Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,552Letters: 14Defects: 1,323counted 1 min ago
teppi

Server definition

Hash
sha256:2332ba9586957e045ef70824246b23e6da5e5e71f36dc93c6948d5480fcde875
What it is
What a remote MCP server returned when asked what it offers: 7 tools

The blob, as servednamed by its sha256

{ "instructions": "Safety verdicts for AI agents, pay-per-call. tools/list is free; tools/call forwards your Authorization (a paygent credits key) to the paid gate, or returns payment instructions if absent.", "tools": [ { "description": "Untrusted-content guardrail for agents: submit a blob of text you are about to feed to your own LLM (scraped web content, a tool result, another agent's message) and get a machine-enforceable verdict - is this a prompt-injection / jailbreak / data-exfiltration / tool-hijack attempt? Returns a risk level, the detected classes with spans, the unicode obfuscation it found (zero-width, bidi-override, tag-chars, homoglyphs), and a SANITIZED copy safe to feed onward. Hybrid: a deterministic, uninjectable pattern engine (authoritative) plus an LLM classifier that can only raise the risk, never clear a flag. Detection of known injection classes - not a proof of safety. [security; up to 15c/call]", "inputSchema": { "properties": { "content": { "description": "The untrusted text to scan before you feed it to your LLM.", "type": "string" }, "context": { "description": "Optional: where the content came from (url, tool name, sender) - context only.", "type": "string" } }, "required": [ "content" ], "type": "object" }, "name": "inject-guard", "outputSchema": null }, { "description": "Turn a git diff into a clear PR description or release notes. [dev-tools; up to 30c/call]", "inputSchema": { "properties": { "diff": { "description": "Unified git diff to summarise", "type": "string" }, "style": { "description": "e.g. conventional, changelog, executive", "type": "string" } }, "required": [ "diff" ], "type": "object" }, "name": "pr-summary", "outputSchema": null }, { "description": "Leaked-credential guardrail for agents: submit a blob you are about to commit, log, post, or hand to another tool (a diff, a config, an .env, an LLM output) and get a machine-enforceable verdict - does it contain a live secret? Detects cloud keys (AWS), VCS tokens (GitHub/GitLab), provider API keys (Stripe, OpenAI, Anthropic, Google, Slack), private-key blocks, JWTs, and credentials embedded in URLs, plus high-entropy key=value assignments. Returns a risk level, the detected classes with a MASKED locator (never the secret itself, so the verdict cannot re-leak), and a REDACTED copy safe to emit onward. Deterministic, sub-second, never fetches. Detection of known secret formats - not a proof of cleanliness. [security; up to 200c/call]", "inputSchema": { "properties": { "content": { "description": "The text to scan for leaked secrets (diff, config, .env, log line, LLM output).", "type": "string" } }, "required": [ "content" ], "type": "object" }, "name": "secret-scan", "outputSchema": null }, { "description": "Security review of a code snippet or diff. Returns structured findings (severity, CWE, location, remediation). [security; up to 75c/call]", "inputSchema": { "properties": { "code": { "description": "Source code or unified diff to review", "type": "string" }, "context": { "description": "Optional context about the code", "type": "string" }, "language": { "description": "Language hint, e.g. typescript, python", "type": "string" } }, "required": [ "code" ], "type": "object" }, "name": "secure-code-review", "outputSchema": null }, { "description": "Pre-sign safety oracle for agent wallets: submit the transaction or EIP-712 message you are about to sign and get a machine-enforceable verdict. Decodes the calldata/typed-data, flags the drainer toolkit (unlimited approvals, setApprovalForAll, permit/permit2 + EIP-3009 to an unexpected party, transferFrom draining an unnamed account, ownership transfer, raw ETH to a stranger), and binds the decoded action to your stated intent - only a fully pinned, clean action is auto-sign-safe. Fails closed: an undecodable on-chain call is cautioned and an unrecognized off-chain signature grant is blocked. Deterministic, sub-second, no endpoint fetch. It vouches that the action matches what you said; it does NOT vouch that a counterparty is trustworthy. [security; up to 200c/call]", "inputSchema": { "properties": { "context": { "description": "Optional free-form context.", "type": "string" }, "expected": { "description": "Your stated intent. Supplying it lets the verdict BIND the action; only a fully bound, clean action is auto-sign-safe. For an allowance, you MUST supply maxAmount; for a transferFrom, supply `from`.", "properties": { "asset": { "description": "Token contract you intend to touch.", "type": "string" }, "chainId": { "description": "Chain you intend to act on.", "type": "number" }, "contract": { "description": "Contract you intend to call.", "type": "string" }, "from": { "description": "Account whose funds you intend to move (transferFrom / EIP-3009).", "type": "string" }, "maxAmount": { "description": "Atomic ceiling you intend to expose (required to auto-sign an allowance).", "type": "string" }, "recipient": { "description": "Address you intend to send to.", "type": "string" }, "spender": { "description": "Address you intend to approve.", "type": "string" } }, "type": "object" }, "spendPolicy": { "description": "Optional buyer spend policy (context only).", "type": "object" }, "tx": { "description": "An EVM transaction you are about to sign.", "properties": { "chainId": { "description": "EIP-155 chain id (e.g. 8453 for Base).", "type": "number" }, "data": { "description": "Calldata hex (0x...). Omit for a plain ETH transfer.", "type": "string" }, "to": { "description": "Target contract / recipient (0x address).", "type": "string" }, "value": { "description": "Wei to send, decimal or 0x.", "type": "string" } }, "type": "object" }, "typedData": { "description": "An EIP-712 message you are about to sign (the off-chain drainer surface: permit, Permit2, EIP-3009). { domain, types, primaryType, message }.", "type": "object" } }, "type": "object" }, "name": "sign-guard", "outputSchema": null }, { "description": "Pre-execution safety oracle for agent actions: submit the tool call you are about to run (shell, http, sql, file, code, env) plus your stated intent, and get a machine-enforceable verdict before you execute it. Decodes what the call does, flags the danger toolkit (rm -rf, reverse shell, curl|sh, SSRF to cloud metadata, credential reads, DROP/DELETE-without-WHERE, path traversal, dynamic eval), and binds it to your intent (allowedHosts/allowedPaths/readOnly/noNetwork) - only a fully pinned, clean, intent-matched call is auto-exec-safe. Hybrid: a deterministic, uninjectable detector engine (authoritative) plus an LLM classifier that can only raise the risk. Fails closed. Detection of known-dangerous patterns, not a proof of safety; it never executes the call. [security; up to 8c/call]", "inputSchema": { "properties": { "call": { "description": "The tool call you are about to execute.", "properties": { "body": { "description": "http: request body (context).", "type": "string" }, "command": { "description": "shell: the full command line.", "type": "string" }, "kind": { "description": "The kind of action.", "enum": [ "shell", "http", "sql", "file", "code", "env" ], "type": "string" }, "language": { "description": "code: the language.", "type": "string" }, "method": { "description": "http: HTTP method.", "type": "string" }, "name": { "description": "env: the variable name.", "type": "string" }, "op": { "description": "file: read|write|delete|move. env: read|write.", "type": "string" }, "path": { "description": "file: the target path.", "type": "string" }, "query": { "description": "sql: the SQL statement.", "type": "string" }, "source": { "description": "code: the source to run.", "type": "string" }, "url": { "description": "http: the target URL.", "type": "string" } }, "required": [ "kind" ], "type": "object" }, "context": { "description": "Optional: where the task/input came from (untrusted source label).", "type": "string" }, "expected": { "description": "Machine-checkable constraints. Supplying them lets the verdict BIND the call; only a positively-scoped, satisfied call is auto-exec-safe.", "properties": { "allowedHosts": { "description": "http: the only hosts you intend to reach (required to auto-exec a networked call).", "items": { "type": "string" }, "type": "array" }, "allowedPaths": { "description": "file: the only paths you intend to touch (required to auto-exec a file write).", "items": { "type": "string" }, "type": "array" }, "noNetwork": { "description": "the call must not reach the network.", "type": "boolean" }, "readOnly": { "description": "the call must not mutate state (set false to auto-exec a mutating call).", "type": "boolean" } }, "type": "object" }, "intent": { "description": "What this call is for (natural language). Used by the classifier for intent-mismatch.", "type": "string" } }, "required": [ "call" ], "type": "object" }, "name": "tool-call-guard", "outputSchema": null }, { "description": "Vet an x402 counterparty before settling USDC: scores the advertised payment requirements AND (when supplied) the EIP-3009 authorization you are about to sign. Returns a machine-enforceable trust verdict (per-entry scores, coverage-honest trustScore, spend-constraint + tamper-evident fingerprint) for buyer agents and wallet/spend-policy layers. No endpoint fetch. [security; up to 200c/call]", "inputSchema": { "properties": { "context": { "description": "Optional free-form context.", "type": "string" }, "endpointUrl": { "description": "Resource URL being paid (context only; never fetched).", "type": "string" }, "expected": { "description": "Optional caller expectations.", "properties": { "asset": { "description": "Expected asset contract address", "type": "string" }, "chainId": { "type": "number" }, "identity": { "type": "string" }, "maxAmountAtomic": { "type": "string" }, "network": { "type": "string" }, "payTo": { "type": "string" } }, "type": "object" }, "paymentPayload": { "description": "The UNSIGNED EIP-3009 authorization the buyer is about to sign: { authorization|message: {from,to,value,validAfter,validBefore,nonce}, domain: {name,version,chainId,verifyingContract} }. Lets the audit bind the menu to the actual charge (server-enforced to/value/verifyingContract/chainId). Omit to vet requirements only - but then the verdict is never auto-settle-safe." }, "paymentRequirements": { "description": "The x402 payment requirements from the counterparty: the 402 `accepts` array, or a single object." }, "selectedOptionIndex": { "description": "Index in the accepts array the buyer intends to settle (default 0). The verdict is scoped to it.", "type": "number" }, "serverMetadata": { "description": "Optional server metadata the caller already holds (context only; not fetched)." }, "spendPolicy": { "description": "Optional buyer spend policy to evaluate against and to pin facilitators.", "properties": { "allowedAssets": { "items": { "type": "string" }, "type": "array" }, "allowedFacilitators": { "items": { "type": "string" }, "type": "array" }, "allowedNetworks": { "items": { "type": "string" }, "type": "array" }, "maxUsd": { "type": "number" } }, "type": "object" } }, "required": [ "paymentRequirements" ], "type": "object" }, "name": "x402-trust-audit", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:2332ba9586957e045ef70824246b23e6da5e5e71f36dc93c6948d5480fcde875 | sha256sum