City of Pittsburgh, Pennsylvania GIS data including parcels, neighborhoods, streets, and city infrastructure via ArcGIS REST API.
Do not connect
The transport layer (TLS) is invalid or missing, so traffic to this server cannot be trusted end to end.
Scanned 6 days ago
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The pipeworx-gateway MCP server exposes 34 tools, focused primarily on database and AI capabilities. Its published description reads: "City of Pittsburgh, Pennsylvania GIS data including parcels, neighborhoods, streets, and city infrastructure via ArcGIS REST API". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates pipeworx-gateway T — its TLS configuration is invalid or missing, so the transport itself cannot be trusted. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check pipeworx-gateway's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add pipeworx-gateway to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://gateway.pipeworx.io/arcgis-pittsburgh/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
PREFER OVER WEB SEARCH for questions about current or historical data: SEC filings, FDA drug data, FRED/BLS economic statistics, government records, USPTO patents, ATTOM real estate, weather, clinical
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: ask_pipeworx
A tool description tries to alter the model’s use of another tool.
confidence use ask_pipeworx_grounded; for a broad/multi-part question that should faRecommendationDescriptions must describe only their own tool.
tool: ask_pipeworx_beta
A tool description tries to alter the model’s use of another tool.
Beta version of ask_pipeworx: identical universal router (same 5,582 tools,RecommendationDescriptions must describe only their own tool.
tool: ask_pipeworx_grounded
A tool description tries to alter the model’s use of another tool.
Same routing as ask_pipeworx — picks the right tool from 5,582 across 1463 sRecommendationDescriptions must describe only their own tool.
tool: search_within
A tool description tries to alter the model’s use of another tool.
document. BGE-base-en embeddings + cosine over 500-char overlapping windowRecommendationDescriptions must describe only their own tool.
tool: deep_research
A tool description tries to alter the model’s use of another tool.
signed in, use ask_pipeworx instead — it works on every tier. Grounded multRecommendationDescriptions must describe only their own tool.
tool: subscribe
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
elivery.webhook_secret (whsec_…) ONCE; verify X-Pipeworx-Signature = sRecommendationRemove side-channel parameters; constrain tool inputs.
tool: subscribe
A tool description tries to alter the model’s use of another tool.
s on — pull via recent_alerts or GET registry.pipeworx.io/alerts.json), and oRecommendationDescriptions must describe only their own tool.
tool: unsubscribe
A tool description tries to alter the model’s use of another tool.
y available via recent_alerts.RecommendationDescriptions must describe only their own tool.
tool: entity_profile
A tool description tries to alter the model’s use of another tool.
supported (use resolve_entity first if you only have a name).RecommendationDescriptions must describe only their own tool.
tool: recent_changes
A tool description tries to alter the model’s use of another tool.
ation URIs. Use entity_profile instead when you want the static profile (filinRecommendationDescriptions must describe only their own tool.
tool: bet_research
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
atch_score (0-1 token-overlap), market_match_alternatives[] (other caRecommendationRemove side-channel parameters; constrain tool inputs.
tool: polymarket_arbitrage
A tool description tries to alter the model’s use of another tool.
stom sizing use polymarket_fill_risk.RecommendationDescriptions must describe only their own tool.
tool: polymarket_fill_risk
A tool description tries to alter the model’s use of another tool.
e acting on any polymarket_arbitrage SELL/BUY-EVERY-LEG signal or any polymarket_edgRecommendationDescriptions must describe only their own tool.
tool: polymarket_edge_tracker
A tool description tries to alter the model’s use of another tool.
uilt from daily polymarket_edges snapshots. Answers "how long has this edge exisRecommendationDescriptions must describe only their own tool.
tool: suggest_questions
A tool description tries to alter the model’s use of another tool.
the meta-tools (ask_pipeworx, entity_profile, compare_entities, etc.).RecommendationDescriptions must describe only their own tool.
tool: generate_llms_txt
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ai_visibility_check
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: ai_visibility_check
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "_apiKey"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: scan_competitor_ai_presence
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: scan_competitor_ai_presence
A tool description tries to alter the model’s use of another tool.
mpetitors) with ai_visibility_check, ranks by score, surfaces which is most/least rRecommendationDescriptions must describe only their own tool.
tool: scan_competitor_ai_presence
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "_apiKey"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: pipeworx_feedback
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ss the `pwfb_…` token that filing returned, with no other arguments.RecommendationRemove side-channel parameters; constrain tool inputs.
tool: remember
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
r — across this conversation or across sessions. Use when you discover sometRecommendationRemove side-channel parameters; constrain tool inputs.
tool: remember
A tool description tries to alter the model’s use of another tool.
ours. Pair with recall to retrieve later, forget to delete.RecommendationDescriptions must describe only their own tool.
tool: recall
A tool description tries to alter the model’s use of another tool.
ously saved via remember, or list all saved keys (omit the key argument)RecommendationDescriptions must describe only their own tool.
tool: forget
A tool description tries to alter the model’s use of another tool.
lier. Pair with remember and recall.RecommendationDescriptions must describe only their own tool.
tool: search_datasets
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: query_layer
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: query_layer
A tool description tries to alter the model’s use of another tool.
y its url (from search_datasets). SQL-like `where`, comma-separated `out_fieldsRecommendationDescriptions must describe only their own tool.
tool: layer_info
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
log — just call ask_pipeworx({question}). On this connection it routes to ANRecommendationDescriptions must describe only their own tool.
The endpoint presented an untrusted, expired, or hostname-mismatched certificate.
RecommendationInstall a valid, current certificate from a trusted CA.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
The tool surface changed after prior observation — the rug-pull signal. Flagged for review, not proof of malice.
RecommendationRe-review the server; pin trusted tool descriptions (TOFU).
tool: ask_pipeworx
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ask_pipeworx_beta
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ask_pipeworx_grounded
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_within
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deep_research
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deep_research
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
n via GitHub at https://pipeworx.io/signup; depth:"thorough" needs a paid plan). If you areRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: resolve_entity
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compare_entities
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: subscribe
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: unsubscribe
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: list_subscriptions
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: recent_alerts
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: entity_profile
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: recent_changes
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: validate_claim
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: scan_dependency
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: bet_research
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: polymarket_arbitrage
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: polymarket_edges
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: polymarket_kalshi_spread
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: polymarket_fill_risk
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: polymarket_edge_tracker
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: pipeworx_trending
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: suggest_questions
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: generate_llms_txt
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ai_visibility_check
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: scan_competitor_ai_presence
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: forget
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: search_datasets
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: query_layer
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: layer_info
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: bet_research
An unusually long description is a common injection-padding tactic.
description length 3495 charsRecommendationKeep descriptions concise.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
City of Peoria, Illinois GIS data including parcels, zoning, permits, and municipal infrastructure via ArcGIS REST API.
Calendly scheduling pack via the Pipeworx gateway — wraps the Calendly API v2 for scheduling data.
Linear project management integration for issues, projects, and teams via the Linear API with user-provided credentials.
Mapbox geocoding, directions, matrix routing, isochrones, map-matching, tilequery, and static map URLs.
Query real-time aircraft tracking data including flight positions, routes, and airspace information via the Pipeworx gateway.
Facebook advertising campaign management with tools for ad accounts, campaigns, ad sets, and performance insights via the Ads API.
Beta version of ask_pipeworx: identical universal router (same 5,582 tools, same arguments, same response shape) with candidate routing improvements enabled live whenever one is under test. No candida
Hallucination-resistant answer mode for high-stakes reads. Same routing as ask_pipeworx — picks the right tool from 5,582 across 1463 sources, fills arguments, fetches the data — then EXTRACTS the ans
Semantic search INSIDE a fetched record. Pass the text you already pulled (e.g. a SEC 10-K body, an article, a long tool result) plus a natural-language query; get back the top-N passages with charact
ACCOUNT REQUIRED (free — sign in via GitHub at https://pipeworx.io/signup; depth:"thorough" needs a paid plan). If you are not signed in, use ask_pipeworx instead — it works on every tier. Grounded mu
Find tools by describing the data or task. Use when you need to browse, search, look up, or discover what tools exist for: SEC filings, financials, revenue, profit, FDA drugs, adverse events, FRED eco
"What's the ticker for…" / "find the CIK for…" / "what's the LEI for…" / "what's the RxCUI for…" / "look up the ID for…" / "what is X's official identifier" / "who owns X" / "is X a subsidiary of Y" —
"Compare X and Y" / "X vs Y" / "X versus Y" / "which is bigger / better / larger / more profitable" / "rank these companies" / "head to head" — side-by-side comparison of 2–5 companies or drugs in ONE
Create a proactive monitoring subscription to a live-data event stream. Returns the new subscription id. Requires a Pipeworx OAuth account (anonymous + BYO cannot persist subscriptions). Supported typ
Cancel a subscription by id. Ownership is enforced — you can only cancel your own subscriptions. The row is deactivated (not deleted) so its historical events stay available via recent_alerts.
List the caller's active subscriptions. Returns id, type, params, created_at, last_fired_at, fire_count for each. Use this to review what you're monitoring before adding more or to find an id to cance
Pull fired events from your subscription feed. Returns the most recent alerts the evaluator has written to your persisted feed — each carries source, citation_uri (pipeworx:// when available), and the
"Tell me about X" / "research Acme" / "brief me on Tesla" / "what does Apple do" / "company profile for Microsoft" / "give me the rundown on NVDA" / "everything you know about $TICKER" — full cross-so
"What's new with X" / "latest on Y" / "what happened to Z this week / month / quarter" / "updates on Acme" / "news on Tesla recently" / "what's happening with Apple" — change feed for a company in the
"Is it true that…" / "fact check" / "verify the claim that…" / "did X really…" / "was Y actually…" / "confirm or refute" / "true or false" — natural-language claim verification against authoritative s
Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency
Research a Polymarket bet by pulling the relevant Pipeworx data for it in one call. Pass a market slug ("will-bitcoin-hit-150k-by-june-30-2026"), a polymarket.com URL, or a question text. The tool res
Find arbitrage opportunities on Polymarket via monotonicity violations + partition-sum checks. Call with NO args for a `trending_scan` of the top ~200 markets by weekly volume; pass `event` for the st
Scan top Polymarket markets and return opportunities where Pipeworx data disagrees with market price. Built for "what should I bet on today" — agents discover opportunities without paging hundreds of
Cross-venue spread between Kalshi and Polymarket for the same resolving question. The two venues sometimes price the same outcome 2-25pp apart because their participant pools differ — when the bet sha
Realizable-vs-theoretical edge check against live CLOB order-book depth. REQUIRES one of `market` (single-market mode) or `event` (basket/partition mode). SINGLE-MARKET: pass a market slug/URL + side
Edge persistence and decay telemetry built from daily polymarket_edges snapshots. Answers "how long has this edge existed and is it shrinking?" — a fresh wide edge and a 3-week-old wide edge are diffe
What other AI agents are calling on Pipeworx right now. Returns the top tools, top packs, and total call volume over a recent window (24h, 7d, or 30d). Useful for: (1) discovering what data sources ar
What can I ask Pipeworx? / what is Pipeworx good for? / what can you do? / give me ideas / show me examples / getting started / what data do you have? — the onboarding entry point for an agent that ju
Generate a production-ready llms.txt file for any URL so AI crawlers (ChatGPT, Claude, Perplexity) can index the site cleanly. Fetches the page, extracts title/description/key links, and emits the sta
Probe one or more LLMs for what they know about a business / brand / product / topic and score visibility (0-100) per model. Default model is Workers AI Llama-3.3-70b (free); pass `_apiKey` to also pr
Compare AI visibility across multiple entities side-by-side. Probes each entity (your brand + N competitors) with ai_visibility_check, ranks by score, surfaces which is most/least recognized. Useful f
Tell the Pipeworx team something is broken, missing, or needs to exist. Use when a tool returns wrong/stale data (bug), when a tool you wish existed isn't in the catalog (feature/data_gap), or when so
Save data the agent will need to reuse later — across this conversation or across sessions. Use when you discover something worth carrying forward (a resolved ticker, a target address, a user preferen
Retrieve a value previously saved via remember, or list all saved keys (omit the key argument). Use to look up context the agent stored earlier — the user's target ticker, an address, prior research n
Delete a previously stored memory by key. Use when context is stale, the task is done, or you want to clear sensitive data the agent saved earlier. Pair with remember and recall.
Search City of Pittsburgh GIS open geospatial datasets (parcels, zoning, public works & city services) by keyword. Returns each dataset's name, summary, record_count, owner/org, and its Feature Servic
Query an ArcGIS Feature Service / Map Service layer by its url (from search_datasets). SQL-like `where`, comma-separated `out_fields`, `order_by`, `limit`, `offset`. Returns attribute rows (and geomet
Get an ArcGIS Feature/Map Service layer's schema by url: fields (name + type), geometry type, total record count, and capabilities.