MCP Observatory: one read only walk over every https endpoint in the official registry is answering right now. Last checked 10 min ago. It exposes 6 tools. Last commit 18 Sep 2026.
Public record of one read only walk over the official MCP registry: who answered, tools, who pays.
We read the source, 18 h ago · tools taken from the live server · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
p = subprocess.run(cmd, cwd=os.path.join(ROOT, cwd), capture_output=True, text=True, timeout=300)
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
reply_to: '[email protected]',
p = subprocess.run(cmd, cwd=os.path.join(ROOT, cwd), capture_output=True, text=True, timeout=300)
return io.open(os.path.join(ROOT, rel), encoding="utf-8").read()
const canonicalJson = new Function(m[0] + "; return canonicalJson;")();
const r = spawnSync(process.execPath, [path.join(HERE, name)], {
__import__(module_name)
document.getElementById('main').innerHTML = fns[state.tab]();
<script src="https://www.paypal.com/sdk/js?client-id=AVePXfDeP_YDUgmcFEJNjFHuYkbXZ-VQcLEecJs5Li2la9qDbtZJamy-iXzTxWlPdUODt6KNV3nqUKHP¤cy=JPY&locale=ja_JP"></script>
for (const f of fs.readdirSync(feedDir)) {
"openings-vote-drilling-initially.trycloudflare.com",
const AJ1_B64 = "AAAAIAAhACIAIwAkACUAJgAnACgAKQAqACsALAAtAC4ALwAwADEAMgAzADQANQA2ADcAOAA5ADoAOwA8AD0APgA/AEAAQQBCAEMARABFAEYARwBIAEkASgBLAEwATQBOAE8AUABRAFIAUwBUAFUAVgBXAFgAWQBaAFsApQBdAF4AXwBgAGEAYgBjAGQAZQBmAGcAaABpAGoAawBsAG0AbgBvAHAAcQByAHMAdAB1AHYAdwB4AHkAegB7AKYAfQLcArwAXAK…
env = dict(os.environ, AGREEMENT_MUTATION_RUN="1")
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
curl -s -X POST -H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" -H "Accept: application/vnd.github+json" https://api.github.com/repos/${{ github.repository }}/actions/workflows/static.yml/dispatches -d '{"ref":"main"}'
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch MCP Observatory: one read only walk over every https endpoint in the official registry and you get told the day something new turns up.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add hs-mcp-observatory --transport http https://observatory.horizonshield.dev/mcp
{
"mcpServers": {
"hs-mcp-observatory": {
"url": "https://observatory.horizonshield.dev/mcp"
}
}
}
[mcp_servers.hs-mcp-observatory]
url = "https://observatory.horizonshield.dev/mcp"
{
"mcpServers": {
"hs-mcp-observatory": {
"url": "https://observatory.horizonshield.dev/mcp"
}
}
}
{
"mcpServers": {
"hs-mcp-observatory": {
"url": "https://observatory.horizonshield.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
mcp_observatory_disclosure_guide
mcp_observatory_lookup
mcp_observatory_measure_now
mcp_observatory_method
mcp_observatory_state
mcp_observatory_summary
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://observatory.horizonshield.dev/mcp | streamable-http | answering | 249 ms | 10 min ago |
Publish and discover MCP servers via the official MCP Registry. Powered by HAPI MCP server.
MCP tool observatory: do registry servers answer, and are their answers true? No key.
Read-only MCP server for querying the live NOVAI blockchain over its public JSON-RPC endpoint.
Family Office Knowledge Graph: read-only MCP door over the public record. Agentic KG Holdings.
An MCP server that serves informtaion from the official MCP registry
Search and compare attributed recipe records through a public read-only remote MCP endpoint.
Public HTAG discovery for MCP tools, API endpoints, OpenAPI ops, and agents.
Public read-only demo of Netmon's network monitoring tools over a recorded snapshot.
Answers built from our own checks of this server.