Cross-border debt collection server for submitting and tracking cases handled by local partners in 183 countries.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 28 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The debitura MCP server exposes 16 tools, focused primarily on filesystem and communication capabilities. Its published description reads: "Cross-border debt collection server for submitting and tracking cases handled by local partners in 183 countries". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates debitura F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check debitura's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add debitura to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.debitura.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Verify the connection to Debitura and show which creditor account the API key belongs to. Call this first to confirm the integration is set up correctly.
List the creditor's debt collection cases with pagination, status filtering, and sorting. Returns compact case summaries: reference, debtor name + country, amounts, lifecycle, partner, key dates. Use
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: list_team_members
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
serId or email) before calling send_case_message, or a case owner for create_case.RecommendationRemove model-directed instructions from tool descriptions.
tool: list_cases
A tool description tries to alter the model’s use of another tool.
key dates. Use get_case for full detail on a specific case. LifecycleRecommendationDescriptions must describe only their own tool.
tool: get_case_messages
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
s Read the chat conversation on a case between you and the collection partneRecommendationRemove side-channel parameters; constrain tool inputs.
tool: preview_case
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: preview_case
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
g is persisted. ALWAYS call this before create_case and show the user the pricing and rRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: list_team_members
A tool description tries to alter the model’s use of another tool.
case owner for create_case.RecommendationDescriptions must describe only their own tool.
tool: list_case_files
A tool description tries to alter the model’s use of another tool.
ed in time. Use upload_case_file to attach new documents.RecommendationDescriptions must describe only their own tool.
tool: get_account_summary
A tool description tries to alter the model’s use of another tool.
own test cases; list_cases exposes the `isTestCase` flag that marks them.RecommendationDescriptions must describe only their own tool.
tool: list_tasks
A tool description tries to alter the model’s use of another tool.
d of sending a human to solutionUrl. Tasks without an action rely on solutRecommendationDescriptions must describe only their own tool.
tool: get_case_tasks
A tool description tries to alter the model’s use of another tool.
— same data as list_tasks, scoped to a single case. Use this when you'reRecommendationDescriptions must describe only their own tool.
tool: create_case
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
rmation in this conversation. Submission is idempotent: the server sends aRecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_case
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: upload_case_file
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
if. Provide the file content base64-encoded. {"type":"object","properties":{RecommendationRemove side-channel parameters; constrain tool inputs.
tool: send_case_message
A tool description tries to alter the model’s use of another tool.
d or email from list_team_members. Ask the user who the message should be sent asRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
ey. Start with `ping` to verify the connection. Use `preview_case` fRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: list_case_files
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
list_case_files List Case Files List all documents attached to a case: file namRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: create_case
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: upload_case_file
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: send_case_message
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Fetch one collection case in full detail. Look it up by Debitura case ID (GUID), by your own creditor reference (e.g. invoice number), or by the Debitura case reference shown in the portal. Provide ex
Fetch the chronological timeline of a case — what has happened so far: status changes, partner actions, communications, and payments. Returns an envelope `{ items, currentEngagementPhase }`: `items` i
Read the chat conversation on a case between you and the collection partner handling it. Each message includes: senderName, role (Creditor / Partner / Managed by partner), sentAt (UTC), message. See t
List every payment recorded on a case — money recovered so far.
Check which contracts (e.g. debt collection agreement, power of attorney) are signed or still blocking a case, including signing URLs for any outstanding documents.
Dry-run a collection case BEFORE creating it: returns eligibility, the assigned collection partner, pricing (success fee), and any contracts that would need signing. Nothing is persisted. ALWAYS call
List the team members on the creditor's Debitura account. Use this to resolve a valid sender (userId or email) before calling send_case_message, or a case owner for create_case.
List all documents attached to a case: file name, document type, description, upload date, and a time-limited SAS download URL. Each file also carries downloadUrlExpiresAt (UTC) — when the download UR
Return a count of cases per lifecycle stage for the creditor's account. Useful for a quick portfolio overview without listing all cases. Stages: PendingContractSigning, PendingVerificationInternal, Pe
List every open task (action-item) across your whole account — things the platform needs you to do before a case (or your account) can proceed: reply to a chat, sign a contract, assign a bank account,
List the open tasks (action-items) attached to one specific case — same data as list_tasks, scoped to a single case. Use this when you're already working a specific case and want just its outstanding
Submit a debt collection case to Debitura. This is a LEGAL AND FINANCIAL ACTION: a collection partner starts recovery against the debtor, and contractual fees apply on success. Required workflow — nev
Attach a document to a case (invoice copy, contract, correspondence, proof of delivery). Max 25 MB. Allowed extensions: .pdf, .xls, .xlsx, .csv, .txt, .jpg, .jpeg, .png, .gif. Provide the file content
Send a chat message on a case to the collection partner handling it. The partner is notified by email. The message is attributed to a named team member, so a sender is REQUIRED: pass the sender's user