Talandor Sandbox
Methodology

Facts before confidence.

In one minute

We check public MCP endpoints without credentials or tool calls, record what is observable, and compare complete public snapshots over time. The result separates measured facts, research sampling and publisher-provided content.

How to read a report

Measured by Talandor Sandbox: reachability, MCP protocol, authentication challenge, public tool count and latency.

Estimated by Talandor Sandbox: client setup guidance based on published configuration requirements. “Likely compatible” is not a hands-on client test.

Provided by the MCP publisher: tool names, descriptions, schemas and annotations. This content can be written in any language, copied as provided and clearly labelled.

Operational states

Unknown
No exploitable observation was available. This is not a claim that the endpoint is broken.
Operational
A valid MCP response and a complete public tools/list contract were observed, with no confirmed failure in progress.
Reachable · auth required
The endpoint is reachable and returned an expected authentication challenge. Private tools were not inspected and no credentials were used.
Degraded
The endpoint responded, but a non-essential step was incomplete, slow or reproducibly invalid.
Unreachable now
This point-in-time scan failed to reach or qualify the endpoint. It does not prove a lasting outage; “Down” is reserved for a confirmed watch state.

Cadence and scope

An anonymous check runs once when submitted. The research sample covers up to 50 indexed endpoints on a six-hour collection pass. When public worker monitoring is enabled, availability checks run about every five minutes and deep public-contract checks about every hour. Personal watches are not active in this deployment.

Snapshots and diffs

Only snapshots marked full (a recognized protocol and an exhausted public tools/list) can become a contract baseline. A partial snapshot never replaces a full baseline and is never called complete. A diff compares protocol-compatible full snapshots by semantic hash, then classifies changes such as removed tools or newly required inputs. The current contract-diff rule version is 0.1.0.

Client rules and dates

Client setup guidance is inference, not a certification. The displayed client rules are versioned as v0.2 and reviewed . Each report also shows the observed protocol version and observation time.

Glossary

Official Registry
The upstream catalogue. Talandor Sandbox indexes only entries with a safe public HTTPS Streamable HTTP endpoint; package-only and unsafe targets are excluded.
Research sample
Up to 50 indexed endpoints checked on a six-hour collection cadence.
Public watch
A worker watch explicitly marked for the public monitoring page; it is separate from the research sample.
Personal watch
A private user watch; personal monitoring is not active in this deployment.

What we test

Talandor Sandbox checks public HTTPS Streamable HTTP endpoints, negotiates the supported MCP protocol versions, reads public tools/list pages within bounded limits, records authentication challenges and compares snapshots over time.

What we never do

We never collect credentials, follow redirects to private networks, execute third-party code or call your tools. Descriptions and schemas are untrusted data.

Reporting and opt-out

For a report correction or endpoint opt-out request, email support@talandor.com and include the public report URL. Never send credentials.

Anonymous reports do not enroll an endpoint in a personal watch. Public worker monitoring is limited to watches explicitly marked public.

Limits

A protected server may expose only its authentication surface. Without credentials, Talandor Sandbox cannot claim a private tools contract or a contract diff. Publisher-provided content is copied as provided and is not translated or verified.