Deploy production REST APIs from JSON schemas in seconds, managing projects, schemas, and deployments.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The rationalbloks-backend MCP server exposes 45 tools, focused primarily on database and developer capabilities. Its published description reads: "Deploy production REST APIs from JSON schemas in seconds, managing projects, schemas, and deployments". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates rationalbloks-backend F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check rationalbloks-backend's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add rationalbloks-backend to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.rationalbloks.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
List all your RationalBloks projects with their status and URLs
Get detailed information about a specific project
Get the JSON schema definition of a project in FLAT format. Returns the schema structure where each table name maps directly to field definitions. This is the same format required for create_project a
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_schema
A tool description tries to alter the model’s use of another tool.
at required for create_project and update_schema. USE CASES: Review current scRecommendationDescriptions must describe only their own tool.
tool: list_clusters
A tool description tries to alter the model’s use of another tool.
ou MUST pass as create_project's cluster_id to deploy a project onto your ownRecommendationDescriptions must describe only their own tool.
tool: get_job_status
A tool description tries to alter the model’s use of another tool.
minutes, check get_project_info for detailed pod status. If status is 'failed',RecommendationDescriptions must describe only their own tool.
tool: get_project_info
A tool description tries to alter the model’s use of another tool.
roperties). Use get_schema to review current schema. If replicas show 0/2,RecommendationDescriptions must describe only their own tool.
tool: get_version_history
A tool description tries to alter the model’s use of another tool.
commit SHA for rollback_project.RecommendationDescriptions must describe only their own tool.
tool: get_template_schemas
A tool description tries to alter the model’s use of another tool.
s directly with create_project or modify them for your needs. TIP: Study theseRecommendationDescriptions must describe only their own tool.
tool: create_project
A tool description tries to alter the model’s use of another tool.
4. Monitor with get_job_status (2-5 min deployment) After creation, use get_jRecommendationDescriptions must describe only their own tool.
tool: update_schema
A tool description tries to alter the model’s use of another tool.
ORKFLOW: 1. Use get_schema to see current schema 2. Modify following ALL rRecommendationDescriptions must describe only their own tool.
tool: deploy_staging
A tool description tries to alter the model’s use of another tool.
h a job_id. Use get_job_status with the job_id to monitor progress. DeploymentRecommendationDescriptions must describe only their own tool.
tool: rollback_project
A tool description tries to alter the model’s use of another tool.
r rollback, use get_job_status to monitor the redeployment. Rollback is usefulRecommendationDescriptions must describe only their own tool.
tool: get_graph_template_schemas
A tool description tries to alter the model’s use of another tool.
s directly with create_graph_project or modify them for your needs. TIP: Study theseRecommendationDescriptions must describe only their own tool.
tool: get_graph_schema_at_version
A tool description tries to alter the model’s use of another tool.
ion/commit. Use get_graph_version_history to find commit SHAs. Useful for comparing schemRecommendationDescriptions must describe only their own tool.
tool: create_graph_project
A tool description tries to alter the model’s use of another tool.
4. Monitor with get_job_status (2-5 min deployment) After creation, use get_jRecommendationDescriptions must describe only their own tool.
tool: update_graph_schema
A tool description tries to alter the model’s use of another tool.
5. Monitor with get_job_status NOTE: This only saves the schema. You MUST calRecommendationDescriptions must describe only their own tool.
tool: deploy_graph_staging
A tool description tries to alter the model’s use of another tool.
h a job_id. Use get_job_status to monitor progress. Deployment typically takesRecommendationDescriptions must describe only their own tool.
tool: rollback_graph_project
A tool description tries to alter the model’s use of another tool.
olled back. Use get_graph_version_history to find the commit SHA of the version you wantRecommendationDescriptions must describe only their own tool.
tool: create_graph_node
A tool description tries to alter the model’s use of another tool.
e deployed (use deploy_graph_staging first). The entity_type must match an entity kRecommendationDescriptions must describe only their own tool.
tool: create_graph_node
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
QUIRES: Project must be deployed (use deploy_graph_staging first). The entity_type must match an entity key froRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: create_graph_relationship
A tool description tries to alter the model’s use of another tool.
ect schema. Use get_graph_data_schema to see available relationship types. Example:RecommendationDescriptions must describe only their own tool.
tool: delete_graph_relationship
A tool description tries to alter the model’s use of another tool.
nternal ID. Use get_node_relationships to find relationship IDs.RecommendationDescriptions must describe only their own tool.
tool: fulltext_search_graph
A tool description tries to alter the model’s use of another tool.
ueries. Unlike search_graph_nodes (which filters by specific property), this searRecommendationDescriptions must describe only their own tool.
tool: get_graph_data_schema
A tool description tries to alter the model’s use of another tool.
ntity keys (for create_graph_node, list_graph_nodes, etc.) and relationship keysRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
create_project, get_schema, deploy_staging, etc. (19 tools) 2. GRAPH (NeoRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: create_project
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: update_schema
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deploy_staging
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deploy_production
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_project
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: rollback_project
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: create_graph_project
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: update_graph_schema
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deploy_graph_staging
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: deploy_graph_production
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_graph_project
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: rollback_graph_project
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: create_graph_node
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: update_graph_node
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_graph_node
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: create_graph_relationship
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_graph_relationship
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: bulk_create_graph_nodes
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: bulk_create_graph_relationships
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: create_project
An unusually long description is a common injection-padding tactic.
description length 2426 charsRecommendationKeep descriptions concise.
tool: create_graph_project
An unusually long description is a common injection-padding tactic.
description length 2450 charsRecommendationKeep descriptions concise.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Get information about the authenticated user
List your registered BYOC resource pools (client-owned Kubernetes clusters). Each returned cluster has an 'id' you MUST pass as create_project's cluster_id to deploy a project onto your own infrastruc
Check the status of a deployment job. STATUS VALUES: pending (job queued), running (deployment in progress), completed (success), failed (deployment failed). TIMELINE: Typical deployment takes 2-5 min
Get detailed project info including deployment status and resource usage. DEPLOYMENT STATUS: Running (healthy), Pending (starting), CrashLoopBackOff (init container failed - usually schema format erro
Get the deployment and version history (git commits) for a project. Shows all schema changes with commit SHA, timestamp, and message. USE CASES: Review what changed between deployments, find the last
Get pre-built template schemas for common use cases. ⭐ USE THIS FIRST when creating a new project! Templates show the CORRECT schema format with: proper FLAT structure (no 'fields' nesting), every fie
Get your subscription tier, limits, and usage
Get resource usage metrics (CPU, memory) for a project
Get the schema as it was at a specific version/commit
Create a new RationalBloks project from a JSON schema. ⚠️ CRITICAL RULES - READ BEFORE CREATING SCHEMA: 1. FLAT FORMAT (REQUIRED): ✅ CORRECT: {users: {email: {type: "string", max_length: 255}}} ❌ WRON
Update a project's schema (saves to database, does NOT deploy). ⚠️ CRITICAL: Follow ALL rules from create_project: • FLAT format (no 'fields' nesting) • string: MUST have max_length • decimal: MUST ha
Deploy a project to the staging environment. This triggers: (1) Schema validation, (2) Docker image build, (3) GitHub commit, (4) Kubernetes deployment, (5) Database migrations. The operation is ASYNC
Promote staging to production (requires paid plan)
Delete a project (removes GitHub repo, K8s deployments, and database)
Rollback a project to a previous version. ⚠️ WARNING: This reverts schema AND code to the specified commit. Database data is NOT rolled back. Use get_version_history to find the commit SHA of the vers
Rename a project (changes display name, not project_code)
Get the graph schema definition of a project. Returns the hierarchical schema with nodes (entities) and relationships. Graph schemas define entity hierarchies and typed relationships — a different for
Get pre-built graph template schemas for common use cases. ⭐ USE THIS FIRST when creating a new graph project! Templates show the CORRECT graph schema format with: proper node definitions (description
Get the deployment and version history for a graph project. Shows all schema changes with commit SHAs, timestamps, version numbers, and messages. Use this to find a specific version for rollback opera
Get the graph schema as it existed at a specific version/commit. Use get_graph_version_history to find commit SHAs. Useful for comparing schemas across versions or auditing changes.
Get detailed graph project information including Kubernetes deployment status, Neo4j database health, pod status, and resource usage. Use this after deployment to verify the graph project is running c
Create a new Neo4j graph database project from a hierarchical JSON schema. ⚠️ GRAPH SCHEMA FORMAT — READ BEFORE CREATING: Graph schemas define nodes (entities) and relationships, NOT flat database tab
Update a graph project's schema (saves to database, does NOT deploy). ⚠️ Follow ALL rules from create_graph_project: • Must have "nodes" key with at least one entity • Each entity needs "description"
Deploy a graph project to the staging environment. This triggers: (1) Schema validation, (2) Neo4j entity code generation, (3) Docker image build, (4) GitHub commit, (5) Kubernetes deployment with Neo
Promote graph staging to production. Creates a separate production Neo4j instance with its own credentials and database. Requires paid plan.
Delete a graph project (removes GitHub repo, K8s deployments, Neo4j database, and credentials)
Rollback a graph project to a previous version. ⚠️ WARNING: This reverts schema AND code to the specified commit. Neo4j data is NOT rolled back. Use get_graph_version_history to find the commit SHA of
Create a single node in a deployed graph project. REQUIRES: Project must be deployed (use deploy_graph_staging first). The entity_type must match an entity key from the project schema. Use get_graph_d
Get a specific node by its entity_id from a deployed graph project. Returns all node properties including created_at and updated_at timestamps.
List nodes of a specific entity type from a deployed graph project. Supports pagination with limit/offset. Returns nodes ordered by creation date (newest first).
Update properties of an existing node in a deployed graph project. Only send the fields you want to change — unspecified fields remain unchanged.
Delete a node and all its relationships from a deployed graph project. ⚠️ This also removes all relationships connected to this node (DETACH DELETE).
Create a relationship between two nodes in a deployed graph project. The rel_type must match a relationship key from the project schema. Use get_graph_data_schema to see available relationship types.
Get all relationships connected to a specific node. Supports direction filtering (incoming, outgoing, both) and relationship type filtering.
Delete a specific relationship by its internal ID. Use get_node_relationships to find relationship IDs.
Create multiple nodes at once (up to 500 per call). Uses Neo4j UNWIND for high performance. Essential for knowledge graph population — create hundreds of entities from a single book chapter or article
Create multiple relationships at once (up to 500 per call). Uses Neo4j UNWIND for high performance. Essential for connecting knowledge — link hundreds of concepts, people, and events in one operation.
Search for nodes by property values in a deployed graph project. Supports exact match and contains search (prefix value with ~ for contains). Examples: Exact: filters: {"name": "Alan Turing"} Contains
Search across ALL string properties of ALL nodes in a deployed graph using free-text queries. Unlike search_graph_nodes (which filters by specific property), this searches every text field at once. Pe
Walk the graph from a starting node, discovering connected knowledge. Returns all nodes reachable within max_depth hops, with their distance from the start. Essential for exploring knowledge graphs —
Get statistics about a deployed graph: total node count, total relationship count, counts per entity type, counts per relationship type. Essential for understanding the current state of a knowledge gr
Get the runtime schema of a DEPLOYED graph project — shows the actual entity types and relationship types available for data operations. Returns: Available entity keys (for create_graph_node, list_gra