Robin Saige we check the tools AI agents call

Security Recipes

io.github.stevologic/security-recipes

Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

— the operator's own registry description reported

Publisher io.github.stevologic · first seen 2026-08-27 · endpoint https://security-recipes.ai/mcp

allow
verdict
rich-solo
cluster
ok_tools
answers
75
tools served

Dependency rating derived

allow
allow — alive & usable · kind unknown · V n/a
allow — because answers ●, 75 tools legible (band B) ●, no confirmed drift in 2 probes ●; not yet checked: truth (0 runs)

Cluster rich-solo · distinctiveness 0.785 (unusual). Every figure is a percentile or class within the 15,472-server censussee the whole spectrum.

Does it answer? Q1 · observed
answersalive_tools
latency298 ms
vs populationtypical
protocolcurrent
authopen
Can it be used? Q4 · observed
tools75
vs populationhigh
capabilities6
harnessB
Did it hold when checked? Q3–Q4 · derived
identitysolo
servers on its host1
verifiabilityunassessed
duplicate inventoryno
drift events0
answers trueno primary

🔏 Signed receipt rr_71462b500f2f9a05cb211fee · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.

Q1Does it answer?alive & usable — 2 probes ●evidence ↓
Q2What is it?kind unknown ● evidence ↓
Q3Can it be checked?V n/a for this kind ◐evidence ↓
Q4Did it hold?harness B · truth not yet run · no drift ●evidence ↓
Q5What company does it keep?rich-solo · 1 on its host (context, not verdict) ◐evidence ↓

● observed · ◐ derived · ○ reported — the verdict synthesizes Q1–Q4; Q5 is context. Methodology →

History observed

Every probe we made, oldest → newest (2 shown, 2026-08-30 → 2026-09-06). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.

changelog (1 events)
datetypewhat changed
2026-08-30outcomefirst probe: ok_tools

What kind of tools these are derived

Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):

naturetoolsmeaning what checking applies
unclassified50not classifiable from its textTier-1 only until its tools describe themselves
retrieval-public13serves public factstruth-checkable against a public source — the V-ladder applies in full
generative7creates contentno answer key exists; disclosure + stability checks, never truth verdicts
action3changes the worldno true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions
orchestration2routes other toolsidentity + fronted-service disclosure checks (gateway vs costume)

Tools last seen observed

recipes_a2a_agent_card_trust_profile recipes_agent_capability_risk_register recipes_agent_handoff_boundary_pack recipes_agent_identity_ledger recipes_agent_memory_boundary_pack recipes_agent_skill_supply_chain_pack recipes_agent_trust_fabric_pack recipes_agentic_action_runtime_pack recipes_agentic_aivss_risk_scoring_pack recipes_agentic_app_intake_pack recipes_agentic_approval_receipt_pack recipes_agentic_assurance_pack recipes_agentic_catastrophic_risk_annex recipes_agentic_control_plane_blueprint recipes_agentic_entitlement_review_pack recipes_agentic_exposure_graph recipes_agentic_incident_response_pack recipes_agentic_measurement_probe_pack recipes_agentic_posture_snapshot recipes_agentic_protocol_conformance_pack recipes_agentic_readiness_scorecard recipes_agentic_red_team_drill_pack recipes_agentic_red_team_replay_harness recipes_agentic_run_receipt_pack recipes_agentic_soc_detection_pack recipes_agentic_source_freshness_watch recipes_agentic_standards_crosswalk recipes_agentic_system_bom recipes_agentic_telemetry_contract recipes_agentic_threat_radar recipes_browser_agent_boundary_pack recipes_context_egress_boundary_pack recipes_context_poisoning_guard_pack recipes_critical_infrastructure_secure_context_pack recipes_cve_catalog_info recipes_cve_get recipes_cve_search recipes_design_partner_pilot_pack recipes_enterprise_trust_center_export recipes_get recipes_hosted_mcp_readiness_pack recipes_list recipes_match_finding recipes_mcp_authorization_conformance_pack recipes_mcp_connector_intake_pack recipes_mcp_connector_trust_pack recipes_mcp_elicitation_boundary_pack recipes_mcp_gateway_policy recipes_mcp_risk_coverage_pack recipes_mcp_server_get recipes_mcp_servers_list recipes_mcp_stdio_launch_boundary_pack recipes_mcp_tool_risk_contract recipes_mcp_tool_surface_drift_pack recipes_mcp_upstream_call recipes_mcp_upstream_context recipes_mcp_upstream_servers recipes_mcp_upstream_tools recipes_model_provider_routing_pack recipes_playbook_get recipes_playbook_plan recipes_playbooks_list recipes_quality_report recipes_refresh recipes_search recipes_secure_context_attestation_pack recipes_secure_context_buyer_diligence_brief recipes_secure_context_customer_proof_pack recipes_secure_context_eval_pack recipes_secure_context_evidence_contract recipes_secure_context_lineage_ledger recipes_secure_context_trust_pack recipes_secure_context_value_model recipes_server_info recipes_workflow_control_plane

Harness readiness observed

Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band B — usable, with rough edges.

legibility checktools passingok
name is clear & specific75/75
has a description75/75
description is substantive75/75
parameters are typed75/75
parameters are described3/753/75

75 of 75 tools graded · 75 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.

Truth checks observed

Not in the Tier-2 trade lane, or not yet checked. Tier-2 re-derives a server's answers against published primary sources — see truth checks.

Protocol conformance observed

2025-06-18
protocol version
session model
3.4.7
server version security-recipes-mcp

Capabilities: experimental extensions logging prompts resources tools

Drift observed

No confirmed drift on record. Baseline set 2026-09-06; changes appear here after human review.

raw probe records
probed (UTC) outcomehttpmsprotocol
2026-09-06T06:17:10Zok_tools2002982025-06-18
2026-08-30T06:16:58Zok_tools2004872025-06-18

Watch or embed this verdict

verdict badge

Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:

[![Robin Saige verdict](https://robinsaige.com/badge/io.github.stevologic/security-recipes.svg)](https://robinsaige.com/s/io.github.stevologic/security-recipes)

Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.

← overview

Operator of this server? Everything we hold about it is on this page — free, no account, for anyone. Wrong attribution, stale probe, misclassification? Dispute this record →