Integrates with NOAA's oceanographic and meteorological APIs to provide access to water level data, tide predictions, currents, weather measurements, station information, and celestial calculations for maritime applications.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The noaa-tides-currents-mcp-server MCP server exposes 26 tools, focused primarily on general-purpose capabilities. Its published description reads: "Integrates with NOAA's oceanographic and meteorological APIs to provide access to water level data, tide predictions, currents, weather measurements, station information, and cele…". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates noaa-tides-currents-mcp-server F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check noaa-tides-currents-mcp-server's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add noaa-tides-currents-mcp-server to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://perigeetides.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Get observed water levels from a NOAA tide station as a time series. Choose the interval: "6" = standard 6-minute observations (preliminary or verified, max 31 days per request), "1" = 1-minute prelim
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: noaa_get_water_levels
A tool description tries to alter the model’s use of another tool.
ure tides — use noaa_get_tide_predictions.RecommendationDescriptions must describe only their own tool.
tool: noaa_get_water_level_summaries
A tool description tries to alter the model’s use of another tool.
time series use noaa_get_water_levels; for future tides use noaa_get_tide_predictionsRecommendationDescriptions must describe only their own tool.
tool: noaa_get_tide_predictions
A tool description tries to alter the model’s use of another tool.
). Compare with noaa_get_water_levels for actual conditions.RecommendationDescriptions must describe only their own tool.
tool: noaa_get_currents
A tool description tries to alter the model’s use of another tool.
Find them with noaa_search_stations (type "currents") or noaa_find_nearest_stationsRecommendationDescriptions must describe only their own tool.
tool: noaa_get_current_predictions
A tool description tries to alter the model’s use of another tool.
e station — see noaa_get_prediction_offsets.RecommendationDescriptions must describe only their own tool.
tool: noaa_get_meteorological_data
A tool description tries to alter the model’s use of another tool.
ta is served by noaa_get_water_levels, not this tool.RecommendationDescriptions must describe only their own tool.
tool: noaa_search_stations
A tool description tries to alter the model’s use of another tool.
coordinates use noaa_find_nearest_stations instead.RecommendationDescriptions must describe only their own tool.
tool: noaa_find_nearest_stations
A tool description tries to alter the model’s use of another tool.
before calling noaa_get_tide_predictions, "currents" before noaa_get_currents — currentRecommendationDescriptions must describe only their own tool.
tool: noaa_get_station_info
A tool description tries to alter the model’s use of another tool.
atum values use noaa_get_station_datums; for harmonic constituents use noaa_get_harmoniRecommendationDescriptions must describe only their own tool.
tool: noaa_get_harmonic_constituents
A tool description tries to alter the model’s use of another tool.
ns use offsets (noaa_get_prediction_offsets).RecommendationDescriptions must describe only their own tool.
tool: noaa_get_sea_level_rise_projections
A tool description tries to alter the model’s use of another tool.
0?"). Pair with noaa_get_sea_level_trends (observed) and noaa_get_high_tide_flooding (floRecommendationDescriptions must describe only their own tool.
tool: noaa_get_high_tide_flooding
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "report"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: noaa_get_high_tide_flooding
A tool description tries to alter the model’s use of another tool.
orical flag via noaa_get_station_info.RecommendationDescriptions must describe only their own tool.
tool: nws_get_wind_forecast
A tool description tries to alter the model’s use of another tool.
right now, use noaa_get_meteorological_data (product "wind"). For the official marine textRecommendationDescriptions must describe only their own tool.
tool: nws_get_marine_forecast
A tool description tries to alter the model’s use of another tool.
OAA station use noaa_get_meteorological_data (product "wind").RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: noaa_get_water_levels
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_water_level_summaries
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_tide_predictions
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_currents
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_current_predictions
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_meteorological_data
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_search_stations
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_find_nearest_stations
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_station_info
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_station_datums
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_harmonic_constituents
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_prediction_offsets
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_sea_level_trends
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_sea_level_rise_projections
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_extreme_water_levels
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_top_ten_water_levels
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: noaa_get_high_tide_flooding
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nws_get_wind_forecast
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nws_get_marine_forecast
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Get verified summary water-level products from a NOAA station: - high_low: each day's observed highs/lows with ty = HH (higher high), H, L, LL (lower low). Max 1 year per request. - daily_mean: daily
Get NOAA harmonic tide predictions (future or past) for a station. interval="hilo" (recommended for "when is high/low tide") returns the daily tide events with type H/L — up to 10 years per request. O
Get observed current speed and direction from a NOAA current meter station. Current stations use alphanumeric IDs (e.g. "cb0102" Chesapeake, "bh0101" Boston Harbor) — NOT the 7-digit water-level stati
Get predicted tidal currents for a NOAA current prediction station. interval="max_slack" (recommended for navigation) returns the tidal-current events — maximum flood, maximum ebb, and slack water tim
Get observed meteorological/oceanographic sensor data from a NOAA station. Products: air_temperature, water_temperature, wind (speed/gust/direction), air_pressure, air_gap (bridge clearance to water s
Search the NOAA CO-OPS station directory by capability type, name, and/or state. Filter with: - type: what the station does (waterlevels, tidepredictions, currents, currentpredictions, met, ...) — pic
Find the NOAA stations closest to a latitude/longitude point, sorted by distance. Use this to answer "what's the tide station near <place>?" — geocode the place to coordinates first, then call this. F
Get a NOAA station's full metadata record: location, state, time zone, tide type, Great Lakes flag, capability flags, and links to available sub-resources. Optionally expand sub-resources inline via t
Get the accepted tidal datum values for a station: the elevations of MHHW, MHW, MTL, MSL, DTL, MLW, MLLW, STND, NAVD88 (where computed), plus GT (great diurnal range), MN (mean range), LAT/HAT (lowest
Get the harmonic constituents NOAA uses to compute tide or current predictions at a station — the amplitude, phase, and angular speed of each tidal constituent (M2, S2, N2, K1, O1, ...). For water-lev
Get the offsets a subordinate (type "S") prediction station applies to its reference station's predictions. kind "tide": returns refStationId, time offsets for high/low tide (minutes), height offsets
Get the long-term relative sea level trend at a NOAA station: trend and error (reported by NOAA in mm/yr or inches/decade — the payload's trendUnits field says which), the observation period (startDat
Get NOAA's Interagency Sea Level Rise Scenario projections for a station (from the 2022 technical report): projected relative sea level (meters or feet, see units field) per decade through 2150 under
Get NOAA's extreme water level exceedance statistics for a station: the annual exceedance probability levels (e.g. the 1%-annual-chance "100-year" level) and historical extreme events, computed from t
Get a station's highest recorded water levels: analysis "toptenwaterlevels" returns the ten highest events on record (with date, height, causal event name like "Great New England Hurricane", and categ
Get NOAA high tide flooding (HTF, "nuisance"/"sunny day" flooding) statistics for a station. Reports: - daily: flood occurrence per day (REQUIRES start_date and end_date, YYYYMMDD) - monthly / seasona
Get the moon phase for a date (or each day of a date range if end_date is given): phase name (New Moon, Waxing Crescent, ...), illuminated fraction, age in days within the 29.53-day cycle, distance (k
Find the date(s) of the next occurrence(s) of a principal moon phase (New Moon, First Quarter, Full Moon, Last Quarter) from a starting date. Use for: "when is the next full moon?", planning around sp
Get sunrise, sunset, solar noon, dawn/dusk (civil), nautical dawn/dusk, astronomical dawn/dusk, golden hour, and day length for a location and date (or each day of a range if end_date is given). Times
Get the sun's position for a date, time, and location: azimuth (degrees clockwise from north as rendered here), altitude above the horizon (degrees), plus approximate declination and right ascension.
Find the next occurrence(s) of a sun event (sunrise, sunset, dawn, dusk, solarNoon, night, nightEnd, goldenHourStart, goldenHourEnd, nauticalDawn, nauticalDusk, astronomicalDawn, astronomicalDusk) at
Get the NWS hourly wind FORECAST (speed, gust, direction — plus wave height where the grid carries it) for a latitude/longitude. Data comes from the NWS forecast grid (api.weather.gov gridpoints — num
Get the official NWS Coastal Waters Forecast (CWF) narrative for the marine zone covering a latitude/longitude — day-part wind/seas text ("SE winds 10 to 15 kt... Bay waters choppy"), including Small
Get curated reference documentation for NOAA CO-OPS concepts and parameters. Topics: - products: Every NOAA CO-OPS data product and which tool serves it - datums: Vertical datums (MLLW, MSL, IGLD...)
Show how this MCP connection is authenticated: the Perigee account it is linked to (if any), how it signed in (OAuth connector or API key), its rate-limit tier, and the requests-per-minute limit. Use