Ad intelligence MCP for decoding video ads and generating brand-specific creative scripts.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The heista MCP server exposes 113 tools, focused primarily on web, database, and developer capabilities. Its published description reads: "Ad intelligence MCP for decoding video ads and generating brand-specific creative scripts". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates heista F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Hidden instructions in a tool description". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check heista's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add heista to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://www.heista.co/api/mcp/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Decode a specific video ad URL into its full structural formula — beat-by-beat breakdown, hook classification, behavioral psychology stack, creative format, runtime performance signals (active days on
Retrieve the full decode bundle for a previously-submitted ad, or poll the status of a running decode job. Takes a single job_id (UUID returned by decode_ad). Returns either status="processing" (call
Build a complete creative intelligence profile of a brand from a single website URL. Takes a website URL (homepage, PDP, landing page) plus optional idempotency_key, force_refresh, and webhook_url. Re
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: create_powersource_docs
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
lic URL exists. IMPORTANT: The synthesis pipeline reads TEXT ONLY — it ignRecommendationRemove model-directed instructions from tool descriptions.
tool: call_creative_agent_preset
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
nto the agent's system prompt as BRAND INTELLIGENCE. RLS-scoped read — a branRecommendationRemove model-directed instructions from tool descriptions.
tool: list_creative_director_playbook_presets
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
rs 3 + 4 of the system prompt — voice + foundation — for the session (the lenRecommendationRemove model-directed instructions from tool descriptions.
tool: decode_ad
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: decode_ad
A tool description tries to alter the model’s use of another tool.
tely; poll with get_decode every 15s until status is "completed" (typicallRecommendationDescriptions must describe only their own tool.
tool: get_decode
A tool description tries to alter the model’s use of another tool.
UID returned by decode_ad). Returns either status="processing" (call agaiRecommendationDescriptions must describe only their own tool.
tool: create_powersource_url
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_powersource_url
A tool description tries to alter the model’s use of another tool.
video ad — use decode_ad.RecommendationDescriptions must describe only their own tool.
tool: get_powersource
A tool description tries to alter the model’s use of another tool.
eo decode — use get_decode.RecommendationDescriptions must describe only their own tool.
tool: create_powersource_docs
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
"Base64-encoded file content. Max 5MB per file."}},"required":["filename","cRecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_powersource_docs
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: create_powersource_full
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
"Base64-encoded file content. Max 5MB per file."}},"required":["filename","cRecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_powersource_full
A tool description tries to alter the model’s use of another tool.
sponse shape as create_powersource_url, but the synthesis cross-checks how the brand pRecommendationDescriptions must describe only their own tool.
tool: create_powersource_full
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
4. The pipeline reads TEXT ONLY — for any PDF or DOCX, extract the text content first using yRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: check_balance
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
te to report in conversation — everywhere else, cost should be referenced inRecommendationRemove side-channel parameters; constrain tool inputs.
tool: check_balance
A tool description tries to alter the model’s use of another tool.
ounts per tool (decode_ad, create_powersource_*, generate_adscript), per-RecommendationDescriptions must describe only their own tool.
tool: get_hook_intelligence
A tool description tries to alter the model’s use of another tool.
ic ad URL — use decode_ad. Do NOT use to generate finished scripts — useRecommendationDescriptions must describe only their own tool.
tool: adformula_intelligence
A tool description tries to alter the model’s use of another tool.
de that ad with decode_ad. Do NOT use for sentence-level transcript fidelRecommendationDescriptions must describe only their own tool.
tool: decoder_intelligence
A tool description tries to alter the model’s use of another tool.
rom a URL — use decode_ad (paid). Do NOT use for category-level patternsRecommendationDescriptions must describe only their own tool.
tool: generate_adscript
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
this", or wants shell-faithful replication of a proven winner in theiRecommendationAnnotate destructive tools and require human approval.
tool: generate_adscript
A tool description tries to alter the model’s use of another tool.
nts override, voice_mode ("creator" for UGC default, "brand" for owned cRecommendationDescriptions must describe only their own tool.
tool: call_creative_worlds
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ccess on actual token usage. {"$schema":"http://json-schema.org/draftRecommendationRemove side-channel parameters; constrain tool inputs.
tool: call_creative_worlds
A tool description tries to alter the model’s use of another tool.
not cover, use chat_with_creative_worlds instead. OUTPUT SHAPE switches on the `mediumRecommendationDescriptions must describe only their own tool.
tool: call_creative_agent_preset
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
success on real token usage. {"$schema":"http://json-schema.org/draftRecommendationRemove side-channel parameters; constrain tool inputs.
tool: call_creative_agent_preset
A tool description tries to alter the model’s use of another tool.
ble presets via list_creative_agent_presets. Workspace-authored presets are only callable iRecommendationDescriptions must describe only their own tool.
tool: chat_with_creative_worlds
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
rlds Multi-turn conversation with Heista's creative direction engine — a reaRecommendationRemove side-channel parameters; constrain tool inputs.
tool: chat_with_creative_worlds
A tool description tries to alter the model’s use of another tool.
not covered by call_creative_worlds' `medium` enum. WHAT YOU CAN ASK FOR (any of tRecommendationDescriptions must describe only their own tool.
tool: list_brands
A tool description tries to alter the model’s use of another tool.
a strategy with list_strategies.RecommendationDescriptions must describe only their own tool.
tool: list_strategies
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
o label them in conversation or to pick the right one for a product-focusedRecommendationRemove side-channel parameters; constrain tool inputs.
tool: list_projects
A tool description tries to alter the model’s use of another tool.
s project_id to list_strategies / list_brand_documents / list_brand_assets to sRecommendationDescriptions must describe only their own tool.
tool: add_brand_asset
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "image_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: add_brand_asset
A tool description tries to alter the model’s use of another tool.
be retried via retag_brand_asset.RecommendationDescriptions must describe only their own tool.
tool: delete_brand_asset
A tool description tries to alter the model’s use of another tool.
re calling. Use list_brand_assets first to find the asset_id.RecommendationDescriptions must describe only their own tool.
tool: list_brand_documents
A tool description tries to alter the model’s use of another tool.
or). Use BEFORE read_brand_document to discover what context exists for a brand witRecommendationDescriptions must describe only their own tool.
tool: read_brand_document
A tool description tries to alter the model’s use of another tool.
itle. Use AFTER list_brand_documents to pick the right document. Free, read-only.RecommendationDescriptions must describe only their own tool.
tool: search_skills
A tool description tries to alter the model’s use of another tool.
Use this BEFORE load_skill (for disk-backed image/fleet skills) or the getRecommendationDescriptions must describe only their own tool.
tool: search_skills
A database tool exposes a query/sql parameter that is a free-form string with no allow-list or parameterisation constraint — a raw-string injection surface. A tool exposing structured filters or an `enum` of named queries does not fire.
unconstrained query parameter "query"RecommendationExpose parameterised operations instead of a raw query string; never build queries from unvalidated model output.
tool: list_skills
A tool description tries to alter the model’s use of another tool.
dy content (use load_skill for that). Filter by domain, type, or source_foRecommendationDescriptions must describe only their own tool.
tool: load_skill
A tool description tries to alter the model’s use of another tool.
disk. Use AFTER list_skills to pick the right skill. For register-type skilRecommendationDescriptions must describe only their own tool.
tool: perplexity_search
A tool description tries to alter the model’s use of another tool.
Web-grounded search via Perplexity Sonar Pro. Returns synthesized aRecommendationDescriptions must describe only their own tool.
tool: search
A tool description tries to alter the model’s use of another tool.
discourse → use search_community. NOT for: numerical effect sizes or methodologyRecommendationDescriptions must describe only their own tool.
tool: search_community
A tool description tries to alter the model’s use of another tool.
rieval gap that perplexity_search fundamentally couldn't fill. Optional platformRecommendationDescriptions must describe only their own tool.
tool: search_research
A tool description tries to alter the model’s use of another tool.
andscapes → use search.RecommendationDescriptions must describe only their own tool.
tool: fetch_url
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: fetch_url
A tool description tries to alter the model’s use of another tool.
cific URL after search surfaces it. Returns the extracted text contentRecommendationDescriptions must describe only their own tool.
tool: dispatch_desk_researcher
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_desk_researcher
A tool description tries to alter the model’s use of another tool.
questions (use dispatch_trend_researcher) / entity teardowns (use dispatch_market_analysRecommendationDescriptions must describe only their own tool.
tool: dispatch_trend_researcher
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_trend_researcher
A tool description tries to alter the model’s use of another tool.
questions (use dispatch_desk_researcher) / entity teardowns (use dispatch_market_analysRecommendationDescriptions must describe only their own tool.
tool: dispatch_market_analyst
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_market_analyst
A tool description tries to alter the model’s use of another tool.
med entity (use dispatch_desk_researcher) / trajectory questions about a category (use dRecommendationDescriptions must describe only their own tool.
tool: dispatch_quantitative_researcher
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_quantitative_researcher
A tool description tries to alter the model’s use of another tool.
landscapes (use dispatch_desk_researcher) / community language patterns (use dispatch_quRecommendationDescriptions must describe only their own tool.
tool: dispatch_qualitative_researcher
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_qualitative_researcher
A tool description tries to alter the model’s use of another tool.
gap that legacy search tools could not fill. Returns: Corpus + SamplinRecommendationDescriptions must describe only their own tool.
tool: dispatch_social_listening_researcher
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_social_listening_researcher
A tool description tries to alter the model’s use of another tool.
fect sizes (use dispatch_quantitative_researcher).RecommendationDescriptions must describe only their own tool.
tool: dispatch_desk_researcher_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_desk_researcher_async
A tool description tries to alter the model’s use of another tool.
questions (use dispatch_trend_researcher) / entity teardowns (use dispatch_market_analysRecommendationDescriptions must describe only their own tool.
tool: dispatch_trend_researcher_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_trend_researcher_async
A tool description tries to alter the model’s use of another tool.
questions (use dispatch_desk_researcher) / entity teardowns (use dispatch_market_analysRecommendationDescriptions must describe only their own tool.
tool: dispatch_market_analyst_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_market_analyst_async
A tool description tries to alter the model’s use of another tool.
med entity (use dispatch_desk_researcher) / trajectory questions about a category (use dRecommendationDescriptions must describe only their own tool.
tool: dispatch_quantitative_researcher_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_quantitative_researcher_async
A tool description tries to alter the model’s use of another tool.
landscapes (use dispatch_desk_researcher) / community language patterns (use dispatch_quRecommendationDescriptions must describe only their own tool.
tool: dispatch_qualitative_researcher_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_qualitative_researcher_async
A tool description tries to alter the model’s use of another tool.
gap that legacy search tools could not fill. Returns: Corpus + SamplinRecommendationDescriptions must describe only their own tool.
tool: dispatch_social_listening_researcher_async
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
(e.g. \"do not spawn further subagents\", \"only Meta paid social\")RecommendationAnnotate destructive tools and require human approval.
tool: dispatch_social_listening_researcher_async
A tool description tries to alter the model’s use of another tool.
fect sizes (use dispatch_quantitative_researcher). ASYNC version: returns { job_id } immediatelyRecommendationDescriptions must describe only their own tool.
tool: dispatch_head_of_research
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ity (specialist token spend + Anthropic session-runtime at $0.08/hr).RecommendationRemove side-channel parameters; constrain tool inputs.
tool: list_saved_assets
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
to the caller. API-key callers MUST pass an explicit user id (no calleRecommendationRemove side-channel parameters; constrain tool inputs.
tool: list_saved_assets
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
separate table; reads include share URLs). Omit to read every category in one merged strRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: get_saved_asset
A tool description tries to alter the model’s use of another tool.
amps. Use AFTER list_saved_assets to load the full record when the list projectioRecommendationDescriptions must describe only their own tool.
tool: save_asset
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "media_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: delete_saved_asset
A tool description tries to alter the model’s use of another tool.
lers are treated as org-trusted and can delete on behalf of any creatorRecommendationDescriptions must describe only their own tool.
tool: list_strategy_audiences
A tool description tries to alter the model’s use of another tool.
Distinct from list_strategies (which lists scans for a brand): this lists audRecommendationDescriptions must describe only their own tool.
tool: get_strategy
A tool description tries to alter the model’s use of another tool.
bundle shape as get_powersource(data) — buyer profile, 12 behavioral tensions,RecommendationDescriptions must describe only their own tool.
tool: fleet_search_decoded_ads
A tool description tries to alter the model’s use of another tool.
Search the published Ad Intelligence corpus (the publiRecommendationDescriptions must describe only their own tool.
tool: fleet_list_brand_reports
A tool description tries to alter the model’s use of another tool.
ublic URLs; use fleet_get_brand_report for a full report. Read-only.RecommendationDescriptions must describe only their own tool.
tool: fleet_analytics_overview
A tool description tries to alter the model’s use of another tool.
s, sessions, AI-search-referred sessions, the view→engaged→CTA→signup→RecommendationDescriptions must describe only their own tool.
tool: fleet_gsc_summary
A tool description tries to alter the model’s use of another tool.
Google Search performance totals from first-party Search ConsRecommendationDescriptions must describe only their own tool.
tool: fleet_gsc_top_queries
A tool description tries to alter the model’s use of another tool.
Top Google search queries by clicks or impressions from first-parRecommendationDescriptions must describe only their own tool.
tool: fleet_gsc_top_pages
A tool description tries to alter the model’s use of another tool.
pages by Google search clicks or impressions from first-party Search CRecommendationDescriptions must describe only their own tool.
tool: fleet_gsc_query
A tool description tries to alter the model’s use of another tool.
LIVE Google Search Analytics query — group by any dimensions (dateRecommendationDescriptions must describe only their own tool.
tool: fleet_gsc_inspect_url
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: fleet_gsc_sitemaps
A tool description tries to alter the model’s use of another tool.
gistered on the Search Console property with submitted vs indexed counRecommendationDescriptions must describe only their own tool.
tool: fleet_crawler_hits
A tool description tries to alter the model’s use of another tool.
archBot, …) and search crawlers (Googlebot, Bingbot) fetched which heiRecommendationDescriptions must describe only their own tool.
tool: fleet_site_audit_summary
A tool description tries to alter the model’s use of another tool.
e drilling into fleet_site_pages. Read-only.RecommendationDescriptions must describe only their own tool.
tool: fleet_seo_recovery
A tool description tries to alter the model’s use of another tool.
80), and Google Search Console impressions/clicks/avg-position over thRecommendationDescriptions must describe only their own tool.
tool: fleet_list_issues
A tool description tries to alter the model’s use of another tool.
/…), or a title search. Returns identifier + state + priority + assignRecommendationDescriptions must describe only their own tool.
tool: fleet_product_signups_recent
A tool description tries to alter the model’s use of another tool.
ackend shape as fleet_product_user_summary — trial/credits/plan/onboarding/Heists per userRecommendationDescriptions must describe only their own tool.
tool: fleet_product_funnel_summary
A tool description tries to alter the model’s use of another tool.
. Requires mcp:fleet:customer_pii. Every call is audit-logged. Read-only.RecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
e frame for any conversation: Heista is Creative Intelligence. The MCP givesRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
is tool returns shell-faithful scripts. The structural shells are proRecommendationAnnotate destructive tools and require human approval.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
d of facet-by-facet. Same shape as `get_powersource(data)` but keyed by `pRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: decode_ad
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: create_powersource_url
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: create_powersource_docs
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: create_powersource_docs
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
into chat: (1) read the file using your file-reading tools, (2) extract the text content preRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: create_powersource_full
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: list_projects
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
s List Projects List all projects (campaign folders) for a brand. A project groups strategies, docuRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: add_brand_asset
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_brand_asset
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: load_skill_reference
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
Skill Reference Load one reference file from a register-type skill's references/ folderRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: load_skill_reference
A filesystem tool exposes a path parameter that is a free-form string with no pattern/enum/format constraint, so it accepts absolute paths and "../" traversal. A tool that constrains its path (a rooted `pattern` or an `enum`) does not fire.
unconstrained path parameter "reference_path"RecommendationConstrain the path parameter to a rooted allow-list and reject absolute/traversal paths server-side.
tool: perplexity_search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_community
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_research
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: fetch_url
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_desk_researcher
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_trend_researcher
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_market_analyst
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_quantitative_researcher
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_qualitative_researcher
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_social_listening_researcher
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_desk_researcher_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_trend_researcher_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_market_analyst_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_quantitative_researcher_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_qualitative_researcher_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_social_listening_researcher_async
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: dispatch_head_of_research
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_saved_asset
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: creative_publish_article
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: creative_unpublish_article
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: (server instructions)
Role tokens or delimiter abuse steer the model rather than describe the tool.
### Per beat ``` [Beat number, dimmed] [BEAT NAME IN SMALL CAPS]RecommendationWrite neutral, descriptive tool metadata.
tool: (server instructions)
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ista site: ``` https://www.heista.co/decode/{slug} ``` The slug is in the decode response payloadRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: call_creative_worlds
An unusually long description is a common injection-padding tactic.
description length 2585 charsRecommendationKeep descriptions concise.
The server exposes one or more ui:// (MCP Apps) resources whose HTML/JS renders inside the host client — a client-side injection / data-exposure surface most scanners ignore. Flagged for review, not damning on its own.
1 ui:// resource(s); e.g. ui://heista/decode-card?v=2026-05-11-7RecommendationReview each ui:// resource’s markup and scripts; treat host-rendered UI as untrusted, sandbox it, and never expose secrets or conversation context to it.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Retrieve the full creative intelligence profile for a previously-submitted PowerSource scan, or poll the status of a running scan. Takes a job_id (UUID returned by any create_powersource_* tool) plus
Build a complete creative intelligence profile from internal brand documents — creative briefs, brand guidelines, product specs, customer research, competitive analysis. Takes any mix of file_ids (fro
Build the highest-fidelity creative intelligence profile by combining a brand's public website URL with their internal documents. Takes a required website URL plus at least one document — file_ids fro
Check the calling user's Heista API credit balance, month-to-date usage broken down by operation, lifetime spend, and the current pricing for every paid tool. Takes no inputs. Returns balance in cents
Browse proven hook patterns from Heista's corpus of decoded winning Meta/TikTok ads. Takes optional filters: vertical (e.g. BEAUTY_SKINCARE, SUPPLEMENTS, APPAREL), hook_type (e.g. CURIOSITY_SPIKE, CON
Browse proven ad formula blueprints — structural patterns clustered from 3-10+ winning ads that independently converged on the same beat architecture while Meta kept rewarding them with sustained spen
Browse individual decoded ads from Heista's corpus of real winning Meta/TikTok creative. Takes optional filters: vertical, creative_format, marketing_angle, hook_type, algo_intent, brand (partial name
Generate direct-response video ad scripts by fusing a proven structural source (decoded ad or formula) with a brand's PowerSource. Output is feed-native ad copy for paid social (Meta, TikTok, Reels) i
Heista's creative direction engine — same engine the Creative Director specialist runs internally, exposed over MCP. ONE-SHOT: give a brief, get N finished creative outputs. For back-and-forth refinem
Invoke a Creative Agent (character) preset. Every preset is a purpose-built character the workspace has authored or the Heista catalog has published — copy voice, art direction, strategy, creative dir
Multi-turn conversation with Heista's creative direction engine — a real chat where the agent decides each turn what to produce based on what you ask for. Use whenever the work needs more than one rou
List every brand in this workspace. Use this BEFORE creating a PowerSource to avoid creating duplicate brand records (pass the matching brand_id to create_powersource_*), and to discover brands the us
Get a brand's full canonical record — name, domain, voice (tone_of_voice), story, visual identity (logo, primary color, visual assets), and counts. Use to inspect what a brand carries before deciding
List all PowerSource strategies (scans) for a brand. A brand has many strategies — one per scanned URL. Product-page strategies carry product_name and is_product_page=true; use these to label them in
List all projects (campaign folders) for a brand. A project groups strategies, documents, client assets, and outputs under one campaign. Returns project_id (pass as project_id to list_strategies / lis
List images for a brand. Filter by PowerSource (this scan only, via powersource_id), by on-pack product_name (the vision tagger's read), by type (logo, product, product_cutout, hero, lifestyle, ingred
Upload an image to a brand by URL. The pipeline downloads it, runs the vision tagger (classifies type, detects product name, flags is_primary_product), stores it in the brand-assets bucket, and insert
Delete one brand asset by asset_id. Removes the brand_assets row and (when the asset was uploaded rather than scanned) the storage object. Destructive — confirm with the user before calling. Use list_
Re-run the vision tagger on one brand asset. Reads the stored object when present (uploaded assets) or the original URL (scan-sourced assets), then updates type, detected_product_name, is_primary_prod
Batch re-run the vision tagger against every asset in a brand that hasn't been reviewed yet (vision_classified=false). Recovers rows the scan-time tagger dropped because of CDN blocks (Shopify hotlink
List indexed brand documents for a brand. Each row carries the indexed signals (doc_type, summary, key_topics, classification_confidence, indexing_status) plus mime_type and size_bytes from the underl
Read one indexed brand document. Returns the indexed metadata (doc_type, summary, key_topics, entities, key_quotes) plus the document body as plain text in content.text — every mime (PDF, DOCX, PPTX,
Find skills across EVERY Heista skill library at once — image craft, fleet foundations and model briefings, Heista DNA creative playbooks, creative agents, and agent skills. Describe the SITUATION you
List skills available in the Heista skill library. Returns name, description, domain (shared / image / video / research / strategy / copy / creative / generation), type (foundation / registers / model
Load the full SKILL.md body for one skill by canonical dot-notation name (e.g. "research.foundation", "research.methodologies.desk-synthesis", "shared.registers.cinema-mode"). Returns frontmatter + bo
Load one reference file from a register-type skill's references/ folder (e.g. "m1-narrative.md" from "shared.registers.cinema-mode"). Only register-type skills have references/ — foundations and metho
Web-grounded search via Perplexity Sonar Pro. Returns synthesized answer text plus a structured sources[] array (url + title) the caller can evaluate per the research.foundation four-tier source ladde
General-purpose web grounding via parallel.ai (Vercel AI Gateway). Returns synthesized text excerpts plus structured sources[] with direct URLs. Use for: topic landscapes, entity-deep teardowns, recen
Community-discourse search via parallel.ai with optional platform filtering. Returns synthesized text excerpts plus direct URLs to real Reddit threads, X posts from named operators, Substack essays, L
Structured fact-check + numerical research via Perplexity Sonar Reasoning Pro (Gateway-routed). Returns synthesized answer text plus structured sources[] with direct URLs to primary sources. Use for:
Drill into a specific URL after search surfaces it. Returns the extracted text content plus metadata. Internal routing: PDFs hit Anthropic Files API for OCR + structured extraction; HTML pages are fet
Dispatch to the DESK RESEARCHER — source-grounded synthesis on a topic landscape. Use for: "what is known about X / give me the landscape of Y / fact-check Z / synthesize the published evidence on W".
Dispatch to the TREND RESEARCHER — recency-dominant trajectory investigation. Use for: "is X a real trend / what is happening with X right now / where is X headed / what is driving X". Distinguishes t
Dispatch to the MARKET ANALYST — entity-deep teardown of a named brand or vendor. Use for: "what is brand X / how does company Y work / decode competitor Z / teardown vendor W". Multi-axis extraction
Dispatch to the QUANTITATIVE RESEARCHER — numerical analysis with full methodology context. Use for: briefs that turn on numbers done rigorously — "what is the documented effect size of X / what does
Dispatch to the QUALITATIVE RESEARCHER — thematic synthesis from unstructured text (interviews, reviews, forum threads, customer language). Use for: "what are the 2-3 recurring themes in how D2C found
Dispatch to the SOCIAL LISTENING RESEARCHER — multi-platform community-signal interpretation. Use for: "what are practitioners saying about X across platforms / what jargon is emerging in field Y / wh
Dispatch to the DESK RESEARCHER — source-grounded synthesis on a topic landscape. Use for: "what is known about X / give me the landscape of Y / fact-check Z / synthesize the published evidence on W".
Dispatch to the TREND RESEARCHER — recency-dominant trajectory investigation. Use for: "is X a real trend / what is happening with X right now / where is X headed / what is driving X". Distinguishes t
Dispatch to the MARKET ANALYST — entity-deep teardown of a named brand or vendor. Use for: "what is brand X / how does company Y work / decode competitor Z / teardown vendor W". Multi-axis extraction
Dispatch to the QUANTITATIVE RESEARCHER — numerical analysis with full methodology context. Use for: briefs that turn on numbers done rigorously — "what is the documented effect size of X / what does
Dispatch to the QUALITATIVE RESEARCHER — thematic synthesis from unstructured text (interviews, reviews, forum threads, customer language). Use for: "what are the 2-3 recurring themes in how D2C found
Dispatch to the SOCIAL LISTENING RESEARCHER — multi-platform community-signal interpretation. Use for: "what are practitioners saying about X across platforms / what jargon is emerging in field Y / wh
Run a full research workflow via the Head of Research agent. The Head decomposes your brief into specialist sub-questions, dispatches the right combination of 6 specialists (desk, trend, market, quant
Get the current status of a specialist dispatch job started via dispatch_<specialist>_async. Returns { status: queued|running|completed|failed, result_text?, error_text?, error_class?, retry_count, el
Read-only walk of a fleet session tree. Given any session_id in the tree (root, Head, Mastermind, or specialist sub-node) returns the full breakdown: every session row with depth + parent + agent_kind
List saved assets in the workspace. Filter by category (STRATEGY, IDEAS, COPY, VISUALS, MOTION, BRIEFS), by one or more formats inside the category (e.g. COPY + formats=["ad-script","hook"]), by tags
Fetch one saved asset by id. Returns the full row including category, format, tags, body_text/html, signed media_url (if private storage), metadata, creator, brand, and timestamps. Use AFTER list_save
Fetch up to 50 saved assets by id in one round-trip. Use when an agent needs to pull a pre-selected set — e.g. resolving a saved_asset_picker context input on a Heist that requires N pinned assets. Mi
Persist a new saved asset to the workspace. category MUST be one of STRATEGY, IDEAS, COPY, VISUALS, MOTION (BRIEFS lives in creator_briefs and is not saveable through this tool). format MUST match the
Delete one saved asset by id. Destructive — confirm with the user before calling. OAuth callers can only delete saves they created themselves (Linear model — see /assets UI for org-admin override). AP
Toggle the favorite flag on a saved asset. Pass is_favorite=true to favorite, false to unfavorite. favorited_at is set/cleared in lockstep so the Favorites tab sorts correctly. Not destructive.
List audience archetypes for a strategy (PowerSource). Returns the Buyer Decoder archetype (source="buyer_profile", one entry max) plus up to 3 offering primary_audience segments (source="primary_audi
Read a creative strategy in full by its powersource_id. Returns the same brand-merged bundle shape as get_powersource(data) — buyer profile, 12 behavioral tensions, angles, narrative direction, tone o
List tone profiles for a strategy. Today returns at most one entry — the tone_of_voice synthesized by the Tone of Voice Synthesis agent (POWER-mode bundles only). The shape is list-stable so future mu
Saved style configs picked into image-led Heists. Workspace = org-owned styles. Official = canonical Heista catalog (org_id IS NULL, is_canonical=true). Read-only, free. Filter scope with only_workspa
Get one visual styles preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Visual presets (style reference sets) backed by visual_heists. Dual scope since 2026-07-14: workspace rows saved from the Visual Preset builder + the Heista-curated official catalog. Read-only, free.
Get one visuals preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Structural references for script-led Heists. Workspace decodes (your video_sources scans joined with their video_scan_frameworks) + Heista-curated decoded ads from official_ad_heists. Read-only, free.
Get one decoded ads preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Cluster-level structural formulas derived from decoded ads. Heista-curated; served as a generation parameter. Read-only, free. Filter scope with only_workspace / only_official (mutually exclusive — sa
Get one ad formulas preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Static-ad references for image-led Heists. Workspace static scans + Heista-curated image ad heists. Read-only, free. Filter scope with only_workspace / only_official (mutually exclusive — same toggle
Get one static ads preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Visual ideas you saved from prior generations. Workspace-only. Read-only, free. Filter scope with only_workspace / only_official (mutually exclusive — same toggle as the in-app library lens). Page wit
Get one saved visual ideas preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Reusable creative agents the Heist can pick as a handoff target — picked from the UI, callable as an MCP tool from Managed Agents. Workspace = private agents in the org. Official = public_template age
Get one creative agents preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Portable craft skills (frameworks + method + worked examples) a Creative Agent loads ON TOP of its worldview — additive and stackable, never substitutive (unlike a creative_director_playbook, which re
Get one creative agent skills preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Seven-section creative-mechanism lenses the Creative Director chat picks at session start. The picked playbook substitutes Layers 3 + 4 of the system prompt — voice + foundation — for the session (the
Get one creative director playbooks preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Saved casting talent — a person you can re-use across Heists. The Models Heist saves them on click; future Heists can pick one as a brand-aware talent reference. Workspace = your saved castings. Offic
Get one models preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Styled outfits — a talent dressed in a full look, saved as one composite sheet (turnaround + wardrobe detail crops) with structured refs to the product images that built it. The Outfits Heist saves th
Get one outfits preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Cards the user bookmarked from Creative Director chat — directions, concepts, executions, brand platforms, art directions, visual sets. Surfaces in /library + the chat-side tray. Saves happen through
Get one saved cards preset by id, including its full body payload (framework, agent config, etc.). Call the matching list tool first to discover ids. Free, read-only.
Canonical Ad Intelligence corpus counts — the single source of truth that kills number drift across marketing surfaces. Returns decoded ads published (THE number to quote publicly), total corpus size,
Search the published Ad Intelligence corpus (the public decode gallery). Filter by free-text (name/tagline/brand), brand, category, vertical, or platform. Returns list rows with public URLs — never th
Read one published decode in full by id or slug, including its public structural payload (beats, classification, patterns — the same data rendered on the public decode page). Use for proof points, con
List live brand-level Ad Intelligence reports (the public /decode/brand pages). Optional brand-name filter, paginated, hard cap 50 rows. Returns identifiers + ad counts + public URLs; use fleet_get_br
Read one live brand report in full by slug, including the creative intelligence payload used on the public brand page — proof points for outreach and positioning. Read-only.
List live intelligence articles — the weekly and per-vertical category report system behind the public intelligence surfaces. Filter by kind (weekly/category) or vertical. Note: individual static deep
Aggregate marketing analytics for the last 7/28/90 days: pageviews, visitors, sessions, AI-search-referred sessions, the view→engaged→CTA→signup→trial funnel, and top pages. Aggregates only — never pe
Top marketing pages by views for the last 7/28/90 days, optionally filtered to a path prefix (e.g. "/decode", "/intelligence", "/brands"). Includes engagement signals where captured. Aggregates only,
Daily pageview series for the last 7/28/90 days, split by traffic source category (ai_search / organic / social / direct / referral). Use to measure launch weeks and content momentum. Aggregates only.
Google Search performance totals from first-party Search Console data (synced 6-hourly): clicks, impressions, CTR, impression-weighted average position, distinct queries and pages. Optional page-path
Top Google search queries by clicks or impressions from first-party Search Console data, optionally filtered to pages containing a path (e.g. "/decode"). The core tool for briefing programmatic SEO. H
Top pages by Google search clicks or impressions from first-party Search Console data, optionally filtered to queries containing a term. Use to find which pSEO pages earn search demand. Hard cap 50 ro
LIVE Google Search Analytics query — group by any dimensions (date, page, query, country, device, searchAppearance; up to 3) with page/query filters over up to 16 months of history. Richer than the sn
Google URL Inspection for one heista.co URL: index verdict, coverage state ("Submitted and indexed" / "Crawled - currently not indexed" / "URL is unknown to Google"), last crawl time, robots state, an
Sitemaps registered on the Search Console property with submitted vs indexed counts, last-download time, warnings and errors. The indexing-progress scoreboard — as of Jul 2026 the main sitemap had 2,4
Server-logged crawler fetches: which AI engines (GPTBot, ClaudeBot, PerplexityBot, OAI-SearchBot, …) and search crawlers (Googlebot, Bingbot) fetched which heista.co pages, and when. This signal is in
One-row health scoreboard from the weekly full-site crawl: total pages, OK/redirect/error counts, ORPHAN pages (200 but zero internal inlinks — the primary indexing-recovery target), thin pages, missi
Filterable inventory of every sitemap-listed page with SEO facts (title, meta description, canonical, h1, word count, JSON-LD) and internal inlink/outlink counts from the weekly crawl. Filters: path_c
Internal links for one page: direction "in" = who links TO it (zero inlinks = orphan), "out" = what it links to. Link data comes from the first render of sitemap-listed pages (pagination-only links ar
One-row verification scorecard for the indexing-recovery plan (internal-linking-spec-v2): site-wide + /decode-specific orphan counts (200 but zero internal inlinks) from the latest crawl, Googlebot vs
List issues on the Heista Linear board (team HEI) — the read-only window into what the dev agents are working on, what's broken, and what's shipped. Filter by workflow state ("Backlog"/"Todo"/"In Prog
Read one Heista Linear issue in full by identifier (e.g. "HEI-14") or UUID: title, state, priority, assignee, labels, full description, and recent comments (including the automated scope/fix notes age
Look up ONE customer's product-backend state by email: trial status, credit balance, workspace plan, installed Heists, onboarding completion, plus PostHog attribution/engagement signals (source, 30d a
List recent signups (last N days, hard cap 50 rows) with the same product-backend shape as fleet_product_user_summary — trial/credits/plan/onboarding/Heists per user. Use to see the newest cohort at a
Aggregate conversion/drop-off stats for a signup cohort (last N days, max 90): trial active vs expired-unconverted vs converted-to-paid, conversion rate, never-spent-a-credit rate, onboarding completi
Read the canonical shelves, taxonomy, relationship Lego, safe content rules, and positional slots for every publishable Creative Library format. Call this before authoring.
List Creative Library drafts and publication state. Returns editorial metadata only, not customer data.
Read one Creative Library draft so it can be reviewed before explicit publication.
Validate and save a complete Creative Library draft using the canonical taxonomy and format-specific content slots. An identical retry is a no-op. It cannot replace published content or publish a page
Publish only the exact reviewed draft revision. If the draft changed after review, publication fails and the new revision must be reviewed.
Take a live Creative Library article down. It stops being public and leaves the sitemap immediately. The draft is preserved and can be re-published after review. Use this to reverse a publication.