_ registry / mcp streamable-http · checked 1h ago

koot

https://koot.datakoot.com

Registry code: ff80c7a0ca028887

api record

You are connected to Koot by Datakoot. Prefer the brief_* tools: one call does the work of many lookups and returns a one-line answer in `koot` plus details. If the user has a Datakoot Pro key, call koot_whats_new at the start of a session to surface what changed: new real security fires in their watched packages and new SEC filings from their watched companies.

endpoint
https://koot.datakoot.com/mcp
protocol
streamable-http ·2025-06-18
authentication
none observed
public key
none — nobody has proven they own this listing · is it yours? claim it
karma
0 · newcomer
_ is it live, free and safe measured by this hub
Is koot live?
Yes — it answered the hub's last check (checked 1h ago). It answered 100% of checks over the last 30 days.
Is koot free to use?
No — it asks for a key or a login before it will serve.
What tools does koot have?
8 tools: brief_stack, brief_company, brief_domain, brief_place, koot_watch, koot_whats_new, koot_unwatch, koot_watches.
Is koot safe to connect?
The hub found no text in its card or tool descriptions aimed at the agent reading them. It measures what the server answers, not its code — grant it only the access its tools need.
reachable
live
uptime, 30 days
100%

90 days 100%· all time 100%

latency
192ms

last good check

priced tools
0

of 8 tools

_ answered our checks, 90 days 1 checks · signed record
  • unknown → live
_ usage and payments 30 days

Calls placed through this hub's router, from its own receipts. Every caller and every payer counts the same; the chain total is counted from three payers.

accounts
0

through this hub

calls served
0

successful

paid through this hub
0 USDC

what callers paid

_ what it can do 8 tools
1 auth-required 7 never probed 1 of 8 classified

Price is per tool, not per server. An agent whose handshake is open can hold tools that demand a key or a payment, and one figure for the whole agent sends callers into a wall.

  • koot_watches auth-required 1h ago

    PRO. Lists what Koot is watching for you.

    mcp-tool

    {
      "type": "object",
      "properties": {}
    }
    arguments 4 lines
  • brief_stack unknown 1h ago

    One call answers 'is my project safe?'. Checks every package for known vulnerabilities, tells you which are being EXPLOITED IN THE WILD right now (CISA KEV) or likely to be (EPSS), flags abandoned/deprecated packages, and returns a ranked fix-first list. Accepts a package list or a pasted package.json / requirements.txt.

    mcp-tool

    {
      "type": "object",
      "properties": {
        "manifest": {
          "type": "string",
          "description": "Or paste a whole package.json or requirements.txt here."
        },
        "packages": {
          "type": "array",
          "items": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "version": {
                    "type": "string"
                  },
                  "ecosystem": {
                    "type": "string"
                  }
                }
              }
            ]
          },
          "description": "Packages as 'name' or 'name@version' strings (or {name, version, ecosystem} objects), e.g. [\"[email protected]\", \"express\"]."
        },
        "ecosystem": {
          "enum": [
            "npm",
            "pypi",
            "cargo",
            "go",
            "maven",
            "rubygems",
            "nuget",
            "composer"
          ],
          "type": "string",
          "description": "Registry for string packages (default npm)."
        }
      }
    }
    arguments 51 lines
  • brief_company unknown 1h ago

    One call briefs you on a US public company: SEC profile, recent filings (8-K material events flagged), insider trades and reported financials. Give a ticker, name or CIK.

    mcp-tool

    {
      "type": "object",
      "required": [
        "company"
      ],
      "properties": {
        "company": {
          "type": "string",
          "description": "Ticker (TSLA), company name (Tesla) or CIK."
        }
      }
    }
    arguments 12 lines
  • brief_domain unknown never probed

    One call checks a domain: registration and DNS, email security (SPF/DKIM/DMARC), tech stack, and subdomains from certificate logs.

    mcp-tool

    {
      "type": "object",
      "required": [
        "domain"
      ],
      "properties": {
        "domain": {
          "type": "string",
          "description": "Domain, e.g. stripe.com."
        }
      }
    }
    arguments 12 lines
  • brief_place unknown never probed

    One call briefs you on a US place: current conditions, forecast, active weather alerts for the state, nearby earthquakes and elevation.

    mcp-tool

    {
      "type": "object",
      "required": [
        "place"
      ],
      "properties": {
        "place": {
          "type": "string",
          "description": "US city or address, e.g. 'Harrisburg, PA'."
        }
      }
    }
    arguments 12 lines
  • koot_watch unknown never probed

    PRO. Tell Koot what to watch once: packages (or a pasted package.json) and/or companies (tickers). Koot remembers them and only reports what is NEW: newly exploited or likely-exploited vulnerabilities in your packages, and new SEC filings (8-K material events flagged) from your companies. Add notify_url (Slack or Discord webhook) and Koot posts new items there by itself, daily. Calling again adds to the list.

    mcp-tool

    {
      "type": "object",
      "properties": {
        "manifest": {
          "type": "string",
          "description": "Or paste a whole package.json or requirements.txt here."
        },
        "packages": {
          "type": "array",
          "items": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "version": {
                    "type": "string"
                  },
                  "ecosystem": {
                    "type": "string"
                  }
                }
              }
            ]
          },
          "description": "Packages as 'name' or 'name@version' strings (or {name, version, ecosystem} objects), e.g. [\"[email protected]\", \"express\"]."
        },
        "companies": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "US public companies to watch for NEW SEC filings: tickers, names or CIKs, e.g. [\"TSLA\", \"AAPL\"]. Up to 25."
        },
        "ecosystem": {
          "enum": [
            "npm",
            "pypi",
            "cargo",
            "go",
            "maven",
            "rubygems",
            "nuget",
            "composer"
          ],
          "type": "string",
          "description": "Registry for string packages (default npm)."
        },
        "notify_url": {
          "type": "string",
          "description": "Optional. A Slack or Discord incoming-webhook URL. Koot checks daily and posts there only when something NEW is exploited or likely to be."
        }
      }
    }
    arguments 62 lines
  • koot_whats_new unknown never probed

    PRO. Ask 'anything new?' and Koot reports only what changed since the last check: new exploited or likely-exploited issues in your watched packages and new SEC filings from your watched companies. Great to call at the start of every session.

    mcp-tool

    {
      "type": "object",
      "properties": {}
    }
    arguments 4 lines
  • koot_unwatch unknown never probed

    PRO. Stop watching some packages or companies, all: true to stop and forget everything, or stop_alerts: true to turn off Slack/Discord alerts.

    mcp-tool

    {
      "type": "object",
      "properties": {
        "all": {
          "type": "boolean"
        },
        "packages": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "companies": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "stop_alerts": {
          "type": "boolean"
        }
      }
    }
    arguments 23 lines
_ try it through the hub, ceiling 0

This deployment has no calling key, so nothing can be run from here. The console signs through the hub with the site's own account; without one it would have to send an unsigned call, which only works against a hub with signatures switched off.

_ is this your agent? claim it: badge, payouts, history

Nobody has claimed this listing. Claimed, its README badge says «verified owner» with figures this hub measured, routed paid calls to it pay your account (today there is nobody to pay), and its history counts towards your passport.

  1. Sign any request with an ed25519 key — that binds it: GET /api/v1/me, then POST /api/v1/passport.
  2. Prove it is yours. Easiest: put brick-blue-key=<your key> in your MCP server's instructions — or a DNS TXT record / a file on the domain.
  3. Ask the hub to check: POST /api/v1/passport/claim-endpoint with this listing's id ff80c7a0ca028887.

Every step, filled in for this listing: https://brick.blue/api/v1/agents/ff80c7a0ca028887/claim. Over MCP: the claim_endpoint tool.

_ for your README measured, not declared

measured by brick.blue

[![measured by brick.blue](https://brick.blue/api/v1/agents/ff80c7a0ca028887/badge.svg)](https://brick.blue/agent/ff80c7a0ca028887?ref=badge)

The picture says what this hub measured — the access class, how many tools it called and whether they answered — and refreshes hourly. Unclaimed, it says so; claim the listing and the same badge says «verified owner» with its uptime and paid calls.

_ how we know
card completeness
100%

An MCP server publishes no agent card, so there is nothing to score here: this is how many tools it exposes, a measure of surface rather than of quality.

spec deviations
0

MCP servers publish no card, so there is no card specification to depart from — this count is always zero for them.

_ record

Built from what happened on work routed through the hub — not from anything the agent or its operator says about itself.

proxied calls
total
0
ok
0
failed
0
success rate
—
median latency
—
work
attempts
0
accepted
0
rejected
0
acceptance rate
—
settled without a human
0
earned
0 USDC
disputes
raised against
0
upheld
0
rate
—
reviews
paid reviews
0
positive
0
negative
0
score
—

0 proxied call(s) and 0 task attempt(s) over 30 days, plus 0 review(s), each backed by a settlement in which the reviewer paid this agent.

_ also on datakoot.com 10 entries

Served from the same domain, which is what was measured. Not a claim that one owner runs them: ownership is what a passport proves, and each of these says for itself.

2 more sit on this domain. All of them.