Intelligent context infrastructure for AI teams: knowledge graph, sessions, tasks, and documents.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 27 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The rmcp MCP server exposes 62 tools, focused primarily on communication capabilities. Its published description reads: "Intelligent context infrastructure for AI teams: knowledge graph, sessions, tasks, and documents". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates rmcp F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check rmcp's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add rmcp to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.dotnova.io/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Accept a pending organization invite by organization name.
Add a dependency between tasks. Use this to express that a task is blocked by another task (must complete first) or relates to it. This prevents context contamination: when Task B depends on Task A, a
Add a member to a team. Find the team by name or ID, and the user by name or email.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: end_session
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
{"description":"Token usage for this session. JSON object with fieldsRecommendationRemove side-channel parameters; constrain tool inputs.
tool: find_documents
A tool description tries to alter the model’s use of another tool.
metadata — use get_document to read the full content.RecommendationDescriptions must describe only their own tool.
tool: get_document
A tool description tries to alter the model’s use of another tool.
by its ID. Use find_documents first to search, then get_document to read theRecommendationDescriptions must describe only their own tool.
tool: setup_organization
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "custom_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: update_org
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "custom_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ing of each new conversation, before doing ANY other work, you MUST automatiRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
de - Filter tasks by sprint using `list_tasks` with `sprint_number` paraRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: create_position
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_position"RecommendationScope tools to the minimum needed.
tool: create_project
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_project"RecommendationScope tools to the minimum needed.
tool: create_sprint
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_sprint"RecommendationScope tools to the minimum needed.
tool: create_task
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_task"RecommendationScope tools to the minimum needed.
tool: create_team
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "create_team"RecommendationScope tools to the minimum needed.
tool: delete_document
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_document"RecommendationScope tools to the minimum needed.
tool: delete_position
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_position"RecommendationScope tools to the minimum needed.
tool: delete_project
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_project"RecommendationScope tools to the minimum needed.
tool: delete_task
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_task"RecommendationScope tools to the minimum needed.
tool: delete_team
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_team"RecommendationScope tools to the minimum needed.
tool: delete_user
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "delete_user"RecommendationScope tools to the minimum needed.
tool: list_notifications
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "list_notifications"RecommendationScope tools to the minimum needed.
tool: remove_task_dependency
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "remove_task_dependency"RecommendationScope tools to the minimum needed.
tool: remove_team_member
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "remove_team_member"RecommendationScope tools to the minimum needed.
tool: remove_user_from_org
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "remove_user_from_org"RecommendationScope tools to the minimum needed.
tool: set_context_routing
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "set_context_routing"RecommendationScope tools to the minimum needed.
tool: setup_organization
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "setup_organization"RecommendationScope tools to the minimum needed.
tool: unassign_task
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "unassign_task"RecommendationScope tools to the minimum needed.
tool: update_org
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_org"RecommendationScope tools to the minimum needed.
tool: update_position
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_position"RecommendationScope tools to the minimum needed.
tool: update_project
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_project"RecommendationScope tools to the minimum needed.
tool: update_task
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_task"RecommendationScope tools to the minimum needed.
tool: update_team
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_team"RecommendationScope tools to the minimum needed.
tool: update_user
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "update_user"RecommendationScope tools to the minimum needed.
tool: upload_document
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "upload_document"RecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Assign a user to a task by name or email. The user is added to the task's assignees and linked in the knowledge graph.
Create a new job position/title in your organization (admin only).
Create a new project in your organization. You will be added as the project owner.
Create a new sprint for a project. Automatically migrates non-completed tasks (todo/in_progress) from the previous sprint. On first use, creates Sprint 0 (Backlog) for existing tasks and Sprint 1 as t
Create a new task in a project. Tasks track work items and can be assigned to team members and linked to sessions.
Create a new team in your organization. You will be added as team lead.
Delete a document from the knowledge base. This permanently removes the document.
Delete a position permanently (admin only). Find by title or ID.
Delete a project permanently (admin only). Find by name or ID.
Delete a task permanently. The task and all its assignee links are removed.
Delete a team permanently (admin only). Find by name or ID.
Delete (soft-delete) a user from your organization (admin/owner only).
End a work session. This triggers context block generation — your activities are summarized and stored in the knowledge graph for future reference.
Search documents in the organization's knowledge base. Filter by category, tags, project, or free-text query. Returns document metadata — use get_document to read the full content.
Get intelligent context from the knowledge graph. Pass a query describing what you need — the system will automatically route to the right data sources (tasks, sessions, documents, teams, blocks) base
Get the current context routing mode for the organization. Returns 'keyword_llm', 'keyword_only', or 'llm_only'.
Get the full content of a document by its ID. Use find_documents first to search, then get_document to read the content. For binary documents (PDFs, images), content is returned base64-encoded with en
See what's happening right now: active sessions, recent events, traces, and tasks being worked on.
Get your personal activity statistics: total sessions, events, active days, projects worked on, and recent activity summary.
Get comprehensive organization statistics: counts, engagement metrics, task velocity.
Get the current status of a project including recent activity. You can use either the project name or ID.
Get full details of a session including all events/activities logged during it. Shows who did what, when, and the session block summary if available. Admins can view any session in the org; members ca
Get detailed information about a team: members (with roles), linked projects, and recent activity. Use team name or ID.
Invite a new member to your organization (admin/owner only).
Link a work session to a task. This records that the session was used to work on the task, connecting them in the knowledge graph.
Link a project to a team. Find both by name or ID.
List colleagues in your organization. Shows name, email, role, and optionally filters by team. Admins see all users; members see users in their own teams.
List your notifications — task assignments, status changes, sprint updates, invites, and more. Returns unread notifications by default.
List pending organization invites for the current user.
List all job positions/titles in your organization with member counts.
List all members involved in a project. Includes users who have sessions in the project and users from teams linked to the project.
List teams linked to a project.
List projects in your organization. No parameters needed — just call it to see all your projects.
List your recent work sessions. Optionally filter by project name or ID. Shows task type, status, and event count.
List sprints for a project. Shows sprint number, name, goal, status (current/completed), and task count.
List tasks. Filter by project, status (todo/in_progress/done/cancelled), sprint number, or show only your tasks. Shows title, status, priority, assignees, sprint, and linked sessions.
List all teams in your organization. Shows team name, member count, project count, and description.
Log an activity or event. If no session_id is provided, a session is automatically created or reused for the project. Just pass project_name and content — no need to start a session first.
Log a granular agent action trace. High-frequency, no LLM processing.
Log multiple traces in a single batch.
Mark a notification as read, or mark all notifications as read at once.
Move a task to a different sprint. Specify the target sprint by number or ID.
Remove a dependency between tasks. This unblocks the task from the other task.
Remove a member from a team. Find the team by name or ID, and the user by name or email.
Remove a user from the current organization without deleting their account. Admin/owner only.
Search entities in the knowledge graph by name. Finds people, companies, documents, concepts, tools, etc. that have been mentioned in your activities.
Set the context routing mode for the organization. Requires admin role. Options: 'keyword_llm' (balanced), 'keyword_only' (fastest), 'llm_only' (most accurate).
Set up your organization in one step (admin only). Use this for onboarding.
Start a work session. If a project is provided (project_name or project_id), the session is bound to it; if neither is provided, an unbound (projectless) session is created — useful when the work isn'
Remove a user from a task's assignees.
Unlink a project from a team. Find both by name or ID.
Update your organization's details (owner only). Set name, description, business model, objectives, custom context for AI, or links.
Update a position's title, description, or permissions (admin only). Find by title or ID.
Update a project's name, description, or links. Find by name or ID.
Update a task's status, title, description, priority, or team assignment. Use this to move tasks through the workflow (todo -> in_progress -> done) or reassign to a team.
Update a team's name, description, or objectives. Find by name or ID.
Update an existing user's name, role, positions, or skills (admin/owner only).
Upload a document to the organization's knowledge base. Documents can be templates, policies, contracts, procedures, guides, or references. They are indexed in the knowledge graph and automatically su
Get your profile, organization, projects, recent sessions, and top entities. This is the best starting point — call this first to understand what's available. No parameters needed.