PediBot
REMOTE · PEDIBOT.XYZ · SCANNED OCT 7
Children's health from published guidelines: doses, vaccines, growth charts, warning signs.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2113 tokens (~264/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the PediBot MCP server?
PediBot is a hosted endpoint at https://pedibot.xyz/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · pedibot.xyz
claude mcp add --transport http xyz-pedibot-pedibot 'https://pedibot.xyz/mcp'
{
"mcpServers": {
"xyz-pedibot-pedibot": {
"url": "https://pedibot.xyz/mcp"
}
}
} {
"servers": {
"xyz-pedibot-pedibot": {
"type": "http",
"url": "https://pedibot.xyz/mcp"
}
}
} [mcp_servers.xyz-pedibot-pedibot] url = "https://pedibot.xyz/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xyz-pedibot-pedibot": {
"type": "remote",
"url": "https://pedibot.xyz/mcp",
"enabled": true
}
}
} openclaw mcp add xyz-pedibot-pedibot --url 'https://pedibot.xyz/mcp' --transport streamable-http
mcp_servers:
xyz-pedibot-pedibot:
url: "https://pedibot.xyz/mcp" {
"McpServers": {
"xyz-pedibot-pedibot": {
"Transport": "http",
"Url": "https://pedibot.xyz/mcp"
}
}
} assistant mcp add xyz-pedibot-pedibot -t streamable-http -u 'https://pedibot.xyz/mcp'
{
"mcpServers": {
"xyz-pedibot-pedibot": {
"type": "http",
"url": "https://pedibot.xyz/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 7 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 17. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes. Other categories moved too: Schema Quality & AI Usability fell 1.
- 4 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 3 Oct 26 0
- Tool “child_medicine_dose” rewrote its description, which is the text the model reads security
- Tool “paediatric_guide_finder” rewrote its description, which is the text the model reads security
- Tool “paediatric_warning_sign_check” rewrote its description, which is the text the model reads security
- Stability: unverified → 0.03 ▲ functional
- “paediatric_guide_finder” reworded the description of “topic” cosmetic
- “paediatric_warning_sign_check” reworded the description of “symptoms” cosmetic
- 2 Oct 26 72
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 9 Oct 2026 · Probed https://pedibot.xyz/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=pedibot.xyz | CN=YE2,O=Let's Encrypt,C=US | 25 Aug 2026 | 23 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 5837350dabeb7c7be02b548604b59dc3f8f |
| SANs: pedibot.xyz | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of pedibot.xyz. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| xyz. | present | 3599, 18130 | 8, 8 | Verified |
| pedibot.xyz. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(self), microphone=(self), camera=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://pedibot.xyz/mcp | Verified | 200 | |
| http (plaintext) | http://pedibot.xyz/mcp | HTTPS enforced | 308 | https://pedibot.xyz/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
child_friendly_health_explanation Child friendly health explanation ~183
The same sourced answer, rewritten to be read aloud to a child aged 5 to 10: three to five short, warm sentences, no frightening words, one simple comparison and one thing the child can do. The medical content still comes only from published guidelines and the triage still runs first. For parent apps, school nurses and companion agents, in eight languages. Use when the answer will be read by or to a child aged 5 to 10. For the parent's own question use paediatric_question_with_sources.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | ISO 3166-1 alpha-2, used if the triage finds a warning sign |
| lang | string | – | Language of the explanation |
| question | string | yes | What to explain, e.g. 'why do I have a fever?' or 'what is a vaccine?' |
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string | – | The explanation, in child-friendly language |
| banner | string|null | – | Warning for the adult when a warning sign was found |
| disclaimer | string | – | Information from published guidelines, not medical advice |
| level | string | – | Triage level; if not routine, an adult must read the banner |
| sources | array | – | The documents the content comes from |
No examples provided.
child_growth_percentile Child growth percentile ~329
Where a child sits on the growth charts, calculated exactly from the WHO LMS tables (Child Growth Standards 2006, Growth Reference 2007) and, for the United States and Australia after age 2, the CDC 2000 charts: weight, height, weight-for-height and BMI percentiles and z-scores, with the WHO cut-offs (wasting, stunting, overweight, thinness). Severe acute malnutrition is flagged as urgent. With a country, it says which chart that country's health record uses; 78 countries covered. Use when you have a child's sex, age and weight or height and want the percentile. For malnutrition with an arm measurement, or general questions about growth, use paediatric_question_with_sources.
| Name | Type | Req | Description |
|---|---|---|---|
| age_months | number | yes | Age in months, 0 to 240. The WHO charts go to 228 months (19 years); 229 to 240 need country US, whose CDC charts reach 20 years. |
| country | string | – | ISO 3166-1 alpha-2: picks the chart the country uses when PediBot has it, and reports which one it uses |
| height_cm | number | – | Length (under 2, lying down) or height in centimetres. Give weight_kg, height_cm or both. |
| lang | string | – | Language of the labels |
| sex | string | yes | m for a boy, f for a girl |
| weight_kg | number | – | Weight in kilograms. Give weight_kg, height_cm or both: at least one is needed. |
| Name | Type | Req | Description |
|---|---|---|---|
| country | object | – | The charts the country's health record uses, how well PediBot's calculation matches them, and the official source |
| indicators | array | – | name, label, value, z, percentile, flag and flag_label for each indicator |
| level | string | – | routine, or urgent for severe acute malnutrition |
| reference | string | – | who or cdc: the tables used |
| sources | array | – | The WHO or CDC reference used |
| warnings | array | – | What to do when the result is urgent |
No examples provided.
child_medicine_dose Child medicine dose ~371
Paracetamol or ibuprofen dose for a child by weight, read from fixed tables: the model is never involved in a number. Takes the brand printed on the bottle (35 brands across 57 countries: Calpol, Tylenol, Crocin, Panadol, Apiretal, Dalsy, Nurofen, Advil and more) or the generic name, and returns the mg range, the millilitres for each strength sold, the interval, the daily maximum and the age warnings. Refuses and refers when the child is too young to be medicated at home. Use when asked how much paracetamol (acetaminophen) or ibuprofen to give a child; needs the weight. For fluids in vomiting or diarrhoea use oral_rehydration_plan; for any other medicine use paediatric_question_with_sources.
| Name | Type | Req | Description |
|---|---|---|---|
| age_months | number | – | Age in months, if known: it changes the warnings and can refuse the dose |
| country | string | – | ISO 3166-1 alpha-2 of where the bottle was bought: the strength sold there is listed first (in Haiti and the Dominican Republic children's ibuprofen is 200 mg/5 ml, twice the usual) |
| drug | string | yes | Brand printed on the bottle (Calpol, Tylenol, Crocin, Panadol, Apiretal, Dalsy, Nurofen, Advil…) or the generic name: paracetamol (acetaminophen) or ibuprofen. Only those two medicines are covered; a… |
| lang | string | – | Language of the warnings |
| weight_kg | number | yes | The child's weight in kilograms, 1 to 120; the dose is calculated from it |
| Name | Type | Req | Description |
|---|---|---|---|
| disclaimer | string | – | Information from published guidelines, not a prescription |
| generic | string | – | The active substance the brand resolves to |
| interval_hours | array | – | Minimum and maximum hours between doses |
| max_doses_per_day | integer | – | Hard ceiling of doses in 24 hours |
| mg_max | number | – | Upper end of the dose in milligrams for this weight |
| mg_min | number | – | Lower end of the dose in milligrams for this weight |
| ml_by_form | array | – | Millilitres for each strength sold |
| refer | boolean | – | true when the child must be seen instead of medicated at home |
| warnings | array | – | Age limits and combinations to avoid |
No examples provided.
childhood_vaccination_schedule Childhood vaccination schedule ~229
The official childhood vaccination schedule of a country, for 92 countries: 8 transcribed by hand from the ministry's own document and 84 read from the WHO's immunization schedule database (all of Africa, the Gulf, Latin America). Returns every age with the vaccines due and what each protects against, the issuing body, the source URL and the review date. With the child's age it also returns what is due now and what comes next. A transcribed table, not a recollection of one. Use when asked which vaccines a child gets, or are due, in a given country. For what a vaccine does or its side effects use paediatric_question_with_sources.
| Name | Type | Req | Description |
|---|---|---|---|
| age_months | number | – | The child's age in months, to return what is due now and next |
| country | string | yes | ISO 3166-1 alpha-2 code, upper case, of one of the 92 countries with a schedule (the enum). For any other country there is no schedule and the tool says so. |
| lang | string | – | Language of the labels |
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | The country code resolved |
| due | array | – | What is due at the given age |
| meta | object | – | Name of the schedule, issuing body, source URL and review date |
| next | object|null | – | The next appointment after that age |
| schedule | array | – | Each age with the vaccines due |
| text | string | – | The same, as a readable text |
No examples provided.
oral_rehydration_plan Oral rehydration plan ~212
How much oral rehydration solution to offer a child who is vomiting or has diarrhoea: volume per intake, how often, and what to do when the child brings it back up. By age, from the AEMPS leaflet for the solution, the SEUP parent sheet on vomiting and the UK Dioralyte leaflet. These are fluids, not medicine, and the figures come from the leaflets, never from a model. Use when a child is vomiting or has diarrhoea; only the age is needed. If there are signs of dehydration (no urine for hours, very sleepy, sunken eyes, no tears) or blood, check paediatric_warning_sign_check first.
| Name | Type | Req | Description |
|---|---|---|---|
| age_months | number | – | Age in months: under 1 month, under and over one year get different guidance |
| lang | string | – | Language of the guidance |
| vomiting | boolean | – | True if the child is vomiting: adds what to do when the solution is brought back up |
| Name | Type | Req | Description |
|---|---|---|---|
| lines | array | – | The guidance, step by step |
| refer | boolean | – | true when the child must be seen |
| sources | array | – | The leaflets the figures come from |
| warnings | array | – | When to stop and seek care |
No examples provided.
paediatric_guide_finder Paediatric guide finder ~176
Finds PediBot's published parent guides on a topic, in the requested language, and returns up to five, best match first: title, topic and link. Each guide is written only from published guidelines and names the organisation behind every clinical sentence. When no guide matches, the list is empty. Useful for agents that want to hand a parent something to read rather than a paragraph, in eight languages. Use when the user wants something to read or share on a topic. To answer a specific question use paediatric_question_with_sources.
| Name | Type | Req | Description |
|---|---|---|---|
| lang | string | – | Language of the guides |
| topic | string | yes | A few words in any of the eight languages, matched against guide titles and topics; a short noun phrase works best ('fever', 'head lice', 'first solid foods'), not a whole question. |
| Name | Type | Req | Description |
|---|---|---|---|
| guides | array | – | title, topic and url of each guide |
No examples provided.
paediatric_question_with_sources Paediatric question with sources ~241
A parent's paediatric question answered only from published guidelines (WHO, NHS, CDC, SEUP, AEP, MedlinePlus, national health ministries), in English, Spanish, French, German, Russian, Arabic, Portuguese or Hindi. A rule-based triage runs before the model and flags emergencies with the country's number; doses come from fixed tables, never from the model; an answer that the sources do not support is refused instead of guessed. Use when a parent asks a free-form question about a baby's or child's health. For a medicine dose use child_medicine_dose; for a vaccination calendar use childhood_vaccination_schedule; to screen symptoms for danger use paediatric_warning_sign_check, which is faster and uses no AI.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | ISO 3166-1 alpha-2 of the parent's country, so the emergency number is the right one |
| lang | string | – | Language of the answer. Sources are quoted whatever language they were written in. |
| question | string | yes | The question in plain words, e.g. 'my 2 year old has had a fever of 39 for two days' |
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string | – | The answer, naming the organisation behind each clinical sentence |
| banner | string|null | – | The warning to show first when the level is not routine, with the country's number |
| disclaimer | string | – | Information from published guidelines, not medical advice |
| level | string | – | routine, urgent, emergency or mental_health, from the rule-based triage |
| sources | array | – | The documents cited, with organisation, title and URL |
| verification | string | – | ok, regenerated, no_source or asked_age: how the answer passed the citation check |
No examples provided.
paediatric_warning_sign_check Paediatric warning sign check ~256
Checks a description of a child's symptoms against 97 fixed warning-sign rules, each tied to a published parent sheet, in eight languages and four scripts: breathing difficulty, seizures, meningitis signs, dehydration, poisoning, bites, heatstroke, newborn jaundice. Returns the level (emergency, urgent, mental_health, or routine when no rule fires), the rules that fired with their source, the warning text and the country's emergency number. No model: the same result every time. Use when symptoms are described, first, to know if the child needs emergency care, a visit today or home care. For the full explanation afterwards use paediatric_question_with_sources; for fluids in vomiting or diarrhoea with no danger sign, oral_rehydration_plan.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | ISO 3166-1 alpha-2, to return the right emergency number |
| lang | string | – | Language of the warning and the reasons |
| symptoms | string | yes | What is happening, in the parent's own words and any of the eight languages, e.g. 'my baby is breathing fast and his lips look blue'. Include the age if known: some rules depend on it (fever under 3… |
| Name | Type | Req | Description |
|---|---|---|---|
| age_months | number|null | – | The age read from the text, if any |
| banner | string|null | – | The warning to show, or null when routine |
| call | string|null | – | The number to dial, only for an emergency in a known country |
| disclaimer | string | – | Not a diagnosis |
| level | string | – | routine, urgent, emergency or mental_health |
| numbers | object | – | The country's emergency and poison numbers |
| rules | array | – | Each rule that fired: id, level, reason in the requested language and the document it comes from |
No examples provided.
What is the PediBot MCP server?
PediBot is an MCP server listed in the public MCP registry as xyz.pedibot/pedibot. Children's health from published guidelines: doses, vaccines, growth charts, warning signs. This page covers its hosted endpoint (https://pedibot.xyz/mcp).
Is the PediBot MCP server safe to use?
PediBot scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the PediBot MCP server expose?
PediBot exposes 8 tools: paediatric_question_with_sources, child_friendly_health_explanation, paediatric_warning_sign_check, child_growth_percentile, child_medicine_dose, and 3 more. Their descriptions and schemas cost roughly 1,997 tokens of context every time the server is loaded.
Does the PediBot MCP server require authentication?
No. We connected to PediBot without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the PediBot MCP server still maintained?
PediBot is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.