Security Preflight is answering right now. Last checked 10 min ago. It exposes 5 tools. Last commit 18 Sep 2026.
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 9 September 2026. No other catalogue keeps this.
We read the source, 19 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
state = pickle.loads(row[0])
r = subprocess.run([sys.executable, "-c", code], capture_output=True, text=True)
$("kpis").innerHTML = cells.map(([l,v,d]) =>
self.environ = dict(os.environ if environ is None else environ)
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add security-preflight --transport http https://mcp.viridisconservation.com/security-preflight/mcp
{
"mcpServers": {
"security-preflight": {
"url": "https://mcp.viridisconservation.com/security-preflight/mcp"
}
}
}
[mcp_servers.security-preflight]
url = "https://mcp.viridisconservation.com/security-preflight/mcp"
{
"mcpServers": {
"security-preflight": {
"url": "https://mcp.viridisconservation.com/security-preflight/mcp"
}
}
}
{
"mcpServers": {
"security-preflight": {
"url": "https://mcp.viridisconservation.com/security-preflight/mcp"
}
}
}
This server publishes 1 more address. The block above uses the one we reach during checks; the full list is under Endpoints below, and the author may intend a particular one for your client.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
get_security_receipt
security_preflight
describe_agent
scan_source
screen_injection
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp.viridisconservation.com/security-preflight/mcp | streamable-http | answering | 326 ms | 10 min ago |
| https://mcp.viridis-security.com/security-preflight/mcp | streamable-http | answering | 443 ms | 10 min ago |
Read and write checked code rationale stored outside source comments.
Read and write checked code rationale stored outside source comments.
Execution-verified code generation and verification with signed, offline-checkable certificates.
Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.
Offline self-checking to reduce AI-style wording in source code and documentation.
Branch-scoped runbooks, remote checkpoints, and auditable verification receipts.
Agentic Reddit/HN buying-signal detection for Claude Code, Cursor, and Windsurf via MCP.
Zero-cost MCP server for local code inspection and best-practice recommendations
Answers built from our own checks of this server.