Keyless open data for 84 German cities: 12 lean read-only MCP tools covering 67 data types.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The infranode MCP server exposes 12 tools, focused primarily on general-purpose capabilities. Its published description reads: "Keyless open data for 84 German cities: 12 lean read-only MCP tools covering 67 data types". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates infranode F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check infranode's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add infranode to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.infranode.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Get base data for a German city (population, area, coordinates). Sourced from Wikidata. Read-only. Useful as a first lookup to confirm a city exists and get its core attributes. For a broader question
Get a ONE-CALL overview of everything InfraNode knows about a German city. Start here for any city question. Returns: the city's base data, a CATALOG of all 81 available data types (weather, air quali
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_city
A tool description tries to alter the model’s use of another tool.
e at all) use ``get_city_overview`` instead.RecommendationDescriptions must describe only their own tool.
tool: get_city_overview
A tool description tries to alter the model’s use of another tool.
types that is ``get_city_resource(slug, resource=<type>)``), plus a small live hiRecommendationDescriptions must describe only their own tool.
tool: get_city_resource
A tool description tries to alter the model’s use of another tool.
coverage with ``get_city_overview(slug)`` or the ``infranode://catalog`` resourceRecommendationDescriptions must describe only their own tool.
tool: air_quality
A tool description tries to alter the model’s use of another tool.
readings use ``get_city_resource(slug, resource='air')`` instead.RecommendationDescriptions must describe only their own tool.
tool: weather
A tool description tries to alter the model’s use of another tool.
weather) use ``get_city_overview`` instead, which already includes a live weatheRecommendationDescriptions must describe only their own tool.
tool: station_board_departures
A tool description tries to alter the model’s use of another tool.
the EVA from ``get_city_resource(slug, resource='stations')``. Read-only.RecommendationDescriptions must describe only their own tool.
tool: station_board_arrivals
A tool description tries to alter the model’s use of another tool.
the EVA from ``get_city_resource(slug, resource='stations')``. Read-only.RecommendationDescriptions must describe only their own tool.
tool: transit_departures
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: list_cities
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
alid city slugs before invoking any city-scoped tool. Read-only. {"properties":{},"type":"object"}RecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
d of failing. Field names are snake_case and English across all data typesRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: get_city
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_city_overview
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_city_resource
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: air_quality
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: weather
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: pois
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: station_board_departures
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: station_board_arrivals
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: transit_departures
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compare
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Fetch ANY per-city data type by its key (generic accessor, 81 data types). One tool for the whole breadth of InfraNode: live data (air, traffic, transit stops, parking, charging, water-level, flood, s
Get official air quality for a German city (PM10, NO2 and more). Sourced from the Umweltbundesamt (UBA). Read-only. For live nearest-station hourly readings use ``get_city_resource(slug, resource='air
Get current weather observations for a German city. Sourced from the Deutscher Wetterdienst (DWD): temperature, wind, precipitation and related fields. Read-only, current conditions only (not a foreca
Get points of interest in a German city, filtered by type. Sourced from OpenStreetMap. Read-only.
Get live departures for ANY railway station by its EVA number. Covers all train categories including local/regional (S/RB/RE) and long distance, with real-time delays, cancellations and disruption mes
Get live arrivals for ANY railway station by its EVA number. Mirror of ``station_board_departures`` for arriving trains (all categories, real-time delays, disruption messages). Get the EVA from ``get_
Get live public-transport departures with real-time delays for a stop. Sourced from GTFS-RT/HVV/VGN. Unlike the static stop list (``get_city_resource(slug, resource='transit')``), this returns minute-
List all covered cities (slug, federal state, population, coverage). Takes no arguments. Call this first to discover valid city slugs before invoking any city-scoped tool. Read-only.
List all data sources with license, attribution and availability. Takes no arguments. Shows which upstream sources InfraNode bundles and whether each is currently active. Read-only.
Compare ONE resource across MULTIPLE cities in a single response. Fans the resource out over the listed cities and returns a per-city ``source_status`` (ok/disabled/no_data/error/not_found), so a miss