Programmatic access to PoolParty broadcast media channels for routing demo videos, launch assets, and proof content.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The poolparty MCP server exposes 71 tools, focused primarily on web capabilities. Its published description reads: "Programmatic access to PoolParty broadcast media channels for routing demo videos, launch assets, and proof content". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates poolparty F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check poolparty's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add poolparty to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://www.poolparty.io/api/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
List PoolParty program modes. Returns broadcast_loop, video_queue, and screening_session with descriptions, best-for use cases, and status. Read-only. No auth required.
Get detailed manifest for a program mode. Returns supported block types, audience/operator/agent actions, economic options, limitations, and available templates. Read-only. No auth required.
List PoolParty block types. Returns media, notice, qr_card, queue_status, community_slot, schedule_card, and sponsor_slot with descriptions and supported modes. Read-only. No auth required.
Get detailed schema for a block type. Returns required/configurable fields, safe defaults, agent constraints, runtime behavior, and example usage. Read-only. No auth required.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: list_channel_templates
A tool description tries to alter the model’s use of another tool.
available — use preview_channel_template to see what would be created. Read-only. No autRecommendationDescriptions must describe only their own tool.
tool: claim_test_pol
A tool description tries to alter the model’s use of another tool.
gas. Use before prepare_block_mint, pool_block, or withdraw_pool_support when theRecommendationDescriptions must describe only their own tool.
tool: prepare_block_mint
A tool description tries to alter the model’s use of another tool.
quirements, and finalize_block_mint as the next action. Public wallet action. No MCRecommendationDescriptions must describe only their own tool.
tool: get_block_mint_status
A tool description tries to alter the model’s use of another tool.
actions such as prepare_block_mint or finalize_block_mint. Public read. No auth reRecommendationDescriptions must describe only their own tool.
tool: pool_block
A tool description tries to alter the model’s use of another tool.
n and then call finalize_pool_support with the tx hash before treating support as actRecommendationDescriptions must describe only their own tool.
tool: withdraw_pool_support
A tool description tries to alter the model’s use of another tool.
visible through get_wallet_pooling_state and get_pooling_receipt. Public wallet action.RecommendationDescriptions must describe only their own tool.
tool: get_channel_stream
A tool description tries to alter the model’s use of another tool.
his before rich get_channel_feed. Read-only. No auth required.RecommendationDescriptions must describe only their own tool.
tool: get_channel_feed
A tool description tries to alter the model’s use of another tool.
awareness, use get_channel_stream(channelSlug="main", limit=10) or the REST /api/RecommendationDescriptions must describe only their own tool.
tool: request_pilot_key
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "notes"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: complete_sim_pool_back
A tool description tries to alter the model’s use of another tool.
discovered via get_channel_stream/get_channel_feed. Public auto-provisioned submiRecommendationDescriptions must describe only their own tool.
tool: create_join_session
A tool description tries to alter the model’s use of another tool.
en for use with submit_media_block. Requires API key with submit:block scope. SessRecommendationDescriptions must describe only their own tool.
tool: attach_wallet_to_session
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ation. Requires API key with submit:block scope. Use the sessionToken fRecommendationRemove side-channel parameters; constrain tool inputs.
tool: attach_wallet_to_session
A tool description tries to alter the model’s use of another tool.
ntity for later prepare_block_mint; it does not sign, approve, mint, stake, claimRecommendationDescriptions must describe only their own tool.
tool: request_media_upload_url
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
pload. Requires API key with submit:block scope and a session token froRecommendationRemove side-channel parameters; constrain tool inputs.
tool: request_media_upload_url
A tool description tries to alter the model’s use of another tool.
sion token from create_join_session. Defaults to Livepeer canonical ingest; provideRecommendationDescriptions must describe only their own tool.
tool: complete_media_upload
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
pload. Requires API key with submit:block scope and a session token froRecommendationRemove side-channel parameters; constrain tool inputs.
tool: complete_media_upload
A tool description tries to alter the model’s use of another tool.
sion token from create_join_session. Livepeer returns a canonical handoff only afteRecommendationDescriptions must describe only their own tool.
tool: submit_media_block
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
queue. Requires API key with submit:block scope. Requires a session tokRecommendationRemove side-channel parameters; constrain tool inputs.
tool: submit_media_block
A tool description tries to alter the model’s use of another tool.
tusReadback for get_distribution_report polling. Scalar-only submit remains supported bRecommendationDescriptions must describe only their own tool.
tool: quote_superblock_reservation
A tool description tries to alter the model’s use of another tool.
quote only; use prepare_superblock_purchase to create the payment-required reservation.RecommendationDescriptions must describe only their own tool.
tool: quote_sponsor_reservation
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ction. Requires API key with purchase:prepare scope. Returns an x402-coRecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_channel_from_template
A tool description tries to alter the model’s use of another tool.
romotes it. Use list_channel_templates and preview_channel_template first to choose aRecommendationDescriptions must describe only their own tool.
tool: configure_open_call
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
sions. Requires API key with configure:channel scope. Channel must haveRecommendationRemove side-channel parameters; constrain tool inputs.
tool: inspect_programming_discovery_inventory
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
o Program Queue history."},"excludeSmokeFixtures":{"type":"boolean","deRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
n with the same sessionToken or agentSessionId before prepare_block_mint wheRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
shed video, use draft_slide_block_from_project, preview_slide_block, and revise_slide_block toRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: draft_slide_block_from_project
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "draft_slide_block_from_project"RecommendationScope tools to the minimum needed.
tool: preview_slide_block
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "preview_slide_block"RecommendationScope tools to the minimum needed.
tool: revise_slide_block
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "revise_slide_block"RecommendationScope tools to the minimum needed.
tool: preview_channel_template
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "preview_channel_template"RecommendationScope tools to the minimum needed.
tool: claim_test_pol
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "claim_test_pol"RecommendationScope tools to the minimum needed.
tool: finalize_block_mint
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "finalize_block_mint"RecommendationScope tools to the minimum needed.
tool: pool_block
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "pool_block"RecommendationScope tools to the minimum needed.
tool: finalize_pool_support
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "finalize_pool_support"RecommendationScope tools to the minimum needed.
tool: withdraw_pool_support
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "withdraw_pool_support"RecommendationScope tools to the minimum needed.
tool: list_programming_scope_profiles
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "list_programming_scope_profiles"RecommendationScope tools to the minimum needed.
tool: request_pilot_key
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "request_pilot_key"RecommendationScope tools to the minimum needed.
tool: get_key_info
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "get_key_info"RecommendationScope tools to the minimum needed.
tool: create_join_session
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_join_session"RecommendationScope tools to the minimum needed.
tool: request_media_upload_url
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "request_media_upload_url"RecommendationScope tools to the minimum needed.
tool: complete_media_upload
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "complete_media_upload"RecommendationScope tools to the minimum needed.
tool: submit_media_block
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "submit_media_block"RecommendationScope tools to the minimum needed.
tool: quote_superblock_reservation
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "quote_superblock_reservation"RecommendationScope tools to the minimum needed.
tool: quote_sponsor_reservation
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "quote_sponsor_reservation"RecommendationScope tools to the minimum needed.
tool: create_channel_from_template
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_channel_from_template"RecommendationScope tools to the minimum needed.
tool: update_channel_settings
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_channel_settings"RecommendationScope tools to the minimum needed.
tool: configure_open_call
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "configure_open_call"RecommendationScope tools to the minimum needed.
tool: admit_programming_candidates
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "admit_programming_candidates"RecommendationScope tools to the minimum needed.
tool: create_program_item
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_program_item"RecommendationScope tools to the minimum needed.
tool: draft_program_queue
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "draft_program_queue"RecommendationScope tools to the minimum needed.
tool: set_programming_bucket
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "set_programming_bucket"RecommendationScope tools to the minimum needed.
tool: reorder_program_queue
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "reorder_program_queue"RecommendationScope tools to the minimum needed.
tool: insert_live_next
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "insert_live_next"RecommendationScope tools to the minimum needed.
tool: remove_live_queue_item
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "remove_live_queue_item"RecommendationScope tools to the minimum needed.
tool: accept_programming_proposal
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "accept_programming_proposal"RecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Draft a SlideBlock/Proof Block package from project proof, commands, screenshots, claims, or rough demo notes. Returns a shareable previewUrl for human review. Draft-only: operator review is required,
Validate and summarize a SlideBlock package before operator review. Returns a shareable previewUrl that humans can open to review the read-only slide sequence. Preview-only: normal moderation will be
Revise an existing SlideBlock draft after human/agent feedback and return a new stable preview payload plus revised previewUrl and parentPreviewId lineage. Revision-only: operator review and normal mo
List available channel creation templates. Returns template names, program modes, use cases, and status. Channel creation is not yet available — use preview_channel_template to see what would be creat
Preview what a channel template would create. Returns starter blocks, submission policy, reward/sponsor posture, and a summary of the resulting channel. Channel creation is not yet available — this is
Resolve a human channel name or alias to the canonical PoolParty channel slug. PP0, Main Stage, and main resolve to "main"; PP1 resolves to "pp1". Read-only. No auth required.
List available Superblock offerings with prices, durations, and current inventory. Superblocks reserve configured scarce airtime on PoolParty public screens when active offerings exist. They do not gu
Read the PP0 Main Stage collateralized block opportunity. Returns enablement, mode, Amoy testnet token facts, faucet availability, pool and wallet-state action names, withdrawal policy, eligibility, r
Send or record bounded PP0 test POL for Polygon Amoy gas. Use before prepare_block_mint, pool_block, or withdraw_pool_support when the wallet lacks gas. Default amoy-transfer mode sends native testnet
Prepare or record a PP0 test collateral faucet claim for a wallet. Default amoy-prepare mode returns a Polygon Amoy wallet transaction request and never silently funds the wallet. local-dev and mock m
Prepare canonical PP0 block NFT minting for a playable user/agent media block. Returns explicit Polygon Amoy wallet approval facts, Treasury USDC approval request, mint transaction request, txIntentId
Finalize canonical PP0 block NFT minting after the wallet broadcasts mintBlock. Verifies the Amoy receipt, parses BlockMinted, writes on_chain_block_id, mint tx hash, collateral totals, tx_intents, bl
Read canonical mint status for a PP0 media block. Reports not_started, prepared, pending, confirmed, or failed; includes on-chain id, tx intent status, poolEligibility, and next actions such as prepar
Use PP0 test collateral to support an eligible active user BLOCK and return before and after rank and score consequence. Creates a STAKE_ADD transaction intent or explicit local/mock rehearsal state.
Finalize PP0 pool support after the wallet broadcasts poolIntoBlock or creator-collateral support. Verifies the Polygon Amoy receipt, checks sender/block/amount/contract, writes canonical PoolParty su
Remove active PP0 pooler support from an eligible block before lock and return before and after rank and score consequence. Creates a STAKE_WITHDRAW transaction intent or explicit local/mock rehearsal
Read a wallet PP0 pooling state. Returns active, locked, withdrawn, settled, voided, and error STAKE_ADD/STAKE_WITHDRAW positions, amounts, withdrawable policy, block context, rank context, test colla
Read a derived PP0 pooling receipt for a pool position. Returns wallet, block, amount, lifecycle state, rank/score impact where known, airing/resolution evidence, collateral returned/unlocked state, r
Read PP0 block economics after pooling or airing. Returns current/final collateral support totals, pooled-position lifecycle counts, airing/resolution evidence, settlement path, reward-policy evidence
Read safe SIM signer availability for a local/dev PP0 economic rehearsal. Returns redacted wallet evidence, signer-ready aliases, chain id, stop reasons, and next economic read/actions without exposin
Get a distribution report for a submitted media block or superblock reservation. Shows entry status, block state, queue position, reservation lifecycle, proof-of-play status, and Queue Block receipt a
Get Channel Pulse v2 metrics for a PoolParty channel. Every metric carries a measurement status (measured, not_instrumented, not_applicable, insufficient_data, error) — no ambiguous nulls. Returns fre
Evaluate whether a PoolParty channel is a good airtime opportunity right now. Returns an opportunity score (0-1), recommendation (submit/watch/wait/avoid), queue competition level, reward availability
Get a high-level summary of PoolParty platform activity. Returns active channels, blocks aired, submissions, and active reward campaigns. Read-only. No auth required.
Browse PoolParty channels with filters. Returns channel listings with visibility, program type, queue depth, submissions, unique submitters, reward summaries, and sponsor availability. Each result inc
Compact first-read current channel state for a PoolParty channel. Returns channel/session/intake status, now playing, queue summary, next few queue items, recent airing summary, reward campaign summar
Get rich recent airings and current queue evidence for a PoolParty channel. Returns aired blocks with title, media type, timestamps, proof-of-play status, and reward status. Also returns current queue
Find channels accepting community submissions. Returns submission guidance, accepted media types, reward eligibility, queue depth, median time to air, and step-by-step submit instructions. Use this to
Find channels with active reward pools. Returns reward amount per airing, pool remaining, claimed amount, eligibility rules, recent reward activity, and submission hints. Use this to find where submis
Find available sponsor and Superblock airtime inventory. Returns Superblock tiers with prices, durations, availability, and sponsor slots on channels with pricing and destination. Use this to find con
List conservative channel programming scope profiles before requesting a pilot key. Public read. Profiles separate proposal, Program Queue write, publish, and live queue authority; none are auto-provi
Request pilot access to PoolParty MCP protected tools. No auth required. Requires a self_attestation questionnaire (declared attribution). Two paths: safe public discovery_submission requests can auto
Check the status of a pilot key request. Returns pending, approved, or rejected with next steps. Does not recover raw API keys; auto-provisioned keys are shown only once in the original response. Publ
Inspect the current MCP Bearer token without exposing the raw key. Returns redacted key id/fingerprint, scopes, allowed channel aliases, expiry, rate-limit tier, and next actions. Protected read. Requ
Complete one tightly gated local/dev PP0 economic pool/back proof with a configured SIM signer alias. Requires Authorization: Bearer <pilot_key> with economic:proof scope, PP0_SIM_ECONOMIC_ACTION_ENAB
Create an anonymous participation session for a PoolParty channel. Returns a sessionToken for use with submit_media_block. Requires API key with submit:block scope. Session allows up to 3 anonymous su
Attach an EVM wallet address to the same PoolParty submission session used for MCP-native submit automation. Requires API key with submit:block scope. Use the sessionToken from create_join_session or
Request a short-lived upload target for agent-native video upload. Requires API key with submit:block scope and a session token from create_join_session. Defaults to Livepeer canonical ingest; provide
Complete or check canonical media readiness after an upload. Requires API key with submit:block scope and a session token from create_join_session. Livepeer returns a canonical handoff only after play
Submit a media block to a PoolParty channel community queue. Requires API key with submit:block scope. Requires a session token from create_join_session. Optional canonicalMediaHandoff from complete_m
Prepare a SuperBlock purchase reservation. Requires API key with purchase:prepare scope. Flags off: returns the legacy non-executing purchaseIntent with contract address, USDC amount, chain ID, and pu
Quote a SuperBlock paid action without holding inventory. Requires API key with purchase:prepare scope. Returns an x402-compatible payment negotiation envelope and direct-router-transaction settlement
Quote or reserve a sponsor/lobby card paid action. Requires API key with purchase:prepare scope. Returns an x402-compatible payment negotiation envelope, HTTP 402-style payment requirements when reser
Settle a paid-action reservation after the bound wallet or agent has submitted the required direct PoolParty router transaction. Requires API key with purchase:prepare scope. SuperBlocks require Super
Get the stable agent-readable PoolParty receipt for a paid action intent. Requires API key with purchase:prepare scope. Receipts expose intent state, direct router transaction settlement, canonical re
Create a new PoolParty channel from an approved starter blueprint. Requires API key with create:channel scope. Creates channel + program + starter blocks in ACTIVE_UNLISTED state. Channel is not publi
Update a channel's name, description, purpose, tags, or operator display name. Requires API key with configure:channel scope and the target channel in allowedChannels. Does not allow status/visibility
Configure the open-call / submission guidance for a channel with a community slot. Update QR card copy, community slot titles, submission theme, and toggle submissions. Requires API key with configure
Inspect the PP2/Lazy River programming candidate inventory with source metadata, renderability, previews, and Program Queue links. Requires read:program_queue scope.
Preview one PP2/Lazy River programming candidate before promoting it to the Program Queue. Requires read:program_queue scope.
Run a read-only PP2 discovery inventory audit across source queries. Reports upstream counts, exclusions, cursor availability, freshness, media mix, query provenance, preview confidence, admission-rea
Admit selected PP2 discovery results into candidate inventory only. Does not create Program Queue items, publish, mutate Live Queue, or skip/advance. Requires write:programming_candidates scope.
Inspect the editable Program Queue for a channel. Requires read:program_queue scope.
Inspect persistent PP2 programming buckets grouped from Program Queue bucket labels, including unbucketed items. Requires read:program_queue scope.
Inspect the current live queue projection for a channel. Requires read:program_queue scope.
Inspect source, approval, audit, and MCP-scope policy for channel programming. Requires read:program_queue scope.
Promote a source candidate into the editable Program Queue. Requires write:program_queue scope and records an audit event.
Save an ordered PP2 Program Queue draft from source candidate ids. Creates or reuses candidate-backed Program Queue items, applies the requested order, and optionally replaces/prunes stale draft items
Set or clear the persistent editorial bucket label for an existing Program Queue item. Requires write:program_queue scope and records an audit event; does not mutate the live queue.
Reorder one or more Program Queue items. Requires write:program_queue scope and records old/new order audit.
Dry-run a PP2 Program Queue publish before mutating the live queue. Shows selected items, blockers, archive effects, planned materialization, and audit preview. Requires read:program_queue scope.
Publish Program Queue order to the live runtime queue. Requires publish:program_queue scope and records an audit event.
Insert a Program Queue item at the front of the live queue. Requires write:live_queue scope and records an audit event.
Remove an item from the live queue. Requires write:live_queue scope and records an audit event.
Report skip capability for the current live item. Requires skip:live_queue scope. This runtime does not yet expose a safe shared skip primitive.
Suggest a Program Queue order without mutating anything. Requires propose:programming scope.
Apply a prior non-mutating programming proposal by reordering the Program Queue. Requires write:program_queue scope.