Production-safety audits for AI-generated code, with a fix for every finding.
nittim is a remote MCP server published at nittim.com. It has been probed 8 times since 9/12/2026. It answered in 8 of them (100.0%), a near-uninterrupted record. Median response time is 709 ms, a delay an agent will notice. It exposes a broad tool surface of 15 tools. On the protocol side it still runs 2025-11-25 and has not moved to the newer spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
audit_repo — Multiple optional parameters with unclear purposeestimate_audit — Parameters lack clear required/optional designationverify_fix — Parameter 'ref' has no descriptionrun_module — ModuleKey parameter lacks explanation of valid valuesdispute_finding — Multiple optional parameters with unclear relationshipsRisk: low
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
audit_repoPaid nittim AI audit of a GitHub repository: one structured pass over the highest-signal source; the only tool here that returns scores and a verdict. Answers with the audit's id, not the report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.DELIVERED AS A BATCH: the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours.
repoUrlstringrequiredgithubTokenstringconfirmedCostobjectauthorizationstringfullScanbooleanpayInsteadbooleandeployedUrlstringaudit_sourcePaid nittim AI audit of source files you post, for a project with no GitHub remote. Send SOURCE files, not build output — no node_modules or dist. On nittim's own key this answers with the audit's id; the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. On your own key (BYOK Pro) the report comes back in this call instead. Costs 5.14 credits (a paid+subscribed org's included allowance, an unspent Audit, then prepaid credits), always saved as a PRIVATE report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm
namestringrequiredfilesarrayrequireduploadGrantstringconfirmedCostobjectauthorizationstringfullScanbooleanscan_sourceFree nittim look: committed secrets and known CVEs over posted source files. No account, no key, no nittim credits. Hard evidence only: never scores, never a production verdict. Send SOURCE files, not build output (no node_modules, no dist, no binaries).
namestringrequiredfilesarrayrequireduploadGrantstringestimate_auditPrice an audit before buying one: give a GitHub repository URL, or a manifest of paths and byte sizes — no file content, nothing uploaded — and get the tier (Audit or Full Audit), the pass count and the exact price. No account or key is needed: it never charges, runs no audit, calls no model and stores nothing. Signed in it also returns your credit balance and whether an unspent Audit covers the run; a guest quote omits both. `fullScan: true` prices Full Audit.
repoUrlstringgithubTokenstringfilesarrayfullScanbooleanget_auditRetrieve a nittim audit by its UUID, at any stage: the finished markdown digest (verdict, scores, top findings) plus its report link, or — no error, nothing charged — that it is still running, or why it failed and what happened to the charge. Free. Reading needs the key of the account that owns the audit.
idstringrequiredverify_fixNEEDS A KEY: mint one at https://nittim.com/keys. Re-checks ONE finding from a finished audit against the repository's current code, or a commit named in the call, and answers fixed, still present, or undetermined — with the reason. It reads only the file that finding cites. Free, capped per day, and it moves no score or verdict: the report keeps recording what was true of the commit it ran on.
auditIdstringrequiredfindingKeystringrequiredrefstringlist_modulesList every audit module nittim can run: the two deterministic scanners (secret scan + OSV dependency CVE check) and the LLM-reasoned checks. Returns each module's key, tier, and a plain-English description of what it checks. Each module's key identifies it for running individually.
get_loopReturns the current text of nittim's free, tool-agnostic self-review checklist — the same content served at https://nittim.com/selfcheck.md. Reviews a codebase against the public shape of nittim's 13-category Priority Framework, plus a 14th on what the code gives away, and states the procedure for running it as a loop. No arguments. No key, no account and no charge — nothing here is sent anywhere.
describe_protocolHow this server works, in full: how a paid call quotes and charges, the two audit tiers, the Nittim Loop and its reward rules and caps, and dispute guidance. Free, no key, no charge, no side effects — it reads static text and calls no model. `section` picks one page; omitted, it returns all of them.
sectionstringmint_keyFor a client that cannot sign in over OAuth: a short, one-time link to https://nittim.com/keys/claim/<token>. Opening it, signed in, mints a real nittim API key and shows it once — the key itself is NEVER returned by this tool or by any other MCP result. The link expires in a few minutes and works exactly once. Free.
keyNamestringrun_moduleRun ONE nittim audit module against a GitHub repository, never producing scores or a verdict. The two deterministic modules (secret-scan, dependency-cve) return scanner evidence directly, free, with nothing to confirm. Deep-tier modules make one focused model call, cost 5.03 credits each and follow the protocol below. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.
repoUrlstringrequiredmoduleKeystringrequiredgithubTokenstringconfirmedCostobjectauthorizationstringjudge_outputRun a cross-vendor judge model over any text you post: code, a document, another model's output, anything. Returns findings + rationale ONLY — never a score, never a pass/fail verdict. Costs 5.03 credits. The judge always comes from a different vendor family than whatever produced the content, and the answer says which one ran. `modelUnderTest` names that family. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.
contentstringrequiredcriteriastringcontextstringmodelUnderTeststringconfirmedCostobjectauthorizationstringDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/com-nittim-nittim)<a href="https://mcpmetrics.io/servers/com-nittim-nittim"><img src="https://mcpmetrics.io/badge/com.nittim/nittim/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
Host AI-generated HTML/CSS/JS instantly. Files, zips, or clone an existing page. Live in seconds.
Don't just collect requests—ship them. Loops integrates with AI Agents like Claude, Codex, and Cursor to write the code for top-voted features and notifies users the moment it’s live.
AI music production assistant — audio profiling, AI mixing sessions, and service inquiries.
Premium agentic endpoint for ai-safety-incident-logger-mcp.
Let your AI assistant build pages and courses, manage contacts, and run email campaigns in AXL.
Voice-led, FSRS-scheduled flashcards from YouTube, PDFs, web, or text. Auto-graded quizzes.
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 06:40:42 | Legacy | 400 | 571 | 200 | 602 | 2025-11-25 |
| 2026-09-13 04:35:29 | Legacy | 400 | 823 | 200 | 800 | 2025-11-25 |
| 2026-09-13 01:33:33 | Legacy | 400 | 508 | 200 | 483 | 2025-11-25 |
| 2026-09-12 23:31:36 | Legacy | 400 | 835 | 200 | 848 | 2025-11-25 |
| 2026-09-12 21:29:15 | Legacy | 400 | 843 | 200 | 870 | 2025-11-25 |
| 2026-09-12 19:27:29 | Legacy | 400 | 653 | 200 | 637 | 2025-11-25 |
| 2026-09-12 17:24:09 | Legacy | 400 | 610 | 200 | 635 | 2025-11-25 |
| 2026-09-12 15:21:42 | Legacy | 400 | 709 | 200 | 728 | 2025-11-25 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.