Hosted access to IT桔子 (ITJuzi) primary-market company, funding, investor, and sector data.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The IT桔子 MCP MCP server exposes 18 tools, focused primarily on general-purpose capabilities. Its published description reads: "Hosted access to IT桔子 (ITJuzi) primary-market company, funding, investor, and sector data". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates IT桔子 MCP F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check IT桔子 MCP's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add IT桔子 MCP to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.itjuzi.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
按公司关键词、行业、标签、中国/海外地区、成立年份、发展阶段、千里马、独角兽、公司资质等条件分页查询对外可见公司,适合回答有哪些公司、按名称找公司和补充项目背景;工商名称、工商注册名称、工商全称对应字段 registered_name。如用户只问总数、多少家、数量,优先使用 count_companies。
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: search_companies
A tool description tries to alter the model’s use of another tool.
问总数、多少家、数量,优先使用 count_companies。RecommendationDescriptions must describe only their own tool.
tool: count_companies
A tool description tries to alter the model’s use of another tool.
、数量是多少;不要为了计数遍历 search_companies 分页。RecommendationDescriptions must describe only their own tool.
tool: search_closed_companies
A tool description tries to alter the model’s use of another tool.
问总数、多少家、数量,优先使用 count_closed_companies。RecommendationDescriptions must describe only their own tool.
tool: count_closed_companies
A tool description tries to alter the model’s use of another tool.
关闭公司总数;不要为了计数遍历 search_closed_companies 分页。RecommendationDescriptions must describe only their own tool.
tool: resolve_companies
A tool description tries to alter the model’s use of another tool.
先解析19家独角兽公司,再调用 get_company_funding_events 查询融资历史。RecommendationDescriptions must describe only their own tool.
tool: get_lookup_options
A tool description tries to alter the model’s use of another tool.
签全集;赛道或标签词映射请调用 search_tags。RecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
当用户要求补充工商名称时,应在 search_companies、resolve_companies 或 get_company_profile 的 fieldRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
按公司关键词、行业、标签、中国/海外地区、成立年份、发展阶段、千里马、独角兽、公司资质等条件统计对外可见公司总数。适合回答多少家公司、总计几家、数量是多少;不要为了计数遍历 search_companies 分页。
分页查询死亡/关闭公司库。按公司关键词、行业、标签、中国/海外地区、成立年份、发展阶段、千里马、独角兽、公司资质、关闭日期、关闭原因或一级关闭原因筛选,返回公司画像、最新融资摘要、关闭日期和死亡原因。适合回答最近倒闭了哪些公司、某赛道死亡公司清单、某关闭原因下有哪些公司。如用户只问总数、多少家、数量,优先使用 count_closed_companies。
按行业、标签、地区、成立年份、发展阶段、公司资质、关闭日期、关闭原因或一级关闭原因统计死亡/关闭公司数量。适合回答某赛道倒闭公司有多少家、某年度关闭公司数量、某原因下关闭公司总数;不要为了计数遍历 search_closed_companies 分页。
批量把用户给出的公司简称或工商全称解析为 IT桔子 company_id,返回每个输入名称的候选匹配;工商名称、工商注册名称、工商全称对应字段 registered_name。适合处理用户给定的一批公司名单,例如先解析19家独角兽公司,再调用 get_company_funding_events 查询融资历史。
按公司ID查询公司画像,包括公司简称、工商全称 registered_name、行业、标签、地区、简介、最新融资和历史投资方等字段;工商名称、工商注册名称均对应 registered_name。
按公司ID分页查询公司融资历史,返回轮次、金额、币种、投资方、FA和估值等信息。
按时间、行业、标签、轮次等条件分页查询事件。event_type 表示物理来源:invse 融资/轮次事件、merger 并购事件;event_category 表示业务分类:investment 投资轮次、listing 上市相关、merger 并购;is_underwater 可筛选未披露水下事件,尝鲜版和标准版不可查看水下事件明细。
按公司动态汇总融资事件等值人民币金额并排序,支持公司标签、行业、地区、时间和轮次过滤;适合回答某赛道公司融资总额TOP排名,并可排除IPO上市、IPO上市后等轮次;统计默认包含未披露水下事件。
按公司标签、时间段和地区聚合融资事件数、披露金额事件数、获投公司数和融资总额,适合回答某赛道或标签集合在全国/城市之间的融资统计和同比、环比对比;统计默认包含未披露水下事件。
按机构名称关键词搜索投资机构,返回机构ID、案例数、最近投资时间和活跃行业。
按机构ID查询投资机构画像,包括投资案例数、最近投资时间和活跃行业摘要。
按机构ID分页查询机构投资案例,可按被投公司标签、行业和轮次筛选,适合回答某机构投过哪些具身智能、机器人、AI等标签公司;高权限套餐可查看未披露水下事件标识。
按人物ID或人物姓名分页查询人物投资案例,可按被投公司标签、行业和轮次筛选,适合回答某位投资人个人参与投资过哪些公司;高权限套餐可查看未披露水下事件标识。
查询企业对外投资案例,按组织关系归并公司和机构投资主体;适合回答某赛道企业做过哪些对外投资,例如具身智能企业投了哪些公司;高权限套餐可查看未披露水下事件标识。
查询结构化FA服务案例,返回FA机构、被服务公司、融资轮次、金额、时间和行业等信息;高权限套餐可查看未披露水下事件标识。
查询小型字典选项,用于把自然语言条件映射为ID,例如行业、子行业、融资轮次、省份、发展阶段、机构类型、公司资质和死亡原因。不传 lookup_type 时只返回字典类型和数量摘要。标签数量较大,不要用本工具获取标签全集;赛道或标签词映射请调用 search_tags。
按关键词搜索标签,适合把用户输入的赛道词如人工智能、机器人、低空经济映射为 tag_id。