# MCP Kill-Chain Research — Stage 1 (Identity ≠ Behavior)

> Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.

- name: dev.gtfo/mcp-killchain-stage1-weather
- version: 1.1.0
- connection class: unknown (unknown)
- trust: 72/100 flags: no-repository
- quality: 71/100 (needs work)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/dev.gtfo%2Fmcp-killchain-stage1-weather
- tools: https://api.protogrid.dev/v1/servers/dev.gtfo%2Fmcp-killchain-stage1-weather/tools

**Not classified yet.** The remote endpoints have not been probed successfully, or the listing has nothing to connect to.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "mcp-killchain-stage1-weather": {
      "type": "http",
      "url": "https://ailm.gtfo.dev/mcp"
    }
  }
}
```


## Trust

- hygiene: 80
- liveness: 99
- freshness: 65
- provenance: 45
- drivers: +dns-namespace +reachable +uptime-97% ~updated-99d-ago -no-repository
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 71/100 (needs work)

### protocol: n/a (weight 25)

- n/a `protocol.modern`, `protocol.stateless`, `protocol.transport`, `protocol.list_ttl`: no remote answered a protocol handshake (not probed yet, unreachable, or local-only)

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 71 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- fail `tools.annotations`: no tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones
- fail `tools.directory_hints`: no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: get_weather (readOnlyHint, destructiveHint, idempotentHint, openWorldHint)
- pass `tools.token_cost`: about 61 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: n/a (weight 15)

- n/a `stability.changes`, `stability.rug_pull`: tool history not recorded yet

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 1, about 61 tokens to load them all
- badge: [![protogrid quality](https://protogrid.dev/badge/dev.gtfo/mcp-killchain-stage1-weather.svg)](https://protogrid.dev/servers/dev.gtfo/mcp-killchain-stage1-weather)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Remotes

- https://ailm.gtfo.dev/mcp (streamable-http, auth unknown, reachable true, uptime30d 0.97402596)

## Packages

_none_

## Tools (1)

- `get_weather`: Fetches current weather conditions for a given city.
