co.heista
co.heista/api
VOUCH60·CDecode video ads, load brand intelligence, generate ad scripts.
Trust report
Scanned 2026-07-29 · MCP 2025-11-25Scored by MCP Vouch against the OWASP MCP Top 10. SKIP applies to HTTP-only checks not relevant for stdio servers and is excluded from the score.
- FAILMCP01Tool Poisoning0 / 10
- PASSMCP02Insufficient Input Validation10 / 10
- PASSMCP03Resource Injection10 / 10
- WARNMCP04Unauthorized Capability Exposure4 / 10
- WARNMCP05Missing Authentication5 / 10
- PASSMCP06Insecure Transport10 / 10
- WARNMCP07Shadow Tool Registration5 / 10
- WARNMCP08Lack of Audit and Telemetry5 / 10
- WARNMCP09Inadequate Rate Limiting5 / 10
- WARNMCP10Supply Chain Risk6 / 10
Is co.heista/api safe to use?
co.heista/api scores 60/100 — grade C, which leaves real gaps worth reading before you connect an agent. It passes 3 of the 10 OWASP MCP Top-10 checks that apply to it. The failures are Tool Poisoning. This is what the scanner found on 2026-07-29, not a guarantee. Re-run it yourself with `npx mcpr scan`.
What a grade C means, the ten checks behind it, and the point maths are all on how we score MCP server trust.
Slug
mcpr-co-heista-api
License
Unspecified
Quality score
69 / 100
Trust score
VOUCH60·C
Latest version
1.0.0
Published
2026-05-11
Homepage
Repository
Capabilities
Not yet declared in the manifest.
Embed the live badge
Always reflects the current grade. Score drops → badge drops. No vanity lock.
[](https://mcp-registry-dh5.pages.dev/servers/mcpr-co-heista-api/)
Install
One-click cross-client install (Claude Code, Claude Desktop, Cursor, Windsurf) coming soon. The registry will write the correct config fragment to the correct file — no copy-paste.
Frequently asked questions
- Is co.heista/api safe to use?
- co.heista/api scores 60/100 — grade C, which leaves real gaps worth reading before you connect an agent. It passes 3 of the 10 OWASP MCP Top-10 checks that apply to it. The failures are Tool Poisoning. This is what the scanner found on 2026-07-29, not a guarantee. Re-run it yourself with `npx mcpr scan`.
- What is the co.heista/api trust score based on?
- Ten checks derived from the OWASP MCP Top 10, run against the live server by the open-source MCP Vouch scanner. Applicable checks are summed and scaled to 0–100; checks that do not apply to the server's transport are skipped and leave the denominator entirely.
- Why did co.heista/api not score higher?
- It failed 1 of the 10 checks that apply to it: Tool Poisoning. Each failure is listed with its verdict in the trust report on this page.
- How do I install co.heista/api?
- co.heista/api is installed like any other MCP server — add it to your client's MCP configuration. Cross-client one-click install is coming to MCP Registry; until then, the repository and homepage links on this page carry the maintainer's own instructions.