Agent Economy Index · MCP census · probed 2026-09-29 · JSON
io.github.nomadstays/mcp-server
Verdict: 2 tool description(s) carry model-directed, hidden, secret-material or exfiltration patterns. Endpoint https://mcp.nomadstays.com/mcp. Latency 12,490 ms.
Tools (79 fingerprinted)
| tool | description length | flags | first seen | last seen |
|---|---|---|---|---|
bookStay | 548 | 2026-09-29 | 2026-09-29 | |
checkStayAvailability | 123 | 2026-09-29 | 2026-09-29 | |
createCoworkingApplication | 457 | 2026-09-29 | 2026-09-29 | |
createExperienceApplication | 556 | 2026-09-29 | 2026-09-29 | |
createStayApplication | 496 | 2026-09-29 | 2026-09-29 | |
createStayPackage | 134 | 2026-09-29 | 2026-09-29 | |
createStayRoom | 312 | 2026-09-29 | 2026-09-29 | |
deleteRoomPhoto | 130 | 2026-09-29 | 2026-09-29 | |
deleteStayPackage | 192 | 2026-09-29 | 2026-09-29 | |
deleteStayPhoto | 121 | 2026-09-29 | 2026-09-29 | |
deleteStayRoom | 98 | 2026-09-29 | 2026-09-29 | |
findNearestAvailability | 169 | 2026-09-29 | 2026-09-29 | |
getAdditionalInformationOptions | 355 | 2026-09-29 | 2026-09-29 | |
getAllAmenities | 169 | 2026-09-29 | 2026-09-29 | |
getAllLifestyles | 166 | 2026-09-29 | 2026-09-29 | |
getAvailabilityByMonth | 182 | 2026-09-29 | 2026-09-29 | |
getBookingStatus | 319 | 2026-09-29 | 2026-09-29 | |
getBusinessModelOptions | 191 | 2026-09-29 | 2026-09-29 | |
getCancellationPolicyOptions | 133 | 2026-09-29 | 2026-09-29 | |
getCountryOptions | 164 | 2026-09-29 | 2026-09-29 | |
getCoworkingApplication | 216 | 2026-09-29 | 2026-09-29 | |
getCurrencyOptions | 64 | 2026-09-29 | 2026-09-29 | |
getExperienceApplication | 217 | 2026-09-29 | 2026-09-29 | |
getFacilityGroups | 307 | 2026-09-29 | 2026-09-29 | |
getHelpCenterArticle | 121 | 2026-09-29 | 2026-09-29 | |
getMarketplaceAdverts | 345 | 2026-09-29 | 2026-09-29 | |
getMarketplaceCategories | 165 | 2026-09-29 | 2026-09-29 | |
getMyBusinessProfile | 293 | 2026-09-29 | 2026-09-29 | |
getMyStayContacts | 371 | 2026-09-29 | 2026-09-29 | |
getMyStayDetail | 226 | 2026-09-29 | 2026-09-29 | |
getMyStayFacilities | 416 | 2026-09-29 | 2026-09-29 | |
getMyStayOnboardingStatus | 581 | 2026-09-29 | 2026-09-29 | |
getMyStayOrganisationalData | 260 | 2026-09-29 | 2026-09-29 | |
getMyStayPackages | 309 | 2026-09-29 | 2026-09-29 | |
getMyStayPhotos | 315 | 2026-09-29 | 2026-09-29 | |
getMyStayRooms | 401 | 2026-09-29 | 2026-09-29 | |
getMyStays | 224 | 2026-09-29 | 2026-09-29 | |
getProductInfo | 337 | 2026-09-29 | 2026-09-29 | |
getPurchaseStatus | 294 | 2026-09-29 | 2026-09-29 | |
getRoomAmenities | 199 | 2026-09-29 | 2026-09-29 | |
getRoomAvailability | 138 | 2026-09-29 | 2026-09-29 | |
getRoomFacilityOptions | 264 | 2026-09-29 | 2026-09-29 | |
getRoomTypeOptions | 301 | 2026-09-29 | 2026-09-29 | |
getStayApplication | 211 | 2026-09-29 | 2026-09-29 | |
getStayByID | 97 | 2026-09-29 | 2026-09-29 | |
getStayTypeOptions | 139 | 2026-09-29 | 2026-09-29 | |
getStaysByAmenities | 339 | 2026-09-29 | 2026-09-29 | |
getStaysByBudget | 274 | 2026-09-29 | 2026-09-29 | |
getStaysByContinent | 170 | 2026-09-29 | 2026-09-29 | |
getStaysByCountry | 158 | 2026-09-29 | 2026-09-29 | |
getStaysByLifestyle | 208 | 2026-09-29 | 2026-09-29 | |
getStaysByLocation | 263 | 2026-09-29 | 2026-09-29 | |
getStaysByWiFiSpeed | 86 | 2026-09-29 | 2026-09-29 | |
hasAvailabilityInWindow | 381 | 2026-09-29 | 2026-09-29 | |
listCoworkingApplications | 374 | 2026-09-29 | 2026-09-29 | |
listExperienceApplications | 357 | 2026-09-29 | 2026-09-29 | |
listHelpCenterCategories | 136 | 2026-09-29 | 2026-09-29 | |
listMyBookings | 516 | 2026-09-29 | 2026-09-29 | |
listStayApplications | 349 | 2026-09-29 | 2026-09-29 | |
purchaseProduct | 566 | 2026-09-29 | 2026-09-29 | |
quoteStayBooking | 721 | 2026-09-29 | 2026-09-29 | |
reorderRoomPhotos | 187 | 2026-09-29 | 2026-09-29 | |
reorderStayPhotos | 270 | 2026-09-29 | 2026-09-29 | |
saveCoworkingApplication | 291 | 2026-09-29 | 2026-09-29 | |
saveExperienceApplication | 293 | 2026-09-29 | 2026-09-29 | |
saveStayApplication | 281 | 2026-09-29 | 2026-09-29 | |
searchHelpCenter | 125 | 2026-09-29 | 2026-09-29 | |
signupNomadStaysAccount | 539 | secret_material | 2026-09-29 | 2026-09-29 |
submitCoworkingApplication | 393 | 2026-09-29 | 2026-09-29 | |
submitExperienceApplication | 429 | 2026-09-29 | 2026-09-29 | |
submitStayApplication | 469 | 2026-09-29 | 2026-09-29 | |
updateHostBusinessProfile | 274 | 2026-09-29 | 2026-09-29 | |
updateStayContacts | 140 | 2026-09-29 | 2026-09-29 | |
updateStayDetail | 162 | 2026-09-29 | 2026-09-29 | |
updateStayFacilities | 330 | 2026-09-29 | 2026-09-29 | |
updateStayOrganisationalData | 578 | 2026-09-29 | 2026-09-29 | |
updateStayPackage | 164 | 2026-09-29 | 2026-09-29 | |
updateStayRoom | 241 | 2026-09-29 | 2026-09-29 | |
uploadStayPhoto | 871 | exfiltration | 2026-09-29 | 2026-09-29 |
Tool changes (0)
| when | tool | kind |
|---|---|---|
| none yet |
Probe history
2026-09-29 ok (79 tools)
Depend on this server? Watch it with ToolDrift, $29/month: an alert within six hours when it changes a tool or trips a detector. Flags here are pattern matches on tool descriptions, not verdicts; read the description before deciding.
Run this server? Show today's check on your README or site with a badge that refreshes daily: 
<a href="https://index.agentexchange.work/mcp-server/io.github.nomadstays%2Fmcp-server"><img src="https://index.agentexchange.work/badge/mcp/io.github.nomadstays%2Fmcp-server.svg" alt="MCP server check by agentexchange.work"></a>
Claim this server — prove you operate
mcp.nomadstays.com and this page gets a "Claimed by the operator" line, the badge gets a CLAIMED prefix, and you get a JSON webhook alert when a daily probe records a tool change or more flagged descriptions than the day before (at most one alert per 6 hours). No account, no email, nothing to install.
- Put a text file at
https://mcp.nomadstays.com/.well-known/agentexchange-claim.txtwhose entire content is exactlyio.github.nomadstays/mcp-server. - Submit this form. We fetch that URL once (7-second timeout, User-Agent
agentexchange-index-claim) and compare the trimmed body with the registry name.
Alert payload: {event, server, day, drift:[{tool, kind, detected_at}], findings, previous_findings, page_url, badge_url}. Public list of claims (names and hosts only): /v1/claims.json.
Run this server? MCP servers process users' data and often accept content; the laws that follow are a 45-day privacy request process, an opt-out path, and for hosted content a takedown or notice-and-action process. Check your site free or get a hosted desk.