An observation record, not an assessment. Every row below is a change we recorded directly, with the content hash before and after. https://mcp.syntermedia.ai
4 of these transitions happened while the reported version string stayed the same. A consumer pinning that version would have received a different tool surface with nothing in the version to indicate it. That is a compatibility and review fact, not a security finding and not an allegation of wrongdoing — unversioned iteration is normal practice and is frequently deliberate.
| observed at (UTC) | change | version signal | reported version | tools | surface hash |
|---|---|---|---|---|---|
| 2026-09-30 07:40:03Z | PARAMS_CHANGED | SILENT — version string did not move | 1.28.1 (unchanged) | no tool-name change recorded | — |
| 2026-09-28 19:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 1.28.1 (unchanged) | +synter_audience | 3668add0d752 → 2f5fa83b9845 |
| 2026-09-26 01:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 1.28.1 (unchanged) | +read_google_drive_file +synter_audience_cancel_export +synter_audience_capacity +synter_audience_export +synter_audience_export_status +synter_audience_query +synter_audience_schema +synter_signal_audience_export +synter_signal_entity_relations +synter_signal_entity_resolve +synter_signal_trait_search +tech_intel_company_to_url +tech_intel_get_account_usage +tech_intel_get_domain_keywords +tech_intel_get_domain_technologies +tech_intel_get_sites +tech_intel_get_technology_changes +tech_intel_get_trust_signals +tech_intel_product_search −builtwith_company_to_url −builtwith_get_account_usage −builtwith_get_domain_keywords −builtwith_get_domain_technologies −builtwith_get_sites −builtwith_get_technology_changes −builtwith_get_trust_signals −builtwith_product_search −growth_run_pipeline −prospector_get_contacts −revenuebase_audience_balance −revenuebase_audience_cancel_export −revenuebase_audience_export −revenuebase_audience_export_status −revenuebase_audience_query −revenuebase_audience_schema −watt_entity_enrich −watt_entity_find −watt_entity_relations −watt_entity_resolve −watt_trait_search | d59d5d99c868 → 3668add0d752 |
| 2026-09-25 07:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 1.28.1 (unchanged) | +prospector_dedupe_leads +prospector_get_bounced_leads +prospector_reconcile_campaign_leads +prospector_remove_leads +prospector_suppress_leads +prospector_update_campaign_settings +prospector_update_lead_custom_variables +prospector_verify_leads | 76cd7a3ccbe3 → d59d5d99c868 |
This section is identical for ~92% of publishers and is published as
shared context, not as a finding about mcp.syntermedia.ai. 90 dependency
packages sit beneath the measured MCP population; 41 have a
single maintainer and 31 have not published in over two years.
The widest is zod at
80.46% of npm-backed servers (8529 servers,
1 maintainer, last publish 2026-09-13).
These are properties of the shared SDK dependency closure. Any page claiming this set as
one operator's personal exposure is misreading a universal fact as a private one.
Source: state/mcp-census/chokepoint-maintainers.json, as_of 2026-10-07.
Observation window 2026-09-21 → 2026-10-10.
22,294 servers were observed; 2,214
were seen to change and 20,080 were observed and
recorded no change — that negative control is why a non-zero count here means something.
Across the corpus, 4,781 of
6,334 changes carried no version signal, and
1,690 of those added or removed tools.
What this does NOT cover: servers outside the observed set; changes that
occurred before 2026-09-21; changes that began and reverted between two observations;
and any server reachable only with credentials we do not hold. A server's absence from this
record is not evidence it did not change — only that we did not observe it.
Universe captured 2026-10-10T19:40:03.823Z. Produced by core/surface_history_page.cjs (reads core/surface_clock producers).
Hashes are of the served tool surface and are recomputable from the server's own response.