Leash Index

Index / devtools

MapMap

ai-mapmap-mapmap declares 43 capabilities across 43 tools, with 2 critical issues.

88/100 exposureHigh exposure

Manifest retrieved 2026-09-14 from tools/list on https://mcp.mapmap.ai/mcp, published in the official MCP registry as ai.mapmap/mapmap 1.0.0. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · no-revocation · All 43 tools

43 of 43 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

critical · irreversible-uncapped · 1 of 43 tools

1 tool is classified as irreversible and declares no limit.

high · no-expiry · All 43 tools

43 of 43 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 43 tools

43 of 43 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 28 of 43 tools

28 tools can modify data and declare no limit.

low · uncapped-read · 14 of 43 tools

14 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
cheapest_charging_along_routeread inferred
cheapest_fuel_along_routeread inferred
check_adr_tunnelread inferred
check_clearance_on_routeread inferred
check_style_contrastread inferred
clusterwrite assumed
create_stylewrite inferred
elevationwrite assumed
geo_areawrite assumed
geo_bboxwrite assumed
geo_bearingwrite assumed
geo_centroidwrite assumed
geo_destinationwrite assumed
geo_distancewrite assumed
geo_lengthwrite assumed
geo_nearest_point_on_linewrite assumed
geo_point_in_polygonwrite assumed
geo_simplifywrite assumed
geocodewrite assumed
get_jobread inferred
get_styleread inferred
get_usageread inferred
list_place_categoriesread inferred
list_style_layersread inferred
match_tracewrite assumed
matrixwrite assumed
nearby_placesread inferred
optimise_routeswrite assumed
order_stopswrite assumed
plan_daywrite assumed
plan_ev_routewrite assumed
reachable_areawrite assumed
replan_routeswrite assumed
report_map_issuewrite assumed
reverse_geocodewrite assumed
routewrite assumed
search_along_routeread inferred
set_layer_paintwrite inferred
set_palettewrite inferred
submit_integration_retrosend inferred
submit_optimise_jobwrite inferred
validate_geodataread inferred
verify_placesread inferred
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.