Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"mcp-fortress","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
No successful checks in the window.
Not distributed through a package registry we index.
| when | check | result | http | latency | detail |
|---|---|---|---|---|---|
| 4 d ago | mcp initialize | failed | 404 | 559 ms | http 404 |
| 11 d ago | mcp initialize | failed | 404 | 366 ms | http 404 |
| 18 d ago | mcp initialize | failed | 404 | 333 ms | http 404 |
| 26 d ago | mcp initialize | failed | 404 | 686 ms | http 404 |
| 29 d ago | mcp initialize | failed | 404 | 427 ms | http 404 |
| 1 mo ago | mcp initialize | failed | 404 | 395 ms | http 404 |
| 1 mo ago | mcp initialize | failed | 404 | 428 ms | http 404 |
| 1 mo ago | mcp initialize | failed | 404 | 343 ms | http 404 |
Attributed to the source that supplied each field. Treated as claims, not facts.
No long description beyond the summary.
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.