# club.elron/public-rentals

Search Elron Club furnished apartments, availability, prices, details, and rental applications.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.2.0
- **Author:** club.elron
- **License:** Unknown
- **Endpoints:** streamable-http https://elron.club/api/agent/public/mcp
- **Source:** https://elron.club/api/agent/public/mcp
- **Endpoint health:** reachable (last checked 2026-09-12T15:50:19.320Z, 4 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-12T15:50:19.320Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

23 declared. Observed from a live `tools/list` probe.
- `waitlist.subscribe` — Activate newsletter updates for one canonical Elron region immediately after the customer explicitly requests them. An explicit customer request may reverse a p
- `waitlist.unsubscribe` — Use an opaque unsubscribe token from an Elron marketing email to stop every waitlist marketing update.
- `rentals.search` — Return a compact, actionable shortlist of published furnished apartments by location, availability, capacity, rooms, duration, and monthly rent. Defaults to 10 
- `rentals.get` — Return localized customer-safe apartment details, verified availability, duration pricing, deposit, included services, terms, eligibility, media, and inquiry/ap
- `rentals.check_availability` — Check the current published availability state and earliest date for one rental. This does not create a hold or reservation.
- `rentals.get_pricing` — Return current published monthly pricing by supported duration, parking, deposit, inclusions, payment method, and minimum-stay terms. Pricing is informational u
- `applications.start` — Create or reuse a duplicate-safe applicant workspace for one published rental. Requires explicit current privacy consent and an idempotency key. Email verificat
- `applications.get_status` — Read the privacy-minimized status and next actions for one scoped application session token.
- `applications.update` — Update bounded applicant, tenancy, and billing data for one email-verified session using its exact current version and a durable idempotency key.
- `applications.create_document_upload` — Create a 15-minute, exact-size and exact-content-type signed upload form for one email-verified application at its exact current version.
- `applications.complete_document_upload` — Verify the uploaded object, content signature, session ownership, expiry, and exact application version before creating the protected document record.
- `applications.upload_document` — Upload one bounded PDF, JPEG, or PNG identity or company-registry document to an email-verified application using its exact version and a durable idempotency ke
- `applications.submit` — Submit one complete email-verified application for review using its exact version, explicit current credit-check and truth-confirmation consent, and a durable i
- `viewings.get_status` — Read customer-safe viewing proposals and confirmed viewing state for one email-verified application session.
- `viewings.propose_availability` — Propose one to five bounded future viewing slots from an email-verified application at its exact version using a durable idempotency key.
- `viewings.respond_to_proposal` — Accept or decline one pending Elron Club proposal with explicit confirmation, an exact application version, and a durable idempotency key. Acceptance may send t
- `quotes.create` — Snapshot customer-safe approved request terms into a 24-hour quote. The application must be submitted, internally approved, due-diligence positive, and solvency
- `quotes.get` — Read one privacy-minimized quote and its live expiry/availability-hold state using the application session that owns it.
- `quotes.accept` — With explicit customer confirmation, accept one exact active quote and atomically claim a 30-minute request-owned availability hold. This does not create or sig
- `reservations.get_status` — Read privacy-minimized hold, contract, signature, payment, reservation, or confirmation state for one application session.
- `contracts.get_signing_link` — Return a secure signing URL only when the active signer invitation email matches the email-verified application session. Human verification, review, and signatu
- `payments.get_status` — Return due and received payment truth for the scoped application. An approved human-action URL is returned only from an exact, unexpired provider session; no au
- `bookings.get_confirmation` — Return a privacy-minimized booking confirmation only after the request has converted into the authoritative Stay workflow.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"public-rentals\": {\n      \"type\": \"http\",\n      \"url\": \"https://elron.club/api/agent/public/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 27, ceiling 51 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/club.elron%2Fpublic-rentals
- Install plan: https://forgeregistry.com/api/v1/packages/club.elron%2Fpublic-rentals/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/club.elron%2Fpublic-rentals
- HTML page: https://forgeregistry.com/registry/club.elron%2Fpublic-rentals
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
