Leash Index

Index / data

Daystruct

ai-daystruct-api-daystruct declares 21 capabilities across 21 tools, with 2 critical issues.

48/100 exposureElevated

Manifest retrieved 2026-09-14 from tools/list on https://api.daystruct.ai/mcp, published in the official MCP registry as ai.daystruct.api/daystruct 1.1.0. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · no-revocation · All 21 tools

21 of 21 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

critical · irreversible-uncapped · 1 of 21 tools

1 tool is classified as irreversible and declares no limit.

high · no-expiry · All 21 tools

21 of 21 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 21 tools

21 of 21 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 2 of 21 tools

2 tools can modify data and declare no limit.

low · uncapped-read · 18 of 21 tools

18 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
daystruct_statusread declared
search_entitiesread declared
get_entity_evidenceread declared
get_context_contractread declared
answer_software_questionsread declared
check_security_exposureread declared
lookup_vulnerabilityread declared
check_release_supportread declared
select_modelread declared
read_recent_evidence_changesread declared
get_daystruct_validated_guidanceread declared
list_daystruct_guidance_scopesread declared
resolve_task_capabilitieswrite assumed
create_task_sessionwrite inferred
record_task_eventread inferred
get_task_sessionread declared
close_task_sessiondelete inferred
search_daystruct_libraryread declared
resolve_daystruct_bundleread declared
discover_daystruct_capabilitiesread declared
prepare_daystruct_capabilitiesread declared
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.