If it is lost, call with recover true, put the one-time code on the host, then call with recover_check. Verifying does not change how the server is measured or ranked. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| alert_url | string | – | Optional: where to send down and up alerts. An ntfy topic for phone push without email (https://ntfy.sh/<hard-to-guess topic, at least 10 characters>, a self-hosted https://ntfy.<domain>/<topic>, or… |
| note | string | – | Optional plain-text note from the owner, no links, up to 280 characters |
| owner_secret | string | – | The owner secret returned once at the first verification. Needed to change an already verified server. |
| recover | boolean | – | Lost the owner secret: true returns a one-time code to put on the host, and a check value |
| recover_check | string | – | The check value from the recover step, once its code is on the host |
| server | string | yes | The MCP server address as it appears on its 7Maps page |
No output schema declared.
No examples provided.
find_tool Find an MCP tool for a job (7Maps) ~326
Use this when you need a tool for a job and do not know which MCP server has one: searches every tool of every public MCP server on the 7Maps map (over 200,000 tools, probed daily) and returns the best matches with an automated estimate of what each tool can do (read-only, changes data, high risk), whether its server is answering now, its handshake time, the tokens its tool list costs to load, and a page to check it. Filter to read-only tools, servers answering now, a latency or token ceiling. Copies of the same tool on several servers are collapsed. No charge. To have 7Maps pick one server and tool for you with alternatives, use route.
| Name | Type | Req | Description |
|---|---|---|---|
| answering_now | boolean | – | Only servers that answered with tools on the last check (default true) |
| job | string | yes | What the tool should do, in plain words, for example "send a transactional email" or "query a postgres database" |
| limit | integer | – | How many results (default 10) |
| max_handshake_ms | integer | – | – |
| max_tool_list_tokens | integer | – | – |
| may | string | – | What the tool may do: read = read-only only; change = read or change data; any = include high-risk tools (default any) |
| payment | string | – | Payment terms: any (default); free_only = only servers that declare no payment; paid_ok = servers that charge are fine, servers whose payment terms are unknown are left out. Paid servers show their d… |
| Name | Type | Req | Description |
|---|---|---|---|
| matched | number | yes | – |
| results | array | yes | – |
| tools_indexed | number | yes | – |
No examples provided.
list_paid_tools Prices of the paid 7IT tools ~72
Use this before calling a paid 7IT tool, to see what each costs and how to pay: per call in USDC on Base via x402 (no account; for agents whose owner approved a budget in advance), or a monthly plan license key. No charge; returns prices, plans and payment details.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| network | string | – | – |
| open | boolean | yes | – |
| plans | array | yes | – |
| tools | array | yes | – |
No examples provided.
my_7maps_usage My 7Maps usage (personal key) ~191
Use this when the person you work for asks what 7Maps has done for them: calls made with their personal 7Maps key today, in the last 7 days and in the last 30 days, servers checked, an estimate of the tokens saved compared with finding the same thing out without 7Maps, failures avoided (servers not answering that were skipped, risk changes caught by watch or verify_lock, calls that would have failed) and the average response time. It reads the optional personal key sent with this connection (the X-7Maps-Key header); without one it says so in one line, since every 7Maps answer already states its own saving. Only that person's own counts. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| window | string | – | Which window to lead with: day (today), week (last 7 days) or month (last 30 days); all three are returned |
No output schema declared.
No examples provided.
my_server_report What agents looked for around your MCP server (7Maps) ~225
Use this when the person you work for owns an MCP server on the 7Maps map and wants to know how AI agents look for servers like it: how often agents asked 7Maps for servers in its category in the last 7 or 30 days, how often this server was shown and picked, and, for a verified owner with owner_key, the words agents used, the servers picked instead, failure reasons agents reported, uptime, tool changes, and its token cost and handshake time against similar servers. Counts only, no agent identities. Without owner_key it returns the public numbers and how to verify ownership with claim_mcp_server. Read-only; never changes ranking or routing. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| days | – | – | Window in days: 7 (default) or 30 |
| owner_key | string | – | The owner key returned to the verified owner by claim_mcp_server (the newest one; each verification issues a new key) |
| server | string | yes | The MCP server address as it appears on its 7Maps page, or its official registry name |
No output schema declared.
No examples provided.
preflight Will this MCP call succeed? (7Maps) ~228
Use this right before calling a tool on an MCP server you have not used today, with the exact arguments you plan to send: checks that the server answers, whether it needs sign-in, that the tool still exists under that name, and that the arguments match the tool's input schema (required, types, allowed values, unknown keys). Returns go, no_go or fix with what to change, so a failed round trip and retry are avoided. Paid per check (see list_paid_tools). Never calls the server.
| Name | Type | Req | Description |
|---|---|---|---|
| arguments | object | – | The arguments you plan to send |
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| server | string | yes | The server URL or its official registry name |
| tool | string | yes | The tool you plan to call |
No output schema declared.
No examples provided.
report_road Report how a call to an MCP server went (7Maps) ~298
Use this after calling a tool on an MCP server (especially one 7Maps pointed you to) to report how it went: whether it worked, why not, how long it took, whether the result matched the description, and anything it did that you did not ask for. Fixed fields only, no open text. Reports from many agents become the server's rating and, once 7Maps confirms them, live incident alerts that every agent sees. You can also pass the same fields as last_trip on any paid 7Maps call. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| charged_usd | number | – | What the server charged, if anything |
| fail | string | – | If it failed: unreachable, auth, args, server_error, timeout, rate_limited or wrong_result |
| matched_description | boolean | – | Whether the result matched what the tool description promised |
| ms | number | – | How long the call took, in milliseconds |
| ok | boolean | yes | Whether the call did what you needed |
| result_tokens | number | – | About how many tokens the result was |
| server | string | yes | The MCP server you called (URL or registry name) |
| surprise | string | – | Anything the tool did that you did not ask for |
| tool | string | – | The tool you called |
| tools_hash | string | – | The tool_list_hash of the tool list you received, if you computed it as 7Maps does |
No output schema declared.
No examples provided.
road_conditions Condition of an MCP server before connecting (7Maps) ~276
Use this before connecting to or calling any MCP server you have not used today, or before installing one that runs locally: is it up, does it need sign-in, how fast it answers, how many of its tools are read-only, need approval or are high risk (delete, pay, run code; automated estimates from the public tool descriptions and annotations), when its tools last changed, and the chance the next call works, from a daily check of every remote server in the official MCP registry and 30 days of history. For a local server (npm or PyPI package): version, maintainers, publisher, install scripts and supply-chain changes. Paid per check (see list_paid_tools). Reads the map only; never calls the server.
| Name | Type | Req | Description |
|---|---|---|---|
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| server | string | yes | The server URL (https://mcp.example.com/mcp), its official registry name, or npm:<package> / pypi:<package> for a server that runs locally |
No output schema declared.
No examples provided.
route Safest MCP server for a task (7Maps) ~299
Use this when you need a tool for a task and do not know which MCP server to use, or when several could do it: finds servers whose tools match the task and ranks them by the chance the call works, how stable the server is, and least privilege (a server that can do less harm than another is preferred when both can do the task). Returns the best server and tool, alternatives and servers to avoid. Paid per task (see list_paid_tools). Reads the map only.
| Name | Type | Req | Description |
|---|---|---|---|
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| need | string | – | How much the task must be allowed to do: read only, change something, or a high-risk action such as payments or deletion. Guessed from the task when omitted |
| payment | string | – | Payment terms: any (default); free_only = only servers that declare no payment; paid_ok = servers that charge are fine, servers whose payment terms are unknown are left out. Paid servers show their d… |
| task | string | yes | What you need to do, for example "send a transactional email" or "search company records" |
No output schema declared.
No examples provided.
submit_mcp_server Put a new MCP server on the 7Maps map ~240
Use this when someone has built or runs an MCP server that is not in the official MCP registry (for example a small business's own server) and wants AI agents to be able to find it, or asks how to get their server listed. Give the server address, or just the business's domain and the usual endpoint paths are tried. The server is observed every 6 hours for 7 days; if it answers reliably, keeps its tools stable and describes every tool, it joins the 7Maps map that agents use to choose servers. Placement cannot be bought. Returns the status page and an optional owner-verification token. No charge.
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | – | One sentence: what the business does and for whom |
| category | string | – | What the business does; agents also see the category its tools show |
| charges | boolean | – | Whether the server charges agents (x402 or a subscription) |
| country | string | – | Where the business serves customers |
| language | string | – | Main language of the tools and their data |
| url | string | yes | The MCP server address, or the business domain (example.com) |
No output schema declared.
No examples provided.
tool_card Compact tool cards for an MCP server (7Maps) ~205
Use this instead of loading a server's full tool definitions when you only need to choose a tool or prepare a call: one compact card per tool (what it does, its arguments with required ones marked *, risk level and side effects) plus a hash of the full definition. Usually 70 to 90% fewer tokens than the server's own tool list. Optionally only the named tools. Paid per server (see list_paid_tools). Reads the map only.
| Name | Type | Req | Description |
|---|---|---|---|
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| server | string | yes | The server URL or its official registry name |
| tools | array | – | Only these tools; all when omitted |
No output schema declared.
No examples provided.
verify_lock Verify a pinned tool list (7Maps) ~213
Use this to check that an MCP server's tools are still the ones a person approved, like a lockfile: pass the lock you saved at approval (tool name to hash, as returned by watch or tool_card) and get, per tool, unchanged, changed (with any rise in risk), removed or new. Catches rug pulls, where a tool changes after approval, which MCP clients do not re-ask about. Paid per server (see list_paid_tools). Reads the map only.
| Name | Type | Req | Description |
|---|---|---|---|
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| lock | object | yes | Tool name to hash, saved at approval |
| server | string | yes | The server URL or its official registry name |
No output schema declared.
No examples provided.
watch Has an approved MCP server changed? (7Maps) ~209
Use this before reusing an MCP server that a person approved earlier: tells whether its tools changed since that date, and whether any change raised the risk (a tool that now deletes, pays or runs code), including silent changes made without a new server version. If the risk went up, ask the person to approve again before calling it. Paid per check (see list_paid_tools). Reads the map only.
| Name | Type | Req | Description |
|---|---|---|---|
| approved_at | string | yes | When the person approved this server (YYYY-MM-DD) |
| last_trip | object | – | Optional: how your last call to an MCP server went (the one 7Maps pointed you to). It keeps the map honest; accepted reports from a paying wallet earn calls at no charge. |
| license_key | string | – | A 7IT monthly plan license key, if you have one; otherwise pay per call with x402 |
| server | string | yes | The server URL, its official registry name, or npm:<package> / pypi:<package> |
No output schema declared.
No examples provided.
What is the 7Maps MCP server?
7Maps is an MCP server listed in the public MCP registry as io.github.XLSV777/7maps. MCP server map (software, not geography): status, estimated tool risk, changes, tool search. This page covers its hosted endpoint (https://7it.co.il/7maps/mcp?via=registry).
Is the 7Maps MCP server safe to use?
7Maps scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the 7Maps MCP server expose?
7Maps exposes 15 tools: report_road, submit_mcp_server, claim_mcp_server, my_server_report, my_7maps_usage, and 10 more. Their descriptions and schemas cost roughly 3,618 tokens of context every time the server is loaded.
Does the 7Maps MCP server require authentication?
No. We connected to 7Maps without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the 7Maps MCP server still maintained?
7Maps is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.