Recao ranks a competitor's EU App Store ads by longevity, sourced from Apple's official Ad Repository.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 27 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The recao MCP server exposes 17 tools, focused primarily on AI capabilities. Its published description reads: "Recao ranks a competitor's EU App Store ads by longevity, sourced from Apple's official Ad Repository". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates recao F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check recao's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add recao to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://recao.app/api/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search the Apple Ad Repository for apps or developers advertising on the EU App Store. Returns ids to use with get_competitor_ads. Start here with your competitor's app name.
Get all Apple App Store ads a competitor has run (EU storefronts, up to 1 year back), with creative copy, placements, formats, and an inferred winner analysis: ads sorted by how long they've been runn
Get full details and locale/creative variations for one specific ad (use adId from get_competitor_ads). Shows every language variant, creative asset URLs, and icon variations. Useful to see how a comp
Get a Recao GTM playbook: the go-to-market moves a solo app founder's agent runs, wired to the competitor data tools. Start with 'the-roadmap' (diagnoses the founder's stage and its binding constraint
Request a free Recao account for your human. This does NOT create an active account: it registers a PENDING one and emails your human an activation link; nothing works and no terms are accepted until
Get the checkout link to upgrade this account to a paid plan (Indie €29/mo: 10 competitors + weekly auto-reports; Pro €79/mo: 25 competitors, new channels first, full API). Payment happens in the brow
List this account's company memory, one line per entry (name + description), newest first. Traverse index-first: scan this, then memory_recall(name) for full bodies. Memory accrues automatically from
Read one memory entry's full body by name (get names from memory_index).
Write (or update) a memory entry on this account: decisions, campaign outcomes, learnings. Use a short kebab-case name and a one-line description (that's the index line); details go in body. Your futu
Where the founder's agent starts its go-to-market work: diagnose which stage of the Recao Roadmap this account is in (S0 pre-launch to S4 scale), the binding constraint, and the playbook to run. Reads
Generate a UGC persona: your agent passes a persona brief (physical look plus vibe of one invented creator), and we return stills of that invented person plus an avatar_id. The persona brief anchors t
Render UGC video scenes as ad-ready clips, metered per second of video (the estimate shows the exact price before anything renders). Pass 3 to 6 scenes (5 to 8 seconds each, one action per scene, spok
Check a generate_clips render job by its job_id. Returns the status (processing, done, or error). When done, returns the finished clip URLs, the model used, and the booked cost in EUR. When it errored
Stitch rendered scene clips into one ad-ready MP4 with burned-in subtitles and crossfades. Pass 1 to 6 clips in order, each with its mp4 url, its duration in seconds (3 to 12), and an optional subtitl
Check an assemble_video job by its job_id. Returns the status (processing, done, or error). When done, returns the final MP4 url, the aspect, clip count, total duration, and the booked cost in EUR. Wh
Show this account's metered generation spend this period and its billing position: the usage cap, what has accrued toward it, and whether generation is waiting on a payment. Use it to report costs bac
Show the authenticated account (plan, email, verification state), or confirm you're anonymous.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: search_app_advertiser
A tool description tries to alter the model’s use of another tool.
ids to use with get_competitor_ads. Start here with your competitor's app name.RecommendationDescriptions must describe only their own tool.
tool: get_ad_details
A tool description tries to alter the model’s use of another tool.
(use adId from get_competitor_ads). Shows every language variant, creative assetRecommendationDescriptions must describe only their own tool.
tool: sign_up
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
, not you). The API key in the response stays inert until then. ConsentRecommendationRemove side-channel parameters; constrain tool inputs.
tool: sign_up
A tool description tries to alter the model’s use of another tool.
r human instead of calling it. After activation, reconnect with header `AuRecommendationDescriptions must describe only their own tool.
tool: memory_index
A tool description tries to alter the model’s use of another tool.
scan this, then memory_recall(name) for full bodies. Memory accrues automaticRecommendationDescriptions must describe only their own tool.
tool: memory_recall
A tool description tries to alter the model’s use of another tool.
(get names from memory_index).RecommendationDescriptions must describe only their own tool.
tool: roadmap_status
A tool description tries to alter the model’s use of another tool.
pen it: write a memory_note named 'company-stage' with your MRR band and fuRecommendationDescriptions must describe only their own tool.
tool: generate_avatar
A tool description tries to alter the model’s use of another tool.
me character in generate_clips takes, and the stills are the customer's refereRecommendationDescriptions must describe only their own tool.
tool: generate_clips
A tool description tries to alter the model’s use of another tool.
inutes, so poll clips_status with that id to get per-scene clip URLs plus thRecommendationDescriptions must describe only their own tool.
tool: clips_status
A tool description tries to alter the model’s use of another tool.
Check a generate_clips render job by its job_id. Returns the status (pRecommendationDescriptions must describe only their own tool.
tool: assemble_video
A tool description tries to alter the model’s use of another tool.
the clips from clips_status (map each to url, duration_s, subtitle). Paid pRecommendationDescriptions must describe only their own tool.
tool: assemble_status
A tool description tries to alter the model’s use of another tool.
Check an assemble_video job by its job_id. Returns the status (processiRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
book to run, or search_app_advertiser to pull a rival's ads. sign_up gets a free APIRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: search_app_advertiser
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_competitor_ads
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_ad_details
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: generate_avatar
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: generate_clips
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: assemble_video
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.