Live ski snow, multi-model forecasts, powder rankings, and a grounded Answer Engine for 500+ resorts.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 29 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The snowsure-mcp MCP server exposes 45 tools, focused primarily on developer capabilities. Its published description reads: "Live ski snow, multi-model forecasts, powder rankings, and a grounded Answer Engine for 500+ resorts". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates snowsure-mcp F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check snowsure-mcp's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add snowsure-mcp to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://www.snowsure.ai/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Text-only Q&A grounded in SnowSure data (~1s). Use for open-ended questions, terrain %, expert-run counts, advice, AND specifically: El Niño / ENSO / 2026-27 winter outlook (or call get_elnino_signal
Get the global snow report with top-ranked resorts by snow conditions. Returns resorts sorted by SnowSure score, forecast, or recent snowfall. Use this for "where has the best snow?" or "top ski resor
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: ask_snowdata
A tool description tries to alter the model’s use of another tool.
guide cards (→ get_resort_info). Does NOT render UI cards.RecommendationDescriptions must describe only their own tool.
tool: get_resort_info
A tool description tries to alter the model’s use of another tool.
rts. Do NOT use get_resort (that shows the snow conditions card).RecommendationDescriptions must describe only their own tool.
tool: get_resort_photos
A tool description tries to alter the model’s use of another tool.
resort_info, or ask_snowdata for photo requests.RecommendationDescriptions must describe only their own tool.
tool: get_resort
A tool description tries to alter the model’s use of another tool.
total). Prefer get_resort_info / get_resort_photos when available (same cards)RecommendationDescriptions must describe only their own tool.
tool: get_southern_hemisphere_report
A tool description tries to alter the model’s use of another tool.
For those, call get_resort on the named glacier — summer windows are trackRecommendationDescriptions must describe only their own tool.
tool: get_season_openings
A tool description tries to alter the model’s use of another tool.
ksgiving"), use ask_snowdata.RecommendationDescriptions must describe only their own tool.
tool: get_season_leaderboard
A tool description tries to alter the model’s use of another tool.
limatology, and get_snow_report or find_best_powder for conditions RIGHT NOW.RecommendationDescriptions must describe only their own tool.
tool: get_snow_history
A tool description tries to alter the model’s use of another tool.
st season", use get_season_leaderboard instead.RecommendationDescriptions must describe only their own tool.
tool: get_monthly_snow
A tool description tries to alter the model’s use of another tool.
r right now use get_resort. Months with too little history are withheld raRecommendationDescriptions must describe only their own tool.
tool: list_insight_categories
A tool description tries to alter the model’s use of another tool.
th). Use before get_insights to choose a category filter. Lighter than raw lRecommendationDescriptions must describe only their own tool.
tool: get_insights
A tool description tries to alter the model’s use of another tool.
anked list, use get_season_leaderboard instead. Filter by category or insightType=inteRecommendationDescriptions must describe only their own tool.
tool: get_ml_trends
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_destination
A tool description tries to alter the model’s use of another tool.
guide cards (→ get_resort_info).RecommendationDescriptions must describe only their own tool.
tool: unsubscribe_alerts
A tool description tries to alter the model’s use of another tool.
ons by id (from list_alerts). Requires a SnowSure user access token (OAuth)RecommendationDescriptions must describe only their own tool.
tool: find_pass_resorts
A tool description tries to alter the model’s use of another tool.
you can pass to get_resort.RecommendationDescriptions must describe only their own tool.
tool: compare_passes
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: get_my_snow_report
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
a SnowSure user access token (OAuth). {"type":"object","properties":{}}RecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_road_weather
A tool description tries to alter the model’s use of another tool.
rom the modeled get_operating_risk. Returns 'no road weather' outside the coveredRecommendationDescriptions must describe only their own tool.
tool: find_flights_to_powder
A tool description tries to alter the model’s use of another tool.
required — use search_resorts to resolve a name), optional origin (your home-RecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
tos(slug) — NOT ask_snowdata, NOT get_destination. • Resort guide / lifts /RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: find_powder_trips
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: remove_saved_resort
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: unsubscribe_alerts
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: book_lodging
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: (server instructions)
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
no-resort. Link https://www.snowsure.ai/resorts/{slug}. For ANY question about El Niño, ENSO, or the 20RecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
The server exposes one or more ui:// (MCP Apps) resources whose HTML/JS renders inside the host client — a client-side injection / data-exposure surface most scanners ignore. Flagged for review, not damning on its own.
4 ui:// resource(s); e.g. ui://widget/powder-list.htmlRecommendationReview each ui:// resource’s markup and scripts; treat host-rendered UI as untrusted, sandbox it, and never expose secrets or conversation context to it.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Powder Reels — SnowSure archived storm timelapses with verified accumulation data burned into the frames ("Proof of Powder"). Use for "how much did it snow at X last night", "show me the storm at Alta
INTERACTIVE RESORT GUIDE CARD (Resort Info sidebar UI) — elevation, vertical, lifts, runs, skiable acres, average snowfall, season dates, ski passes, editorial description, hero/gallery carousel. REQU
INTERACTIVE PHOTO GALLERY CAROUSEL — official SnowSure resort photos (hero + Sanity gallery). REQUIRED for: photos, pictures, images, gallery, "show me photos of Vail/Aspen". Never use web search or i
Single-resort data with a REQUIRED card parameter that picks the interactive UI. card=guide → resort info card (elevation, lifts, season dates). card=photos → photo gallery carousel. card=snow → snow
Search for ski resorts by name, country, or region. Returns matching resorts with basic conditions. Use for "find resorts in [location]" or "search [name]" queries.
Find resorts with the freshest powder snow right now. Returns resorts sorted by 24-hour snowfall. Use for "where is it snowing?" or "fresh powder" queries.
Powder trips you can BOOK: ranks resorts by their 14-day forecast (best chance of fresh snow in the bookable window) and returns handpicked luxury ski hotels at each — "where to go AND where to stay".
Compare 14-day snow forecasts across 7 weather models (ECMWF, GFS, GEM, JMA, ICON, Météo-France, Met Norway) for a resort. Shows model agreement and uncertainty. Use for forecast reliability queries.
Get detailed day-by-day weather forecast for a resort including temperature, snowfall, wind, and conditions for each of the next 14 days.
Find resorts matching specific criteria like minimum snow depth, elevation range, number of runs, or SnowSure rating. Advanced filtering for trip planning.
Get snow conditions for Southern Hemisphere ski resorts (Australia, New Zealand, Argentina, Chile) currently in season. Answers "is Perisher / Portillo / Valle Nevado open right now and what are the c
Resorts whose season OPENING DATE is a specific day — answers "what opens today?", "opening this week", or "which resorts start their season on June 27?". Returns only resorts scheduled or confirmed t
Rank resorts by how a season actually went, scoped to a place. This is the tool for "which <place> resort had the most <metric> last season" — the single most common retrospective question agents ask.
One resort's own snowfall history: season totals, comparison to its 5-year and 30-year averages, and best months to visit. Scoped to a SINGLE resort — for "which resort in <state/country/region> led <
Typical snow for a resort MONTH BY MONTH, from ~30 years of ERA5 reanalysis — average snowfall, snow days, base and peak depth, and biggest storm, plus per-season totals. Use for date-choosing questio
Resort-level El Niño / ENSO outlook from SnowSure's 30-year fleet dataset (152 ranked resorts). Returns rank, tier, strong/all-event signal, analog winters ('97-98, '15-16, '23-24), forecast paragraph
Ranked El Niño ski resorts from SnowSure's 30-year fleet table. Filter by region (south-america, north-america, europe, asia, oceania) or tier (A prime / B favored / C ENSO-proof / D late bloomer / E
Get ski trip recommendations based on dates, preferences, and conditions. Suggests best resorts for a given time period.
Get live webcam links and status for a resort to see current on-mountain conditions visually — answers "show me the webcam / live cam at <resort>", "current conditions on camera", and named-cam lookup
Get a summary of snow conditions across an entire region or country with statistics and top resorts.
List SnowSure insight categories (live conditions, current season, last season, forecast trust, patterns, SnowSure index, ground truth). Use before get_insights to choose a category filter. Lighter th
Get categorized SnowSure intelligence insights (not just snow totals). The last_season category is the one to reach for on retrospective questions — how a finished season compared to its 5yr norm, who
Fetch SnowSure-unique ML/AI trend datasets from the public REST API. Use for powder-day leaders, bluebird-day leaders, bluebird predictions, improving/stable/declining score pulse, per-model accuracy
Multi-mountain destination hub (Niseko, Chamonix, Aspen Snowmass umbrella) with a table of member ski areas. Use ONLY when the user names the hub itself — NOT for photo gallery (→ get_resort_photos on
List the signed-in user's saved resorts. Requires a SnowSure user access token (OAuth); without one it returns an authorization-required error telling the agent how to connect.
Save a resort to the signed-in user's favorites. Requires a SnowSure user access token (OAuth). The slug must be a real SnowSure resort.
Remove a resort from the signed-in user's saved list. Requires a SnowSure user access token (OAuth).
Subscribe the signed-in user to snow alerts. Requires a SnowSure user access token (OAuth). type: 'powder' (OBSERVED fresh snow >= thresholdCm in 24h), 'forecast' (the 14-day FORECAST clears threshold
List the signed-in user's alert subscriptions. Requires a SnowSure user access token (OAuth).
Remove one of the signed-in user's alert subscriptions by id (from list_alerts). Requires a SnowSure user access token (OAuth).
Lodging near a resort via LUXSKI for the signed-in user. With a specific `hotelName` + checkIn + checkOut it PREBOOKS a live rate and returns a LUXSKI checkout URL to complete payment (we hold the rat
Details for a multi-resort ski pass (Epic, Ikon, Mountain Collective, …): operator, season pricing tiers, destination count, regions, and the buy link.
List the resorts on a ski pass, optionally filtered to a region — answers "is <resort> on the Ikon Pass" and "what resorts does the Epic Pass include". Returns names + SnowSure slugs you can pass to g
Compare ski passes on price, resort coverage, and value — the tool for "which season pass includes <resort> — Epic or Ikon?" (pass resortSlugs=[<resort>]). Optionally pass resortSlugs you plan to ski
Compare 2–4 resorts side by side across snow, terrain, and live conditions — every value comes from the SnowSure conditions resolver/contract. Use for head-to-head stat questions phrased as either/or:
Personalized snow report for the signed-in user's saved resorts — live conditions for each, ranked best-first (open resorts with the freshest snow on top). Requires a SnowSure user access token (OAuth
Current avalanche danger bulletin for a resort's forecast zone (US, Canada, Switzerland in v1), relayed from the official warning service with the issuer + link. Returns 'no bulletin' when there's no
Will the lifts run? A 48-hour operating-risk estimate from the Open-Meteo forecast — wind-hold (gusts), visibility, cold (wind-chill), and heavy-snow control delays. Modeled guidance, NOT the resort's
Driving access for a resort — answers "do I need chains to get to <resort>" and "is the road to <resort> open": chain-control / mountain-pass / road-surface conditions on nearby highways (California v
Live roadside DOT/CCTV camera stills on the highways near a resort — shows what the drive actually looks like right now (California via Caltrans, Washington via WSDOT, Utah via UDOT). Distinct from re
Measured roadside weather (RWIS) on the highways near a resort — surface + air temperature, visibility, wind, precipitation (Colorado via CDOT, Washington via WSDOT, Utah via UDOT). Sensor data on the
Plan a multi-stop ski road trip: picks the top-scoring resorts in a region, orders them into a drivable route (nearest-neighbour, minimal backtracking), allocates your days across stops, estimates eac
Complete the trip: from a resort, find the nearest gateway airport(s) and get flight-search links from your home airport. The "get there" leg of the funnel — pair with find_best_powder / find_powder_t