Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,547Letters: 14Defects: 1,324counted 2 min ago
teppi

Server definition

Hash
sha256:3aea324048399b319170ddb6439d9670a03914437236cee58dcd44a73bac8eea
What it is
What a remote MCP server returned when asked what it offers: 5 tools

The blob, as servednamed by its sha256

{ "instructions": null, "tools": [ { "description": "Get a security advisory (vulnerability) by its key.\n\nReturns a security advisory by key, for example a GHSA id taken from a version's advisoryKeys, including the title, CVE aliases, CVSS v3 score and vector, and a link to the full record on osv.dev. Use this only when you already have an advisory ID from get_package_version's advisoryKeys. There is no search here. To find out whether a version has vulnerabilities at all, call get_package_version first; this tool explains one advisory in depth.", "inputSchema": { "properties": { "advisoryKey": { "description": "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys).", "type": "string", "x-in": "path" } }, "required": [ "advisoryKey" ], "type": "object" }, "name": "get_advisory", "outputSchema": { "type": "object" } }, { "description": "Get the resolved dependency graph for one package version.\n\nReturns the full resolved dependency graph (direct and indirect) for a version. Each node has the dependency's exact version and its relation (SELF / DIRECT / INDIRECT). Use it to reason about transitive dependencies and supply chain.", "inputSchema": { "properties": { "package": { "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'.", "type": "string", "x-in": "path" }, "system": { "description": "Package ecosystem.", "enum": [ "npm", "pypi", "go", "maven", "cargo", "nuget", "rubygems" ], "type": "string", "x-in": "path" }, "version": { "description": "Exact version string, e.g. '18.2.0'.", "type": "string", "x-in": "path" } }, "required": [ "system", "package", "version" ], "type": "object" }, "name": "get_dependencies", "outputSchema": { "type": "object" } }, { "description": "List every version of a package and whether each is deprecated.\n\nReturns all published versions of a package with publish date, the default-version flag, and deprecation status. Use it to find the latest version or check if a package is deprecated. Coding agents should call this before recommending a package or version.", "inputSchema": { "properties": { "package": { "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'.", "type": "string", "x-in": "path" }, "system": { "description": "Package ecosystem.", "enum": [ "npm", "pypi", "go", "maven", "cargo", "nuget", "rubygems" ], "type": "string", "x-in": "path" } }, "required": [ "system", "package" ], "type": "object" }, "name": "get_package", "outputSchema": { "type": "object" } }, { "description": "Get license, security advisories, and source links for one package version.\n\nReturns detailed metadata for a single version: SPDX licenses, security advisoryKeys (known vulnerabilities), homepage/issue-tracker/source-repo links, registries, publish date, and deprecation status. Pass any advisoryKey returned here to get_advisory for the vulnerability details.", "inputSchema": { "properties": { "package": { "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'.", "type": "string", "x-in": "path" }, "system": { "description": "Package ecosystem.", "enum": [ "npm", "pypi", "go", "maven", "cargo", "nuget", "rubygems" ], "type": "string", "x-in": "path" }, "version": { "description": "Exact version string, e.g. '18.2.0'.", "type": "string", "x-in": "path" } }, "required": [ "system", "package", "version" ], "type": "object" }, "name": "get_package_version", "outputSchema": { "type": "object" } }, { "description": "Get a project's OpenSSF Scorecard security posture and maintenance signals.\n\nTHE trust check. Returns supply-chain trust signals for a package's source repository: the OpenSSF Scorecard overall score (0-10) and per-check results (Maintained, Code-Review, Signed-Releases, Branch-Protection, Pinned-Dependencies, Dangerous-Workflow, Token-Permissions, Security-Policy, Vulnerabilities, ...), plus stars, forks, open-issue count, and license. Use it to judge whether a dependency is actively maintained and securely operated, not just whether it has a known CVE. Get the projectKey from a version's SOURCE_REPO link (call get_package_version first), e.g. 'github.com/facebook/react'.", "inputSchema": { "properties": { "projectKey": { "description": "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version).", "type": "string", "x-in": "path" } }, "required": [ "projectKey" ], "type": "object" }, "name": "get_project_health", "outputSchema": { "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:3aea324048399b319170ddb6439d9670a03914437236cee58dcd44a73bac8eea | sha256sum