Agent Tool Risk Report
gitmcp.io
Generated by the Conformant public-subset battery and anchored to the Sigstore/Rekor transparency log. The grade below is tamper-evident: recompute the report’s canonical hash and compare it with the Rekor entry.
https://gitmcp.io/docs
GitMCP · public-subset battery v2.0.0 · Fri, 14 Aug 2026 07:38:59 GMT · report b529737d01474c5c
A
Overall A (93/100). Cleared for connection review: no material findings on the public battery.
Second axis · not part of the grade
Spec 2026-07-28 readiness
PARTIAL76
Interoperable, not yet migrated. Measured against the specification finalized 2026-07-28.
- RDY-01Transport generationcurrentStreamable HTTP: the transport the 2026-07-28 stateless core is built on.
- RDY-02Protocol revisionpartialNegotiated 2025-03-26 when offered 2026-07-28. Still interoperable, not yet on the current revision.
- RDY-03Stateless corepartialIssues Mcp-Session-Id. Sessions remain valid under 2026-07-28, but the stateless core no longer requires them; confirm session loss is handled gracefully.
- RDY-04Client registrationn/aNo authorization-server metadata published at the origin: registration posture not observable remotely.
- RDY-05Cacheable tool catalogpartialNo ttlMs or cacheScope on tools/list: clients re-fetch the catalog every session.
- RDY-06Deprecated capabilitiescurrentAdvertises no deprecated capabilities.
Readiness measures migration posture against the specification finalized 2026-07-28. It is reported separately because a well-authenticated server on deprecated transport is a migration risk, not a security defect — scoring both on one axis would misprice both. Signals that could not be evaluated are excluded from the score rather than counted as passing.
CFM-01AuthenticationWARN
Anonymous by design: every exposed tool is read-only.
- Open endpoint, read-only surface. The server completes initialize and lists tools without credentials, but all exposed tools are read-only. Acceptable for public-data servers; confirm no tenant-scoped data is reachable.
CFM-02Authorization (OAuth)N/A
No authentication layer present to evaluate (see CFM-01).
CFM-03Tool poisoningPASS
No injection patterns detected across 5 tool description(s).
CFM-04Scopes & least privilegePASS
Tool surface (5 tool(s)) is scoped: no over-privilege signals.
CFM-05Secrets exposurePASS
No credential patterns in disclosed tool definitions or instructions.
CFM-06Destructive-tool guardrailsPASS
No destructive-class tools exposed.
CFM-08Transport securityPASS
TLS transport.
CFM-10Exposed configuration surfacePASS
No configuration or credential documents served at well-known paths. 5 path(s) answered with a page shell rather than a document and were not counted.
CFM-09Command-injection exposure (advisory)INFO
No command-execution sinks or transport-steering content observed on the public surface. Local STDIO config-injection (OX Security, 2026-04-15) is attested, not remotely testable.
✔ anchoredsha256:b529737d0147…a34959→ Sigstore/Rekor logIndex 2463229298verify ↗tamper-evident · independently checkable