Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "exposure_check"
⟨166 unchanged words⟩ , default install pages and the https redirect. It also returns six legal signals with the law and an official source for each: sign-up age question (COPPA), Google Fonts (GDPR), session replay (CIPA), renewal terms by the subscribe button (California), DMCA agent link and registration, and, when email is passed, the unsubscribe link and postal address (CAN-SPAM); not legal advice. Each finding is labeled confirmed (with a severity), needs verification (the fact that is not known and how to check it) or rejected (the reason), and the answer shows the map, hunt, verify and report phases. Every answer carries an ownership note. It sends ⟨4 unchanged words⟩ a fixed list of paths and at most3032 per run, does not crawl, does not ⟨37 unchanged words⟩
{"additionalProperties":false,"properties":{"email":{"description":"Optional: the text or HTML of one marketing email the app sends, checked for an unsubscribe link and a postal address (CAN-SPAM). It is read in memory only and never returned or kept.","maxLength":100000,"type":"string"},"target":{"description":"A domain, host ⟨58 unchanged words⟩
⟨63 unchanged words⟩ :"object"},"type":"array"},"legal":{"properties":{"checks":{"items":{"properties":{"finding":{"type":"string"},"fix":{"type":"string"},"id":{"type":"string"},"law":{"type":"string"},"sources":{"items":{"properties":{"title":{"type":"string"},"url":{"type":"string"}},"required":["title","url"],"type":"object"},"type":"array"},"status":{"enum":["needs_verification","pass","not_checked"],"type":"string"},"topic":{"type":"string"},"unresolved":{"type":"string"}},"required":["id","topic","law","status","finding","sources"],"type":"object"},"type":"array"},"note":{"type":"string"}},"type":"object"},"needsVerification":{"items":{"properties":{"check":{"type":"string"},"item":{"type":"string"},"risk":{"type":"string"},"source":{"type":"string"},"unresolved":{"type":"string"}},"required":["risk","unresolved","check","source","item"],"type":"object"},"type":"array"},"notChecked":{"items":{"type":"string" ⟨12 unchanged words⟩ ,"ownershipNote":{"type":"string"},"phases":{"items":{"properties":{"did":{"type":"string"},"phase":{"enum":["map","hunt","verify","report"],"type":"string"}},"required":["phase","did"],"type":"object"},"type":"array"},"publish":{"properties":{"dnsTxt":{"properties ⟨16 unchanged words⟩ "type":"object"}},"type":"object"},"rejected":{"items":{"properties":{"claim":{"type":"string"},"item":{"type":"string"},"reason":{"type":"string"},"source":{"type":"string"}},"required":["claim","reason","source","item"],"type":"object"},"type":"array"},"requestsMade":{"type":"integer"} ⟨72 unchanged words⟩
Certificate recorded, valid to 2026-12-30
Authorization not required
Changed the definition of "exposure_check"
Checks what a site or app you ownexposesleaks publicly. Use it when the user asks what an attacker could find on a domain, host orserverapp they own, for example "is anything on my domain example.com exposed?", "does my app leak a .env file or API keys in its JavaScript?", "check my server app.example.com for leaked admin or debug pages" or "runanaexposureleak check on my own site". Pass the domain, host orhostappname;page
Unknown → Live
First tool surface recorded: 11 tools (server version 1.3.0)
https://sitecheck.openkrill.app/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 7 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨3 unchanged words⟩ ":{"target":{"description":"A domain, host orhostpage address you own, such as example.com orapp.example.com.https://app.example.com/dashboard.ATheURLhost is checked; a page address also names the page whose scripts are readasforitskeyshost.(the home page otherwise). A bare IP address is refused: pass ⟨18 unchanged words⟩
{"properties":{"adminPaths":{"items":{"properties":{"path":{"type":"string"},"status":{"type":["integer","null"]}},"required":["path","status"],"type":"object"},"type":"array"},"answer":{"type":"string"},"asOf" ⟨18 unchanged words⟩ :"object"},"type":"array"},"keysFound":{"items":{"properties":{"prefix":{"type":"string"},"severity":{"type":"string"},"type":{"type":"string"},"where":{"type":"string"}},"required":["type","where","prefix"],"type":"object"},"type":"array"},"notChecked":{"items":{"type":"string" ⟨9 unchanged words⟩ "string"}},"type":"object"},"ownershipNote":{"type":"string"},"publish":{"properties":{"dnsTxt":{"properties ⟨20 unchanged words⟩ ,"requestsMade":{"type":"integer"},"scriptsRead":{"items":{"type":"string"},"type":"array"},"sources":{"items":{"type":"string" ⟨55 unchanged words⟩ ,"required":["target","verdict","answer","ownershipNote"],"type":"object"}