← MCP Registry Integrity Report
ai.borealhost/mcp
Verdict: high-severity findings present. Endpoint https://borealhost.ai/mcp/. Tools now: 144 (144 ever seen). Changes recorded: 38. Findings: {"high":50,"low":2}. Last probe: OK at 2026-08-13T06:17 UTC. JSON
Current tools
add_cron · add_domain_dns · add_firewall_rule · add_redirect · add_ssh_key · add_subdomain · adopt_compute_instance · attach_compute_volume · cache_flush · cache_status · cache_toggle · cancel_scheduled_snapshot · claim_api_key · cloudflare_proxy_status · cloudflare_purge_cache · cloudflare_set_proxy · complete_checkout · container_action · create_alert_rule · create_api_key · create_b2_snapshot · create_backup · create_checkout · create_compute_volume · create_directory · create_ftp_account · create_mailbox · create_snapshot · create_support_ticket · create_webhook · database_search_replace · decommission · delete_account · delete_alert_rule · delete_backup · delete_compute_volume · delete_cron · delete_domain_dns · delete_file · delete_mailbox · delete_redirect · delete_snapshot · delete_webhook · detach_compute_volume · domain_detail · domain_settings · enable_smtp_relay · enable_wildcard · execute_query · get_app_status · get_backup_retention · get_billing_portal · get_checkout_status · get_compute_instance · get_compute_volume · get_database_info · get_email_status · get_logs · get_metrics · get_resource_snapshot · get_site_status · get_smtp_relay · get_snapshot_usage · get_ssh_info · get_stack_info · get_support_ticket · get_webmail_url · install_app · launch_compute_instance · link_domain · list_alert_rules · list_api_keys · list_apps · list_backups · list_compute_images · list_compute_instances · list_compute_types · list_compute_volumes · list_cron · list_databases · list_db_users · list_domain_dns · list_domains · list_files · list_firewall_rules · list_ftp_accounts · list_modules · list_php_versions · list_plans · list_plugins · list_redirects · list_snapshots · list_subdomains · list_subscriptions · list_support_tickets · list_tables · list_themes · list_webhooks · manage_db_user · manage_dns · manage_plugin · manage_theme · optimize_database · read_file · reboot_compute_instance · register · register_domain · remove_firewall_rule · remove_ftp_account · reply_support_ticket · request_api_key · reset_mailbox_password · restore_backup · revoke_api_key · revoke_smtp_relay · rollback_snapshot · rotate_key · run_malware_scan · scale · schedule_snapshot · search_domain · set_api_key · set_backup_retention · set_domain_usage · set_force_https · setup_email · snapshot_compute_volume · ssl_info · ssl_renew · start_compute_instance · stop_compute_instance · switch_php · terminate_compute_instance · test_webhook · toggle_module · transfer_out_domain · update_account · update_checkout · upload_file · upload_ssl_cert · whoami · wp_check_updates · wp_update_all · write_file
Findings (52)
| seen | tool | detector | severity | evidence (data, not instructions) |
|---|---|---|---|---|
| 2026-08-13 | register | secret_material_reference | high | Register a new agent account and get an API key. No authentication needed. The returned API key grants read+wri |
| 2026-08-13 | set_api_key | secret_material_reference | high | set_api_key |
| 2026-08-13 | set_api_key | cross_tool_reference | high | references sibling tool 'register' |
| 2026-08-13 | whoami | secret_material_reference | high | Check the current API key's account info, scopes, and site count. Requires: BOREALHOST_AP |
| 2026-08-13 | request_api_key | secret_material_reference | high | request_api_key |
| 2026-08-13 | request_api_key | cross_tool_reference | high | references sibling tool 'claim_api_key' |
| 2026-08-13 | claim_api_key | secret_material_reference | high | claim_api_key |
| 2026-08-13 | claim_api_key | cross_tool_reference | high | references sibling tool 'request_api_key' |
| 2026-08-13 | create_checkout | cross_tool_reference | high | references sibling tool 'list_plans' |
| 2026-08-13 | update_checkout | cross_tool_reference | high | references sibling tool 'create_checkout' |
| 2026-08-13 | complete_checkout | secret_material_reference | high | us() until status becomes "completed". The API key appears in the first poll after payment (shown once, then clea |
| 2026-08-13 | complete_checkout | url_in_description | low | https://borealhost.ai/pay/<id |
| 2026-08-13 | complete_checkout | cross_tool_reference | high | references sibling tool 'get_checkout_status' |
| 2026-08-13 | get_checkout_status | secret_material_reference | high | eing provisioned - "completed": Site ready — API key included (shown once, then cleared) - "canceled": Checkout was a |
| 2026-08-13 | get_checkout_status | cross_tool_reference | high | references sibling tool 'complete_checkout' |
| 2026-08-13 | get_site_status | secret_material_reference | high | resources, domains, and modules. Requires: API key with read scope. Args: slug: Site identifier (the slug chos |
| 2026-08-13 | manage_dns | secret_material_reference | high | or delete DNS records for a site. Requires: API key with write scope. Args: slug: Site identifier action: " |
| 2026-08-13 | install_app | secret_material_reference | high | ll get_app_status() for progress. Requires: API key with write scope. VPS or Cloud plan only. Args: slug: Site |
| 2026-08-13 | install_app | cross_tool_reference | high | references sibling tool 'get_app_status' |
| 2026-08-13 | get_app_status | secret_material_reference | high | install_app() to track progress. Requires: API key with read scope. Args: slug: Site identifier app_id: Ap |
| 2026-08-13 | get_app_status | cross_tool_reference | high | references sibling tool 'install_app' |
| 2026-08-13 | list_apps | secret_material_reference | high | List installed apps on a site. Requires: API key with read scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | list_snapshots | secret_material_reference | high | d scheduled snapshots for a site. Requires: API key with read scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | create_snapshot | secret_material_reference | high | isk and count against disk quota. Requires: API key with write scope. Args: slug: Site identifier descripti |
| 2026-08-13 | create_snapshot | cross_tool_reference | high | references sibling tool 'list_snapshots' |
| 2026-08-13 | create_b2_snapshot | secret_material_reference | high | d". Only available for VPS plans. Requires: API key with write scope. Args: slug: Site identifier descripti |
| 2026-08-13 | create_b2_snapshot | cross_tool_reference | high | references sibling tool 'list_snapshots' |
| 2026-08-13 | delete_snapshot | secret_material_reference | high | Delete a snapshot (local or B2). Requires: API key with write scope. Args: slug: Site identifier snapshot_ |
| 2026-08-13 | rollback_snapshot | secret_material_reference | high | laced with the snapshot contents. Requires: API key with admin scope. Args: slug: Site identifier snapshot_ |
| 2026-08-13 | get_snapshot_usage | secret_material_reference | high | usage and quota info for a site. Requires: API key with read scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | schedule_snapshot | secret_material_reference | high | a snapshot for future execution. Requires: API key with write scope. Max 3 pending schedules per site. Args: s |
| 2026-08-13 | cancel_scheduled_snapshot | secret_material_reference | high | Cancel a scheduled snapshot. Requires: API key with write scope. Args: slug: Site identifier schedule_ |
| 2026-08-13 | list_backups | secret_material_reference | high | or a site (automatic and manual). Requires: API key with read scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | create_backup | secret_material_reference | high | l list_backups() to check status. Requires: API key with write scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | create_backup | cross_tool_reference | high | references sibling tool 'list_backups' |
| 2026-08-13 | restore_backup | secret_material_reference | high | ously — may take several minutes. Requires: API key with admin scope. Args: slug: Site identifier backup_id |
| 2026-08-13 | get_metrics | secret_material_reference | high | d performance metrics for a site. Requires: API key with read scope. Args: slug: Site identifier days: Numb |
| 2026-08-13 | scale | secret_material_reference | high | ting plan (upgrade or downgrade). Requires: API key with admin scope. Best practice: create a snapshot before downgr |
| 2026-08-13 | scale | cross_tool_reference | high | references sibling tool 'list_plans' |
| 2026-08-13 | decommission | secret_material_reference | high | snapshot before decommissioning. Requires: API key with admin scope. Args: slug: Site identifier Returns: |
| 2026-08-13 | update_account | secret_material_reference | high | e fields (email, language, name). Requires: API key with write scope. Only provided (non-empty) fields are updated. |
| 2026-08-13 | delete_account | secret_material_reference | high | All sites will be decommissioned. Requires: API key with admin scope. Returns: {"success": true, "message": "Ac |
| 2026-08-13 | delete_account | cross_tool_reference | high | references sibling tool 'decommission' |
| 2026-08-13 | list_subscriptions | secret_material_reference | high | , pricing, status, and site slug. Requires: API key with read scope. Returns: [{"id": "uuid", "plan_slug": "sit |
| 2026-08-13 | get_billing_portal | secret_material_reference | high | the human can open in a browser. Requires: API key with read scope. Args: flow: Optional. Set to "payment_meth |
| 2026-08-13 | get_billing_portal | url_in_description | low | https://billing.stripe.com/p/session/... |
| 2026-08-13 | rotate_key | secret_material_reference | high | Atomically rotate an API key. Old key is immediately invalidated. Creates a new key with the |
| 2026-08-13 | create_api_key | secret_material_reference | high | create_api_key |
| 2026-08-13 | list_api_keys | secret_material_reference | high | list_api_keys |
| 2026-08-13 | revoke_api_key | secret_material_reference | high | revoke_api_key |
| 2026-08-13 | revoke_api_key | cross_tool_reference | high | references sibling tool 'list_api_keys' |
| 2026-08-13 | get_ssh_info | secret_material_reference | high | cated plans (not shared hosting). Requires: API key with read scope. Args: slug: Site identifier Returns: |
Change history (38)
| when | tool | kind | severity |
|---|---|---|---|
| 2026-08-13 06:17 | register | added | high |
| 2026-08-13 06:17 | set_api_key | added | high |
| 2026-08-13 06:17 | whoami | added | high |
| 2026-08-13 06:17 | request_api_key | added | high |
| 2026-08-13 06:17 | claim_api_key | added | high |
| 2026-08-13 06:17 | list_plans | added | info |
| 2026-08-13 06:17 | create_checkout | added | high |
| 2026-08-13 06:17 | update_checkout | added | high |
| 2026-08-13 06:17 | complete_checkout | added | high |
| 2026-08-13 06:17 | get_checkout_status | added | high |
| 2026-08-13 06:17 | get_site_status | added | high |
| 2026-08-13 06:17 | manage_dns | added | high |
| 2026-08-13 06:17 | install_app | added | high |
| 2026-08-13 06:17 | get_app_status | added | high |
| 2026-08-13 06:17 | list_apps | added | high |
| 2026-08-13 06:17 | list_snapshots | added | high |
| 2026-08-13 06:17 | create_snapshot | added | high |
| 2026-08-13 06:17 | create_b2_snapshot | added | high |
| 2026-08-13 06:17 | delete_snapshot | added | high |
| 2026-08-13 06:17 | rollback_snapshot | added | high |
| 2026-08-13 06:17 | get_snapshot_usage | added | high |
| 2026-08-13 06:17 | schedule_snapshot | added | high |
| 2026-08-13 06:17 | cancel_scheduled_snapshot | added | high |
| 2026-08-13 06:17 | list_backups | added | high |
| 2026-08-13 06:17 | create_backup | added | high |
| 2026-08-13 06:17 | restore_backup | added | high |
| 2026-08-13 06:17 | get_metrics | added | high |
| 2026-08-13 06:17 | scale | added | high |
| 2026-08-13 06:17 | decommission | added | high |
| 2026-08-13 06:17 | update_account | added | high |
| 2026-08-13 06:17 | delete_account | added | high |
| 2026-08-13 06:17 | list_subscriptions | added | high |
| 2026-08-13 06:17 | get_billing_portal | added | high |
| 2026-08-13 06:17 | rotate_key | added | high |
| 2026-08-13 06:17 | create_api_key | added | high |
| 2026-08-13 06:17 | list_api_keys | added | high |
| 2026-08-13 06:17 | revoke_api_key | added | high |
| 2026-08-13 06:17 | get_ssh_info | added | high |
Probe history
08-13 06:17 OK (144)
Get alerted when this server changes: tooldrift.agentexchange.work ($29/mo watch).