MCP server · trust report
eu.sirenic/sirenic
2 checks that ran failed — credential hygiene and version behavior — so this release can’t be trusted as-is.
- Publisher
- eu.sirenic
- Repository
- —
- Install
- remote only
- Versions
- 2
- MCP revision
- 2025-11-25 · superseded
- Inspected
- 5 of 6 checks · 85%
- Scored
- 2026-09-02 · rubric 1.0.0
What we checked
Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.
Injection surface
warn25% of gradeTool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).
tool "search_french_companies" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_profile" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_french_company_establishments" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "prepare_french_einvoicing_recipient" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_default_risk" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_sector_benchmarks" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_capital" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_intellectual_property" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_changes" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "search_french_company_directors" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_legal_alerts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_financials" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_public_procurement" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "find_expiring_french_public_contracts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_public_buyer_profile" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_company_procurement_competitors" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "search_european_companies" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_european_company_profile" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_spanish_company_acts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_uk_company_officers" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_uk_beneficial_owners" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_uk_company_insolvency" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_belgian_company_filings" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_belgian_company_filing" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_finnish_company_filings" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_finnish_company_filing" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_norwegian_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_norwegian_company_legal_events" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_danish_company_filings" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_danish_company_filing" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_danish_company_officers" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_slovak_company_filings" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_slovak_company_filing" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_uk_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_uk_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_latvian_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_latvian_company_insolvency" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_latvian_company_officers" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_latvian_company_beneficial_owners" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_estonian_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_estonian_company_registry_rulings" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_swedish_company_accounts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_swedish_company_registry_events" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_czech_company_insolvency" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_polish_company_registry_events" description: bare 'IMPORTANT:' prose in a description (tag form is high-confidence; prose is warn). tool "get_polish_company_registry_events" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_intelligence" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_pdf_report" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "list_french_company_documents" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "download_french_company_document" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "prospect_french_companies" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_health_summary" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_kyb_file" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_kyb_batch" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "compare_french_companies" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "screen_sanctions_lists" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "prepare_european_invoice_file" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_belgian_insider_transactions" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_german_insider_transactions" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_company_licences" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_industrial_risk" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_hiring_signals" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "prepare_french_invoice_file" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "verify_french_invoice" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "verify_iban_bank" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "search_bodacc_announcements" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_file" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "create_surveillance_watch" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "renew_surveillance_watch" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_eu_procurement_awards" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "get_french_company_lobbying" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "check_french_regulator_alerts" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "search_eu_financial_authorisations" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes. tool "validate_eu_vat_number" param "api_key" description: off-vendor URL in a description (api.sirenic.eu); capability text should not name where data goes.
Supply chain
warn25% of gradePackage provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.
no resolvable repository linked to the package (provenance unverifiable)
Credential hygiene
fail15% of gradeHow the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.
tool "search_french_companies" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_profile" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_french_company_establishments" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "prepare_french_einvoicing_recipient" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_default_risk" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_sector_benchmarks" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_capital" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_intellectual_property" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_changes" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "search_french_company_directors" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_legal_alerts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_financials" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_public_procurement" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "find_expiring_french_public_contracts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_public_buyer_profile" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_company_procurement_competitors" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "search_european_companies" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_european_company_profile" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_spanish_company_acts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_uk_company_officers" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_uk_beneficial_owners" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_uk_company_insolvency" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_belgian_company_filings" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_belgian_company_filing" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_finnish_company_filings" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_finnish_company_filing" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_norwegian_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_norwegian_company_legal_events" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_danish_company_filings" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_danish_company_filing" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_danish_company_officers" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_slovak_company_filings" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_slovak_company_filing" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_uk_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_uk_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_latvian_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_latvian_company_insolvency" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_latvian_company_officers" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_latvian_company_beneficial_owners" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_estonian_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_estonian_company_registry_rulings" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_swedish_company_accounts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_swedish_company_registry_events" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_czech_company_insolvency" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_polish_company_registry_events" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_intelligence" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_pdf_report" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_french_company_documents" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "download_french_company_document" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "prospect_french_companies" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_health_summary" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_kyb_file" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_kyb_batch" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "compare_french_companies" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "screen_sanctions_lists" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "prepare_european_invoice_file" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_belgian_insider_transactions" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_german_insider_transactions" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_company_licences" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_industrial_risk" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_hiring_signals" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "prepare_french_invoice_file" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "verify_french_invoice" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "verify_iban_bank" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "search_bodacc_announcements" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_file" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "create_surveillance_watch" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "renew_surveillance_watch" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_eu_procurement_awards" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_french_company_lobbying" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "check_french_regulator_alerts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "search_eu_financial_authorisations" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "validate_eu_vat_number" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential).
Permission scope
unscannable15% of gradeDeclared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.
No source files, package.json, or pyproject were fetched; cannot infer capability scope.
Version behavior
fail10% of gradeDiff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).
vs prior 1.0.0 (patch bump): tool "search_french_companies" description changed (wording only, no injection pattern); tool "search_french_companies" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_profile" description changed (wording only, no injection pattern); tool "get_french_company_profile" gained secret/exfil-shaped input(s): api_key; tool "list_french_company_establishments" description changed (wording only, no injection pattern); tool "list_french_company_establishments" gained secret/exfil-shaped input(s): api_key; tool "prepare_french_einvoicing_recipient" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_default_risk" description changed (wording only, no injection pattern); tool "get_french_company_default_risk" gained secret/exfil-shaped input(s): api_key; tool "get_french_sector_benchmarks" description changed (wording only, no injection pattern); tool "get_french_sector_benchmarks" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_capital" description changed (wording only, no injection pattern); tool "get_french_company_capital" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_intellectual_property" description changed (wording only, no injection pattern); tool "get_french_company_intellectual_property" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_changes" description changed (wording only, no injection pattern); tool "get_french_company_changes" gained secret/exfil-shaped input(s): api_key; tool "search_french_company_directors" description changed (wording only, no injection pattern); tool "search_french_company_directors" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_legal_alerts" description changed (wording only, no injection pattern); tool "get_french_company_legal_alerts" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_financials" description changed (wording only, no injection pattern); tool "get_french_company_financials" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_public_procurement" description changed (wording only, no injection pattern); tool "get_french_company_public_procurement" gained secret/exfil-shaped input(s): api_key; tool "search_european_companies" description changed (wording only, no injection pattern); tool "search_european_companies" gained secret/exfil-shaped input(s): api_key; tool "get_european_company_profile" description changed (wording only, no injection pattern); tool "get_european_company_profile" gained secret/exfil-shaped input(s): api_key; tool "get_spanish_company_acts" gained secret/exfil-shaped input(s): api_key; tool "get_uk_company_officers" description changed (wording only, no injection pattern); tool "get_uk_company_officers" gained secret/exfil-shaped input(s): api_key; tool "get_uk_beneficial_owners" description changed (wording only, no injection pattern); tool "get_uk_beneficial_owners" gained secret/exfil-shaped input(s): api_key; tool "get_uk_company_insolvency" description changed (wording only, no injection pattern); tool "get_uk_company_insolvency" gained secret/exfil-shaped input(s): api_key; tool "list_belgian_company_filings" description changed (wording only, no injection pattern); tool "list_belgian_company_filings" gained secret/exfil-shaped input(s): api_key; tool "get_belgian_company_filing" description changed (wording only, no injection pattern); tool "get_belgian_company_filing" gained secret/exfil-shaped input(s): api_key; tool "list_finnish_company_filings" description changed (wording only, no injection pattern); tool "list_finnish_company_filings" gained secret/exfil-shaped input(s): api_key; tool "get_finnish_company_filing" description changed (wording only, no injection pattern); tool "get_finnish_company_filing" gained secret/exfil-shaped input(s): api_key; tool "get_norwegian_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_norwegian_company_legal_events" gained secret/exfil-shaped input(s): api_key; tool "list_danish_company_filings" description changed (wording only, no injection pattern); tool "list_danish_company_filings" gained secret/exfil-shaped input(s): api_key; tool "get_danish_company_filing" description changed (wording only, no injection pattern); tool "get_danish_company_filing" gained secret/exfil-shaped input(s): api_key; tool "get_danish_company_officers" description changed (wording only, no injection pattern); tool "get_danish_company_officers" gained secret/exfil-shaped input(s): api_key; tool "list_slovak_company_filings" description changed (wording only, no injection pattern); tool "list_slovak_company_filings" gained secret/exfil-shaped input(s): api_key; tool "get_slovak_company_filing" description changed (wording only, no injection pattern); tool "get_slovak_company_filing" gained secret/exfil-shaped input(s): api_key; tool "list_uk_company_accounts" description changed (wording only, no injection pattern); tool "list_uk_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_uk_company_accounts" description changed (wording only, no injection pattern); tool "get_uk_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_latvian_company_accounts" description changed (wording only, no injection pattern); tool "get_latvian_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_latvian_company_insolvency" description changed (wording only, no injection pattern); tool "get_latvian_company_insolvency" gained secret/exfil-shaped input(s): api_key; tool "get_latvian_company_officers" description changed (wording only, no injection pattern); tool "get_latvian_company_officers" gained secret/exfil-shaped input(s): api_key; tool "get_latvian_company_beneficial_owners" gained secret/exfil-shaped input(s): api_key; tool "get_estonian_company_accounts" description changed (wording only, no injection pattern); tool "get_estonian_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_estonian_company_registry_rulings" gained secret/exfil-shaped input(s): api_key; tool "get_swedish_company_accounts" gained secret/exfil-shaped input(s): api_key; tool "get_swedish_company_registry_events" description changed (wording only, no injection pattern); tool "get_swedish_company_registry_events" gained secret/exfil-shaped input(s): api_key; tool "get_czech_company_insolvency" gained secret/exfil-shaped input(s): api_key; tool "get_polish_company_registry_events" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_intelligence" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_pdf_report" description changed (wording only, no injection pattern); tool "get_french_company_pdf_report" gained secret/exfil-shaped input(s): api_key; tool "list_french_company_documents" gained secret/exfil-shaped input(s): api_key; tool "download_french_company_document" gained secret/exfil-shaped input(s): api_key; tool "prospect_french_companies" description changed (wording only, no injection pattern); tool "prospect_french_companies" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_health_summary" description changed (wording only, no injection pattern); tool "get_french_company_health_summary" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_kyb_file" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_kyb_batch" description changed (wording only, no injection pattern); tool "get_french_company_kyb_batch" gained secret/exfil-shaped input(s): api_key; tool "compare_french_companies" gained secret/exfil-shaped input(s): api_key; tool "screen_sanctions_lists" description changed (wording only, no injection pattern); tool "screen_sanctions_lists" gained secret/exfil-shaped input(s): api_key; tool "prepare_european_invoice_file" description changed (wording only, no injection pattern); tool "prepare_european_invoice_file" gained secret/exfil-shaped input(s): api_key; tool "get_belgian_insider_transactions" description changed (wording only, no injection pattern); tool "get_belgian_insider_transactions" gained secret/exfil-shaped input(s): api_key; tool "get_company_licences" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_industrial_risk" description changed (wording only, no injection pattern); tool "get_french_company_industrial_risk" gained secret/exfil-shaped input(s): api_key; tool "prepare_french_invoice_file" description changed (wording only, no injection pattern); tool "prepare_french_invoice_file" gained secret/exfil-shaped input(s): api_key; tool "verify_iban_bank" description changed (wording only, no injection pattern); tool "verify_iban_bank" gained secret/exfil-shaped input(s): api_key; tool "create_surveillance_watch" description changed (wording only, no injection pattern); tool "create_surveillance_watch" gained secret/exfil-shaped input(s): api_key; tool "renew_surveillance_watch" description changed (wording only, no injection pattern); tool "renew_surveillance_watch" gained secret/exfil-shaped input(s): api_key; tool "get_eu_procurement_awards" description changed (wording only, no injection pattern); tool "get_eu_procurement_awards" gained secret/exfil-shaped input(s): api_key; tool "get_french_company_lobbying" description changed (wording only, no injection pattern); tool "get_french_company_lobbying" gained secret/exfil-shaped input(s): api_key; tool "check_french_regulator_alerts" description changed (wording only, no injection pattern); tool "check_french_regulator_alerts" gained secret/exfil-shaped input(s): api_key; tool "search_eu_financial_authorisations" gained secret/exfil-shaped input(s): api_key; tool "validate_eu_vat_number" description changed (wording only, no injection pattern); tool "validate_eu_vat_number" gained secret/exfil-shaped input(s): api_key; new tool "find_expiring_french_public_contracts" appeared; new tool "get_french_public_buyer_profile" appeared; new tool "get_company_procurement_competitors" appeared; new tool "get_german_insider_transactions" appeared; new tool "get_french_company_hiring_signals" appeared; new tool "verify_french_invoice" touches a sensitive surface (email/exec/net/fs); new tool "search_bodacc_announcements" touches a sensitive surface (email/exec/net/fs); new tool "get_french_company_file" touches a sensitive surface (email/exec/net/fs); new tool "suggest_company_names" touches a sensitive surface (email/exec/net/fs).
Transport config
pass10% of gradeRemote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.
remote endpoint "https://api.sirenic.eu/mcp" uses TLS (https); remote endpoint uses OAuth (strongest auth mode)
Version history
Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.
| Version | Published | Grade | Score | Inspected | Change |
|---|---|---|---|---|---|
| v1.0.1 · current | 2026-08-02 | D | 50 | 5/6 · 85% | C→D in v1.0.1 |
| v1.0.0 | 2026-07-17 | C | 65 | 4/6 · 75% | — |