audit_mcp
shallowonline.sasame/research · Verify this server
Grade one MCP server A-D against the Agent-Tool Discoverability Standard. SaSame, operated by SASAME S.R.L., continuously observes and measures the Model Context Protocol ecosystem and publishes verifiable evidence and history; the MCP Factory is internal machinery and an optional product surface behind it; measurement only, not endorsement. Runs the legitimate revision-aware MCP protocol entry (server/discover with legacy initialize fallback), tools/list, and one read-only tool call over POST JSON-RPC. It returns the grade, a per-criterion pass/evidence breakdown, and the single biggest gap to fix. This returns the grade and analysis ONLY — if you want a signed, portable certificate of the same audit, use verify_mcp_ready instead. DIRECTORY PRE-FLIGHT: these criteria cover the MECHANICAL reject reasons of the Claude Connectors Directory and ChatGPT Apps Directory (annotations, typed schemas, description clarity, liveness, graceful errors, anti-ghost) — run it before you submit. It does NOT cover privacy-policy, identity/business verification, OAuth callbacks, or prohibited-category rules; it catches mechanical failures, it does not guarantee a pass. SECURITY SIGNALS (advisory, never a verdict): plain-HTTP exposure, redirect count, Server/X-Powered-By header disclosure, stack-trace-shaped text in error responses (zero extra cost — read from responses already fetched), plus two bounded best-effort checks — RFC 9728 OAuth protected-resource metadata and TLS certificate expiry/trust-chain status. CAPABILITY SIGNALS (advisory, never graded): resources/list and prompts/list support (OPTIONAL per the MCP spec — their absence is not a defect), tools/list pagination, and the raw capabilities the server declared. Protocol inspection only — no auth-bypass, no payment. Free. Best run against YOUR OWN server. (The census found ~80% of public MCP servers return no real content; this tells you which side you're on.)
1 trials · measured 2 days ago
audit_mcp scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against online.sasame/research, measured 31 Aug 2026 under methodology v0.2.0. Every measured component scored 100.
Component breakdown
| Component | Weight | Value |
|---|---|---|
| Reliability | 35% | not applicable |
| Schema integrity | 25% | 100.0 |
| Failure behaviour | 15% | not applicable |
| Latency | 15% | not applicable |
| Concurrency | 10% | not applicable |
Tool details
- Transport
- remote
- Credential class
- open
- Category
- Finance & compliance
- Input schema
- not declared
- Output schema
- not declared
- Side-effect classification
- unclassified
Score history
| Day | Score | Tier | Methodology |
|---|---|---|---|
| 2026-08-31 | 100.0 | shallow | v0.2.0 |
Probe evidence
| Probe | Outcomes |
|---|---|
| schema_integrity | pass: 1 |
Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.
Embed this score
Available for every tool, scored or not — not a verification perk. Always links back to this page.
[](https://vouch.tools/tools/2c403fab-6939-481f-aad7-4c4feb248ec1)