Leash Index

Index / payments

Gondola Award Travel Search

ai-gondola-gondola declares 39 capabilities across 39 tools, with 2 critical issues.

78/100 exposureHigh exposure

Manifest retrieved 2026-09-14 from tools/list on https://mcp.gondola.ai/mcp, published in the official MCP registry as ai.gondola/gondola 0.1.5. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · irreversible-uncapped · 4 of 39 tools

4 tools are classified as irreversible and declare no limit.

critical · no-revocation · All 39 tools

39 of 39 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

high · no-expiry · All 39 tools

39 of 39 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 39 tools

39 of 39 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 2 of 39 tools

2 tools can modify data and declare no limit.

low · uncapped-read · 33 of 39 tools

33 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
book_hoteldelete declared
book_vehicledelete declared
cancel_vehicle_bookingdelete declared
compare_ratesread declared
create_rate_alertwrite inferred
credit_card_coverageread declared
delete_rate_alertdelete declared
diagnose_ratesread declared
get_bookingread declared
get_booking_linkread declared
get_flight_creditsread declared
get_flight_pointsread declared
get_free_night_creditsread declared
get_hotel_detailsread declared
get_hotel_ratesread declared
get_hotel_reviewsread declared
get_hotel_statsread declared
get_loyalty_accountsread declared
get_multi_night_ratesread declared
get_past_tripsread declared
get_payment_methodsread declared
get_rate_alertsread declared
get_similar_hotelsread declared
get_suggested_searchesread declared
get_suite_upgrade_creditsread declared
get_travel_profilesread declared
get_traveler_contextread declared
get_upcoming_tripsread declared
get_vehicle_bookingread declared
get_vehicle_booking_coverageread declared
get_vehicle_booking_linkread declared
get_vehicle_detailsread declared
optimize_loyalty_portfolioread declared
predict_priceread declared
search_eventsread declared
search_flightsread declared
search_hotelsread declared
search_vehiclesread declared
update_traveler_profilewrite inferred
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.