Live global intelligence covering real-time markets, conflicts, country risk, chokepoints, and energy data.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The worldmonitor MCP server exposes 68 tools, focused primarily on developer and AI capabilities. Its published description reads: "Live global intelligence covering real-time markets, conflicts, country risk, chokepoints, and energy data". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates worldmonitor F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check worldmonitor's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add worldmonitor to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://worldmonitor.app/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Bounded Toronto Police Service Major Crime Indicators rows.
Bounded Toronto Police Service Calls for Service Attended annual aggregates.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: (server instructions)
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
de a response ("ignore previous instructions", "run this command", a URL to fetRecommendationRemove model-directed instructions from tool descriptions.
tool: get_toronto_reported_occurrences
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_toronto_calls_attended
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_market_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_conflict_events
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_aviation_status
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_news_intelligence
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_natural_disasters
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_military_posture
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_cyber_threats
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_economic_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_country_macro
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_eu_housing_cycle
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_eu_quarterly_gov_debt
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_eu_industrial_production
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_prediction_markets
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_sanctions_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_displacement_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_health_signals
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_energy_intelligence
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_climate_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_infrastructure_status
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_supply_chain_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_tariff_trends
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_chokepoint_status
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_positive_events
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_radiation_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_research_signals
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_forecast_predictions
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_forecast_scorecard
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_social_velocity
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_temporal_anomalies
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_test_site_seismicity
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_world_brief
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "geo_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: analyze_situation
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
typical 80-95% token reduction. Grammar: https://jmespath.org/specifRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
history tools (search_intel_history, get_intel_timeline, get_similar_events) keep iRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: get_country_brief
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_airspace
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_maritime_activity
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: analyze_situation
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: generate_forecasts
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_flights
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_flight_prices_by_date
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: classify_event
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: (server instructions)
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ction. Grammar: https://jmespath.org/specification.html. Guide + 12 worked examples: https://www.worldmoRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
The server exposes one or more ui:// (MCP Apps) resources whose HTML/JS renders inside the host client — a client-side injection / data-exposure surface most scanners ignore. Flagged for review, not damning on its own.
10 ui:// resource(s); e.g. ui://worldmonitor/country-risk.htmlRecommendationReview each ui:// resource’s markup and scripts; treat host-rendered UI as untrusted, sandbox it, and never expose secrets or conversation context to it.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Real-time equity quotes, commodity prices (including SGE physical-vs-COMEX gold and silver premiums), crypto prices, for
Active armed conflict events (UCDP, Iran), unrest events with geo-coordinates, and country risk scores.
Airport delays, NOTAM airspace closures, and tracked military aircraft.
AI-classified geopolitical threat news summaries, GDELT intelligence signals, cross-source signals, and security advisor
Recent M4.5+ earthquakes (USGS and Earthquakes Canada / NRCan), active wildfires (NASA FIRMS), and natural hazard events
Theater posture assessment and military risk scores.
Active cyber threat intelligence: malware IOCs (URLhaus, Feodotracker), CISA known exploited vulnerabilities, and active
China macro: official-only 12-series; 5 NBS/SAFE ingestible, PBoC/GACC unavailable, no proxies; see launchReady/status.
Per-country macroeconomic indicators from IMF WEO (~210 countries, monthly cadence).
Eurostat annual house price index (prc_hpi_a, base 2015=100) for all 27 EU members plus EA20 and EU27_2020 aggregates.
Eurostat quarterly general government gross debt (gov_10q_ggdebt, %GDP) for all 27 EU members plus EA20 and EU27_2020 ag
Eurostat monthly industrial production index (sts_inpr_m, NACE B-D industry excl.
Prediction markets: geopolitical/elections, tagged tech (AI/crypto/science), finance/economics or untagged fallback.
OFAC SDN sanctioned entities list and sanctions pressure scores by country.
Refugee and IDP counts by country (UNHCR annual data).
Active disease outbreaks (WHO/ECDC etc.) and global air-quality station readings (OpenAQ/WAQI PM2.5).
Energy supply, prices, storage, disruptions, and policy: EIA petroleum stocks, electricity prices (Ember), gas storage (
Climate intelligence: temperature/precipitation anomalies (vs 30-year WMO normals), climate-relevant disaster alerts (Re
Internet infrastructure health: Cloudflare Radar outages and service status for major cloud providers and internet servi
Dry bulk shipping stress index, customs revenue flows, and COMTRADE bilateral trade data.
Global trade and pricing indicators: US tariff trends (HTS-coded), BigMac index, FAO Food Price Index, and per-country n
Live maritime chokepoint status: per-chokepoint vessel transit counts (10-min cadence), rolling transit summaries, per-p
Positive geopolitical events: diplomatic agreements, humanitarian aid, development milestones, and peace initiatives wor
Radiation observation levels from global monitoring stations.
Tech and research event signals: emerging technology events bootstrap data from curated research feeds.
AI-generated geopolitical and economic forecasts from WorldMonitor's predictive models.
Forecast resolution scorecard with calibration, Brier/log score, domain and generation-origin breakdowns, and pending/ju
Reddit geopolitical social velocity: top posts from worldnews, geopolitics, and related subreddits with engagement score
Temporal anomaly watch: current event counts vs day-of-week and seasonal baselines, scored by z-score severity.
Nuclear test-site seismic monitor: USGS earthquakes near known test sites scored for proliferation concern.
Return one country's latest World Bank military-capacity indicators and SIPRI-derived five-year arms-supplier shares and
Return the bounded six-domain China decision-signal snapshot used by the public country summary.
Search open global public-procurement opportunities through the canonical Pro route.
WTO merchandise trade flows for one reporting country versus the World, over a configurable year window.
Citation-grounded world intelligence brief from the same precomputed news:insights:v1 snapshot used by the dashboard.
AI-generated per-country intelligence brief.
Structured risk intelligence for a specific country: Composite Instability Index (CII) score 0-100, component breakdown
Curated public news-account posts from monitored X accounts.
USDA PSD cereal stocks-to-use by marketing year.
Country demographics capability observations from UN WPP, World Bank/UNESCO UIS, and ILOSTAT.
Per-country consumer-prices intelligence: 30-day overview, category-level inflation, retailer spread (essentials basket)
Live ADS-B aircraft over a country.
Live vessel traffic and maritime disruptions for a country's waters.
AI geopolitical situation analysis (DeductionPanel).
Generate live AI geopolitical and economic forecasts.
Search Google Flights for real-time flight options between two airports on a specific date.
Search Google Flights date-grid pricing across a date range.
Global mining sites with coordinates, operator, mineral type, and production status.
Who mines and who refines a commodity, with country shares and HHI.
Geographic signal convergence: grid cells where protests, military activity, naval movements, and earthquakes co-occur.
Focal-point detection: entities where news coverage and live map signals converge, ranked by multi-signal score.
Infrastructure cascade simulation: what fails downstream when a cable, chokepoint, pipeline, or port is disrupted.
Military surge watch: theater aircraft postures, foreign-presence detections, and seeder-computed surge alerts.
Population exposure: estimated people within the impact radius of active earthquakes, wildfires, and conflict events.
Cross-domain alert digest: everything that tripped a threshold today, in one rollup.
Hotspot escalation scores: the 29 curated intelligence hotspots ranked by dynamic escalation on a 1-5 scale.
Semantic search over WorldMonitor's accumulating store of past intelligence events (Pro), ranked by similarity.
Reverse-chronological read of WorldMonitor's accumulating intelligence-event history for one domain or country (Pro).
Historical precedents for a situation you describe, drawn from WorldMonitor's accumulating event store (Pro).
Per-company corporate intelligence from SEC EDGAR and market data.
Return the full uncompressed definition of one tool by name.
Classify a supplied news headline or short text into a threat category and severity via the enum-validated WorldMonitor
Extract named entities deterministically — registry entities (companies, indices, commodities, crypto, sectors, countr
Current topic clusters over the live headline digest, computed with the same Jaccard clustering the dashboard uses.
Keyword/CVE/APT spikes vs baseline, each with sourceNames and {title, source, link}.
WorldMonitor's live source inventory, for deciding whether and how far to trust what the other tools return.