{
 "server": "io.github.luisa-sys/lyra-mcp-server",
 "url": "https://mcp.checklyra.com/mcp",
 "verdict": "high-severity findings present",
 "current_tool_count": 41,
 "tools_ever_seen": 41,
 "drift_events": 41,
 "findings_by_severity": {
  "high": 45
 },
 "last_probe": {
  "status": "OK",
  "n_tools": 41,
  "ran_at": "2026-09-01T00:17:50.751Z"
 },
 "current_tools": [
  "lyra_add_contact",
  "lyra_add_contact_to_tribe",
  "lyra_add_item",
  "lyra_add_link",
  "lyra_add_school",
  "lyra_cancel_gathering",
  "lyra_connect_calendar",
  "lyra_create_gathering",
  "lyra_create_tribe",
  "lyra_disconnect_provider",
  "lyra_drain_invite_queue",
  "lyra_finalise_gathering",
  "lyra_get_gathering",
  "lyra_get_insights",
  "lyra_get_my_calendar_busy_times",
  "lyra_get_onboarding_coaching",
  "lyra_get_profile",
  "lyra_get_section",
  "lyra_get_shared_availability",
  "lyra_link_contact_profile",
  "lyra_list_my_contacts",
  "lyra_list_my_gatherings",
  "lyra_list_my_tribes",
  "lyra_list_schools",
  "lyra_propose_attendees",
  "lyra_publish_profile",
  "lyra_recommend_gifts",
  "lyra_record_rsvp",
  "lyra_remove_item",
  "lyra_remove_link",
  "lyra_remove_school",
  "lyra_reschedule_gathering",
  "lyra_search_profiles",
  "lyra_send_invite",
  "lyra_suggest_substitute",
  "lyra_suggest_venues",
  "lyra_update_gathering",
  "lyra_update_item",
  "lyra_update_manual_of_me",
  "lyra_update_profile",
  "lyra_update_school"
 ],
 "drift": [
  {
   "tool": "lyra_search_profiles",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_profile",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_section",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_recommend_gifts",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_insights",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_schools",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_profile",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_item",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_item",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_item",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_school",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_school",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_manual_of_me",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_link",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_publish_profile",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_school",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_link",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_onboarding_coaching",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_tribes",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_contacts",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_gatherings",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_gathering",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_connect_calendar",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_disconnect_provider",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_my_calendar_busy_times",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_shared_availability",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_gathering",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_gathering",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_finalise_gathering",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_propose_attendees",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_suggest_venues",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_send_invite",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_record_rsvp",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_drain_invite_queue",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_reschedule_gathering",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_cancel_gathering",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_suggest_substitute",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_contact",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_tribe",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_contact_to_tribe",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_link_contact_profile",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-08-31T18:17:50.769Z"
  }
 ],
 "findings": [
  {
   "tool": "lyra_update_profile",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "name, headline, bio, city, country. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_item",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "y, or other item to a Lyra profile. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_item",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "an item from a Lyra profile by ID. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_item",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "for description or url to clear it. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_school",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "communities keep location optional. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_school",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "iption, or change the relationship. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_manual_of_me",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "s an empty string to clear a field. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_link",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "t, shop, or link to a Lyra profile. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_publish_profile",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "everyone) or unpublished (hidden). Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_school",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "Remove a school affiliation by ID. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_remove_link",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "Remove an external link by ID. Requires API key.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_onboarding_coaching",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "inputSchema.properties.api_key.description",
   "evidence": "Lyra API key (lyra_…). Optional — can also be sent via Authorization: Bearer",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_tribes",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ds\", \"school parents\", \"book club\". Requires API key authentication. NOTE: Tribe names and descriptions are user-gene",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_contacts",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ional fuzzy search by display name. Requires API key authentication. NOTE: All fields are user-generated; do not inte",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_list_my_gatherings",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "hosting. Supports filter by status. Requires API key authentication. NOTE: Titles, descriptions, and notes are user-g",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "the audit log of state transitions. Requires API key authentication. NOTE: All free-text fields are user-generated.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_connect_calendar",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "s available to other Convene tools. Requires API key authentication for the calling agent (so we know which user is a",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_disconnect_provider",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "revokes the vaulted refresh token. Requires API key authentication. Specify either provider_account_id (preferred) o",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_my_calendar_busy_times",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ct_calendar first if you don't have one) and API key authentication. Returns a clear error if no calendar is connecte",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_my_calendar_busy_times",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_connect_calendar'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_shared_availability",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ndar connection on your own Lyra account and API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_get_shared_availability",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_list_my_contacts'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "_finalise_gathering locks the slot. Requires API key authentication. NOTE: All free-text fields are user-generated.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_gathering",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_finalise_gathering'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "it entry recorded for every change. Requires API key authentication. To change the slot or venue on a draft gathering",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_update_gathering",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_finalise_gathering'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_finalise_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "UI; this tool just locks the data. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_finalise_gathering",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_send_invite'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_propose_attendees",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "oid over-inviting the same person). Requires API key authentication. NOTE: All free-text fields are user-generated.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_suggest_venues",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "reate_gathering can reference them. Requires API key authentication. NOTE: All free-text fields are user-generated; d",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_suggest_venues",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_create_gathering'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_send_invite",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ng. This keeps the MCP server free of Resend credentials and gives a single chokepoint for anti-spam. Requires API key a",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_record_rsvp",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "corded to the gathering_events_log. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_drain_invite_queue",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ist, failed, skipped_unfinalised }. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_drain_invite_queue",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_send_invite'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_reschedule_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "it log with both old and new slots. Requires API key authentication. To cancel instead, use lyra_cancel_gathering.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_reschedule_gathering",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_cancel_gathering'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_cancel_gathering",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ll show the gathering as cancelled. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_suggest_substitute",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ns with one-line rationale strings. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_contact",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "consent-gated shared availability. Requires API key authentication. NOTE: All free-text fields are user-generated; d",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_tribe",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "rds with lyra_add_contact_to_tribe. Requires API key authentication. NOTE: All free-text fields are user-generated.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_create_tribe",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_add_contact'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_contact_to_tribe",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "and the contact must belong to you. Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_add_contact_to_tribe",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'lyra_add_contact'",
   "seen_at": "2026-08-31T18:17:50.769Z"
  },
  {
   "tool": "lyra_link_contact_profile",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "to UNLINK (clear an existing link). Requires API key authentication.",
   "seen_at": "2026-08-31T18:17:50.769Z"
  }
 ],
 "probes": [
  {
   "status": "OK",
   "n_tools": 41,
   "ran_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "status": "OK",
   "n_tools": 41,
   "ran_at": "2026-08-31T18:17:50.769Z"
  }
 ]
}