# io.github.squidcode/tapwatermap

Query US tap-water quality from the EPA's SDWIS records — by city, system, or contaminant.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.github.squidcode
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.tapwatermap.com/mcp
- **Source:** https://tapwatermap.com/developers/
- **Endpoint health:** reachable (last checked 2026-09-07T05:14:17.664Z, 3 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-07T05:14:17.664Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

10 declared. Observed from a live `tools/list` probe.
- `search` — Search TapWaterMap for US cities by name. Returns matching cities with an id you can pass to `fetch`. (ChatGPT/Deep-Research compatible.)
- `fetch` — Fetch the full plain-English EPA tap-water record for a city id (e.g. 'vt/burlington') returned by `search`. (ChatGPT/Deep-Research compatible.)
- `search_cities` — Find covered US cities by name, optionally within a state. Returns counts + the page URL for each.
- `get_city_water` — The core tool: what the EPA has on record for a city's tap water — the active community water systems serving it, populations, sources, and violations (contamin
- `get_water_system` — EPA record for a single water system by its PWSID (e.g. 'VT0005053'): name, population served, source, and violations.
- `list_state_cities` — List all covered cities in a state (with violation counts).
- `find_cities` — Filter/rank cities across the dataset — e.g. cities in TX with open health-based violations, or cities with a specific contaminant. Returns ranked matches.
- `compare_cities` — Compare the EPA records of several cities side by side. Pass cities as 'City, ST' strings.
- `explain_contaminant` — Plain-English explanation of an EPA contaminant by name or code: the EPA name, whether the EPA classifies it as health-based, and how often it appears in our re
- `coverage_stats` — What TapWaterMap covers: states, cities, total EPA violation records, and the data quarter/date.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"tapwatermap\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.tapwatermap.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.squidcode%2Ftapwatermap
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.squidcode%2Ftapwatermap/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.squidcode%2Ftapwatermap
- HTML page: https://forgeregistry.com/registry/io.github.squidcode%2Ftapwatermap
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
