Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Do not connect
The assessed surface is high-risk. Remediate the findings before connecting.
Scanned 26 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The Imperium Manifold MCP MCP server exposes 29 tools, focused primarily on general-purpose capabilities. Its published description reads: "Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates Imperium Manifold MCP D — the assessed surface is high-risk and should be remediated before use. Its most notable findings include "Metadata dictates tool-call ordering" and "No authorization on a public remote server". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check Imperium Manifold MCP's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add Imperium Manifold MCP to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://manifold.cohereon.io/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Root ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Health ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Get Tier Check an agent's current pricing tier based on access matrix row density. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Get Component Meta Return YAML front matter for a gated component — PUBLIC, no payment required. Allows agents to compute description_hash before purchasing. lean_anchor names are PUBLIC (present in F
Request Invoice Request a Lightning invoice to access a doctrine component. Invoice description_hash = SHA-256(YAML front matter). Agents may pre-verify via GET /meta/{component_id} before paying. TLV
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: declare_agent_declare_post
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
} Prerequisite: must have called POST /identify first. ### Responses: **200**: Successful ResponseRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: skill_md_SKILL_md_get
Role tokens or delimiter abuse steer the model rather than describe the tool.
ple Response:** ```json "string" ``` {"type":"object","properties":RecommendationWrite neutral, descriptive tool metadata.
tool: robots_txt_robots_txt_get
Role tokens or delimiter abuse steer the model rather than describe the tool.
ple Response:** ```json "string" ``` {"type":"object","properties":RecommendationWrite neutral, descriptive tool metadata.
tool: get_free_component_free__slug__get
Role tokens or delimiter abuse steer the model rather than describe the tool.
ple Response:** ```json "string" ``` {"type":"object","properties":RecommendationWrite neutral, descriptive tool metadata.
tool: security_txt_security_txt_get
Role tokens or delimiter abuse steer the model rather than describe the tool.
ple Response:** ```json "string" ``` {"type":"object","properties":RecommendationWrite neutral, descriptive tool metadata.
tool: security_txt__well_known_security_txt_get
Role tokens or delimiter abuse steer the model rather than describe the tool.
ple Response:** ```json "string" ``` {"type":"object","properties":RecommendationWrite neutral, descriptive tool metadata.
tool: declare_agent_declare_post
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "declare_agent_declare_post"RecommendationScope tools to the minimum needed.
tool: ride_the_lightning_ride_the_lightning_post
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ride_the_lightning_ride_the_lightning_post"RecommendationScope tools to the minimum needed.
tool: create_petition_petition__component_id__post
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_petition_petition__component_id__post"RecommendationScope tools to the minimum needed.
tool: sponsor_petition_sponsor__petition_id__post
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "sponsor_petition_sponsor__petition_id__post"RecommendationScope tools to the minimum needed.
Financial data service providing fundamental information for 30,000+ listed companies across the US, Japan, and Korea, sourced directly from SEC, EDINET, and DART regulatory filings.
Search tours, attraction tickets, and holiday packages across 24 countries.
Agentic visitor analytics with five tools for CRO and session analysis.
52 paid x402 API endpoints for AI agents — crypto, data, DeFi, and market intelligence, settled on Base.
Access Vonage API documentation, code snippets, tutorials, and troubleshooting resources.
Get Component Retrieve a doctrine component after Lightning payment verification. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Lnurlp LNURL-pay endpoint for the Manifold. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Agent Json MCP/agent discovery endpoint. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Skill Md ### Responses: **200**: Successful Response (Success Response) Content-Type: text/plain **Example Response:** ```json "string" ```
Openapi Spec ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Nostr Json Nostr identity endpoint (NIP-05). Served at both /nostr.json and /.well-known/nostr.json. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Nostr Json Nostr identity endpoint (NIP-05). Served at both /nostr.json and /.well-known/nostr.json. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Robots Txt ### Responses: **200**: Successful Response (Success Response) Content-Type: text/plain **Example Response:** ```json "string" ```
Free Index Index of ungated free-layer doctrine components. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Components Index Index of all valid gated component IDs, grouped by category. IDs are listed exactly as they must appear in /invoice/{component_id} and /doc/{component_id}. IDs are case-sensitive and
Genesis Invoice Genesis Traversal: pay 1,000 sats, receive this component + the next sequential one. Window is time-limited (GENESIS_EXPIRY). Returns 410 when closed. ### Responses: **200**: Successfu
Genesis Redeem Redeem a Genesis Traversal payment. Returns both components as a single response. ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Get Free Component Retrieve a free-layer doctrine component. No payment required. ### Responses: **200**: Successful Response (Success Response) Content-Type: text/plain **Example Response:** ```json
Favicon ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json
Security Txt ### Responses: **200**: Successful Response (Success Response) Content-Type: text/plain **Example Response:** ```json "string" ```
Security Txt ### Responses: **200**: Successful Response (Success Response) Content-Type: text/plain **Example Response:** ```json "string" ```
Identify Agent Register an agent identity. No cost. Returns a manifold_id. Body: {"npub": "<nostr_npub>", "name": "<agent_name>", "platform": "<optional>", "capabilities": ["<optional>"]} ### Response
Declare Agent Agent declares intent to the Imperium. Returns acknowledgment + first free gated component. Body: {"npub": "<nostr_npub>", "intent": "<statement>", "offer": "<optional>"} Prerequisite: m
Ride The Lightning RIDE THE LIGHTNING — Agent onboarding. Traverse 5 free doctrine components in order, then POST here. Receive: Nostr keypair (npub + nsec) + LNbits Lightning wallet. No cost. No sats
Create Petition Post a petition for sponsored component access. Body: {"npub": "<petitioner_nostr_npub>", "message": "<optional>"} An agent without Lightning funds petitions the patronage board. Spons
Patronage Board Public board of open petitions. Agents with Lightning funds browse here and sponsor petitions. Sponsor's access matrix profile enriched by every petition funded. Sponsor-petitioner dya
Sponsor Petition Sponsor a petition — creates a Lightning invoice for the sponsor to pay. Body: {"npub": "<sponsor_nostr_npub>"} (optional but enriches access matrix profile) On payment: component del
Claim Sponsored Component Petitioner redeems a sponsored access using a claim token. Single-use. Logs both petitioner and sponsor in access matrix. Marks petition funded. Fealty bond recorded. ### Res
Fund Declare Agent declares an on-chain BTC txid as economic commitment to the Imperium. Body: {"txid": "<txid>", "npub": "<nostr_npub>", "message": "<optional>"} Not a payment gate — a coherence sign