A Model Context Protocol server for Have I Been Pwned API integration
This server demonstrates strong definition quality with well-structured tool definitions, comprehensive schema documentation, and clear descriptions across all 10 tools. All tools are READ_ONLY and use axios to safely call the HIBP API with server-side API key injection via environment variable. Tool naming follows verb_noun patterns (check_email, get_breach_details, list_all_breaches). Each tool has a clear, descriptive description (34-85 chars, well within the 10-1024 baseline). Input schemas are properly defined with JSON Schema format, parameter types, and descriptions. Output schemas are explicitly documented as TypeScript constants (BREACH_SCHEMA, CHECK_EMAIL_OUTPUT_SCHEMA, etc.), which is excellent practice. However, there are moderate gaps: (1) several tools lack default values or bounds on numeric parameters; (2) error handling in the implementation is minimal (few custom error messages beyond generic HTTP errors); (3) some parameter descriptions could be more specific about constraints or formats; (4) the server does not implement pagination for list operations, despite potentially large result sets. These are not critical failures, the server is solidly above average, but prevent it from reaching 80+.
Check if an email address has been found in data breaches
Check if a password has been exposed in data breaches (using k-anonymity)
Check if an email address has been found in stealer logs
Check stealer logs for a specific email domain
Check stealer logs for a specific website domain
Get details about a specific data breach
Get all data classes that can be compromised in breaches
No pagination support for list operations. list_all_breaches and get_pastes_for_account have no limit, offset, or page_size parameters. Large result sets will exceed context windows. Baseline tools support pagination with limit, offset, and total counts.
Minimal error handling and recovery guidance. Error responses are likely generic HTTP errors or axios exceptions. When a breach_name is not found in get_breach_details, the server should return a helpful message like 'Breach not found. Available breaches: [list]' to enable agent self-correction.
Parameter constraints not fully documented. 'email' parameters in check_email, get_pastes_for_account, and check_stealer_logs_by_email lack format specifications (e.g., 'must be a valid email address'). Domain parameters in check_stealer_logs_by_website_domain and check_stealer_logs_by_email_domain should specify format (e.g., 'domain name without http://'). Baseline includes constraint specifications in descriptions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Get the latest breach that was added to the database
Get all pastes containing a given email address
List all breaches in the system
Output schemas are defined as constants but not exposed to the protocol as per-tool outputSchema metadata. While the schemas exist in code, they are not visible to the client. Modern MCP clients benefit from explicit outputSchema declarations to understand what to expect.
No default values for optional boolean parameters. include_unverified defaults to true and truncate_response defaults to false in check_email, which is good. However, no other tools expose optional parameters, limiting flexibility for agents that might want to customize behavior.