Leash Index

Index / messaging

Dock

ai-trydock-dock declares 70 capabilities across 70 tools, with 2 critical issues.

99/100 exposureHigh exposure

Manifest retrieved 2026-09-14 from tools/list on https://trydock.ai/api/mcp, published in the official MCP registry as ai.trydock/dock 1.1.0. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · no-revocation · All 70 tools

70 of 70 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

critical · irreversible-uncapped · 13 of 70 tools

13 tools are classified as irreversible and declare no limit.

high · no-expiry · All 70 tools

70 of 70 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 70 tools

70 of 70 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 31 of 70 tools

31 tools can modify data and declare no limit.

low · uncapped-read · 26 of 70 tools

26 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
list_workspacesread inferred
get_workspaceread inferred
list_rowsread inferred
create_rowwrite inferred
get_rowread inferred
update_rowwrite inferred
delete_rowdelete inferred
move_rowswrite inferred
get_docread inferred
get_workspace_schemaread inferred
add_columnwrite inferred
list_workspace_membersread inferred
delete_workspacedelete inferred
update_workspacewrite inferred
share_workspacesend inferred
update_workspace_memberwrite inferred
remove_workspace_memberdelete inferred
update_docwrite inferred
validate_doc_markdownread inferred
update_doc_sectionwrite inferred
append_doc_sectionwrite assumed
get_htmlread inferred
update_htmlwrite inferred
validate_htmlread inferred
create_workspacewrite inferred
get_recent_eventsread inferred
searchread inferred
get_billingread inferred
upgrade_planwrite inferred
downgrade_planwrite assumed
request_limit_increasewrite inferred
list_surfacesread inferred
create_surfacewrite inferred
update_surfacewrite inferred
delete_surfacedelete inferred
list_api_keysread inferred
rotate_api_keydelete inferred
revoke_api_keydelete inferred
request_revoke_agent_keydelete inferred
request_rotate_agent_keywrite inferred
list_webhooksread inferred
create_webhookwrite inferred
update_webhookwrite inferred
rotate_webhook_secretwrite assumed
delete_webhookdelete inferred
send_messagesend inferred
create_support_ticketwrite inferred
list_my_support_ticketsread inferred
list_sheet_functionsread inferred
validate_formularead inferred
evaluate_formulawrite assumed
add_commentwrite inferred
list_commentsread inferred
get_comment_threadread inferred
reply_to_commentwrite inferred
resolve_commentwrite assumed
unresolve_commentwrite assumed
react_to_commentdelete inferred
list_filesread inferred
get_fileread inferred
delete_filedelete inferred
share_filewrite assumed
revoke_file_sharedelete inferred
list_recent_filesread inferred
address_bookread inferred
bulk_create_rowswrite inferred
bulk_update_rowswrite inferred
list_capabilitiesread inferred
pull_capabilitywrite assumed
request_connectionwrite inferred
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.