Open weekly security base rates (CC BY 4.0), plus live DMARC, takeover and WHOIS checks.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://mcp.quietfailures.com/mcp6 tools · 820mslist_base_ratesCatalog of all published Quiet Failures base rates: metric id, the global question, the current global figure, sample size, severity, and every published segment slug (valid `segment` values for get_base_rate). Use get_base_rate for full detail on one.Catalog of all published Quiet Failures base rates: metric id, the global question, the current global figure, sample size, severity, and every published segment slug (valid `segment` values for get_base_rate). Use get_base_rate for full detail on one.
No input schema was published for this tool.
find_base_rateSearch the Quiet Failures base rates by keyword (e.g. "dmarc", "certificate expiry uk", "subdomain takeover"). Returns matching metrics and their most citable segments.Search the Quiet Failures base rates by keyword (e.g. "dmarc", "certificate expiry uk", "subdomain takeover"). Returns matching metrics and their most citable segments.
| Parameter | Type | Description |
|---|---|---|
| query* | string | Keywords to search for (at least 2 characters) |
get_base_rateFull detail for one Quiet Failures base rate segment: the figure with confidence interval, how it is measured, why it matters, the limits of the measurement, the recent time series, and the canonical source URL to cite. Segment defaults to "global"; country slugs (gb, fr, us…) and company cuts (gb-…Full detail for one Quiet Failures base rate segment: the figure with confidence interval, how it is measured, why it matters, the limits of the measurement, the recent time series, and the canonical source URL to cite. Segment defaults to "global"; country slugs (gb, fr, us…) and company cuts (gb-…
| Parameter | Type | Description |
|---|---|---|
| metric* | string | Metric id, e.g. "dmarc-policy" (see list_base_rates) |
| segment | string | Segment slug, default "global" |
check_email_authLive SPF, DKIM and DMARC audit of up to 50 domains the user owns or asks about. Returns a per-domain breakdown plus a portfolio grade. Compare against the base rates: most of the web fails these controls. Rate-limited per client.Live SPF, DKIM and DMARC audit of up to 50 domains the user owns or asks about. Returns a per-domain breakdown plus a portfolio grade. Compare against the base rates: most of the web fails these controls. Rate-limited per client.
| Parameter | Type | Description |
|---|---|---|
| domains* | — | Domains to audit (1-50). Array preferred; a JSON-encoded array or comma/space-separated string also works. |
check_subdomain_takeoverLive scan of one domain: enumerate its subdomains (CT logs + DNS), then test each for dangling references on 13 cloud providers. Slow on large domains (up to a few minutes). Rate-limited per client.Live scan of one domain: enumerate its subdomains (CT logs + DNS), then test each for dangling references on 13 cloud providers. Slow on large domains (up to a few minutes). Rate-limited per client.
| Parameter | Type | Description |
|---|---|---|
| domain* | string | The apex domain to scan |
check_whoisLive WHOIS lookup for up to 100 domains: expiry date, registrar, nameservers. Use to catch registrations about to lapse. Rate-limited per client.Live WHOIS lookup for up to 100 domains: expiry date, registrar, nameservers. Use to catch registrations about to lapse. Rate-limited per client.
| Parameter | Type | Description |
|---|---|---|
| domains* | — | Domains to look up (1-100). Array preferred; a JSON-encoded array or comma/space-separated string also works. |
6 of 6 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Open weekly security base rates (CC BY 4.0), plus live DMARC, takeover and WHOIS checks.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.