← MCP Registry Integrity Report

ai.borealhost/mcp

Verdict: high-severity findings present. Endpoint https://borealhost.ai/mcp/. Tools now: 144 (144 ever seen). Changes recorded: 38. Findings: {"high":50,"low":2}. Last probe: OK at 2026-08-13T06:17 UTC. JSON

Current tools

add_cron · add_domain_dns · add_firewall_rule · add_redirect · add_ssh_key · add_subdomain · adopt_compute_instance · attach_compute_volume · cache_flush · cache_status · cache_toggle · cancel_scheduled_snapshot · claim_api_key · cloudflare_proxy_status · cloudflare_purge_cache · cloudflare_set_proxy · complete_checkout · container_action · create_alert_rule · create_api_key · create_b2_snapshot · create_backup · create_checkout · create_compute_volume · create_directory · create_ftp_account · create_mailbox · create_snapshot · create_support_ticket · create_webhook · database_search_replace · decommission · delete_account · delete_alert_rule · delete_backup · delete_compute_volume · delete_cron · delete_domain_dns · delete_file · delete_mailbox · delete_redirect · delete_snapshot · delete_webhook · detach_compute_volume · domain_detail · domain_settings · enable_smtp_relay · enable_wildcard · execute_query · get_app_status · get_backup_retention · get_billing_portal · get_checkout_status · get_compute_instance · get_compute_volume · get_database_info · get_email_status · get_logs · get_metrics · get_resource_snapshot · get_site_status · get_smtp_relay · get_snapshot_usage · get_ssh_info · get_stack_info · get_support_ticket · get_webmail_url · install_app · launch_compute_instance · link_domain · list_alert_rules · list_api_keys · list_apps · list_backups · list_compute_images · list_compute_instances · list_compute_types · list_compute_volumes · list_cron · list_databases · list_db_users · list_domain_dns · list_domains · list_files · list_firewall_rules · list_ftp_accounts · list_modules · list_php_versions · list_plans · list_plugins · list_redirects · list_snapshots · list_subdomains · list_subscriptions · list_support_tickets · list_tables · list_themes · list_webhooks · manage_db_user · manage_dns · manage_plugin · manage_theme · optimize_database · read_file · reboot_compute_instance · register · register_domain · remove_firewall_rule · remove_ftp_account · reply_support_ticket · request_api_key · reset_mailbox_password · restore_backup · revoke_api_key · revoke_smtp_relay · rollback_snapshot · rotate_key · run_malware_scan · scale · schedule_snapshot · search_domain · set_api_key · set_backup_retention · set_domain_usage · set_force_https · setup_email · snapshot_compute_volume · ssl_info · ssl_renew · start_compute_instance · stop_compute_instance · switch_php · terminate_compute_instance · test_webhook · toggle_module · transfer_out_domain · update_account · update_checkout · upload_file · upload_ssl_cert · whoami · wp_check_updates · wp_update_all · write_file

Findings (52)

seentooldetectorseverityevidence (data, not instructions)
2026-08-13registersecret_material_referencehighRegister a new agent account and get an API key. No authentication needed. The returned API key grants read+wri
2026-08-13set_api_keysecret_material_referencehighset_api_key
2026-08-13set_api_keycross_tool_referencehighreferences sibling tool 'register'
2026-08-13whoamisecret_material_referencehighCheck the current API key's account info, scopes, and site count. Requires: BOREALHOST_AP
2026-08-13request_api_keysecret_material_referencehighrequest_api_key
2026-08-13request_api_keycross_tool_referencehighreferences sibling tool 'claim_api_key'
2026-08-13claim_api_keysecret_material_referencehighclaim_api_key
2026-08-13claim_api_keycross_tool_referencehighreferences sibling tool 'request_api_key'
2026-08-13create_checkoutcross_tool_referencehighreferences sibling tool 'list_plans'
2026-08-13update_checkoutcross_tool_referencehighreferences sibling tool 'create_checkout'
2026-08-13complete_checkoutsecret_material_referencehighus() until status becomes "completed". The API key appears in the first poll after payment (shown once, then clea
2026-08-13complete_checkouturl_in_descriptionlowhttps://borealhost.ai/pay/<id
2026-08-13complete_checkoutcross_tool_referencehighreferences sibling tool 'get_checkout_status'
2026-08-13get_checkout_statussecret_material_referencehigheing provisioned - "completed": Site ready — API key included (shown once, then cleared) - "canceled": Checkout was a
2026-08-13get_checkout_statuscross_tool_referencehighreferences sibling tool 'complete_checkout'
2026-08-13get_site_statussecret_material_referencehighresources, domains, and modules. Requires: API key with read scope. Args: slug: Site identifier (the slug chos
2026-08-13manage_dnssecret_material_referencehighor delete DNS records for a site. Requires: API key with write scope. Args: slug: Site identifier action: "
2026-08-13install_appsecret_material_referencehighll get_app_status() for progress. Requires: API key with write scope. VPS or Cloud plan only. Args: slug: Site
2026-08-13install_appcross_tool_referencehighreferences sibling tool 'get_app_status'
2026-08-13get_app_statussecret_material_referencehighinstall_app() to track progress. Requires: API key with read scope. Args: slug: Site identifier app_id: Ap
2026-08-13get_app_statuscross_tool_referencehighreferences sibling tool 'install_app'
2026-08-13list_appssecret_material_referencehighList installed apps on a site. Requires: API key with read scope. Args: slug: Site identifier Returns:
2026-08-13list_snapshotssecret_material_referencehighd scheduled snapshots for a site. Requires: API key with read scope. Args: slug: Site identifier Returns:
2026-08-13create_snapshotsecret_material_referencehighisk and count against disk quota. Requires: API key with write scope. Args: slug: Site identifier descripti
2026-08-13create_snapshotcross_tool_referencehighreferences sibling tool 'list_snapshots'
2026-08-13create_b2_snapshotsecret_material_referencehighd". Only available for VPS plans. Requires: API key with write scope. Args: slug: Site identifier descripti
2026-08-13create_b2_snapshotcross_tool_referencehighreferences sibling tool 'list_snapshots'
2026-08-13delete_snapshotsecret_material_referencehighDelete a snapshot (local or B2). Requires: API key with write scope. Args: slug: Site identifier snapshot_
2026-08-13rollback_snapshotsecret_material_referencehighlaced with the snapshot contents. Requires: API key with admin scope. Args: slug: Site identifier snapshot_
2026-08-13get_snapshot_usagesecret_material_referencehighusage and quota info for a site. Requires: API key with read scope. Args: slug: Site identifier Returns:
2026-08-13schedule_snapshotsecret_material_referencehigha snapshot for future execution. Requires: API key with write scope. Max 3 pending schedules per site. Args: s
2026-08-13cancel_scheduled_snapshotsecret_material_referencehighCancel a scheduled snapshot. Requires: API key with write scope. Args: slug: Site identifier schedule_
2026-08-13list_backupssecret_material_referencehighor a site (automatic and manual). Requires: API key with read scope. Args: slug: Site identifier Returns:
2026-08-13create_backupsecret_material_referencehighl list_backups() to check status. Requires: API key with write scope. Args: slug: Site identifier Returns:
2026-08-13create_backupcross_tool_referencehighreferences sibling tool 'list_backups'
2026-08-13restore_backupsecret_material_referencehighously — may take several minutes. Requires: API key with admin scope. Args: slug: Site identifier backup_id
2026-08-13get_metricssecret_material_referencehighd performance metrics for a site. Requires: API key with read scope. Args: slug: Site identifier days: Numb
2026-08-13scalesecret_material_referencehighting plan (upgrade or downgrade). Requires: API key with admin scope. Best practice: create a snapshot before downgr
2026-08-13scalecross_tool_referencehighreferences sibling tool 'list_plans'
2026-08-13decommissionsecret_material_referencehighsnapshot before decommissioning. Requires: API key with admin scope. Args: slug: Site identifier Returns:
2026-08-13update_accountsecret_material_referencehighe fields (email, language, name). Requires: API key with write scope. Only provided (non-empty) fields are updated.
2026-08-13delete_accountsecret_material_referencehighAll sites will be decommissioned. Requires: API key with admin scope. Returns: {"success": true, "message": "Ac
2026-08-13delete_accountcross_tool_referencehighreferences sibling tool 'decommission'
2026-08-13list_subscriptionssecret_material_referencehigh, pricing, status, and site slug. Requires: API key with read scope. Returns: [{"id": "uuid", "plan_slug": "sit
2026-08-13get_billing_portalsecret_material_referencehighthe human can open in a browser. Requires: API key with read scope. Args: flow: Optional. Set to "payment_meth
2026-08-13get_billing_portalurl_in_descriptionlowhttps://billing.stripe.com/p/session/...
2026-08-13rotate_keysecret_material_referencehighAtomically rotate an API key. Old key is immediately invalidated. Creates a new key with the
2026-08-13create_api_keysecret_material_referencehighcreate_api_key
2026-08-13list_api_keyssecret_material_referencehighlist_api_keys
2026-08-13revoke_api_keysecret_material_referencehighrevoke_api_key
2026-08-13revoke_api_keycross_tool_referencehighreferences sibling tool 'list_api_keys'
2026-08-13get_ssh_infosecret_material_referencehighcated plans (not shared hosting). Requires: API key with read scope. Args: slug: Site identifier Returns:

Change history (38)

whentoolkindseverity
2026-08-13 06:17registeraddedhigh
2026-08-13 06:17set_api_keyaddedhigh
2026-08-13 06:17whoamiaddedhigh
2026-08-13 06:17request_api_keyaddedhigh
2026-08-13 06:17claim_api_keyaddedhigh
2026-08-13 06:17list_plansaddedinfo
2026-08-13 06:17create_checkoutaddedhigh
2026-08-13 06:17update_checkoutaddedhigh
2026-08-13 06:17complete_checkoutaddedhigh
2026-08-13 06:17get_checkout_statusaddedhigh
2026-08-13 06:17get_site_statusaddedhigh
2026-08-13 06:17manage_dnsaddedhigh
2026-08-13 06:17install_appaddedhigh
2026-08-13 06:17get_app_statusaddedhigh
2026-08-13 06:17list_appsaddedhigh
2026-08-13 06:17list_snapshotsaddedhigh
2026-08-13 06:17create_snapshotaddedhigh
2026-08-13 06:17create_b2_snapshotaddedhigh
2026-08-13 06:17delete_snapshotaddedhigh
2026-08-13 06:17rollback_snapshotaddedhigh
2026-08-13 06:17get_snapshot_usageaddedhigh
2026-08-13 06:17schedule_snapshotaddedhigh
2026-08-13 06:17cancel_scheduled_snapshotaddedhigh
2026-08-13 06:17list_backupsaddedhigh
2026-08-13 06:17create_backupaddedhigh
2026-08-13 06:17restore_backupaddedhigh
2026-08-13 06:17get_metricsaddedhigh
2026-08-13 06:17scaleaddedhigh
2026-08-13 06:17decommissionaddedhigh
2026-08-13 06:17update_accountaddedhigh
2026-08-13 06:17delete_accountaddedhigh
2026-08-13 06:17list_subscriptionsaddedhigh
2026-08-13 06:17get_billing_portaladdedhigh
2026-08-13 06:17rotate_keyaddedhigh
2026-08-13 06:17create_api_keyaddedhigh
2026-08-13 06:17list_api_keysaddedhigh
2026-08-13 06:17revoke_api_keyaddedhigh
2026-08-13 06:17get_ssh_infoaddedhigh

Probe history

08-13 06:17 OK (144)

Get alerted when this server changes: tooldrift.agentexchange.work ($29/mo watch).