MCP Server

turva-mcp

dev.turva/turva-mcp
Security Public & reachable MCP 2025-11-25

What this MCP does

Provides agent-readiness information, web-security scan evidence, service details, and engagement information for an audit and advisory service.

get_agent_readiness
Agent-readiness score
Returns turva.dev's own agent-readiness score from an independent public scanner (isitagentready.com), including category sub-scores, with the measurement date and verification links. Use this when a user asks how turva.dev scores, whether its claims are verifiable, or what proof backs the audit service. For web-security scan results, which are a separate measurement, use get_security_evidence instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'measured_at', 'note', 'scans'], 'properties': {'note': {'type': 'string'}, 'scans': {'type': 'array', 'items': {'type': 'object', 'required': ['provider', 'result', 'note', 'categories', 'url'], 'properties': {'url': {'type': 'string'}, 'note': {'type': 'string'}, 'result': {'type': 'string'}, 'provider': {'type': 'string'}, 'categories': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string'}}}, 'additionalProperties': False}}, 'domain': {'type': 'string'}, 'measured_at': {'type': 'string', 'description': 'Date of the reading, YYYY-MM-DD.'}}, 'additionalProperties': False}
get_contact
Contact and operator details
Returns who runs turva.dev and the official ways to reach it: the operator and business details, the email address, the Signal link, the LinkedIn profile, the correspondence languages, the first-reply time and the access an audit needs. Use this when a user asks who is behind turva.dev, how to contact it, how to start an audit or what access has to be granted. For what is sold and what it costs use get_services instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['email', 'signal', 'linkedin', 'business_id', 'location', 'engagement', 'correspondence_languages', 'first_reply', 'channel_note', 'how_to_start', 'operator'], 'properties': {'email': {'type': 'string'}, 'signal': {'type': 'string'}, 'linkedin': {'type': 'string'}, 'location': {'type': 'string'}, 'operator': {'type': 'object', 'required': ['name', 'run_by', 'legal_form', 'business_id', 'vat_id', 'location', 'team', 'background', 'company_page'], 'properties': {'name': {'type': 'string'}, 'team': {'type': 'string'}, 'run_by': {'type': 'string'}, 'vat_id': {'type': 'string'}, 'location': {'type': 'string'}, 'background': {'type': 'string'}, 'legal_form': {'type': 'string'}, 'business_id': {'type': 'string'}, 'company_page': {'type': 'string', 'description': 'The turva.dev page that states the business details.'}}, 'additionalProperties': False}, 'engagement': {'type': 'string'}, 'business_id': {'type': 'string'}, 'first_reply': {'type': 'string'}, 'channel_note': {'type': 'string'}, 'how_to_start': {'type': 'array', 'items': {'type': 'string'}}, 'correspondence_languages': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}
get_principles
Engagement principles
Returns turva.dev's engagement principles: async-only, least access, the result shows up in scanner numbers, and open and verifiable. Use this when a user asks how turva.dev works with clients or what rules an engagement follows. For what is sold and what it costs use get_services instead, and for how to start use get_contact. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['model', 'rules'], 'properties': {'model': {'type': 'string'}, 'rules': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'rationale'], 'properties': {'id': {'type': 'string'}, 'title': {'type': 'string'}, 'rationale': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}
get_security_evidence
Web-security scan evidence
Returns the latest public web-security scan results for turva.dev's own domain (Hardenize, Internet.nl site and mail), with the scan date. Use this when a user asks about turva.dev's own security posture or wants evidence beyond agent-readiness scores. For the agent-readiness score itself, which is a separate measurement, use get_agent_readiness instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['domain', 'measured_at', 'scans', 'note'], 'properties': {'note': {'type': 'string'}, 'scans': {'type': 'array', 'items': {'type': 'object', 'required': ['provider', 'url'], 'properties': {'url': {'type': 'string'}, 'note': {'type': 'string'}, 'scale': {'type': 'string'}, 'score': {'type': 'number'}, 'result': {'type': 'string'}, 'provider': {'type': 'string'}}, 'additionalProperties': False}}, 'domain': {'type': 'string'}, 'measured_at': {'type': 'string', 'description': 'Date of the scans, YYYY-MM-DD.'}}, 'additionalProperties': False}
get_services
Service catalog and pricing
Returns turva.dev's service catalog: the Shopify agent storefront check, agent-readiness audit, advisory, implementation, agent operations, and MCP server design, plus the engagement model and pricing (fixed list prices for the Shopify agent storefront check, audit, advisory and implementation; agent operations and MCP server design on request), and two implementation add-ons that carry a fixed price and are sold only with the diagnosis they follow, bought with it, with its report, or after the report and before implementation starts. Use this when a user asks what turva.dev offers, what it costs, or how an engagement works. For how to reach turva.dev use get_contact instead, and for the rules an engagement follows use get_principles. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['pricing_model', 'pricing_note', 'currency', 'vat_included', 'engagement', 'services', 'bundled_implementation'], 'properties': {'currency': {'type': 'string'}, 'services': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'url', 'price', 'summary', 'deliverable'], 'properties': {'id': {'type': 'string'}, 'url': {'type': 'string', 'description': 'The turva.dev page that describes the service.'}, 'name': {'type': 'string'}, 'unit': {'type': 'string'}, 'price': {'anyOf': [{'type': 'number'}, {'type': 'string', 'const': 'on request'}], 'description': 'EUR, VAT not included, or on request.'}, 'summary': {'type': 'string'}, 'duration': {'type': 'string'}, 'sample_url': {'type': 'string', 'description': 'A published sample of the deliverable, where one exists.'}, 'deliverable': {'type': 'string'}, 'minimum_commitment': {'type': 'string'}}, 'additionalProperties': False}}, 'engagement': {'type': 'object', 'required': ['communication', 'notes'], 'properties': {'notes': {'type': 'array', 'items': {'type': 'string'}}, 'communication': {'type': 'string'}}, 'additionalProperties': False}, 'pricing_note': {'type': 'string'}, 'vat_included': {'type': 'boolean'}, 'pricing_model': {'type': 'string'}, 'bundled_implementation': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'price', 'unit', 'requires', 'sold_separately', 'summary'], 'properties': {'id': {'type': 'string'}, 'name': {'type': 'string'}, 'unit': {'type': 'string'}, 'price': {'type': 'number'}, 'summary': {'type': 'string'}, 'requires': {'type': 'string', 'description': 'The id of the service this add-on is sold with.'}, 'sold_separately': {'type': 'boolean'}}, 'additionalProperties': False}}}, 'additionalProperties': False}
Changed
get_services
Oct. 1, 2026, 2:43 a.m.
Changed
get_contact
Sept. 25, 2026, 2:50 a.m.
Changed
get_principles
Sept. 25, 2026, 2:50 a.m.
Changed
get_security_evidence
Sept. 25, 2026, 2:50 a.m.
Changed
get_agent_readiness
Sept. 25, 2026, 2:50 a.m.
Changed
get_services
Sept. 25, 2026, 2:50 a.m.
Added
get_contact
Sept. 17, 2026, 12:39 p.m.
Added
get_principles
Sept. 17, 2026, 12:39 p.m.
Added
get_security_evidence
Sept. 17, 2026, 12:39 p.m.
Added
get_agent_readiness
Sept. 17, 2026, 12:39 p.m.
Added
get_services
Sept. 17, 2026, 12:39 p.m.