← Back to search

io.github.ccedacero/nyc-property-intel

ccedacero streamable_http Scanned 7h ago

MCP server giving Claude AI access to 22+ NYC public-record databases for real estate due diligence

D
40 / 100

Versions

0.1.1latest
first seen May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 18

get_building_permits
annotations: none low

Get DOB building permit filings and job applications for a property. Shows new building, alteration, and demolition applications with costs, status, proposed changes (stories, units, height), and applicant info. Use this to understand planned or completed construction activity.

bbl str limit int job_type string
get_311_complaints
annotations: none low

Get 311 service request complaints filed at or near a property address. Queries the local 311 database (NYC Open Data). Covers noise, rodents, illegal dumping, graffiti, heat/hot water, illegal parking, street conditions, and ~200 other complaint types. 311 data is a leading-indicator for neighborhood quality and building distress — complaints are filed *before* violations are issued. High complaint volume at an address is a red flag for active tenant issues. Provide either `address` OR `bbl` (not both). Args: address: Street address, e.g. "37-06 80th Street, Queens". bbl: 10-digit NYC BBL. Resolved to street address via PAD table. complaint_type: Filter by complaint type keyword, e.g. "NOISE", "RODENT", "HEAT", "ILLEGAL PARKING". Case-insensitive. since_year: Return only complaints from this year onward (2010–present). status: Filter by status: "Open" or "Closed". limit: Max complaints to return (1–100, default 30).

bbl string limit int status string address string since_year string complaint_type string
get_liens_and_encumbrances
annotations: none low

Get tax liens and mortgage/encumbrance records for a property. Shows DOF tax lien sale list entries and ACRIS recorded documents — mortgages, satisfactions, condo common-charge liens (LOCC), tax lien sale certificates (TLS/ATL/AMTL), and tax-lien discharges (DTL/RTXL) — including party names and amounts. Use this to assess a property's debt profile and lien exposure. Not covered (different filing systems): federal tax liens, mechanic's liens, and court-filed lis pendens.

bbl str limit int include_mortgages bool include_tax_liens bool
get_property_issues
annotations: none low

Get HPD housing violations, DOB building code violations, and ECB/OATH violations for a property. HPD Class C violations are immediately hazardous. ECB violations include penalties and balances due. Returns both summary counts and violation details. Use this to assess a building's regulatory risk profile. Note on historical depth: our local DB retains all historical HPD violations and complaints, while NYC's live Socrata API rolls older records out of its public feed. As a result, the totals reported here may exceed what data.cityofnewyork.us shows for the same BBL — the extra rows are real, just no longer surfaced by NYC Open Data.

bbl str limit int source str status string severity string since_date string include_summary bool
get_evictions
annotations: none low

Get marshal eviction execution records for a property address. Returns evictions that were *executed* (marshal removed tenant), not just filed. Covers residential and commercial evictions citywide from 2017. BBL queries use a local indexed database for fast, exact lookups. Address queries use the Socrata API for full 126K-row dataset coverage. Use this to assess tenant instability and cash-flow risk. Many executed evictions at a building may indicate distressed management, problematic tenants, or an owner pushing out rent-stabilized tenants. Provide either `address` OR `bbl` (not both). Args: address: Street address, e.g. "123 Main St, Brooklyn". bbl: 10-digit NYC BBL. Queried directly via BBL index. eviction_type: Filter by type: "Residential" or "Commercial". since_year: Return only evictions from this year onward (2017–present). limit: Max records to return (1–100, default 25).

bbl string limit int address string since_year string eviction_type string
get_property_history
annotations: none low

Get the history of a NYC property including sales and ownership transfers. Pulls sales from DOF records and ownership transfers from ACRIS deed records. Shows sale prices, dates, buyer/seller names, and document types. Use this to understand a property's transaction history and price trajectory.

bbl str limit int end_date string start_date string include_sales bool doc_type_filter string include_ownership bool include_transactions bool
lookup_property
annotations: none low

Look up a NYC property by address or BBL. Returns the full property profile including building details, zoning, assessed value, owner, and lot characteristics. This is always the first tool to call — you need a BBL before using other tools.

bbl string address string borough string
search_comps
annotations: none low

Find comparable property sales and neighborhood market statistics. Can search by zip code, building class, size, and time period. If a reference BBL is provided, uses that property's characteristics as defaults. Returns individual sales with price per sqft and quarterly market trends.

bbl string limit int months int max_sqft string min_sqft string zip_code string max_price string min_price string include_stats bool building_class string
search_neighborhood_stats
annotations: none low

Get aggregate neighborhood statistics for market research and area analysis. Combines property stock data, sales market activity, violation patterns, and rent stabilization counts at the zip code or neighborhood level. Use this to compare areas, identify investment hotspots, or understand a neighborhood's character before drilling into individual properties. At least one of zip_code or neighborhood is required.

months int zip_code string neighborhood string building_class string include_violations bool include_quarterly_trends bool include_rent_stabilization bool
get_hpd_litigations
annotations: none low

Get HPD litigation history — cases where HPD sued the building owner. HPD only litigates the worst-offending buildings. This is a strong red flag for investors. Shows case types (heat/services, harassment, tenant protection), harassment findings, open judgements, and penalties. A building with HPD litigation history carries significant regulatory risk.

bbl str
get_tax_info
annotations: none low

Get property tax assessment, market value, and exemption details. Shows assessed and market values (land and total), tax class, taxable value, and any active tax exemptions like 421a, J-51, or STAR.

bbl str
get_rent_stabilization
annotations: none low

Get rent stabilization history for a property. Shows stabilized unit counts from 2007-2017 and whether counts are estimated or confirmed by DHCR. Use this to check if a building is rent-stabilized and track unit count changes over time.

bbl str
get_fdny_fire_incidents
annotations: none low

Get FDNY fire and emergency incident history for a property address. Queries the local FDNY incident database (NYC Open Data dataset 8m42-w767). Returns fire incidents, structural fires, EMS responses, and other emergency calls associated with a property's zip code and borough. Falls back to the Socrata API for finer-grained address matching if local table unavailable. Use this to identify fire history, structural fire risk, repeated emergency responses, or patterns of emergency calls at a property's location. Provide either `address` OR `bbl` (not both). If BBL is given, the tool resolves it to a zip code before querying. Args: address: Street address, e.g. "37-06 80th Street, Queens" or "350 5th Ave, Manhattan". Borough or zip code recommended. bbl: 10-digit NYC BBL, e.g. "4008020015". Alternative to address. incident_type: Filter by incident type keyword, e.g. "FIRE", "STRUCTURAL", "EMS", "MEDICAL". Case-insensitive. since_year: Return only incidents from this year onward, e.g. 2018. Data available from 2013. limit: Max incidents to return (1–100, default 20).

bbl string limit int address string since_year string incident_type string
get_hpd_registration
annotations: none low

Get HPD building registration and contact info. Shows the managing agent, corporate owner, head officer, and site manager for a registered NYC building. Required for buildings with 3+ residential units. Use this to find who manages or owns a building.

bbl str
get_hpd_complaints
annotations: none low

Get HPD tenant complaints and reported problems for a property. Complaints are leading indicators of building distress — they show what tenants are reporting before formal violations are issued. Categories include PLUMBING, PAINT/PLASTER, HEAT/HOT WATER, PEST CONTROL, etc. Use this alongside violations to assess a building's condition. Note on historical depth: our local DB retains all historical HPD complaints, while NYC's live Socrata API rolls older records out of its public feed. As a result, totals reported here may exceed what data.cityofnewyork.us shows for the same BBL — the extra rows are real, just no longer surfaced by NYC Open Data.

bbl str limit int status string category string since_date string include_summary bool
analyze_property
annotations: none low

Generate a comprehensive due diligence summary for a NYC property. Combines data from 14 sources concurrently: property profile, HPD/DOB violations, HPD complaints, HPD litigations, HPD registration, evictions, building permits, 311 complaints, sales history, tax assessment, tax liens, ACRIS mortgages, rent stabilization, and comparable sales. Use this when the user wants a complete picture of a property for investment analysis.

bbl str
get_dob_complaints
annotations: none low

Get DOB complaints filed against a property with the Dept of Buildings. Queries the DOB Complaints Received dataset (NYC Open Data `eabe-havv`). Complaints are filed *before* formal violations are issued — they trigger DOB inspections and are the earliest public signal of construction, safety, or code issues at a building. Key insight: compare this with `get_property_issues` violations. If a property has many complaints but few violations, DOB may not be inspecting. If complaints are recent and unresolved, it flags active safety concerns. Common complaint categories: illegal construction (01), elevator (02), plumbing (03), illegal conversion (04), boiler (05), structural (06), facade (07), fire egress (09), work without permit (10), electrical (11). Provide either `address` OR `bbl` (not both). Args: address: Street address, e.g. "350 5th Ave, Manhattan". bbl: 10-digit NYC BBL. Resolved via BIN lookup for accurate matching. category: Filter by complaint category code, e.g. "01" for construction without permit, "04" for illegal conversion. status: Filter by status keyword, e.g. "OPEN", "CLOSED", "REFERRED TO DA". since_year: Return only complaints from this year onward. limit: Max complaints to return (1–100, default 25).

bbl string limit int status string address string category string since_year string
get_nypd_crime
annotations: none low

Get NYPD crime complaints within a radius of a property. Queries the local NYPD complaint database (NYC Open Data) using a geospatial bounding-box search centered on the property's lat/lon. Returns all complaint types — felonies, misdemeanors, and violations — filed within the specified radius. Falls back to Socrata API if local table is unavailable. Uses the property's PLUTO coordinates (lot centroid) for accuracy. Default radius of 300 m covers roughly 3 city blocks in any direction. Use this to assess neighborhood safety for buyers, lenders, or underwriters. Compare felony vs misdemeanor breakdown, trend over years, and dominant offense types (assault, burglary, grand larceny, etc.). Provide either `address` OR `bbl` (not both). Args: address: Street address, e.g. "350 5th Ave, Manhattan". bbl: 10-digit NYC BBL. Coordinates resolved from PLUTO. radius_meters: Search radius in meters (50–800, default 300 ≈ 3 blocks). law_category: Filter by "FELONY", "MISDEMEANOR", or "VIOLATION". Case-insensitive. offense: Filter by offense keyword, e.g. "ASSAULT", "BURGLARY", "GRAND LARCENY", "ROBBERY". Case-insensitive. since_year: Return only complaints from this year onward (2006–present). limit: Max complaints to return (1–200, default 50).

bbl string limit int address string offense string since_year string law_category string radius_meters int

Permissions 5

network medium
Server uses network capabilities via: fetch(), httpx, requests, urllib
filesystem low
Server uses filesystem capabilities via: open(), os, pathlib, tempfile
shell high
Server uses shell capabilities via: subprocess
database medium
Server uses database capabilities via: asyncpg
env_vars low
Server uses env_vars capabilities via: os.environ, os.getenv()

Scan Findings 96

low
Tool 'get_311_complaints' has no annotations annotation_checker · 100%
low
Tool 'get_liens_and_encumbrances' has no annotations annotation_checker · 100%
low
Tool 'get_property_issues' has no annotations annotation_checker · 100%
low
Tool 'get_evictions' has no annotations annotation_checker · 100%
low
Tool 'get_property_history' has no annotations annotation_checker · 100%
low
Tool 'lookup_property' has no annotations annotation_checker · 100%
low
Tool 'search_comps' has no annotations annotation_checker · 100%
low
Tool 'search_neighborhood_stats' has no annotations annotation_checker · 100%
low
Tool 'get_building_permits' has no annotations annotation_checker · 100%
low
Tool 'get_hpd_litigations' has no annotations annotation_checker · 100%
low
Tool 'get_tax_info' has no annotations annotation_checker · 100%
low
Tool 'get_rent_stabilization' has no annotations annotation_checker · 100%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-2xpw-w6gg-jr37) dependency_analyzer · 95%
low
Tool 'get_fdny_fire_incidents' has no annotations annotation_checker · 100%
low
Tool 'get_hpd_registration' has no annotations annotation_checker · 100%
low
Tool 'get_hpd_complaints' has no annotations annotation_checker · 100%
low
Tool 'analyze_property' has no annotations annotation_checker · 100%
low
Tool 'get_dob_complaints' has no annotations annotation_checker · 100%
low
Tool 'get_nypd_crime' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: asyncpg@0.30.0,<1.0 (GHSA-2xpj-f5g2-8p7m) dependency_analyzer · 95%
medium
Vulnerable dependency: asyncpg@0.30.0,<1.0 (PYSEC-2020-24) dependency_analyzer · 95%
medium
Vulnerable dependency: httpx@0.27.0,<1.0 (GHSA-h8pj-cxx2-jfg2) dependency_analyzer · 95%
medium
Vulnerable dependency: httpx@0.27.0,<1.0 (PYSEC-2022-183) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (GHSA-9hjg-9r4m-mvj7) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (GHSA-9wx4-h78v-vm56) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (GHSA-gc5v-m9x4-r6x2) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (PYSEC-2026-1872) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (PYSEC-2026-1873) dependency_analyzer · 95%
medium
Vulnerable dependency: requests@2.31.0 (PYSEC-2026-2275) dependency_analyzer · 95%
medium
Vulnerable dependency: pydantic@2.0,<3.0 (GHSA-5jqp-qgf6-3pvh) dependency_analyzer · 95%
medium
Vulnerable dependency: pydantic@2.0,<3.0 (GHSA-mr82-8j83-vxmv) dependency_analyzer · 95%
medium
Vulnerable dependency: pydantic@2.0,<3.0 (PYSEC-2021-47) dependency_analyzer · 95%
medium
Vulnerable dependency: pydantic@2.0,<3.0 (PYSEC-2026-1812) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-34jh-p97f-mpxf) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-38jv-5279-wg99) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-g4mx-q9vg-27p4) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-gm62-xv2j-4w53) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-pq67-6m6q-mj2v) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-qccp-gfcp-xxvc) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (GHSA-v845-jxx5-vc9f) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2023-192) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2023-212) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-141) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-1994) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-1995) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-1996) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-1998) dependency_analyzer · 95%
medium
Vulnerable dependency: urllib3@2.0.0 (PYSEC-2026-1999) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-537c-gmf6-5ccf) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-6vqw-3v5j-54x4) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-79v4-65xg-pq4g) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-9v9h-cgj8-h64p) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-h4gh-qq45-vh27) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-jwv3-5hgf-82ww) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-m959-cc7f-wv43) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (GHSA-r6ph-v2qm-q3c2) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2024-225) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-1284) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-1285) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-2141) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-35) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-3553) dependency_analyzer · 95%
medium
Vulnerable dependency: cryptography@42.0.0 (PYSEC-2026-3554) dependency_analyzer · 95%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: get_311_complaints manifest_parser · 90%
info
Tool: get_liens_and_encumbrances manifest_parser · 90%
info
Tool: get_property_issues manifest_parser · 90%
info
Tool: get_evictions manifest_parser · 90%
info
Tool: get_property_history manifest_parser · 90%
info
Tool: lookup_property manifest_parser · 90%
info
Tool: search_comps manifest_parser · 90%
info
Tool: search_neighborhood_stats manifest_parser · 90%
info
Tool: get_building_permits manifest_parser · 90%
info
Tool: get_hpd_litigations manifest_parser · 90%
info
Tool: get_tax_info manifest_parser · 90%
info
Tool: get_rent_stabilization manifest_parser · 90%
info
Tool: get_fdny_fire_incidents manifest_parser · 90%
info
Tool: get_hpd_registration manifest_parser · 90%
info
Tool: get_hpd_complaints manifest_parser · 90%
info
Tool: analyze_property manifest_parser · 90%
info
Tool: get_dob_complaints manifest_parser · 90%
info
Tool: get_nypd_crime manifest_parser · 90%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (14) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 90%
low
Permission: filesystem access detected permission_analyzer · 80%
high
Permission: shell access detected permission_analyzer · 95%
medium
Permission: database access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
No dependency files found for SBOM generation sbom_generator · 100%
critical
Database URL with Password found in ccedacero-nyc-property-intel-3ec20c9/scripts/load_rolling_sales.py secret_scanner · 85%
critical
Database URL with Password found in ccedacero-nyc-property-intel-3ec20c9/docs/deploy-hosted.md secret_scanner · 85%
critical
Database URL with Password found in ccedacero-nyc-property-intel-3ec20c9/docs/deployment-plan.md secret_scanner · 85%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%