io.github.XogZ3/botoi-mcp
REMOTE · API.BOTOI.COM · SCANNED AUG 3
49 developer tools via MCP: DNS, WHOIS, IP lookup, JWT, hashing, QR, and more.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 49 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability84
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 2772 tokens (~55/item across 50 items; 49 tools + 1 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · api.botoi.com
claude mcp add --transport http xogz3-botoi-mcp https://api.botoi.com/mcp
[mcp_servers.xogz3-botoi-mcp] url = "https://api.botoi.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xogz3-botoi-mcp": {
"type": "remote",
"url": "https://api.botoi.com/mcp",
"enabled": true
}
}
} openclaw mcp add xogz3-botoi-mcp --url https://api.botoi.com/mcp --transport streamable-http
mcp_servers:
xogz3-botoi-mcp:
url: "https://api.botoi.com/mcp" {
"mcpServers": {
"xogz3-botoi-mcp": {
"type": "http",
"url": "https://api.botoi.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://api.botoi.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=botoi.com | CN=WE1,O=Google Trust Services,C=US | 20 Jul 2026 | 18 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | e1423b6f3b7b50ee1361ecd57bffca99 |
| SANs: botoi.com, api.botoi.com, *.api.botoi.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of api.botoi.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| botoi.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.botoi.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.botoi.com/mcp | HTTPS enforced | 301 | https://api.botoi.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
dev_cron_describe Cron Describe ~32
Convert a cron expression to a human-readable description.
| Name | Type | Req | Description |
|---|---|---|---|
| expression | string | yes | Five-field cron expression |
No output schema declared.
No examples provided.
dev_diff Text Diff ~57
Compute a unified diff between two text strings. Use when comparing file versions, config changes, or code revisions. Returns added, removed, and unchanged lines.
| Name | Type | Req | Description |
|---|---|---|---|
| modified | string | yes | Modified text |
| original | string | yes | Original text |
No output schema declared.
No examples provided.
dev_hash Hash Text ~62
Generate a hash (MD5, SHA-1, SHA-256, SHA-512) of input text. Use for checksums, data integrity, or fingerprinting.
| Name | Type | Req | Description |
|---|---|---|---|
| algorithm | string | yes | Hash algorithm |
| text | string | yes | Text to hash |
No output schema declared.
No examples provided.
dev_jwt_sign JWT Sign ~62
Create and sign a JWT with a given payload and secret.
| Name | Type | Req | Description |
|---|---|---|---|
| expires_in | number | — | Token expiration time in seconds |
| payload | object | yes | JSON payload to encode in the token |
| secret | string | yes | HMAC secret key for signing |
No output schema declared.
No examples provided.
dev_jwt_verify JWT Verify ~33
Verify and decode a JWT. Use when debugging authentication tokens.
| Name | Type | Req | Description |
|---|---|---|---|
| token | string | yes | JWT token to decode |
No output schema declared.
No examples provided.
dev_password_generate Password Generate ~113
Generate a random password with configurable length and complexity.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | — | Number of passwords to generate (1-50) |
| excludeAmbiguous | boolean | — | Exclude ambiguous characters (0, O, I, l, 1, |) |
| length | number | — | Password length (4-256) |
| lowercase | boolean | — | Include lowercase letters |
| numbers | boolean | — | Include digits |
| symbols | boolean | — | Include special characters |
| uppercase | boolean | — | Include uppercase letters |
No output schema declared.
No examples provided.
dev_regex_test Regex Test ~61
Test a regex pattern against a string and return matches.
| Name | Type | Req | Description |
|---|---|---|---|
| flags | string | — | Regex flags (e.g. "gi") |
| pattern | string | yes | Regular expression pattern (without delimiters) |
| testString | string | yes | String to test against |
No output schema declared.
No examples provided.
dev_semver_parse Semver Parse ~51
Parse and validate a semver string into major, minor, patch, pre-release, and build components. Use when checking version compatibility or sorting releases.
| Name | Type | Req | Description |
|---|---|---|---|
| version | string | yes | Version string to validate |
No output schema declared.
No examples provided.
dev_timestamp_convert Timestamp Convert ~91
Convert between Unix timestamps and ISO 8601 dates. Use when normalizing date formats across APIs, logs, or databases. Returns both Unix and ISO representations.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | — | Source format hint (unix, unix_ms, iso) |
| timestamp | string | yes | Timestamp to convert (Unix seconds, Unix ms, or ISO 8601 string) |
| to | string | — | Target format hint |
No output schema declared.
No examples provided.
dev_url_decode URL Decode ~68
URL-decode a percent-encoded string back to readable text. Use when parsing query parameters, redirect URIs, or encoded form values.
| Name | Type | Req | Description |
|---|---|---|---|
| component | boolean | — | Use decodeURIComponent (true) or decodeURI (false) |
| text | string | yes | URL-encoded string to decode |
No output schema declared.
No examples provided.
dev_url_encode URL Encode ~64
URL-encode a string by escaping special characters. Use when building query parameters, form data, or safe URLs that contain reserved characters.
| Name | Type | Req | Description |
|---|---|---|---|
| component | boolean | — | Use encodeURIComponent (true) or encodeURI (false) |
| text | string | yes | String to encode |
No output schema declared.
No examples provided.
dev_uuid UUID Generate ~40
Generate one or more UUIDs (v4 or v7). Use when you need unique identifiers for database records, request tracing, or idempotency keys.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lookup_accessibility Accessibility Check ~58
Run 10 basic accessibility checks on a webpage URL. Returns a score, issues list, and summary. Use when you need a quick accessibility audit.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | URL to check (must start with http:// or https://) |
No output schema declared.
No examples provided.
lookup_address_validate Address Validate ~60
Validate a freeform address and return structured components (street, city, state, postal code, country), GPS coordinates, and confidence score. Use when you need to verify or parse an address.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Freeform address to validate |
No output schema declared.
No examples provided.
lookup_breach_check Breach Check ~49
Check if a password has appeared in known data breaches using k-Anonymity. Returns breach count. Use when you need to verify password safety.
| Name | Type | Req | Description |
|---|---|---|---|
| password | string | yes | Password to check |
No output schema declared.
No examples provided.
lookup_company Company Lookup ~50
Look up company information by domain name. Returns name, industry, employee count, location, and social profiles. Use when enriching leads or researching organizations.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain to look up |
No output schema declared.
No examples provided.
lookup_dns DNS Lookup ~65
Query DNS records (A, AAAA, MX, TXT, CNAME, NS) for a domain. Use when you need to check DNS configuration or troubleshoot domain resolution.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to look up |
| type | string | — | DNS record type |
No output schema declared.
No examples provided.
lookup_dns_monitor DNS Monitor ~57
Check DNS records for a domain and compare against the previous snapshot. Detects record changes over time. Use when monitoring DNS configuration.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to monitor |
| types | array | — | DNS record types to check |
No output schema declared.
No examples provided.
lookup_domain_availability Domain Availability ~59
Check if a domain name is available for registration. Use when brainstorming project names or validating domain ideas. Returns availability status and WHOIS data if registered.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain name to check (e.g. "example.com") |
No output schema declared.
No examples provided.
lookup_email Email Validate ~48
Validate an email address (syntax, MX record, disposable check). Use when you need to verify if an email address is real and deliverable.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address to validate |
No output schema declared.
No examples provided.
lookup_headers HTTP Headers ~29
Fetch HTTP response headers for a URL. Use when inspecting server configuration, security headers, or caching policies.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lookup_ip IP Lookup ~66
Look up geolocation, ISP, and network details for an IP address. Use when you need to determine the physical location, internet provider, or AS number for a given IP.
| Name | Type | Req | Description |
|---|---|---|---|
| ip | string | — | IP address to look up. If omitted, the caller's IP is used. |
No output schema declared.
No examples provided.
lookup_phone Phone Lookup ~54
Parse and validate a phone number, returning country, carrier, line type, and E.164 format. Use when normalizing user-submitted phone numbers or verifying contact data.
| Name | Type | Req | Description |
|---|---|---|---|
| phone | string | yes | Phone number to validate |
No output schema declared.
No examples provided.
lookup_ssl SSL Check ~38
Check SSL certificate details and expiry for a domain. Use when verifying HTTPS configuration or checking certificate validity.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check |
No output schema declared.
No examples provided.
lookup_ssl_cert_expiry SSL Certificate Expiry ~53
Check SSL certificate expiry for a domain. Returns issuer, valid dates, days remaining, and expired/expiring-soon flags. Use when monitoring certificate health.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check |
No output schema declared.
No examples provided.
lookup_tech_detect Tech Detect ~54
Detect technologies used by a website (frameworks, CMS, analytics). Use when analyzing a competitor's tech stack.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The full URL to analyze (must start with http:// or https://) |
No output schema declared.
No examples provided.
lookup_url_metadata URL Metadata ~48
Extract title, description, OG tags, and favicon from a URL. Use when you need to preview or summarize a webpage.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | URL to fetch and extract metadata from |
No output schema declared.
No examples provided.
lookup_vpn_detect VPN Detect ~57
Check if an IP address is a VPN, proxy, or Tor exit node. Use when assessing connection trustworthiness or flagging suspicious traffic. Returns detection type and provider details.
| Name | Type | Req | Description |
|---|---|---|---|
| ip | string | yes | IPv4 address to check |
No output schema declared.
No examples provided.
lookup_whois WHOIS Lookup ~46
Get WHOIS registration data for a domain. Use when you need to find domain ownership, registrar, or expiration date.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to look up |
No output schema declared.
No examples provided.
security_decrypt Decrypt Text ~48
Decrypt AES-256-GCM encrypted text with a passphrase.
| Name | Type | Req | Description |
|---|---|---|---|
| ciphertext | string | yes | Base64-encoded ciphertext to decrypt |
| password | string | yes | Password used during encryption |
No output schema declared.
No examples provided.
security_encrypt Encrypt Text ~46
Encrypt text using AES-256-GCM with a passphrase.
| Name | Type | Req | Description |
|---|---|---|---|
| password | string | yes | Encryption password (used to derive the key) |
| plaintext | string | yes | Text to encrypt |
No output schema declared.
No examples provided.
security_pii_detect PII Detect ~39
Detect personally identifiable information (emails, phones, SSNs) in text.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | The text to scan for PII |
No output schema declared.
No examples provided.
security_totp_generate TOTP Generate ~61
Generate a TOTP secret and provisioning URI for 2FA setup.
| Name | Type | Req | Description |
|---|---|---|---|
| digits | number | — | Number of digits in the code |
| period | number | — | Time step in seconds |
| secret | string | yes | Base32-encoded shared secret |
No output schema declared.
No examples provided.
security_validate_credit_card Validate Credit Card ~35
Validate a credit card number (Luhn check, network detection).
| Name | Type | Req | Description |
|---|---|---|---|
| number | string | yes | Credit card number to validate |
No output schema declared.
No examples provided.
text_base64_decode Base64 Decode ~72
Decode a Base64 string back to UTF-8 text. Use when extracting data from Base64-encoded API responses, tokens, or email headers. Returns the original plaintext string.
| Name | Type | Req | Description |
|---|---|---|---|
| encoded | string | yes | The Base64 string to decode |
| urlSafe | boolean | — | Input uses URL-safe alphabet |
No output schema declared.
No examples provided.
text_base64_encode Base64 Encode ~68
Encode a UTF-8 string to Base64. Use for embedding data in URLs or APIs that require Base64.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | The string to encode |
| urlSafe | boolean | — | Use URL-safe alphabet (- instead of +, _ instead of /, no padding) |
No output schema declared.
No examples provided.
text_csv_to_json CSV to JSON ~73
Parse CSV text into a JSON array of objects. Use when converting spreadsheet or tabular data into structured JSON for processing or storage.
| Name | Type | Req | Description |
|---|---|---|---|
| csv | string | yes | CSV data as a string |
| delimiter | string | — | Column delimiter character |
| has_header | boolean | — | Whether the first row contains column headers |
No output schema declared.
No examples provided.
text_html_to_markdown HTML to Markdown ~46
Convert HTML to clean Markdown. Use when extracting readable content from web pages or migrating HTML docs to Markdown format.
| Name | Type | Req | Description |
|---|---|---|---|
| html | string | yes | HTML string to convert to Markdown |
No output schema declared.
No examples provided.
text_json_format JSON Format ~62
Format and pretty-print a JSON string with configurable indentation. Use when making minified or compact JSON readable for debugging or documentation.
| Name | Type | Req | Description |
|---|---|---|---|
| indent | number | — | Number of spaces for indentation (0-8) |
| json | string | yes | Raw JSON string to format |
No output schema declared.
No examples provided.
text_json_to_yaml JSON to YAML ~52
Convert JSON data to YAML format. Use when generating human-readable config files from JSON data structures.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | JSON object to convert |
| indent | number | — | Number of spaces for indentation |
No output schema declared.
No examples provided.
text_json_validate JSON Validate ~32
Validate whether a string is valid JSON and report parsing errors.
| Name | Type | Req | Description |
|---|---|---|---|
| json | string | yes | JSON string to validate |
No output schema declared.
No examples provided.
text_markdown_to_html Markdown to HTML ~79
Convert Markdown text to HTML. Use when rendering Markdown content for web display or email templates. Returns sanitized HTML.
| Name | Type | Req | Description |
|---|---|---|---|
| gfm | boolean | — | Enable GitHub Flavored Markdown |
| markdown | string | yes | Markdown source text |
| sanitize | boolean | — | Strip script tags, event handlers, iframes, objects, and embeds |
No output schema declared.
No examples provided.
text_xml_to_json XML to JSON ~48
Convert XML documents to JSON. Use when parsing XML API responses, feeds, or config files into a structured JSON format for easier processing.
| Name | Type | Req | Description |
|---|---|---|---|
| xml | string | yes | XML string to convert |
No output schema declared.
No examples provided.
text_yaml_to_json YAML to JSON ~48
Convert YAML configuration or data to JSON. Use when parsing YAML config files for programmatic access or API consumption. Returns a JSON object.
| Name | Type | Req | Description |
|---|---|---|---|
| yaml | string | yes | YAML string to convert |
No output schema declared.
No examples provided.
transform_code_format Code Format ~78
Format source code with language-aware indentation and style rules. Supports JS, TS, Python, Go, Rust, and more. Use when standardizing code style or preparing snippets for documentation.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Source code to format |
| language | string | yes | Programming language (javascript, json, html, css, sql, xml) |
No output schema declared.
No examples provided.
transform_json_to_typescript JSON to TypeScript ~76
Generate TypeScript interfaces from a JSON sample. Use when building type-safe API clients or converting API responses into TypeScript types.
| Name | Type | Req | Description |
|---|---|---|---|
| json | object | yes | Any valid JSON value to convert (object, array, string, number, etc.) |
| name | string | — | Name for the generated interface (default: "Root") |
No output schema declared.
No examples provided.
transform_minify_css Minify CSS ~47
Minify CSS stylesheets by removing whitespace, comments, and redundant rules. Use when reducing stylesheet size for faster page loads.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | CSS code to minify |
No output schema declared.
No examples provided.
transform_minify_js Minify JS ~48
Minify JavaScript code by removing whitespace, comments, and shortening variable names. Use when optimizing bundle size for production deployment.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | JavaScript code to minify |
No output schema declared.
No examples provided.
transform_sql_format SQL Format ~65
Format and beautify SQL queries with proper indentation and keyword casing. Use when cleaning up inline SQL for code reviews, documentation, or debugging.
| Name | Type | Req | Description |
|---|---|---|---|
| indent | number | — | Number of spaces for indentation (default: 2) |
| sql | string | yes | SQL query to format |
No output schema declared.
No examples provided.