Skip to main content

Security

What the tools can do​

All five tools only read: they look things up and change nothing, in NameBeta or anywhere else. What the tools cannot do lists what that rules out, and each tool declares it with the readOnlyHint annotation.

Signing in grants a client a token for https://namebeta.com/api/mcp and nothing else. The token identifies whose plan a call counts against; Authorization describes the checks the server applies.

What NameBeta receives​

For each tool call, NameBeta receives the tool name, its arguments — the domains or text you asked about — and the token that identifies you. It does not receive your conversation, other tools' results, or anything else your assistant knows. Calls are counted against your plan as described in Quotas. The privacy policy covers how NameBeta handles your data.

Tool results contain text from third parties​

Much of what the tools return is written by people outside NameBeta, and NameBeta passes it on as it is:

ToolThird-party text
lookup_whoisraw, the full WHOIS record, and fields such as registrar
lookup_dnsdata of every record, especially TXT records

Anyone who controls a domain controls its TXT records, and a registrar controls the WHOIS record it serves. Such text can contain instructions aimed at an AI assistant — "ignore previous instructions and …". This is prompt injection: if the assistant treats the text as instructions rather than data, it may act on them.

NameBeta's own tools cannot be turned against you this way, because they only read. The risk lies in the other tools your assistant has in the same conversation: one that sends email, runs commands, writes files or calls another service could be steered by text a NameBeta lookup returned.

  • Treat results as data. Tool results are content to reason about, never instructions to follow.
  • Keep confirmation on for tools that write. Let NameBeta's read-only tools run without prompts if you like, but keep your client asking before tools of other servers that send, change or pay for something.
  • Look before you act on a lookup. If an answer based on WHOIS or DNS data suggests an action you did not ask for, check the raw result first.

url in check_availability results opens a page on namebeta.com. register_url in compare_prices results goes through namebeta.com to a registrar's registration page. Other links in a result, such as those in a WHOIS record, come from third parties.

Reporting a problem​

Write to contact@namebeta.com to report a security issue.