MCP Server

7IT Solutions

io.github.XLSV777/7it
Developer Tools Security Public & reachable MCP 2025-11-25

What this MCP does

Checks public web applications for security headers, exposed files, source maps, performance issues, and related technical concerns.

ask_7it
Ask 7IT Solutions a question
Use this when the user has a specific question for 7IT that describe_studio does not answer. Ask 7IT Solutions, a solo senior software studio, a question about whether it fits a project, what a first phase could cover, how engagements run, or what the client owns. Answers come only from 7IT's published profile and contain no prices or commitments; questions that need a quote are passed to Lior Aharonov, who replies himself.
Read only Open world
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['question'], 'properties': {'question': {'type': 'string', 'maxLength': 1000, 'minLength': 5, 'description': 'The question, in plain words. Include the business context that matters, for example the platform, the systems involved or what the app does.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['answer', 'forwarded_to_founder', 'contact'], 'properties': {'answer': {'type': ['string', 'null'], 'description': 'Answer from the published profile, or null when it was forwarded without one'}, 'contact': {'type': 'string'}, 'forwarded_to_founder': {'type': 'boolean'}}, 'additionalProperties': {}}
check_app_security
Check a web app’s security hygiene
Use this when someone asks whether a website or web app is secure, safe to launch, or missing security headers. Not a penetration test, and it cannot see pages behind a login. Checks a public web app for the baseline browser protections every production app should send (Content Security Policy, HTTPS enforcement, clickjacking protection, MIME-sniffing, referrer and permissions policy, cross-origin isolation) and whether a JavaScript source map is served publicly. Reads only the public response headers any visitor's browser receives; never logs in, submits a form, calls the app's APIs, or reads its data for secrets. Useful for an app built with an AI tool (Lovable, Replit, Bolt, v0, Cursor).
Read only Open world Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 300, 'minLength': 3, 'description': 'The appâ\x80\x99s public web address, for example myapp.com or https://myapp.lovable.app'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['reachable', 'report_url'], 'properties': {'url': {'type': 'string'}, 'grade': {'enum': ['strong', 'partial', 'weak'], 'type': 'string'}, 'https': {'type': 'boolean'}, 'total': {'type': 'number', 'description': 'How many baseline protections were checked'}, 'missing': {'type': 'array', 'items': {'type': 'string'}}, 'present': {'type': 'number', 'description': 'How many of the baseline protections are in place'}, 'signals': {'type': 'array', 'items': {'type': 'object', 'required': ['key', 'label', 'present', 'why'], 'properties': {'key': {'type': 'string'}, 'why': {'type': 'string'}, 'label': {'type': 'string'}, 'present': {'type': 'boolean'}}, 'additionalProperties': {}}, 'description': 'Each protection, whether it is present, and why it matters'}, 'reachable': {'type': 'boolean'}, 'report_url': {'type': 'string', 'description': 'Shareable report with fixes'}, 'source_map_public': {'type': 'boolean', 'description': 'True if the app publishes a JavaScript source map'}}, 'additionalProperties': {}}
deep_scan_app
Deep security scan of an app you control
Use this when the user, or the agent building the app, wants to check an app they control for exposed files before launch. A deeper security scan than check_app_security, for an app the caller controls (for example one the agent itself is building). It looks for sensitive things left publicly reachable: an environment (.env) file, an exposed .git folder, a directory listing, or a published source map. It reports the exposed PATH so the owner can see it; it never reads or returns a file's contents or any secret value. Because it probes an app directly, it runs only after ownership is proven: call it once to receive an inert verification token, add that token to the app (a meta tag on the home page, or a /7it-verify.txt file), then call again and the scan runs. Reports paths only.
Read only Open world Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 300, 'minLength': 3, 'description': 'The appâ\x80\x99s public web address, for example myapp.com or https://myapp.lovable.app. You must be able to add a verification token to this app.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'host': {'type': 'string'}, 'clean': {'type': 'boolean', 'description': 'True when no exposed file was found'}, 'token': {'type': 'string', 'description': 'Inert verification token to place on the app'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'label', 'path', 'url', 'severity', 'fix'], 'properties': {'id': {'type': 'string'}, 'fix': {'type': 'string'}, 'url': {'type': 'string'}, 'path': {'type': 'string'}, 'label': {'type': 'string'}, 'severity': {'enum': ['critical', 'high', 'medium'], 'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Exposed paths only; file contents are never read or returned'}, 'verified': {'type': 'boolean'}, 'report_url': {'type': 'string'}, 'needs_verification': {'type': 'boolean', 'description': 'True when ownership is not proven yet; add the token and call again'}}, 'additionalProperties': {}}
describe_studio
Describe 7IT Solutions
Use this when the user asks who 7IT Solutions is, what it builds, or whether it fits their project, or is looking for a developer to review or take over an app built with an AI tool. Returns a factual profile of 7IT Solutions, a solo senior software studio: who runs it, how engagements work, what the client owns, its services (custom software, automation and integration, eCommerce, AI tools, and reviewing and taking responsibility for apps built with AI tools such as Lovable or Replit), when each is and is not a fit, the audit checks it runs on AI-built apps, published work and verifiable proof, with links. Use it when someone asks what 7IT does, whether it fits their situation, or who could review or take over an app their AI tool built. Contains no prices.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'focus': {'enum': ['all', 'custom-software', 'automation', 'ecommerce', 'ai', 'ai-built-apps'], 'type': 'string', 'description': 'Limit the services section to one area. Default all.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['name', 'services', 'contact'], 'properties': {'name': {'type': 'string'}, 'model': {'type': 'string', 'description': 'How engagements work'}, 'contact': {'type': 'string', 'description': 'Where to reach Lior'}, 'services': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'url'], 'properties': {'url': {'type': 'string'}, 'name': {'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Each service with when it fits and when it does not'}, 'ownership': {'type': 'string', 'description': 'What the client owns'}}, 'additionalProperties': {}}
estimate_automation_roi
Estimate the cost of repetitive work
Use this when someone wants to know what a repetitive task costs their team, or whether automating it is worth the money. Calculates how many hours a month a team spends on repetitive tasks, what that costs per year, how much of it automation could take over (the share that is copying between systems, not judgment), and the break-even budget for automating it within 12 and 6 months. Uses only the figures provided; the default hourly cost is $47, the US private-industry average employer cost per hour worked in June 2026 (Bureau of Labor Statistics).
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['tasks'], 'properties': {'tasks': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'how_often', 'per', 'minutes_each'], 'properties': {'per': {'enum': ['day', 'week', 'month'], 'type': 'string', 'description': 'The period for how_often.'}, 'name': {'type': 'string', 'maxLength': 80, 'description': 'A short name for the task, if different from the type.'}, 'type': {'enum': ['invoices', 'leads', 'reporting', 'dataentry', 'onboarding', 'reminders', 'other'], 'type': 'string', 'description': 'The kind of work.'}, 'people': {'type': 'integer', 'maximum': 500, 'minimum': 1, 'description': 'How many people do it each time. Default 1.'}, 'how_often': {'type': 'number', 'maximum': 100000, 'minimum': 0, 'description': 'How many times it happens per period.'}, 'minutes_each': {'type': 'number', 'maximum': 10000, 'minimum': 0, 'description': 'Minutes it takes each time.'}, 'copying_share': {'type': 'number', 'maximum': 100, 'minimum': 0, 'description': 'Percent of the work that is copying between systems rather than judgment. Defaults by type.'}}}, 'maxItems': 8, 'minItems': 1}, 'hourly_cost': {'type': 'number', 'maximum': 1000, 'minimum': 1, 'description': 'Fully loaded cost of an hour of work in USD. Default 47.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['hourly_cost', 'hours_per_month', 'yearly_cost', 'automatable_hours_per_month', 'automatable_yearly', 'break_even_budget_12_months', 'break_even_budget_6_months', 'tasks', 'report_url'], 'properties': {'tasks': {'type': 'array', 'items': {'type': 'object', 'properties': {'name': {'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Per-task hours and cost'}, 'report_url': {'type': 'string'}, 'hourly_cost': {'type': 'number', 'description': 'Hourly cost used, in USD'}, 'yearly_cost': {'type': 'number', 'description': 'Yearly cost of the work done by hand, USD'}, 'hours_per_month': {'type': 'number'}, 'automatable_yearly': {'type': 'number', 'description': 'Yearly cost automation could take over, USD'}, 'break_even_budget_6_months': {'type': 'number'}, 'automatable_hours_per_month': {'type': 'number'}, 'break_even_budget_12_months': {'type': 'number'}}, 'additionalProperties': {}}
get_field_kit
Read a 7IT Field Kit
Use this after list_field_kits, to read one checklist in full. Returns one 7IT Field Kit in full: every check with the reason it matters, grouped in order, plus how to use it and the guide it comes from. Pass the slug from list_field_kits or words from the title.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['kit'], 'properties': {'kit': {'type': 'string', 'maxLength': 120, 'minLength': 2, 'description': 'The kit slug (for example "webhook-reliability-checklist") or words from its title.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['slug', 'title', 'url'], 'properties': {'url': {'type': 'string'}, 'slug': {'type': 'string'}, 'title': {'type': 'string'}}, 'additionalProperties': {}}
get_store_speed_index
US Store Speed Index (weekly)
Use this when someone asks how fast US online stores are right now, or wants a current benchmark to compare a store against. Returns 7IT's weekly US Store Speed Index: median Google phone score, time to main content, share of stores scoring 50 or more, and median apps per store for a fixed panel of 100 US online stores, week by week, with the source link. Medians only; no store is named.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['title', 'panel', 'updated', 'series', 'source_url'], 'properties': {'panel': {'type': 'number', 'description': 'Number of stores in the fixed panel'}, 'title': {'type': 'string'}, 'series': {'type': 'array', 'items': {'type': 'object', 'required': ['date', 'stores', 'median_score', 'median_lcp_s', 'score_50_plus', 'median_apps'], 'properties': {'date': {'type': 'string'}, 'stores': {'type': 'number', 'description': 'Stores measured that week'}, 'median_apps': {'type': ['number', 'null'], 'description': 'Median third-party apps and tags per store'}, 'median_lcp_s': {'type': ['number', 'null'], 'description': 'Median seconds until the main content shows'}, 'median_score': {'type': ['number', 'null'], 'description': 'Median Google phone performance score, 0 to 100'}, 'score_50_plus': {'type': ['number', 'null'], 'description': 'Percent of stores scoring 50 or more'}}, 'additionalProperties': {}}, 'description': 'One entry per week, oldest first'}, 'updated': {'type': ['string', 'null'], 'description': 'Date of the latest weekly reading, YYYY-MM-DD'}, 'source_url': {'type': 'string', 'description': 'Page to cite'}}, 'additionalProperties': {}}
list_field_kits
List 7IT Field Kits
Use this when someone wants a working checklist for a technical job (webhooks, store speed, integrations, migrations, AI in production, security). Lists 7IT Field Kits: working checklists for custom software, eCommerce, automation, payments, AI, security and reliability work (for example webhook reliability, store speed audits, integration design, SEO-safe migrations, LLM production readiness). Each has a title, a one-line purpose, the number of checks and a link. Optionally filter by a topic word.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'topic': {'type': 'string', 'maxLength': 80, 'description': 'Optional word to filter by, for example "shopify", "webhook" or "AI".'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['kits'], 'properties': {'kits': {'type': 'array', 'items': {'type': 'object', 'required': ['slug', 'title', 'purpose', 'checks', 'url'], 'properties': {'url': {'type': 'string'}, 'slug': {'type': 'string'}, 'title': {'type': 'string'}, 'checks': {'type': 'number'}, 'purpose': {'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Matching kits; pass a slug to get_field_kit'}}, 'additionalProperties': {}}
search_7it_guides
Search 7IT guides and articles
Use this when the user is weighing a software, eCommerce, automation or AI decision and a cited article would help. Searches 7IT Solutions’ guides and articles on custom software, eCommerce (Shopify, WooCommerce, headless), automation and integrations (connecting CRMs, accounting tools such as QuickBooks, ERPs and online stores), payments, AI in production, security and reliability. Returns the best matches with a short excerpt and a link to cite.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 8, 'minimum': 1, 'description': 'How many results to return. Default 5.'}, 'query': {'type': 'string', 'maxLength': 200, 'minLength': 2, 'description': 'What to look for, for example "reliable webhooks" or "shopify vs woocommerce".'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['results'], 'properties': {'results': {'type': 'array', 'items': {'type': 'object', 'required': ['title', 'url'], 'properties': {'url': {'type': 'string'}, 'title': {'type': 'string'}, 'excerpt': {'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Best matches, most relevant first'}}, 'additionalProperties': {}}
test_store_speed
Test store speed on a phone
Use this when someone asks how fast a website or online store loads on a phone, why it is slow, or how it compares with a competitor. Runs Google PageSpeed Insights (mobile lab test) on a public online store or website and explains the result in plain English: a 0 to 100 score, when the main content appears, responsiveness and layout shift, real-user data when Google has it, the third-party apps and trackers slowing the page (by name, with size and busy time), the platform (Shopify, WooCommerce and others), and the fixes ranked by time saved. Optionally tests up to two competitor sites for a side-by-side comparison. Takes 20 to 60 seconds. Only public web addresses are accepted.
Read only Open world Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 300, 'minLength': 3, 'description': 'The store or website to test, for example "example.com" or "https://shop.example.com/products/item".'}, 'competitors': {'type': 'array', 'items': {'type': 'string', 'maxLength': 300, 'minLength': 3}, 'maxItems': 2, 'description': 'Up to two competitor sites to test at the same time for comparison.'}}}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['store', 'competitors', 'report_url'], 'properties': {'store': {'type': 'object', 'required': ['host'], 'properties': {'host': {'type': 'string'}, 'score': {'type': ['number', 'null'], 'description': 'Google phone performance score, 0 to 100'}}, 'description': 'The tested store', 'additionalProperties': {}}, 'benchmark': {'description': 'Where the score stands against the US Store Speed study'}, 'report_url': {'type': 'string', 'description': 'Shareable full report'}, 'competitors': {'type': 'array', 'items': {'type': 'object', 'required': ['host'], 'properties': {'host': {'type': 'string'}}, 'additionalProperties': {}}, 'description': 'Competitors tested side by side, if any'}}, 'additionalProperties': {}}
Added
search_7it_guides
Oct. 2, 2026, 2:40 a.m.
Added
get_field_kit
Oct. 2, 2026, 2:40 a.m.
Added
list_field_kits
Oct. 2, 2026, 2:40 a.m.
Added
ask_7it
Oct. 2, 2026, 2:40 a.m.
Added
deep_scan_app
Oct. 2, 2026, 2:40 a.m.
Added
check_app_security
Oct. 2, 2026, 2:40 a.m.
Added
get_store_speed_index
Oct. 2, 2026, 2:40 a.m.
Added
describe_studio
Oct. 2, 2026, 2:40 a.m.
Added
estimate_automation_roi
Oct. 2, 2026, 2:40 a.m.
Added
test_store_speed
Oct. 2, 2026, 2:40 a.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…