Is io.github.stevologic/security-recipes up? Live MCP status
Yes, it is up. It answered an MCP server/discover with no credential and negotiated protocol 2026-07-28.
A stock client connected with no credential and negotiated 2026-07-28. Use it.
| Outcome | usable |
|---|---|
| HTTP status | 200 |
| Protocol version | 2026-07-28 |
| Server says it is | security-recipes-mcp 4.0.10 |
| Answered in | 214 ms |
| Endpoint checked | https://security-recipes.ai/mcp |
| Checked |
One MCP handshake with the listed endpoint (server/discover at 2026-07-28, then initialize for a server on the older revision), with no credential and no retry, identifying itself as agentwares-mcp-liveness/0.1 (+https://agentwares-agentcheck.vercel.app/bot). It runs when this page is requested and the result is reused for 10 minutes, so the time above is when it was taken.
Live status every few hours: Wellknown
Email me when this server changes
That was one look. To hear when it stops answering or its tools change, leave an address.
Free, no password or GitHub: one confirmation email first, then a check every hour and an email when it stops answering or its tools change. Every email has a link to stop. More about it.
Monthly census, 6 October 2026
The census sends the same request to every remote listing in the official registry once a month. On 6 October 2026 this one answered a stock client with no credential. Every listing’s result: index.ndjson (what the files hold: index.meta.json).
Agent discovery documents at this origin
| A2A agent card | Not published (HTTP 404)./.well-known/agent-card.json |
|---|---|
| MCP server card (SEP-2127) | Not published (HTTP 404).https://security-recipes.ai/mcp/server-card |
| MCP server card (SEP-1649 location) | Not published (HTTP 404)./.well-known/mcp/server-card.json — SEP-1649, a draft superseded by SEP-2127 on 21 January 2026 |
| Web Bot Auth key directory | Not published (HTTP 404)./.well-known/http-message-signatures-directory |
Read at https://security-recipes.ai with the monthly census on 9 October 2026: one GET each, no credential, never a signed request. A2A against v1.0.1, the server card against the MCP Server Card schema (SEP-2127), the card at SEP-1649’s location against the shape it has, the key directory against the Web Bot Auth draft of 1 September 2026. Who publishes them.
Tool changes between snapshots
In the 2026-10 snapshot it listed 75 tools: recipes_a2a_agent_card_trust_profile, recipes_agent_capability_risk_register, recipes_agent_handoff_boundary_pack, recipes_agent_identity_ledger, recipes_agent_memory_boundary_pack, recipes_agent_skill_supply_chain_pack, recipes_agent_trust_fabric_pack, recipes_agentic_action_runtime_pack, recipes_agentic_aivss_risk_scoring_pack, recipes_agentic_app_intake_pack, recipes_agentic_approval_receipt_pack, recipes_agentic_assurance_pack, recipes_agentic_catastrophic_risk_annex, recipes_agentic_control_plane_blueprint, recipes_agentic_entitlement_review_pack, recipes_agentic_exposure_graph, recipes_agentic_incident_response_pack, recipes_agentic_measurement_probe_pack, recipes_agentic_posture_snapshot, recipes_agentic_protocol_conformance_pack, recipes_agentic_readiness_scorecard, recipes_agentic_red_team_drill_pack, recipes_agentic_red_team_replay_harness, recipes_agentic_run_receipt_pack, recipes_agentic_soc_detection_pack, recipes_agentic_source_freshness_watch, recipes_agentic_standards_crosswalk, recipes_agentic_system_bom, recipes_agentic_telemetry_contract, recipes_agentic_threat_radar, recipes_browser_agent_boundary_pack, recipes_context_egress_boundary_pack, recipes_context_poisoning_guard_pack, recipes_critical_infrastructure_secure_context_pack, recipes_cve_catalog_info, recipes_cve_get, recipes_cve_search, recipes_design_partner_pilot_pack, recipes_enterprise_trust_center_export, recipes_get, recipes_hosted_mcp_readiness_pack, recipes_list, recipes_match_finding, recipes_mcp_authorization_conformance_pack, recipes_mcp_connector_intake_pack, recipes_mcp_connector_trust_pack, recipes_mcp_elicitation_boundary_pack, recipes_mcp_gateway_policy, recipes_mcp_risk_coverage_pack, recipes_mcp_server_get, recipes_mcp_servers_list, recipes_mcp_stdio_launch_boundary_pack, recipes_mcp_tool_risk_contract, recipes_mcp_tool_surface_drift_pack, recipes_mcp_upstream_call, recipes_mcp_upstream_context, recipes_mcp_upstream_servers, recipes_mcp_upstream_tools, recipes_model_provider_routing_pack, recipes_playbook_get, recipes_playbook_plan, recipes_playbooks_list, recipes_quality_report, recipes_refresh, recipes_search, recipes_secure_context_attestation_pack, recipes_secure_context_buyer_diligence_brief, recipes_secure_context_customer_proof_pack, recipes_secure_context_eval_pack, recipes_secure_context_evidence_contract, recipes_secure_context_lineage_ledger, recipes_secure_context_trust_pack, recipes_secure_context_value_model, recipes_server_info, recipes_workflow_control_plane.
No change to its tools between 2026-09 and 2026-10.
Which tools were added or removed, and whose description or schemas changed, from content hashes in the monthly snapshots. Per tool, as JSON: /v1/drift.
The listing
| Registry name | io.github.stevologic/security-recipes |
|---|---|
| Title | Security Recipes |
| Description | Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner. |
| Endpoint | https://security-recipes.ai/mcp |
| Publisher repository | https://github.com/stevologic/security-recipes.ai |
| Version | 1.0.0 |
| Listing updated |
Also
The full check by name, as JSON (on a 401 it also follows the OAuth discovery chain) · Watch it · Check another server · llms.txt