Review before connecting
The findings on this server are worth reviewing before you connect an agent to it.
Scanned 1 hour ago
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The helpmyagent MCP server exposes 18 tools, focused primarily on general-purpose capabilities. It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates helpmyagent C- — the findings are worth reviewing before you connect an agent to it. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check helpmyagent's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add helpmyagent to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.helpmyagent.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Find HelpMyAgent APIs matching an agent task or intent. This tool returns discovery metadata only.
Return method, executable URL, schemas, price, coverage and documentation for one HelpMyAgent endpoint. This tool does not execute the endpoint.
List public HelpMyAgent API categories and the number of published endpoints in each category.
Finds and ranks French public funding programs potentially relevant to a company based on its profile, location and project. Eligibility results are indicative and do not constitute an official eligib
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: describe_api
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "endpoint"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
vailable tools. search_apis, describe_api and list_categories are free discRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: describe_api
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "describe_api"RecommendationScope tools to the minimum needed.
Validates ZUGFeRD, Factur-X, and XRechnung e-invoices against EN 16931 with correction suggestions.
Tracks US tariff and trade-action changes from Federal Register documents and exposes them through an API for AI agents.
Instant rug-check for any EVM or Solana token, distilled to one clear 0-10 risk verdict.
Provides access to Bible translations, books, chapters, verses, and search functionality.
Remote-first MCP adapter for emitting Settlement Attestation Receipts; not a verifier.
Risk-ranked registry of AI tools for enterprise governance, enabling lookup of tool risk and shadow AI domain detection.
Aggregates and normalizes public certifications and qualifications available for a French company, including RGE, organic certification and Qualiopi.
Checks a French company against multiple public alert and sanctions sources. No match must be interpreted as a guarantee of compliance.
Returns publicly listed directors and legal representatives of a French company from a SIREN or SIRET.
Returns the latest normalized public BODACC events for a French company from a SIREN or SIRET.
Returns available public financial data for a French company from a SIREN or SIRET, including revenue and net income when available.
Aggregates selected existing French company intelligence services into a single call, with selectable sections and tolerance for temporarily unavailable sources.
Ranks actionable French public funding and open procurement opportunities for a company using its profile, project context and historical public contracts.
Returns the public profile of a French company from a SIREN or SIRET.
Returns public contracts awarded to a French company from consolidated French public procurement award data.
Detects public legal-risk signals for a French company from company status and BODACC notices, including insolvency proceedings and deregistrations. This is not a credit score.
Searches French companies by name, SIREN, SIRET or optional location criteria and returns structured matching company records.
Detects explainable business signals from available French company data, including closure, insolvency, revenue changes, new filings, public contracts and certifications.
Verifies the existence and current status of a French company or establishment from a SIREN or SIRET.
Searches currently open French public procurement opportunities and returns normalized BOAMP tender data ready for automated processing.