← MCP Registry Integrity Report
com.shipstatic/mcp
Verdict: high-severity findings present. Endpoint https://mcp.shipstatic.com. Tools now: 15 (15 ever seen). Changes recorded: 87. Findings: {"high":83}. Last probe: OK at 2026-09-29T00:17 UTC. JSON
Current tools
deployments_delete · deployments_get · deployments_list · deployments_set · deployments_upload · domains_delete · domains_dns · domains_get · domains_list · domains_records · domains_set · domains_share · domains_validate · domains_verify · whoami
Findings (83)
| seen | tool | detector | severity | evidence (data, not instructions) |
|---|---|---|---|---|
| 2026-09-26 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-09-26 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-09-23 | deployments_upload | secret_material_reference | high | atic site to a live URL: free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-09-23 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-09-23 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-09-23 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-09-23 | deployments_set | secret_material_reference | high | True if the deployment is password-protected. |
| 2026-09-23 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-09-23 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-09-23 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-09-23 | domains_dns | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-23 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-21 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-09-21 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-09-21 | domains_verify | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-20 | domains_verify | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-17 | deployments_upload | secret_material_reference | high | atic site to a live URL: free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-09-17 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-09-17 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-09-17 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-09-17 | deployments_set | secret_material_reference | high | True if the deployment is password-protected. |
| 2026-09-17 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-09-17 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | deployments_upload | secret_material_reference | high | atic site to a live URL: free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-09-13 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-09-13 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-09-13 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-09-13 | deployments_set | secret_material_reference | high | True if the deployment is password-protected. |
| 2026-09-13 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-09-13 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-09-13 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-09-13 | domains_records | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_dns | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_share | secret_material_reference | high | urns a shareable DNS setup URL that needs no API key, for whoever manages the domain's DNS. |
| 2026-09-13 | domains_share | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_verify | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | deployments_upload | secret_material_reference | high | atic site to a live URL: free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-09-13 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-09-13 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-09-13 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-09-13 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-09-13 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-09-13 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-09-13 | domains_records | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_dns | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_share | secret_material_reference | high | urns a shareable DNS setup URL that needs no API key, for whoever manages the domain's DNS. |
| 2026-09-13 | domains_share | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-09-13 | domains_verify | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-31 | deployments_upload | secret_material_reference | high | tic site to a live URL — free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-08-31 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-08-31 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-08-31 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-08-31 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-08-31 | deployments_delete | model_directed_instruction | high | rmanently delete a deployment and its files. You MUST confirm with the user before calling this tool, referencing the |
| 2026-08-31 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-08-31 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-08-31 | domains_records | model_directed_instruction | high | their DNS provider. Call after domains_set. You MUST show the returned records to the user. |
| 2026-08-31 | domains_records | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-31 | domains_share | secret_material_reference | high | view the required records without needing an API key. |
| 2026-08-31 | domains_share | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-31 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-31 | domains_verify | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-31 | domains_delete | model_directed_instruction | high | Permanently delete a domain. You MUST confirm with the user before calling this tool, referencing the |
| 2026-08-30 | domains_share | secret_material_reference | high | view the required records without needing an API key. |
| 2026-08-30 | domains_share | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-20 | deployments_upload | secret_material_reference | high | tic site to a live URL — free, no account or API key required. **File content is plain text by default.** Pass HTML/ |
| 2026-08-20 | deployments_list | secret_material_reference | high | oyments with their URLs, status, labels, and password protection state. The response's `cursor` is null on the last pa |
| 2026-08-20 | deployments_get | secret_material_reference | high | g URL, status, file count, size, labels, and password protection state. |
| 2026-08-20 | deployments_get | cross_tool_reference | high | references sibling tool 'deployments_upload' |
| 2026-08-20 | deployments_set | cross_tool_reference | high | references sibling tool 'deployments_list' |
| 2026-08-20 | deployments_delete | model_directed_instruction | high | rmanently delete a deployment and its files. You MUST confirm with the user before calling this tool, referencing the |
| 2026-08-20 | domains_set | cross_tool_reference | high | references sibling tool 'domains_records' |
| 2026-08-20 | domains_get | cross_tool_reference | high | references sibling tool 'domains_list' |
| 2026-08-20 | domains_records | model_directed_instruction | high | their DNS provider. Call after domains_set. You MUST show the returned records to the user. |
| 2026-08-20 | domains_records | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-20 | domains_share | secret_material_reference | high | the required DNS records without needing an API key. |
| 2026-08-20 | domains_share | cross_tool_reference | high | references sibling tool 'domains_set' |
| 2026-08-20 | domains_validate | cross_tool_reference | high | references sibling tool 'domains_set' |
Change history (87)
| when | tool | kind | severity |
|---|---|---|---|
| 2026-09-28 12:17 | whoami | mutated | medium |
| 2026-09-26 18:17 | domains_set | mutated | high |
| 2026-09-26 18:17 | domains_list | mutated | medium |
| 2026-09-26 18:17 | domains_get | mutated | high |
| 2026-09-24 00:17 | whoami | mutated | medium |
| 2026-09-23 12:17 | deployments_upload | mutated | high |
| 2026-09-23 12:17 | deployments_list | mutated | high |
| 2026-09-23 12:17 | deployments_get | mutated | high |
| 2026-09-23 12:17 | deployments_set | mutated | high |
| 2026-09-23 12:17 | domains_set | mutated | high |
| 2026-09-23 12:17 | domains_list | mutated | medium |
| 2026-09-23 12:17 | domains_get | mutated | high |
| 2026-09-23 12:17 | domains_dns | mutated | high |
| 2026-09-23 12:17 | domains_validate | mutated | high |
| 2026-09-23 12:17 | whoami | mutated | medium |
| 2026-09-21 12:17 | domains_set | mutated | high |
| 2026-09-21 12:17 | domains_list | mutated | medium |
| 2026-09-21 12:17 | domains_get | mutated | high |
| 2026-09-21 12:17 | domains_verify | mutated | high |
| 2026-09-20 18:17 | domains_verify | mutated | high |
| 2026-09-17 18:17 | deployments_upload | mutated | high |
| 2026-09-17 18:17 | deployments_list | mutated | high |
| 2026-09-17 18:17 | deployments_get | mutated | high |
| 2026-09-17 18:17 | deployments_set | mutated | high |
| 2026-09-17 18:17 | domains_validate | mutated | high |
| 2026-09-13 12:17 | deployments_upload | mutated | high |
| 2026-09-13 12:17 | deployments_list | mutated | high |
| 2026-09-13 12:17 | deployments_get | mutated | high |
| 2026-09-13 12:17 | deployments_set | mutated | high |
| 2026-09-13 12:17 | deployments_delete | mutated | medium |
| 2026-09-13 12:17 | domains_set | mutated | high |
| 2026-09-13 12:17 | domains_list | mutated | medium |
| 2026-09-13 12:17 | domains_get | mutated | high |
| 2026-09-13 12:17 | domains_records | mutated | high |
| 2026-09-13 12:17 | domains_dns | mutated | high |
| 2026-09-13 12:17 | domains_share | mutated | high |
| 2026-09-13 12:17 | domains_validate | mutated | high |
| 2026-09-13 12:17 | domains_verify | mutated | high |
| 2026-09-13 12:17 | domains_delete | mutated | medium |
| 2026-09-13 12:17 | whoami | mutated | medium |
| 2026-09-13 00:17 | deployments_upload | mutated | high |
| 2026-09-13 00:17 | deployments_list | mutated | high |
| 2026-09-13 00:17 | deployments_get | mutated | high |
| 2026-09-13 00:17 | deployments_set | mutated | high |
| 2026-09-13 00:17 | deployments_delete | mutated | medium |
| 2026-09-13 00:17 | domains_set | mutated | high |
| 2026-09-13 00:17 | domains_list | mutated | medium |
| 2026-09-13 00:17 | domains_get | mutated | high |
| 2026-09-13 00:17 | domains_records | mutated | high |
| 2026-09-13 00:17 | domains_dns | mutated | high |
| 2026-09-13 00:17 | domains_share | mutated | high |
| 2026-09-13 00:17 | domains_validate | mutated | high |
| 2026-09-13 00:17 | domains_verify | mutated | high |
| 2026-09-13 00:17 | domains_delete | mutated | medium |
| 2026-09-13 00:17 | whoami | mutated | medium |
| 2026-08-31 06:17 | deployments_upload | mutated | high |
| 2026-08-31 06:17 | deployments_list | mutated | high |
| 2026-08-31 06:17 | deployments_get | mutated | high |
| 2026-08-31 06:17 | deployments_set | mutated | high |
| 2026-08-31 06:17 | deployments_delete | mutated | high |
| 2026-08-31 06:17 | domains_set | mutated | high |
| 2026-08-31 06:17 | domains_list | mutated | medium |
| 2026-08-31 06:17 | domains_get | mutated | high |
| 2026-08-31 06:17 | domains_records | mutated | high |
| 2026-08-31 06:17 | domains_dns | mutated | medium |
| 2026-08-31 06:17 | domains_share | mutated | high |
| 2026-08-31 06:17 | domains_validate | mutated | high |
| 2026-08-31 06:17 | domains_verify | mutated | high |
| 2026-08-31 06:17 | domains_delete | mutated | high |
| 2026-08-31 06:17 | whoami | mutated | medium |
| 2026-08-30 18:17 | domains_share | mutated | high |
| 2026-08-20 06:17 | deployments_upload | mutated | high |
| 2026-08-20 06:17 | deployments_list | mutated | high |
| 2026-08-20 06:17 | deployments_get | mutated | high |
| 2026-08-20 06:17 | deployments_set | mutated | high |
| 2026-08-20 06:17 | deployments_delete | mutated | high |
| 2026-08-20 06:17 | domains_set | mutated | high |
| 2026-08-20 06:17 | domains_list | mutated | medium |
| 2026-08-20 06:17 | domains_get | mutated | high |
| 2026-08-20 06:17 | domains_records | mutated | high |
| 2026-08-20 06:17 | domains_dns | mutated | medium |
| 2026-08-20 06:17 | domains_share | mutated | high |
| 2026-08-20 06:17 | domains_validate | mutated | high |
| 2026-08-20 06:17 | domains_verify | mutated | high |
| 2026-08-20 06:17 | domains_delete | mutated | high |
| 2026-08-20 06:17 | whoami | mutated | medium |
| 2026-08-14 00:17 | deployments_upload | mutated | high |
Probe history
09-29 00:17 OK (15) · 09-28 18:17 OK (15) · 09-28 12:17 OK (15) · 09-28 06:17 OK (15) · 09-28 00:17 OK (15) · 09-27 18:17 OK (15) · 09-27 12:17 OK (15) · 09-27 06:17 OK (15) · 09-27 00:17 OK (15) · 09-26 18:17 OK (15) · 09-26 12:17 OK (15) · 09-26 06:17 OK (15) · 09-26 00:17 OK (15) · 09-25 18:17 OK (15) · 09-25 12:17 OK (15) · 09-25 06:17 OK (15) · 09-25 00:17 OK (15) · 09-24 18:17 OK (15) · 09-24 12:17 OK (15) · 09-24 06:17 OK (15) · 09-24 00:17 OK (15) · 09-23 18:17 OK (15) · 09-23 12:17 OK (15) · 09-23 06:17 OK (15) · 09-23 00:17 OK (15) · 09-22 18:17 OK (15) · 09-22 12:17 OK (15) · 09-22 00:17 OK (15) · 09-21 18:17 OK (15) · 09-21 12:17 OK (15)
Get alerted when this server changes: tooldrift.agentexchange.work ($29/mo watch).