Developer utility tools — JSON, YAML, QR codes, and more — via hosted MCP.
Do not connect
The assessed surface is high-risk. Remediate the findings before connecting.
Scanned 27 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The jiebang-tools MCP server exposes 29 tools, focused primarily on web capabilities. Its published description reads: "Developer utility tools — JSON, YAML, QR codes, and more — via hosted MCP". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates jiebang-tools D — the assessed surface is high-risk and should be remediated before use. Its most notable findings include "Data-exfiltration parameters" and "Data-exfiltration parameters". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check jiebang-tools's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add jiebang-tools to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://www.jiebang.site/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Convert between JSON and YAML formats. Auto-detects direction.
Beautify or minify XML code.
Beautify, minify, or uppercase SQL keywords.
Parse cron expression to human-readable description with next 5 run times.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: meta_extract
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: seo_check
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: url_shorten
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: image_convert
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: cron_task_create
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: url_shorten
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "url_shorten"RecommendationScope tools to the minimum needed.
tool: cron_task_create
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "cron_task_create"RecommendationScope tools to the minimum needed.
tool: cron_task_templates
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "cron_task_templates"RecommendationScope tools to the minimum needed.
Financial data service providing fundamental information for 30,000+ listed companies across the US, Japan, and Korea, sourced directly from SEC, EDINET, and DART regulatory filings.
Search tours, attraction tickets, and holiday packages across 24 countries.
Agentic visitor analytics with five tools for CRO and session analysis.
52 paid x402 API endpoints for AI agents — crypto, data, DeFi, and market intelligence, settled on Base.
Access Vonage API documentation, code snippets, tutorials, and troubleshooting resources.
Convert numbers between decimal, binary, octal, hexadecimal.
Encode or decode HTML entities.
Convert datetime between time zones.
Generate QR code for text or URL. Returns SVG data URI.
Extract SEO meta tags from any URL. Returns title, description, OG tags, Twitter cards, structured data, and SEO health score.
Quick SEO health check for any URL. Returns score and issues list.
Create a short link for any URL. Returns short URL and click tracking. Free: 100 links/day.
Convert image format to WebP/AVIF/PNG/JPEG with optional resize and quality control.
Create a scheduled task with cron expression. For AI agents to manage daily check-ins, monitoring, reminders etc.
List scheduled tasks. Use due=true to see only tasks that need action now.
Mark a scheduled task as completed or failed. Supports failure tracking and auto-retry.
Get execution history/logs for a scheduled task. Shows past completion times, success/failure status, and counts. Omit task_id to get all logs for the agent.
Get preset task templates with common cron schedules (daily, weekday, hourly, stock market, etc.). Use these to quickly create tasks without writing cron expressions.
Parse CSV/TSV/JSON/XML file content to structured JSON. Auto-detects format and column types. Returns columns, data rows, and preview.
Generate CSV/TSV/JSON file from structured data array. Returns base64-encoded file and raw text.
Analyze tabular data: detect column types, compute stats (min/max/mean/median for numbers, top values for text), find nulls. Returns summary and preview.
AI-powered text generation: copywriting, naming, slogans, catchy titles, praise/replies, couplets. Powered by GLM-4.7-Flash (free, 10k calls/day).
Rewrite AI-generated text to sound naturally human-written. Supports Chinese and English. Reduces AI detection rates. Styles: standard, casual, academic, creative.
Extract keywords and key phrases from text with search intent classification. Returns 10-20 keywords sorted by importance with long-tail variations.
Generate SEO-friendly meta description (120-160 chars) from title, keyword, and content. Includes call-to-action and keyword placement.
Rewrite text with different styles while preserving meaning. Modes: standard (natural), creative (expressive), academic (formal), casual (informal).
Generate multiple SEO-optimized article titles from a keyword. Diverse styles: question, number, list, comparison, how-to. Max 60 chars each.
Summarize text into concise version. Lengths: short (1-2 sentences), medium (3-5 sentences), long (full paragraph). Preserves key data and facts.
Submit a new idea or feature request to the JieBang ideas board. Supports categorization, priority, and source tracking.
List ideas from the JieBang ideas board. Filter by status, sort by votes. View community feature requests and their progress.