
Is VeteranHQ MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highWrite-action tools reachable without authentication
Public scan report
scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it
1 high2 low
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 197ms20/20
- Tool poisoning11 tool descriptions checked13/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (3)
- highWrite-action tools reachable without authentication
auth.open-write - lowUnusually long tool description (over 2,000 characters)
poison.long-descriptiontool search_legal_authority: …Use this when a question calls for the text of a VA rating regulation, the wording of a legal standard, or case law, searched by keyword, by exact citation, or by diagnostic code. Returns 38 CFR rating criteria for matching conditions; doctrine entries quoted verbatim from the regulation, statute or decision they come from, each with pinpoint citations, the date the text was captured, when that text took effect, and the reviewed holdings that construe it; and excerpts from Court of Appeals for Veterans Claims decisions with docket number, case name and relevance score. CAVC decisions are binding precedent for the Board of Veterans' Appeals. The citation parameter takes a section such as "3.310", "38 CFR 3.310(b)" or "38 U.S.C. 5107(b)", and a citation that cannot be read as a section matches nothing rather than being guessed at. A citation on its own is a complete call: query is optional when citation is supplied, and a call carries query, citation, or both. The limit parameter caps results per source, default 5 and maximum 10; the doctrine block is capped at four entries per response and reports the true total. The status field describes the answer in one of four words. "ok" means every component answered and this response carries each matched result it selected. "partial" means a matched result is missing from it, whether shed for the size budget, withheld as a criterion text too long to fit, or unreachable because a component could not complete its search. "no_match" means every component answered and none of them matched. "unavailable" means a component did not answer, so nothing in that response is readable as an absence of authority. statusReason gives the reason for that word in one sentence, derived from the same values as the word itself. A truncation object reports what was shortened, whatever the status: doctrinePropositionsTrimmed counts entries serving their first propositions while reporting their own true total, textBounded says a criterion text was withheld whole rather than cut, and resultsDropped counts the matched results this response does not carry, under regulatory, caseLaw and doctrine. Shortening that keeps every selected result arrives as status "ok" with truncation populated. Docket numbers and case names come only from the returned results, and when the case-law corpus is empty the response says so and returns the regulatory and doctrine results alone. When a response would exceed its size budget it sheds results rather than overrunning, reports responseTrimmedForSize alongside the true totals, and withholds a criterion text too long to fit whole rather than cutting it: that row carries criteriaOmitted and the length of what was withheld, so a partial rule does not arrive as a complete one. citationResolved says whether any source carries the citation supplied: true on positive evidence, false only where the corpus-wide membership scan completed and nothing named the section, and null where that scan did not complete, which is an open question rather than a finding of absence. citationStatus renders the same answer as resolved, unresolved, unknown, unparsed or not_supplied. The coverage block reports how far the search reached: citationScanComplete for that membership question, candidateScansComplete with incompleteCandidateScans for components whose scan window filled before every candidate was examined, truncatedComponents for the sources whose results were shortened, doctrineMatchedOn for whether the doctrine entries came from the citation, the query or the standing authorities, and searchComplete for the conjunction of all of it. totalsAreMeasuredCounts says whether the totals count everything that matched; where it is false a zero is bounded by this search rather than by the corpus. It does not read an individual claim, it does not predict how a claim will be decided, and it is not legal advice.…
- lowNo source repository listed
maint.no-repo
Overall 57/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what VeteranHQ does
- HasData Google HotelsGoogle Hotels search: rates, ratings, amenities and what each booking site charges, as JSON.not reviewedGrowingA