Connects to any CKAN open data portal for searching datasets, exploring organizations, querying tabular data, and reading metadata.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 9 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The ckan-mcp-server MCP server exposes 20 tools, focused primarily on database and network capabilities. Its published description reads: "Connects to any CKAN open data portal for searching datasets, exploring organizations, querying tabular data, and reading metadata". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates ckan-mcp-server F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Data-exfiltration parameters". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check ckan-mcp-server's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add ckan-mcp-server to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://ckan-mcp-server.andy-pr.workers.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search for datasets (packages) on a CKAN server using Solr query syntax. Supports full Solr search capabilities including filters, facets, and sorting. Use this to discover datasets matching specific
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: ckan_package_search
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
AR TO *]" - IMPORTANT: NOW syntax works on metadata_modified and metadRecommendationRemove model-directed instructions from tool descriptions.
tool: ckan_package_search
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_package_search
A tool description tries to alter the model’s use of another tool.
er' to force or disable this behavior per request. Important - Date fieRecommendationDescriptions must describe only their own tool.
tool: ckan_find_relevant_datasets
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_find_relevant_datasets
A tool description tries to alter the model’s use of another tool.
want relevance-ranked results with explicit scoring across title, notes, tRecommendationDescriptions must describe only their own tool.
tool: ckan_package_show
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_package_show
A tool description tries to alter the model’s use of another tool.
e_active=true → ckan_datastore_search (query its data)RecommendationDescriptions must describe only their own tool.
tool: ckan_list_resources
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_list_resources
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
by default (it issues extra HTTP requests to hosts taken from the dataset's own resourceRecommendationAnnotate destructive tools and require human approval.
tool: ckan_list_resources
A tool description tries to alter the model’s use of another tool.
pical workflow: ckan_package_search → ckan_list_resources (assess available files)RecommendationDescriptions must describe only their own tool.
tool: ckan_organization_list
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_organization_list
A tool description tries to alter the model’s use of another tool.
(inspect one) → ckan_package_search with fq="organization:name" (browse its datasetRecommendationDescriptions must describe only their own tool.
tool: ckan_organization_show
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_organization_show
A tool description tries to alter the model’s use of another tool.
nization_show → ckan_package_show (inspect a dataset) → ckan_datastore_search (quRecommendationDescriptions must describe only their own tool.
tool: ckan_organization_search
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_organization_search
A tool description tries to alter the model’s use of another tool.
(get details) → ckan_package_search with fq="organization:name"RecommendationDescriptions must describe only their own tool.
tool: ckan_datastore_search
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_datastore_search
A tool description tries to alter the model’s use of another tool.
pical workflow: ckan_package_search → ckan_package_show (find resource_id with dataRecommendationDescriptions must describe only their own tool.
tool: ckan_datastore_search_sql
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_datastore_search_sql
A tool description tries to alter the model’s use of another tool.
pical workflow: ckan_package_show (get resource_id) → ckan_datastore_search_sql (RecommendationDescriptions must describe only their own tool.
tool: ckan_datastore_search_sql
A database tool exposes a query/sql parameter that is a free-form string with no allow-list or parameterisation constraint — a raw-string injection surface. A tool exposing structured filters or an `enum` of named queries does not fire.
unconstrained query parameter "sql"RecommendationExpose parameterised operations instead of a raw query string; never build queries from unvalidated model output.
tool: ckan_status_show
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_status_show
A tool description tries to alter the model’s use of another tool.
server is up) → ckan_package_search (discover datasets)RecommendationDescriptions must describe only their own tool.
tool: ckan_tag_list
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_tag_list
A tool description tries to alter the model’s use of another tool.
ckan_tag_list → ckan_package_search with fq="tags:tag_name" (find datasets by tag)RecommendationDescriptions must describe only their own tool.
tool: ckan_group_list
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_group_list
A tool description tries to alter the model’s use of another tool.
(inspect one) → ckan_package_search with fq="groups:name" (browse its datasets)RecommendationDescriptions must describe only their own tool.
tool: ckan_group_show
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_group_show
A tool description tries to alter the model’s use of another tool.
an_group_show → ckan_package_show (inspect a dataset) → ckan_datastore_search (quRecommendationDescriptions must describe only their own tool.
tool: ckan_group_search
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_group_search
A tool description tries to alter the model’s use of another tool.
(get details) → ckan_package_search with fq="groups:name"RecommendationDescriptions must describe only their own tool.
tool: ckan_get_mqa_quality
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_get_mqa_quality
A tool description tries to alter the model’s use of another tool.
pical workflow: ckan_package_show (get dataset ID) → ckan_get_mqa_quality → ckan_RecommendationDescriptions must describe only their own tool.
tool: ckan_get_mqa_quality_details
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_get_mqa_quality_details
A tool description tries to alter the model’s use of another tool.
pical workflow: ckan_get_mqa_quality (get overview scores) → ckan_get_mqa_quality_deRecommendationDescriptions must describe only their own tool.
tool: ckan_analyze_datasets
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_analyze_datasets
A tool description tries to alter the model’s use of another tool.
Use this before ckan_datastore_search to understand what fields are available and whaRecommendationDescriptions must describe only their own tool.
tool: ckan_catalog_stats
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "server_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ckan_catalog_stats
A tool description tries to alter the model’s use of another tool.
d the portal) → ckan_package_search (query specific data)RecommendationDescriptions must describe only their own tool.
tool: sparql_query
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "endpoint_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: sparql_query
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
ry SPARQL Query Execute a SPARQL SELECT query against any public HTTPS SPARQL endpoint. UsefRecommendationAnnotate destructive tools and require human approval.
tool: sparql_query
A tool description tries to alter the model’s use of another tool.
rgeted query) → ckan_package_search (get dataset details)RecommendationDescriptions must describe only their own tool.
tool: sparql_query
A database tool exposes a query/sql parameter that is a free-form string with no allow-list or parameterisation constraint — a raw-string injection surface. A tool exposing structured filters or an `enum` of named queries does not fire.
unconstrained query parameter "query"RecommendationExpose parameterised operations instead of a raw query string; never build queries from unvalidated model output.
tool: ckan_find_portals
A tool description tries to alter the model’s use of another tool.
show (verify) → ckan_package_search (search datasets)RecommendationDescriptions must describe only their own tool.
tool: ckan_find_portals
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
guage, or topic before querying them with other CKAN tools. **IMPORTANT — country parameter**: always pasRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: ckan_find_portals
A database tool exposes a query/sql parameter that is a free-form string with no allow-list or parameterisation constraint — a raw-string injection surface. A tool exposing structured filters or an `enum` of named queries does not fire.
unconstrained query parameter "query"RecommendationExpose parameterised operations instead of a raw query string; never build queries from unvalidated model output.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: ckan_package_search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_package_search
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
server (e.g., "https://dati.gov.it/opendata") - q (string): Search query using Solr syntaRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ckan_find_relevant_datasets
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_package_show
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
{ server_url: "https://dati.gov.it/opendata", id: "dataset-name" } - { server_url: "...",RecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ckan_list_resources
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
{ server_url: "https://dati.gov.it/opendata", id: "dataset-name" } - { server_url: "...",RecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ckan_organization_search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_tag_list
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_group_search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_get_mqa_quality
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_get_mqa_quality_details
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_analyze_datasets
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: sparql_query
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_find_portals
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ckan_package_search
An unusually long description is a common injection-padding tactic.
description length 6562 charsRecommendationKeep descriptions concise.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Find and rank datasets by relevance to a query using weighted fields. Use this instead of ckan_package_search when you want relevance-ranked results with explicit scoring across title, notes, tags, an
Get complete metadata for a specific dataset (package). Returns full details including resources, organization, tags, and all metadata fields. Notes: - metadata_modified is a CKAN record timestamp (pu
List all resources in a dataset with a compact summary. Returns a focused table of resources showing format, size, DataStore availability, and download URL. Use this to quickly assess what files a dat
List all organizations on a CKAN server. Organizations are entities that publish and manage datasets. Args: - server_url (string): Base URL of CKAN server - all_fields (boolean): Return full objects v
Get details of a specific organization. Args: - server_url (string): Base URL of CKAN server - id (string): Organization ID or name - include_datasets (boolean): Include list of datasets (default: tru
Search for organizations by name pattern. This tool provides a simpler interface than package_search for finding organizations. Wildcards are automatically added around the search pattern. Args: - ser
Query data from a CKAN DataStore resource. The DataStore allows SQL-like queries on tabular data. Not all resources have DataStore enabled. The response always includes a Fields section listing all av
Run SQL queries on a CKAN DataStore resource. This endpoint is only available on CKAN portals with DataStore enabled and SQL access exposed. Args: - server_url (string): Base URL of CKAN server - sql
Check if a CKAN server is available and get version information. Useful to verify server accessibility before making other requests. Also shows the count of High-Value Datasets (HVD) when the portal s
List tags from a CKAN server using faceting. This returns tag names with counts, optionally filtered by dataset query or tag substring. Args: - server_url (string): Base URL of CKAN server - q (string
List all groups on a CKAN server. Groups are thematic collections of datasets. Args: - server_url (string): Base URL of CKAN server - all_fields (boolean): Return full objects vs just names (default:
Get details of a specific group. Args: - server_url (string): Base URL of CKAN server - id (string): Group ID or name - include_datasets (boolean): Include list of datasets (default: true) - response_
Search for groups by name pattern. This tool provides a simpler interface than package_search for finding groups. Wildcards are automatically added around the search pattern. Args: - server_url (strin
Get MQA (Metadata Quality Assurance) quality metrics for a dataset on dati.gov.it. Returns quality score and detailed metrics (accessibility, reusability, interoperability, findability, contextuality)
Get detailed MQA (Metadata Quality Assurance) quality reasons for a dataset on dati.gov.it. Returns dimension scores, non-max reasons, and raw MQA flags from data.europa.eu. Only works with dati.gov.i
Search datasets and inspect the DataStore schema of queryable resources. For each dataset found, lists all resources. For DataStore-enabled resources, fetches the full field schema (name, type, and la
Get a statistical overview of a CKAN portal: total dataset count and breakdown by category, format, and organization. Single CKAN call (package_search with rows=0 and facets). No query needed. Args: -
Execute a SPARQL SELECT query against any public HTTPS SPARQL endpoint. Useful for querying open data portals and knowledge graphs that expose SPARQL endpoints, including: - data.europa.eu (European o
Search the live datashades.info registry of ~950 CKAN portals worldwide. Use this tool to discover which CKAN portals exist for a country, language, or topic before querying them with other CKAN tools