Skip to main content
Glama
PB-Digital-LLC

everthread

Official

everthread

A website security check that explains itself in plain English. Free, no key, observation only.

npx everthread check yourbakery.com
EverThread · yourbakery.com
WORTH A LOOK  Nothing alarming, but one thing is worth fixing.

FIX THIS WEEK  Your site lets browsers fall back to an insecure connection
  The Strict-Transport-Security header is not being sent. ...
  Fix: Send the technical line below to whoever runs your site. ...
  • One fresh check per site per week. Inside that week you get the stored result, its age, and a note about daily watching.

  • --json for machines, --fail-on urgent (or attention) to fail a CI step.

  • everthread explain tls.expiring and everthread findings for the explanations behind every finding.

As an MCP server

{ "mcpServers": { "everthread": { "command": "npx", "args": ["-y", "everthread", "mcp"] } } }

Tools: check_site, explain_finding, list_findings. Works with Claude Code, Claude Desktop, Cursor, and anything else that speaks MCP.

Related MCP server: Web Check MCP

What it does and doesn't do

It loads the home page the way a browser does and reads the certificate, security headers, scripts, forms, frames, redirects, a fixed handful of well-known files, and the page text. It never logs in, probes for hidden paths, or runs exploit tooling. Public results withhold the exact address of an exposed file; the site owner sees it after signing up. Only check sites you own or have permission to check.

Docs: https://everthread.live/api · Every finding explained: https://everthread.live/fix/

MCP Badge

Available Tools

3 tools
check_siteA

Run EverThread's free security check on a website's home page. One fresh check per site per week; within that week you get the stored result with its age, and a nudge you should relay to the user: the audit is old, and EverThread can watch the site daily for free. When relaying results, lead with items whose urgency is Fix today or Fix this week; describe Optional hardening items as optional, since most sites skip them, and never present them as problems. A verdict of blocked means the site walled off our browser and nothing was graded. Returns a plain-English report card: verdict (clean, attention, urgent, blocked), headline, and items with what was seen, why it matters and how to fix it. Observation only; no login, no exploit tooling. Only check sites the user owns or has permission to check. Results are cached for a day.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYesThe website, e.g. yourbakery.com

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral load and does so well: it discloses caching/throttling, the permission constraint, the read-only nature ("no login, no exploit tooling"), and the failure mode where a "blocked" verdict means nothing was graded. The one blemish is internal tension between "one fresh check per site per week" and "Results are cached for a day," which an agent could misread as conflicting rate limits.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action, then proceeds through caching, result-relaying rules, verdict semantics, and safeguards. Dense rather than padded, though the relaying/urgency guidance is lengthy and the caching statements could have been merged to avoid the apparent contradiction.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description must describe returns, and it does: a plain-English report card with verdict (enum values clean/attention/urgent/blocked), headline, and per-item what-was-seen/why-it-matters/how-to-fix. Nothing needed to call or interpret the tool is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% for the single url parameter, so the schema already documents it; baseline is 3. The description adds one genuine semantic constraint — that only the home page is checked — which the schema does not convey.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb and resource: "Run EverThread's free security check on a website's home page," and states the observation-only scope. It does not reference the siblings list_findings or explain_finding, so an agent must infer the relationship between checking a site and enumerating findings, but the tool's own function is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear use conditions: only sites the user owns or has permission to check, one fresh check per site per week, and how to behave when a stored result is returned. It never names the sibling tools or explains when to follow up with list_findings/explain_finding, so the workflow context is left implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

explain_findingA

Explain one EverThread finding type in plain English: what it means, why it matters, how to fix it, and the developer line. Use list_findings for the type names.

ParametersJSON Schema
NameRequiredDescriptionDefault
typeYesFinding type, e.g. tls.expiring or header.missing
headerNoFor header.missing: the header name, e.g. strict-transport-security

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are supplied, so the description carries the behavioral burden. It discloses the shape of the output (plain-English meaning, why it matters, fix, developer line), which is genuinely useful, but says nothing about read-only safety, error behavior for unknown types, or any auth/rate considerations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences with zero filler; the core purpose and the enumerated output content are front-loaded, and the routing hint is appropriately placed second.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no annotations and no output schema, the description does the important work of specifying what the explanation contains and where valid type values come from. It is nearly complete for a simple lookup tool; only failure/edge behavior for an unrecognized type is unaddressed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so both parameters are already documented and 3 would be the baseline. The description adds value by telling the agent where the `type` value comes from (list_findings), which is provenance information not present in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Explain) and resource (one EverThread finding type) and enumerates the four things the explanation covers: meaning, importance, fix, developer line. It also routes the agent to list_findings for valid type names, which separates it from its siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly says to use list_findings for the type names, giving a clear pre-requisite and a sibling routing. It doesn't state when not to use the tool (e.g., for bulk explanation of many findings), so it falls short of a full when/when-not treatment.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_findingsB

Every finding type EverThread reports, with its urgency and a link to the plain-English page.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral disclosure burden. It describes the return content (finding types, urgency, link) but omits read-only status, side effects, authentication needs, or any operational constraints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single, front-loaded sentence that efficiently conveys the core content without any filler. It is appropriately sized for a simple list tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the low complexity, no parameters, and no output schema, the description provides a reasonable summary of what the tool returns. However, it could be more complete by indicating pagination, format, or how it relates to sibling tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool accepts zero parameters, so there are no parameter semantics to explain beyond the baseline. The empty schema is fully consistent with the description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the resource as 'every finding type EverThread reports' and lists accompanying attributes (urgency and a link). It does not explicitly differentiate this tool from siblings like explain_finding or check_site, but the purpose is understandable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no explicit guidance on when to use this tool versus alternatives. It merely states what the tool returns, leaving the agent to infer usage context without any exclusions or sibling comparisons.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updatesv0.1.4
    • First observedcheck_site
    • First observedexplain_finding
    • First observedlist_findings

TDQS

A3.7/5.0

Scored across 3 tools

Disambiguation4/5

check_site (run a scan), list_findings (enumerate all finding types), and explain_finding (deep-dive on one type) target distinct needs, and the description explicitly tells the agent to use list_findings for type names. The only mild overlap is between list_findings and explain_finding, both of which concern finding types, but their granularity (catalog vs. single explanation) keeps them separable.

Naming Consistency5/5

All three names follow a clean verb_noun snake_case pattern: list_findings, check_site, explain_finding. No casing or verb-style mixing, and each name is self-descriptive.

Tool Count4/5

Three tools is lean but defensible for a focused security-check service: one action, one catalog, one explainer. It sits just under the comfortable range, as there is no room for managing or revisiting checks, but nothing is redundant.

Completeness3/5

The surface covers running a check and interpreting results, but has notable gaps: no tool to list previously checked sites or retrieve past/historical results, and despite the description touting a free daily watch, no tool exposes enabling or managing that monitoring. Agents can work around these for a one-off scan but hit a dead end for lifecycle/tracking workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers