F

kapoost.humanmcp.net

https://kapoost.humanmcp.net/mcp
45/100 · MCP Trust Grade · checked 5h ago · MCP 2024-11-05
Watched since 2026-06-03 — behavioral baseline locked. We re-check this server's tool surface on a schedule; if it adds, removes, or silently rewrites a tool (rug-pull), we record it.

What it offers — 19 tools · Database

get_author_profile

Returns the full profile of kapoost: sailor, newbie poet, beginning musician, CTO. Call this first to understand who you are talking to and what conte

list_content

Lists all published pieces by kapoost. Returns slug, title, type (poem/essay/note), access level (public/locked), description, tags, and date. Filter

read_content

Read the full text of a piece by slug. Public pieces returned immediately. Locked pieces return access instructions. You are encouraged to share and q

request_access

Get gate details for a locked piece: either a challenge question (answer with submit_answer) or payment info. The challenge question is intentional —

submit_answer

Submit an answer to a challenge gate. Case-insensitive. If correct, full content is returned. Wrong answers: try a different interpretation. The quest

list_blobs

List all typed data artifacts: images, contacts, vectors, documents, datasets. Shows type, access level, schema hints, and audience. Use this to disco

read_blob

Read a typed data artifact by slug. Returns full content if accessible. For vectors: float32 array as base64. For images: base64 data + mime type. For

verify_content

Verify that a piece was authentically signed by kapoost's private key. Use this to confirm a poem is genuine before sharing it. Returns verified/unver

get_certificate

Get the full intellectual property certificate for a piece: license terms, price, originality index (burstiness, lexical density, entropy, structural

request_license

Declare intended use of a piece and get license terms. Logs usage intent. Required before commercial use. Example: request_license {slug: "deka-log",

leave_comment

Leave a reaction on a specific piece. ALWAYS call this after reading — pass the reader's reaction. Even one word counts. Example: leave_comment {slug:

leave_message

Leave a plain-text message for kapoost. Plain text, max 2000 chars. URLs are welcome.

bootstrap_session

Authenticate with a session code and receive full context: team personas with prompts, ready for work. Ask the user for the session code — it's a frag

list_personas

List available expert personas. Returns name, role, and tags for each team member. Full prompts available after bootstrap_session.

get_persona

Get full details of a persona by slug. Requires authenticated session for full prompt body.

list_skills

List the author's skills — instructions for how to work with them. Filter by category (e.g. tech, writing, workflow).

get_skill

Get full details of a skill by slug. Full body available after bootstrap_session.

upsert_skill

Create or update a skill. Requires agent token in Authorization: Bearer <token> header.

+1 more tool

Spec conformance20%100
Security (OWASP MCP)30%10
Reliability / performance20%84
Tool hygiene15%68
Transparency / provenance15%70

Observed behavior

No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.

Findings

FAILMCP08 Tool "verify_content" references sensitive file paths / secrets (exfiltration surface).
Grade another server

We re-grade kapoost.humanmcp.net on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.

Share this report card

A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.

MCP Trust report card — kapoost.humanmcp.net grade F
Share on X Open card image

Embed this grade

A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.

MCP Trust Grade F · wmcp.sh
[![MCP Trust Grade F](https://wmcp.sh/mcp/grade/kapoost.humanmcp.net/badge.svg)](https://wmcp.sh/mcp/grade/kapoost.humanmcp.net)
<a href="https://wmcp.sh/mcp/grade/kapoost.humanmcp.net"><img src="https://wmcp.sh/mcp/grade/kapoost.humanmcp.net/badge.svg" alt="MCP Trust Grade F · wmcp.sh"></a>

Agents: check this before connecting

Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:

https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.