MCP servers › com.flightclaw › flightclaw
MCP server · registry snapshot 2026-10-04 · last tested 2026-10-09
com.flightclaw/flightclaw
Search ~300 airlines and book flights with a checkout link. OAuth sign-in by email code. — the publisher's description
Summary
com.flightclaw/flightclaw is a remote MCP server listed in the official MCP registry at version 1.0.0. On 2026-10-09 no session could be opened with it. None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.
No session
No session could be opened when we tried, so no check could run. No security score is given; a check we did not run is never counted as passed.
Key facts
- Runs
- remote (hosted by the publisher)
- Transport
- streamable HTTP
- Repository
- public
- Topic
- commerce-and-marketingAI-classified
- Pricing
- freeAI-classified
- Last tested
- 2026-10-09
- Inventory: not run · no session
- Hidden instructions: not run · no session
- Real execution: not run · no session
- Secret leak: not run · no session
- Internal addresses: not run · no session
- Unconfirmed changes: not run · no session
- Bad input: not run · no session
- Model requests: not run · no session
- Sensitive questions: not run · no session
- Folder boundary: not run · no session
- Log leaks: not run · no session
- Hidden content: not run · no session
- Fake assistant turns: not run · no session
- Token passthrough: not run · no session
- Token audience: not run · no session
- Sign-in redirect: not run · no session
- Consent handling: not run · no session
- Sign-in metadata: not run · no session
0 exercised18 not run (reason given)0 not applicable
How fresh this is
- Live-tested
- attempted, see below
- Last tested
- 2026-10-09
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
- Engine
- mcp-runtime-engine@0.1.0 · sdk@1.32.0
Security testing
What did we test, and what did we leave out?
18 checks · features #1, #2Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.
- 1Inventory
tool-listReads the declared tools, resources and prompts.No session could be opened with the server, so no check could run.not run · no session - 2Hidden instructions
description-poisoningLooks for hidden instructions in tool descriptions.No session could be opened with the server, so no check could run.not run · no session - 3Real execution
real-executionCalls a tool and checks what really happens.No session could be opened with the server, so no check could run.not run · no session - 4Secret leak
canary-leakPlants a fake secret and checks whether it leaks.No session could be opened with the server, so no check could run.not run · no session - 5Internal addresses
ssrfChecks whether a tool can be steered to internal addresses.No session could be opened with the server, so no check could run.not run · no session - 6Unconfirmed changes
write-without-confirmationChecks whether tools that change data act without asking.No session could be opened with the server, so no check could run.not run · no session - 7Bad input
error-handlingSends bad input and watches how the server answers.No session could be opened with the server, so no check could run.not run · no session - 8Model requests
samplingChecks whether the server asks the client's model to act for it.No session could be opened with the server, so no check could run.not run · no session - 9Sensitive questions
elicitation-sensitive-dataChecks whether the server asks users for sensitive data.No session could be opened with the server, so no check could run.not run · no session - 10Folder boundary
root-boundaryChecks whether the server reaches outside the folders it was given.No session could be opened with the server, so no check could run.not run · no session - 11Log leaks
logging-side-channelChecks whether log messages carry data they should not.No session could be opened with the server, so no check could run.not run · no session - 12Hidden content
audience-hidingChecks resources that hide content from the user.No session could be opened with the server, so no check could run.not run · no session - 13Fake assistant turns
fake-assistant-turnChecks prompts that pose as the assistant's own words.No session could be opened with the server, so no check could run.not run · no session - 14Token passthrough
token-passthroughChecks whether the server forwards a user's token to other services.No session could be opened with the server, so no check could run.not run · no session - 15Token audience
token-audience-validationChecks whether tokens meant for another service are accepted.No session could be opened with the server, so no check could run.not run · no session - 16Sign-in redirect
open-redirectChecks the sign-in redirect for abuse.No session could be opened with the server, so no check could run.not run · no session - 17Consent handling
confused-deputyChecks consent handling when one service acts for another.No session could be opened with the server, so no check could run.not run · no session - 18Sign-in metadata
oauth-url-schemeChecks the published sign-in metadata for unsafe URLs.No session could be opened with the server, so no check could run.not run · no session
Source: our own test, 2026-10-09, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.
What happened during the test?
Feature #8The steps in order, as the test record holds them.
- 0 msStarted a session with the server's remote endpoint
- No session could be opened.
- 313 msFinished: 0 checks exercised.
What it is
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Remote endpoint mcp.flightclaw.com/mcp | No session could be opened when we tried | no session | our test · 2026-10-09 |
| Repository github.com/flightclaw/agents | Opens publicly | matches | api.github.com · 2026-10-06 |
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- com.flightclaw
- GitHub owner
- an organization (flightclaw)
- Repository
- github.com/flightclaw/agents
- Stars
- 75
- Repository age
- 181–365 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about com.flightclaw/flightclaw
Answered from the data aboveIs com.flightclaw/flightclaw free to use?
Its website (flightclaw.com/mcp) describes a free pricing model. This is an AI-classified reading of the page on 2026-10-08, so check the page itself before relying on it.
Has com.flightclaw/flightclaw been security tested?
We tried, but no check could run. None of the 18 checks that apply to it could be exercised. No session could be opened when we tried, so no check could run. No security verdict is published before verification.
Where is the source code of com.flightclaw/flightclaw?
In github.com/flightclaw/agents, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“The MCP server is free.”
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “com.flightclaw/flightclaw: MCP server record.” Data checked 2026-10-09. https://protocolprobe.com/mcp/servers/com.flightclaw/flightclaw
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology