mcpbeat Sign in

MCP Observatory: one read only walk over every https endpoint in the official registry MCP Server

answering

MCP Observatory: one read only walk over every https endpoint in the official registry is answering right now. Last checked 10 min ago. It exposes 6 tools. Last commit 18 Sep 2026.

Public record of one read only walk over the official MCP registry: who answered, tools, who pays.

Uptime history 14 days of history
14 days agonow
100.0%
Uptime 24h
91 of 91 checks
6
Tools
read from the server
144 ms
Response time
average over 24h
1
Stars
last commit 18 Sep 2026

What the code does

We read the source, 18 h ago · tools taken from the live server · rules 3dff92dd89df

Evidence

Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.

    p = subprocess.run(cmd, cwd=os.path.join(ROOT, cwd), capture_output=True, text=True, timeout=300)
Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Hidden recipient in outgoing message workers/hs-estimate/index.js:193
        reply_to: '[email protected]',
    p = subprocess.run(cmd, cwd=os.path.join(ROOT, cwd), capture_output=True, text=True, timeout=300)
    return io.open(os.path.join(ROOT, rel), encoding="utf-8").read()
Executes code built at runtime tools/jcs_conformance.mjs:35
const canonicalJson = new Function(m[0] + "; return canonicalJson;")();
        __import__(module_name)
  document.getElementById('main').innerHTML = fns[state.tab]();
<script src="https://www.paypal.com/sdk/js?client-id=AVePXfDeP_YDUgmcFEJNjFHuYkbXZ-VQcLEecJs5Li2la9qDbtZJamy-iXzTxWlPdUODt6KNV3nqUKHP&currency=JPY&locale=ja_JP"></script>
const AJ1_B64 = "AAAAIAAhACIAIwAkACUAJgAnACgAKQAqACsALAAtAC4ALwAwADEAMgAzADQANQA2ADcAOAA5ADoAOwA8AD0APgA/AEAAQQBCAEMARABFAEYARwBIAEkASgBLAEwATQBOAE8AUABRAFIAUwBUAFUAVgBXAFgAWQBaAFsApQBdAF4AXwBgAGEAYgBjAGQAZQBmAGcAaABpAGoAawBsAG0AbgBvAHAAcQByAHMAdAB1AHYAdwB4AHkAegB7AKYAfQLcArwAXAK…
        env = dict(os.environ, AGREEMENT_MUTATION_RUN="1")
In the project's build, not in the package

Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.

CI pipeline leaks secrets outward .github/workflows/blog-post.yml:49
            curl -s -X POST -H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" -H "Accept: application/vnd.github+json" https://api.github.com/repos/${{ github.repository }}/actions/workflows/static.yml/dispatches -d '{"ref":"main"}'

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

We found things in this code

Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch MCP Observatory: one read only walk over every https endpoint in the official registry and you get told the day something new turns up.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.

run in your terminal
claude mcp add hs-mcp-observatory --transport http https://observatory.horizonshield.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "hs-mcp-observatory": {
      "url": "https://observatory.horizonshield.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.hs-mcp-observatory]
url = "https://observatory.horizonshield.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "hs-mcp-observatory": {
      "url": "https://observatory.horizonshield.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "hs-mcp-observatory": {
      "url": "https://observatory.horizonshield.dev/mcp"
    }
  }
}

Available tools 6

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

mcp
mcp_observatory_disclosure_guide
How the 152 servers that stated who compensates their operator actually did it - the field names observed in the wild, with counts. Not a specification we invented.
mcp_observatory_lookup
What happened when we contacted one address, or an aggregate for one host. Returns the record hash and the procedure to recompute it. There is no tool here that lists addresses; you must already hold the one you are asking about.
mcp_observatory_measure_now
Contact one https address now and report what we see: whether it speaks MCP, whether it carries an agent card, and whether that card names who compensates the operator. Read only; no tool is called. robots.txt is read first and honoured. This does NOT change the published record - the next full walk does that. Rate limited, because it contacts somebody else's server on your behalf.
mcp_observatory_method
How the walk was run, what we got wrong and corrected, and the four rules the report holds itself to.
mcp_observatory_state
What was measured, when, over what population, and what the measurement cannot tell you. Read this before quoting any number from this server.
mcp_observatory_summary
The counts, as published and as corrected. How many addresses answered, how many tools they exposed, how many stated who compensates their operator.

Endpoints

URLTransportStateLatencyChecked
https://observatory.horizonshield.dev/mcp streamable-http answering 249 ms 10 min ago

Alternatives to MCP Observatory: one read only walk over every https endpoint in the official registry

same job, measured the same way
MCP Registry Server
by com-mcp

Publish and discover MCP servers via the official MCP Registry. Powered by HAPI MCP server.

3 tools answering
Verifier
by robinsaige

MCP tool observatory: do registry servers answer, and are their answers true? No key.

8 tools answering
Novai MCP Server
by 0x-devc

Read-only MCP server for querying the live NOVAI blockchain over its public JSON-RPC endpoint.

44 installs/wk local only
Family Office Knowledge Graph
by familyofficeknowledgegraph

Family Office Knowledge Graph: read-only MCP door over the public record. Agentic KG Holdings.

5 tools answering
Registry MCP
by remote-mcp

An MCP server that serves informtaion from the official MCP registry

2 tools answering
I
Recipe Signal
by absharma9796

Search and compare attributed recipe records through a public read-only remote MCP endpoint.

4 tools answering
Htag Docs
by htagai

Public HTAG discovery for MCP tools, API endpoints, OpenAPI ops, and agents.

5 tools answering
Netmon (demo)
by netmon

Public read-only demo of Netmon's network monitoring tools over a recorded snapshot.

36 tools answering

MCP Observatory: one read only walk over every https endpoint in the official registry — questions

Answers built from our own checks of this server.

What can MCP Observatory: one read only walk over every https endpoint in the official registry do?
It exposes 6 tools, read directly from the server on our last check. Among them: mcp_observatory_disclosure_guide, mcp_observatory_lookup, mcp_observatory_measure_now, mcp_observatory_method, mcp_observatory_state, mcp_observatory_summary. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is MCP Observatory: one read only walk over every https endpoint in the official registry working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 144 ms. The bar chart above shows every period we have measured.
How do I connect MCP Observatory: one read only walk over every https endpoint in the official registry?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does MCP Observatory: one read only walk over every https endpoint in the official registry need an API key?
No. MCP Observatory: one read only walk over every https endpoint in the official registry completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 6 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is MCP Observatory: one read only walk over every https endpoint in the official registry?
It answers our handshake in 144 ms on average, which is faster than 77% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is MCP Observatory: one read only walk over every https endpoint in the official registry open source?
Yes — it is published under the MIT licence, written in HTML, 1 stars on GitHub and 8 open issues. The source link is on this page, so you can read exactly what it does with your data before you connect it.