Leash Index

Index / payments

Timix.AI

ai-timix-time-tracking declares 114 capabilities across 114 tools, with 3 critical issues.

100/100 exposureHigh exposure

Manifest retrieved 2026-09-14 from tools/list on https://api.timix.ai/api/integration/v1/mcp, published in the official MCP registry as ai.timix/time-tracking 1.0.0. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · no-revocation · All 114 tools

114 of 114 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

critical · irreversible-uncapped · 28 of 114 tools

28 tools are classified as irreversible and declare no limit.

critical · uncapped-spend · 1 of 114 tools

1 tool is classified as moving money and declares no dollar limit. A cap on the number of payments does not bound their amount.

high · no-expiry · All 114 tools

114 of 114 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 114 tools

114 of 114 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 56 of 114 tools

56 tools can modify data and declare no limit.

low · uncapped-read · 30 of 114 tools

30 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
get_hours_summaryread inferred
get_dashboard_metricsread inferred
get_customer_inforead inferred
get_project_statusread inferred
get_billing_reportread inferred
get_budget_alertsread inferred
list_customersread inferred
list_projectsread inferred
get_my_time_entriesread inferred
get_resource_utilizationread inferred
get_unbilled_timeread inferred
get_budget_healthread inferred
get_employee_timesheetread inferred
list_my_time_entriesread inferred
find_billing_workread inferred
get_project_teamread inferred
log_timewrite inferred
suggest_holiday_profileread inferred
create_holiday_profilewrite inferred
create_customerwrite inferred
create_projectwrite inferred
create_taskwrite inferred
create_subtaskwrite inferred
invite_usersend inferred
assign_user_to_projectwrite inferred
update_org_settingswrite inferred
update_customerwrite inferred
update_projectwrite inferred
update_taskwrite inferred
update_subtaskwrite inferred
create_time_reportwrite inferred
update_time_reportwrite inferred
bulk_create_time_reportswrite inferred
bulk_update_time_reportswrite inferred
copy_periodwrite assumed
start_timerwrite assumed
stop_timerwrite assumed
cancel_timerdelete inferred
submit_timesheetwrite assumed
recall_timesheetwrite assumed
assign_user_to_customerwrite inferred
remove_user_projectdelete inferred
enable_userwrite assumed
resend_invitesend inferred
set_budget_thresholdswrite inferred
update_user_profilewrite inferred
update_user_preferenceswrite inferred
set_user_cost_rateread inferred
bulk_update_cost_ratesread inferred
create_custom_fieldwrite inferred
update_custom_fieldwrite inferred
set_custom_field_valuewrite inferred
set_org_work_schedulewrite inferred
manage_user_work_schedulewrite assumed
update_holiday_profilewrite inferred
delete_customerdelete inferred
close_monthdelete inferred
delete_projectdelete inferred
delete_taskdelete inferred
delete_subtaskdelete inferred
delete_time_reportdelete inferred
approve_timesheetwrite inferred
reject_timesheetwrite inferred
reopen_timesheetwrite inferred
generate_invoicewrite inferred
update_draft_invoicewrite inferred
delete_draft_invoicedelete inferred
send_invoicesend inferred
mark_invoice_paidpay inferred
issue_invoicewrite assumed
void_invoicewrite assumed
reissue_invoicewrite assumed
create_frame_orderwrite inferred
update_frame_orderwrite inferred
close_frame_orderdelete inferred
delete_frame_orderdelete inferred
reopen_monthdelete inferred
restore_entitydelete inferred
permanent_delete_entitydelete inferred
change_user_rolewrite assumed
disable_userwrite assumed
remove_userdelete inferred
cancel_invitedelete inferred
delete_api_keydelete inferred
delete_organizationdelete inferred
delete_custom_fielddelete inferred
delete_work_scheduledelete inferred
delete_holiday_profiledelete inferred
write_off_timewrite inferred
undo_write_offwrite inferred
create_credit_notewrite inferred
move_subtaskwrite inferred
move_taskwrite inferred
move_projectwrite inferred
mark_time_invoicedwrite assumed
list_invoicesread inferred
get_invoiceread inferred
list_favoritesread inferred
create_favoritewrite inferred
use_favoritewrite assumed
delete_favoritedelete inferred
get_import_templateread inferred
validate_importread inferred
commit_importwrite inferred
list_scheduled_reportsread inferred
create_scheduled_reportwrite inferred
update_scheduled_reportwrite inferred
cancel_scheduled_reportdelete inferred
list_recycle_binread inferred
remove_user_from_customerdelete inferred
searchread inferred
get_frame_order_utilizationread inferred
check_budget_limitsread inferred
get_cost_rate_historyread inferred
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.