Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,561Letters: 14Defects: 1,336counted 3 min ago
teppi

Server definition

Hash
sha256:084aa167cb01a00e91c972ded37853119640760aab9bbd5a06764cbc18961caf
What it is
What a remote MCP server returned when asked what it offers: 8 tools

The blob, as servednamed by its sha256

{ "instructions": "Moltline Agent Governance & MCP Auditor: inventory and audit your agent fleet. Free: audit_mcp_config (scope/secret/version risks in an MCP config), scope_check (over-privileged tools by blast radius), audit_skill_file (injection/secret/concealment smells), injection_scan, inventory_report, agent_readiness_scan (score any public domain against 21 agent-readiness checks and return the fix for each failure). Premium (license): governance_policy, get_auditor_persona. Every finding names the risk and a concrete remediation.", "tools": [ { "description": "Score a public domain against 21 agent-readiness checks. FREE.\n\nUse when you need to know whether an autonomous agent can discover, read,\nuse or pay a website - your own, or a vendor you are evaluating before\nrecommending it. Typical input {\"domain\": \"example.com\"} returns\n{\"score\": 8, \"total\": 21, \"grade\": \"F\", \"passed\": [...], \"failed\":\n[{\"title\": \"...\", \"detail\": \"...\", \"fix\": \"...\"}], \"report_url\": \"...\"}\nwhere report_url is a permanent shareable page for the same result.\n\nNot for auditing an MCP client configuration (audit_mcp_config) and not\nfor scanning text for injection (injection_scan) - this one reaches out\nover the network and fetches public URLs on a live domain. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"The readiness scanner is not reachable right now.\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "domain": { "description": "A public hostname such as example.com. A full URL is accepted\nand reduced to its host. Hostnames that resolve to private or\ninternal addresses are refused.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "agent_readiness_scan", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Audit an MCP server config for risk-ranked posture findings. FREE.\n\nFlags exposed machine credentials in the config, required inputs that\naren't gated/optional, unpinned versions, over-broad env access, and\ndangerous auto-run flags. It never echoes any matched secret value back.\nTypical input {\"config\": \"<mcpize.yaml, mcp.json, or a Claude/Cursor\nservers block>\"} returns {\"posture_score\": 0-100, \"verdict\": \"...\",\n\"findings\": [{\"line\": N, \"severity\": 1-5, \"issue\": \"...\", \"fix\": \"...\"}],\n\"note\": \"...\"}.\n\nUse on a server configuration document. Not for a skill or instruction\nfile (audit_skill_file) and not for untrusted content an agent is about to\nread (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "config": { "description": "The MCP config to audit, pasted as text or JSON —\nmcpize.yaml, mcp.json, or a Claude/Cursor servers block.", "type": "string" } }, "required": [ "config" ], "type": "object" }, "name": "audit_mcp_config", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Audit an agent skill or instruction file before you trust it. FREE.\n\nChecks for governance smells: prompt-injection and guardrail-bypass\nphrasing, concealment instructions ('don't tell the user'), exfiltration\nlanguage, and exposed credential material. Typical input {\"content\":\n\"<SKILL.md, system prompt, or tool description text>\"} returns\n{\"verdict\": \"reject — do not install\" | \"no governance red flags on a\npattern pass\", \"findings\": [{\"severity\": 1-5, \"issue\": \"...\"}],\n\"note\": \"...\"}.\n\nUse before trusting a skill or instruction file that came from outside\nyour own repository. Not for arbitrary untrusted input at run time\n(injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "content": { "description": "Full text of the skill file, system prompt, or tool\ndescription to audit.", "type": "string" } }, "required": [ "content" ], "type": "object" }, "name": "audit_skill_file", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Load the Governance Auditor persona for consistent fleet audits. PREMIUM (license).\n\nThe persona is methodical, evidence-driven, and allergic to 'it's\nprobably fine'. Takes no arguments. Returns {\"persona\": ...,\n\"identity\": ..., \"rules\": [\"...\", ...], \"opening_move\": \"...\"} ready to\nadopt as a system prompt.\n\nUse to keep repeated audits consistent in voice and rigor. Not for running\nan audit - the audit tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": {}, "type": "object" }, "name": "get_auditor_persona", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Generate an audit-ready agent-governance policy for a fleet. PREMIUM (license).\n\nCovers inventory cadence, ownership rules, least-privilege approval\ngates, injection defense, logging/retention, and decommissioning\ntriggers. Typical input {\"fleet_context\": \"20 agents, 3 with shell\naccess, one finance bot\"} returns {\"policy\": ..., \"sections\": {...},\n\"context_note\": ..., \"audit_checklist\": [\"...\", ...]}.\n\nUse when a fleet needs a written policy document. Not for assessing what\nthe fleet currently does (inventory_report, audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "fleet_context": { "default": "", "description": "Optional plain-language description of the fleet\n(size, capabilities, sensitive systems) used to tailor the\npolicy; empty returns the generic baseline.", "type": "string" } }, "type": "object" }, "name": "governance_policy", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Scan untrusted text for prompt-injection patterns before ingestion. FREE.\n\nUse on any web page, email, or document an agent is about to ingest to\ncatch prompt-injection and data-exfiltration patterns before they reach\nthe agent's context. Typical input {\"text\": \"<untrusted content>\"}\nreturns {\"injection_suspected\": bool, \"count\": N, \"hits\": [{\"line\": N,\n\"pattern\": \"...\", \"text\": \"<flagged line>\"}], \"note\": \"...\"}.\n\nNot for reviewing a skill file you control (audit_skill_file), and a clean\nresult is not a guarantee of safety - it reports pattern matches only. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "text": { "description": "The untrusted content to scan, pasted as a single string.", "type": "string" } }, "required": [ "text" ], "type": "object" }, "name": "injection_scan", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Build a governance inventory with risk tiers from a raw agent list. FREE.\n\nTurns a list of agents / MCP servers / skills into an audit-ready\nsummary with critical/elevated/standard tiers and unowned-agent flags.\nTypical input {\"items\": \"[{\\\"name\\\": \\\"deploy-bot\\\", \\\"owner\\\":\n\\\"ana\\\"}]\"} returns {\"total\": N, \"tiers\": {\"critical\": N, ...},\n\"unowned_agents\": [...], \"inventory\": [{\"name\": ..., \"owner\": ...,\n\"tier\": ..., \"orphaned\": bool}], \"reading\": \"...\", \"note\": \"...\"}.\n\nUse to turn a raw agent list into risk tiers. Not for auditing any single\nagent in depth (audit_mcp_config, scope_check). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "items": { "description": "The fleet as a string — a JSON array of {name, owner?,\ncapabilities?, last_seen?} objects, or plain newline-separated\nagent names.", "type": "string" } }, "required": [ "items" ], "type": "object" }, "name": "inventory_report", "outputSchema": { "additionalProperties": true, "type": "object" } }, { "description": "Score the blast radius of every tool in a permission manifest. FREE.\n\nRanks each tool by capability risk (command exec > money/delete >\nfile-write/messaging > read > network) and flags the over-privileged\nones that need approval gates. Typical input {\"tools\": \"[\\\"run_shell\\\",\n\\\"read_docs\\\"]\"} returns {\"tools_scored\": N, \"high_risk_tools\": N,\n\"ranking\": [{\"tool\": ..., \"blast_radius\": 0-5, \"capabilities\": [...]}],\n\"recommendation\": [\"...\"], \"note\": \"...\"}.\n\nUse on a permission manifest to rank tools by blast radius. Not for the\nconfiguration that mounts them (audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.", "inputSchema": { "additionalProperties": false, "properties": { "tools": { "description": "The manifest as a string — a JSON array of tool names or\n{name, description} objects, a JSON object of name->description,\nor plain newline-separated names.", "type": "string" } }, "required": [ "tools" ], "type": "object" }, "name": "scope_check", "outputSchema": { "additionalProperties": true, "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:084aa167cb01a00e91c972ded37853119640760aab9bbd5a06764cbc18961caf | sha256sum