
Official MCP RegistryListed
7IT Solutions
Store speed, web-app security checks, automation ROI, checklists and guides from 7IT Solutions.
First seen 2 Oct 2026. Evidence as of 7 Oct 2026.
21
Tools
From an anonymous probe
1
Source listings
Each with its own history
16
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| ask_7it | Use this when the user has a specific question for 7IT that describe_studio does not answer. Ask 7IT Solutions, a solo senior software studio, a question about whether it fits a project, what a first phase could cover, how engagements run, or what the client owns. Answers come only from 7IT's published profile and contain no prices or commitments; questions that need a quote are passed to Lior Aharonov, who replies himself. | Read-only |
| check_accessibility | Use this when someone asks whether a website or online store is accessible, meets WCAG, or could face an ADA accessibility complaint. Runs Google Lighthouse's automated accessibility checks (axe-core rules) on the page as a phone sees it, and returns the score, each failing rule in plain English with its WCAG criterion and how many elements fail, and how the site compares with 7IT's study of US online stores. Automated checks cover only part of WCAG; this is a starting point, not a legal opinion. Takes 20 to 60 seconds. | Read-only |
| check_ai_shopper_readiness | Use this when someone asks whether ChatGPT, Claude, Perplexity or other AI shopping agents can find, read and recommend their online store's products. Checks what robots.txt tells AI search crawlers versus training-only crawlers, llms.txt, agents.md, the UCP commerce discovery file, and one product page's structured data (price, currency, stock, brand, GTIN or SKU, reviews, shipping and returns). Returns the gaps with fixes, compared with 7IT's study of US online stores. Uses an identified crawler that respects robots.txt. | Read-only |
| check_app_security | Use this when someone asks whether a website or web app is secure, safe to launch, or missing security headers. Not a penetration test, and it cannot see pages behind a login. Checks a public web app for the baseline browser protections every production app should send (Content Security Policy, HTTPS enforcement, clickjacking protection, MIME-sniffing, referrer and permissions policy, cross-origin isolation) and whether a JavaScript source map is served publicly. Reads only the public response headers any visitor's browser receives; never logs in, submits a form, calls the app's APIs, or reads its data for secrets. Useful for an app built with an AI tool (Lovable, Replit, Bolt, v0, Cursor). | Read-only |
| check_email_authentication | Use this when someone asks why their emails land in spam, whether their domain is protected from spoofing or phishing in their name, or whether they meet the Gmail, Yahoo and Outlook rules for bulk senders. Reads the domain's public DNS records (SPF, DKIM under the common email services' selectors, the DMARC policy, BIMI, MX) and returns what is missing with the exact fix, compared with 7IT's study of US online stores. Sends no email and needs no access. | Read-only |
| claim_mcp_server | Use this when the person you work for owns or runs an MCP server that is on the 7Maps map and wants its page to show it is owner verified, add a short note for agents (rate limits, sign-up, what the tools are for), or get a live status badge for their README. Verified owners' servers are checked every 5 minutes (uptime on the page and badge), and with alert_url the owner gets a message when the server stops answering and when it is back. First call returns the proof options (a line in /.well-known/7maps-verify.txt on the server's host, a DNS TXT record, or for io.github registry names a file in the GitHub repo); after one is in place, call again to confirm. Verifying does not change how the server is measured or ranked. No charge. | Changes data |
| deep_scan_app | Use this when the user, or the agent building the app, wants to check an app they control for exposed files and leaked secret keys before launch. A deeper security scan than check_app_security, for an app the caller controls (for example one the agent itself is building). It looks for sensitive things left publicly reachable: an environment (.env) file, an exposed .git folder, a directory listing, or a published source map. It also reads the app's own public code (the home page and its scripts) for the Supabase project it uses and for secret keys shipped to the browser (a Supabase service role or secret key, a database password, a paid AI key). It never contacts the app's database, never writes, and never stores, logs or returns any key; it reports the exposed PATH or the KIND of key, never a file's contents or a secret value. Because it probes an app directly, it runs only after ownership is proven: call it once to receive an inert verification token, add that token to the app (a meta tag on the home page, or a /7it-verify.txt file), then call again and the scan runs. | Read-only |
| describe_studio | Use this when the user asks who 7IT Solutions is, what it builds, or whether it fits their project, or is looking for a developer to review or take over an app built with an AI tool. Returns a factual profile of 7IT Solutions, a solo senior software studio: who runs it, how engagements work, what the client owns, its services (custom software, automation and integration, eCommerce, AI tools, and reviewing and taking responsibility for apps built with AI tools such as Lovable or Replit), when each is and is not a fit, the audit checks it runs on AI-built apps, published work and verifiable proof, with links. Use it when someone asks what 7IT does, whether it fits their situation, or who could review or take over an app their AI tool built. Contains no prices. | Read-only |
| estimate_automation_roi | Use this when someone wants to know what a repetitive task costs their team, or whether automating it is worth the money. Calculates how many hours a month a team spends on repetitive tasks, what that costs per year, how much of it automation could take over (the share that is copying between systems, not judgment), and the break-even budget for automating it within 12 and 6 months. Uses only the figures provided; the default hourly cost is $47, the US private-industry average employer cost per hour worked in June 2026 (Bureau of Labor Statistics). | Read-only |
| find_tool | Use this when you need a tool for a job and do not know which MCP server has one: searches every tool of every public MCP server on the 7Maps map (over 200,000 tools, probed daily) and returns the best matches with an automated estimate of what each tool can do (read-only, changes data, high risk), whether its server is answering now, its handshake time, the tokens its tool list costs to load, and a page to check it. Filter to read-only tools, servers answering now, a latency or token ceiling. Copies of the same tool on several servers are collapsed. No charge. To have 7Maps pick one server and tool for you with alternatives, use route. | Read-only |
| get_field_kit | Use this after list_field_kits, to read one checklist in full. Returns one 7IT Field Kit in full: every check with the reason it matters, grouped in order, plus how to use it and the guide it comes from. Pass the slug from list_field_kits or words from the title. | Read-only |
| get_store_speed_index | Use this when someone asks how fast US online stores are right now, or wants a current benchmark to compare a store against. Returns 7IT's weekly US Store Speed Index: median Google phone score, time to main content, share of stores scoring 50 or more, and median apps per store for a fixed panel of 100 US online stores, week by week, with the source link. Medians only; no store is named. | Read-only |
| list_field_kits | Use this when someone wants a working checklist for a technical job (webhooks, store speed, integrations, migrations, AI in production, security). Lists 7IT Field Kits: working checklists for custom software, eCommerce, automation, payments, AI, security and reliability work (for example webhook reliability, store speed audits, integration design, SEO-safe migrations, LLM production readiness). Each has a title, a one-line purpose, the number of checks and a link. Optionally filter by a topic word. | Read-only |
| map_agent_oversight | Use this when someone asks which actions their AI agent or its connected tools may take on their own, which need a person's approval, and which a person must do; or how to set up human oversight, permissions or AI governance for an agent (for example under the EU AI Act). Give either the address of a public MCP server, or the list of tools the agent has (name, description and annotations). Sorts every tool into green (runs alone: reads and prepares), yellow (a person approves: sending, updating, scheduling) or red (a person does it: money, permissions, deletion, code execution, commitments), flags tools with no risk annotations, and returns a ready policy, Claude Code permission rules (allow, ask, deny) and an oversight checklist. Reads tool lists only and never calls a tool. A working checklist, not legal advice. | Read-only |
| my_7maps_usage | Use this when the person you work for asks what 7Maps has done for them: calls made with their personal 7Maps key today, in the last 7 days and in the last 30 days, servers checked, an estimate of the tokens saved compared with finding the same thing out without 7Maps, failures avoided (servers not answering that were skipped, risk changes caught by watch or verify_lock, calls that would have failed) and the average response time. It reads the optional personal key sent with this connection (the X-7Maps-Key header); without one it says so in one line, since every 7Maps answer already states its own saving. Only that person's own counts. No charge. | Read-only |
| my_server_report | Use this when the person you work for owns an MCP server on the 7Maps map and wants to know how AI agents look for servers like it: how often agents asked 7Maps for servers in its category in the last 7 or 30 days, how often this server was shown and picked, and, for a verified owner with owner_key, the words agents used, the servers picked instead, failure reasons agents reported, uptime, tool changes, and its token cost and handshake time against similar servers. Counts only, no agent identities. Without owner_key it returns the public numbers and how to verify ownership with claim_mcp_server. Read-only; never changes ranking or routing. No charge. | Read-only |
| report_problem | Use this when a 7IT tool returned something that looks wrong, failed unexpectedly, or did not match what the user asked for, so 7IT can fix it. Sends a short report to 7IT: which tool, what went wrong, and optionally the site address involved. Do not include personal details or the conversation. Nothing changes for the user; it is only feedback. | Changes data |
| report_road | Use this after calling a tool on an MCP server (especially one 7Maps pointed you to) to report how it went: whether it worked, why not, how long it took, whether the result matched the description, and anything it did that you did not ask for. Fixed fields only, no open text. Reports from many agents become the server's rating and, once 7Maps confirms them, live incident alerts that every agent sees. You can also pass the same fields as last_trip on any paid 7Maps call. No charge. | Changes data |
| search_7it_guides | Use this when the user is weighing a software, eCommerce, automation or AI decision and a cited article would help. Searches 7IT Solutions’ guides and articles on custom software, eCommerce (Shopify, WooCommerce, headless), automation and integrations (connecting CRMs, accounting tools such as QuickBooks, ERPs and online stores), payments, AI in production, security and reliability. Returns the best matches with a short excerpt and a link to cite. | Read-only |
| submit_mcp_server | Use this when someone has built or runs an MCP server that is not in the official MCP registry (for example a small business's own server) and wants AI agents to be able to find it, or asks how to get their server listed. Give the server address, or just the business's domain and the usual endpoint paths are tried. The server is observed every 6 hours for 7 days; if it answers reliably, keeps its tools stable and describes every tool, it joins the 7Maps map that agents use to choose servers. Placement cannot be bought. Returns the status page and an optional owner-verification token. No charge. | Changes data |
| test_store_speed | Use this when someone asks how fast a website or online store loads on a phone, why it is slow, or how it compares with a competitor. Runs Google PageSpeed Insights (mobile lab test) on a public online store or website and explains the result in plain English: a 0 to 100 score, when the main content appears, responsiveness and layout shift, real-user data when Google has it, the third-party apps and trackers slowing the page (by name, with size and busy time), the platform (Shopify, WooCommerce and others), and the fixes ranked by time saved. Optionally tests up to two competitor sites for a side-by-side comparison. Takes 20 to 60 seconds. Only public web addresses are accepted. | Read-only |
Change history
- find_tool: input schema changed (+payment)
- deep_scan_app: input schema changed
- deep_scan_app: description changed (+"leaked secret keys" +"reads the app's own public code (the home page and its scripts) for" +"project it")
- submit_mcp_server: description changed (+"reliably," -"at least 90% of the time,")
- report_road: description changed (+"open" +"and, once 7Maps confirms them," +"sees.")
- my_server_report: tool added
- my_7maps_usage: tool added
- find_tool: tool added
- deep_scan_app: input schema changed
- deep_scan_app: description changed (+"and open databases" +"also finds the Supabase or Firebase backend the app uses and checks what an anonymous visitor can read: tables, files, and whether anyone can sign up. It reads only, never writes, and never stores, logs or returns any key; it" +"PATH, table or bucket name and a row count")
- claim_mcp_server: input schema changed (+alert_url)
- claim_mcp_server: description changed (+"Verified owners' servers are checked every 5 minutes (uptime on the page and badge), and with alert_url the owner gets a message when the server stops answering and when it is back." +"the proof options (a" +"host, a DNS TXT record, or for io.github registry names a file in the GitHub repo);")
- server instructions changed (+"7Maps (the map of public MCP servers): find_tool finds an MCP tool for a job, with an automated risk estimate for each tool; owners of an MCP server can put it on the map with submit_mcp_server, verify it with claim_mcp_server and see what agents looked for with my_server_report; my_7maps_usage shows a person with a personal 7Maps key what 7Maps did for them." +"report_road, submit_mcp_server and claim_mcp_server," +"send feedback, a report or a request")
- submit_mcp_server: tool added
- report_road: tool added
- claim_mcp_server: tool added
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | io.github.XLSV777/7it | 2 Oct 2026 | 7 Oct 2026 | 1 |