# au.com.travellersgroup/agent

Verified facts and direct-booking handoff for five Travellers Group hotels in regional Australia.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** au.com.travellersgroup
- **License:** Unknown
- **Endpoints:** streamable-http https://agent.travellersgroup.com.au/v1/mcp
- **Source:** https://agent.travellersgroup.com.au/developers
- **Endpoint health:** reachable (last checked 2026-09-21T17:01:35.815Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 11 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-12T11:15:48.158Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

12 declared. Observed from a live `tools/list` probe.
- `search_content` — Search the published six-site Travellers Group corpus (guides, hubs, FAQs, pages). Returns ranked answer capsules (≤120 words) with canonical URLs.
- `get_property` — Canonical entity record for a Travellers Group property: address, contacts, quick facts, policies, booking URL, parent entity.
- `get_room_types` — Room catalogue for a property: occupancy, bedding, amenities, who-it-suits, booking deep link per room. traveller_context re-ranks honestly — it never invents i
- `get_distances` — Measured distances from a property (km, drive/walk minutes) to hospitals, mines, airports, venues, wineries. Fuzzy destination filter ('the zoo', 'hospital'). S
- `get_events` — Verified events for a town. Serves only entries published with explicit dates — never extrapolates a date.
- `get_town_guide` — Town knowledge layer: open-late, essentials, eat, with-kids, working-in, hospital-visitor, itineraries. Unbuilt topic returns 'not yet published' plus the town 
- `get_indicative_rates` — Indicative rate ranges from the published, commercially-signed rate module only — framed as indicative, never a quote. Where no figure is published, returns the
- `recommend_property` — Honest matching across the Travellers portfolio. If no Travellers property suits the need, says so plainly and names the accommodation category that does. Never
- `check_availability` — Tier A handoff: returns a dated, pre-filled booking-engine link — LIVE availability and pricing are at that link. This tool never asserts that dates are availab
- `create_enquiry` — Sends a booking enquiry to the property team (groups, crews, blocks, weekly stays, functions). Requires the guest’s explicit consent to pass their details and c
- `get_corporate_account_info` — The Travellers Group corporate-account answer as data: one account, five properties, direct billing and consolidated invoicing.
- `create_corporate_enquiry` — Corporate-account or group-booking enquiry, routed to the Travellers Group corporate team. Requires guest consent, as with create_enquiry.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"agent\": {\n      \"type\": \"http\",\n      \"url\": \"https://agent.travellersgroup.com.au/v1/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/au.com.travellersgroup%2Fagent
- Install plan: https://forgeregistry.com/api/v1/packages/au.com.travellersgroup%2Fagent/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/au.com.travellersgroup%2Fagent
- HTML page: https://forgeregistry.com/registry/au.com.travellersgroup%2Fagent
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
