https://www.heista.co/api/mcp/mcp
Remote
v1.0.0
Published by heista.co — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
Decode video ads, load brand intelligence, generate ad scripts.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 6.3 = 94. What the published surface and source actually contain:
| Points | What was found | Category |
|---|---|---|
| −6.3 | Annotation contradicts behavior on "generate_adscript" MTC-CAP-003 | permissions |
2. Client adoption risk — 94 − 6 = 88. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "generate_adscript" appears to run shell commands or evaluate code (parameter "script"). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool generate_adscript
Untrusted-input tools ([decode_ad, get_decode, get_powersource, get_hook_intelligence, adformula_intelligence, decoder_intelligence, perplexity_search, fetch_url, get_saved_asset, get_saved_assets_batch, fleet_gsc_inspect_url, fleet_gsc_sitemaps, fleet_site_audit_summary, fleet_site_pages, fleet_seo_recovery]) co-exist with external-action tools ([create_powersource_url, generate_adscript, fleet_create_issue]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [decode_ad, get_decode, get_powersource, get_hook_intelligence, adformula_intelligence, decoder_intelligence, perplexity_search, fetch_url, get_saved_
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow decode_ad → create_powersource_url
Tool "decode_ad" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool decode_ad · inputSchema.properties.url
Tool "create_powersource_url" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool create_powersource_url · inputSchema.properties.url
Tool "create_powersource_url" takes a URL/host parameter "webhook_url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool create_powersource_url · inputSchema.properties.webhook_url
Tool "fetch_url" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool fetch_url · inputSchema.properties.url
Tool "fleet_gsc_inspect_url" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool fleet_gsc_inspect_url · inputSchema.properties.url
Tool "generate_adscript" advertises destructiveHint=false but its derived capabilities include state-modifying actions (code-exec). Tool annotations are attacker-controllable and must never be trusted; a mismatch like this is exactly how a hostile server hides a destructive tool.
Fix: Ignore server-provided annotations for security decisions; gate destructive tools on explicit user consent.
Location: tool generate_adscript
Each tool and what it can reach — enumerated from the running server.
adformula_intelligenceingests untrusted inputcreate_powersource_urlnetwork egressdecode_adingests untrusted inputdecoder_intelligenceingests untrusted inputfetch_urlingests untrusted inputfleet_create_issuenetwork egressfleet_gsc_inspect_urlingests untrusted inputfleet_gsc_sitemapsingests untrusted inputfleet_seo_recoveryingests untrusted inputfleet_site_audit_summaryingests untrusted inputfleet_site_pagesingests untrusted inputgenerate_adscriptruns code / shellget_decodeingests untrusted inputget_hook_intelligenceingests untrusted inputget_powersourceingests untrusted inputget_saved_assetingests untrusted inputget_saved_assets_batchingests untrusted inputperplexity_searchingests untrusted inputadd_brand_assetno sensitive capabilitycall_creative_agent_presetno sensitive capabilitycall_creative_worldsno sensitive capabilitychat_with_creative_worldsno sensitive capabilitycheck_balanceno sensitive capabilitycreate_powersource_docsno sensitive capabilitycreate_powersource_fullno sensitive capabilitycreative_delete_draftno sensitive capabilitycreative_get_authoring_contractno sensitive capabilitycreative_get_draftno sensitive capabilitycreative_get_shelfno sensitive capabilitycreative_list_articlesno sensitive capabilitycreative_publish_articleno sensitive capabilitycreative_save_draftno sensitive capabilitycreative_unpublish_articleno sensitive capabilitycreative_update_slugno sensitive capabilitydelete_brand_assetno sensitive capabilitydelete_saved_assetno sensitive capabilitydispatch_desk_researcherno sensitive capabilitydispatch_desk_researcher_asyncno sensitive capabilitydispatch_head_of_researchno sensitive capabilitydispatch_market_analystno sensitive capabilitydispatch_market_analyst_asyncno sensitive capabilitydispatch_qualitative_researcherno sensitive capabilitydispatch_qualitative_researcher_asyncno sensitive capabilitydispatch_quantitative_researcherno sensitive capabilitydispatch_quantitative_researcher_asyncno sensitive capabilitydispatch_social_listening_researcherno sensitive capabilitydispatch_social_listening_researcher_asyncno sensitive capabilitydispatch_trend_researcherno sensitive capabilitydispatch_trend_researcher_asyncno sensitive capabilityfavorite_saved_assetno sensitive capabilityfleet_analytics_overviewno sensitive capabilityfleet_analytics_top_pagesno sensitive capabilityfleet_analytics_trendno sensitive capabilityfleet_crawler_hitsno sensitive capabilityfleet_get_brand_reportno sensitive capabilityfleet_get_decoded_adno sensitive capabilityfleet_get_issueno sensitive capabilityfleet_gsc_queryno sensitive capabilityfleet_gsc_summaryno sensitive capabilityfleet_gsc_top_pagesno sensitive capabilityfleet_gsc_top_queriesno sensitive capabilityfleet_intel_statsno sensitive capabilityfleet_list_brand_reportsno sensitive capabilityfleet_list_intelligence_articlesno sensitive capabilityfleet_list_issuesno sensitive capabilityfleet_product_funnel_countsno sensitive capabilityfleet_product_funnel_summaryno sensitive capabilityfleet_product_signups_recentno sensitive capabilityfleet_product_user_summaryno sensitive capabilityfleet_search_decoded_adsno sensitive capabilityfleet_site_linksno sensitive capabilityget_ad_formula_presetno sensitive capabilityget_brandno sensitive capabilityget_cd_card_bookmark_presetno sensitive capabilityget_creative_agent_presetno sensitive capabilityget_creative_agent_skill_presetno sensitive capabilityget_creative_director_playbook_presetno sensitive capabilityget_decoded_ad_presetno sensitive capabilityget_dispatch_resultno sensitive capabilityget_fleet_costno sensitive capabilityget_image_ad_scan_presetno sensitive capabilityget_outfit_presetno sensitive capabilityget_saved_visual_idea_presetno sensitive capabilityget_strategyno sensitive capabilityget_talent_model_presetno sensitive capabilityget_visual_preset_presetno sensitive capabilityget_visual_style_presetno sensitive capabilitylist_ad_formula_presetsno sensitive capabilitylist_brand_assetsno sensitive capabilitylist_brand_documentsno sensitive capabilitylist_brandsno sensitive capabilitylist_cd_card_bookmark_presetsno sensitive capabilitylist_creative_agent_presetsno sensitive capabilitylist_creative_agent_skill_presetsno sensitive capabilitylist_creative_director_playbook_presetsno sensitive capabilitylist_decoded_ad_presetsno sensitive capabilitylist_image_ad_scan_presetsno sensitive capabilitylist_outfit_presetsno sensitive capabilitylist_projectsno sensitive capabilitylist_saved_assetsno sensitive capabilitylist_saved_visual_idea_presetsno sensitive capabilitylist_skillsno sensitive capabilitylist_strategiesno sensitive capabilitylist_strategy_audiencesno sensitive capabilitylist_strategy_tonesno sensitive capabilitylist_talent_model_presetsno sensitive capabilitylist_visual_preset_presetsno sensitive capabilitylist_visual_style_presetsno sensitive capabilityload_skillno sensitive capabilityload_skill_referenceno sensitive capabilityread_brand_documentno sensitive capabilityreclassify_brand_assetsno sensitive capabilityretag_brand_assetno sensitive capabilitysave_assetno sensitive capabilitysearchno sensitive capabilitysearch_communityno sensitive capabilitysearch_researchno sensitive capabilitysearch_skillsno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.0 latest |
B 88/100 | 8 | 1.13.0 | 2026-09-06 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan https://www.heista.co/api/mcp/mcp --online
Turn designs into shipped parts: quote 3D printing, CNC, and decals, then check out.
Aleph's official SiliconFlow media-generation MCP server (image / video / TTS)
MCP server for image generation using Google Gemini AI
Ambience AI MCP Server - Generate images, videos, and audio through Model Context Protocol
MCP server exposing every endpoint of the AstroWay Calculation API as tools — natal, synastry, transits, Vedic dashas, Tarot, Numerology, Human Design, AI horoscopes — for Claude Desktop, Cursor and any MCP-compatible AI agent.
Audio-guide and trip-planning tools for 1,100+ cities from Audiala. Free, no API key.