Resolves Japanese food names to nutrition facts from Japan's official Standard Tables of Food Composition.
Do not connect
The assessed surface is high-risk. Remediate the findings before connecting.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The toriigate/food-db MCP server exposes 2 tools, focused primarily on general-purpose capabilities. Its published description reads: "Resolves Japanese food names to nutrition facts from Japan's official Standard Tables of Food Composition". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates toriigate/food-db D+ — the assessed surface is high-risk and should be remediated before use. Its most notable findings include "Cross-tool shadowing" and "No authorization on a public remote server". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check toriigate/food-db's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add toriigate/food-db to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://toriigate.dev/mcp/food-dbStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search Japanese foods by name (Japanese or romaji-free text). Returns candidates with nutrition per 100g, source, and disclaimer.
Get nutrition facts per 100g for a food ID returned by search_food.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_nutrition
A tool description tries to alter the model’s use of another tool.
ID returned by search_food.RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
AWS's official fully managed remote server that provides real-time access to comprehensive AWS documentation, API references, troubleshooting guides, and architectural guidance across multiple knowledge sources including What's New posts, Builder Center content, blog posts, and Well-Architected frameworks for building applications, managing infrastructure, and learning AWS services through natural language queries.
Search live events, conference weeks, host cities, venues, and artist tour schedules.
Live verifiable on-chain data for the $BOBAI token on BNB Chain.
Identity certification, public registry, reputation scoring, and x402 micropayments for AI agents built on Base and Solana.
Search 11M+ products across SG, SEA, and US. Agent-native catalog for AI shopping agents.
Real-time and historical market data for forex, stocks, crypto, indices, and metals via the TickDB API.