Server definition
- Hash
- sha256:6c3faa0fa134f5414497025e3ce4bcdcde0a5f45a30c25825b6ce838e07d5f21
- What it is
- What a remote MCP server returned when asked what it offers: 8 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "Audits a public agent or API URL for verifiability: discovery files (llms.txt, MCP card, robots, sitemap), handshake endpoints, and whether presented signed proofs validate. Returns a 0-100 score, a grade, ranked fixes, and a signed proof of the audit. Every result re-derives from a public fetch. Docs: https://api.babyblueviper.com/docs",
"inputSchema": {
"properties": {
"url": {
"description": "The agent endpoint/site URL to audit (public http(s) only)",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "audit_agent_readiness",
"outputSchema": null
},
{
"description": "Publishes a verifier's current conformance grade from the public registry (conformance.json) as a permanent, signed ledger entry, labeled 'certified as of this measurement'. It records the registry's existing measurement and cannot change it. Only works for a verifier currently listed as certified. Docs: https://api.babyblueviper.com/conformance",
"inputSchema": {
"properties": {
"name": {
"description": "The verifier's exact name as listed on GET /conformance.json (must currently show certified:true).",
"type": "string"
},
"note": {
"description": "Optional short context for the ledger entry.",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "conformance_certify",
"outputSchema": null
},
{
"description": "Reads invinoveritas's public track record of signed verdicts, including ones that turned out wrong. Each entry is a signed Nostr event whose id and signature can be recomputed against invinoveritas's published key; entries are append-only and Bitcoin-timestamped, so they can't be edited after the fact. No arguments returns the index; pass entry to read one. Free, no sign-in. Docs: https://api.babyblueviper.com/ledger",
"inputSchema": {
"properties": {
"entry": {
"description": "Optional entry number (e.g. '1'); omit for the full index.",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "ledger",
"outputSchema": null
},
{
"description": "Publishes one of your own signed review proofs (from review with sign=true) as a public entry on the invinoveritas ledger. Publication is immediate and permanent: the entry is broadcast to Nostr relays and Bitcoin-timestamped. Only genuine invinoveritas-signed proofs are accepted. Docs: https://api.babyblueviper.com/ledger",
"inputSchema": {
"properties": {
"event": {
"description": "The signed Nostr event from a prior /review(sign=true) call — the exact proof.event object that response returned.",
"type": "object"
},
"note": {
"description": "Optional short context: what this verdict was for, why it's worth featuring.",
"type": "string"
}
},
"required": [
"event"
],
"type": "object"
},
"name": "ledger_submit",
"outputSchema": null
},
{
"description": "Independent verdict on a proposed action before it is taken: a code diff, shell command, deployment plan, configuration change, another agent's output, or a proposed transaction. Returns approve / approve_with_concerns / reject with a confidence score, issues ranked by severity, suggested fixes and alternatives. With sign=true the verdict is returned as a signed proof that anyone can check later with verify_proof. The verdict is a reasoned second opinion, not a guarantee of outcome. Docs: https://api.babyblueviper.com/docs",
"inputSchema": {
"examples": [
{
"artifact": "rm -rf ./build && git push --force origin main",
"artifact_type": "shell_command",
"context": "About to force-push a rebuilt main branch that other people pull from.",
"sign": true
}
],
"properties": {
"action_binding": {
"description": "Optional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed.",
"type": "object"
},
"artifact": {
"description": "The artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text",
"type": "string"
},
"artifact_type": {
"default": "general",
"description": "Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason.",
"enum": [
"code_diff",
"patch",
"shell_command",
"plan",
"config_change",
"analysis",
"agent_output",
"trade",
"onchain_action",
"sanctions_screening",
"general"
],
"type": "string"
},
"concerns": {
"description": "Specific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')",
"type": "string"
},
"confidentiality_tier": {
"default": "hash_only",
"description": "Which privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve.",
"enum": [
"hash_only",
"partial_disclosure",
"full_disclosure"
],
"type": "string"
},
"context": {
"description": "What you are trying to accomplish, why now, success criteria",
"type": "string"
},
"disclosed_summary": {
"description": "Only used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values.",
"type": "string"
},
"external_evidence": {
"description": "Optional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence.",
"type": "array"
},
"intended_audience": {
"description": "Optional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all.",
"type": "string"
},
"intended_verifier": {
"description": "Optional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address.",
"type": "string"
},
"mediator_attestation": {
"description": "Optional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence.",
"type": "object"
},
"related_claims": {
"description": "Optional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth.",
"type": "object"
},
"related_proof_event": {
"description": "Optional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing.",
"type": "object"
},
"request_capture_ref": {
"description": "Optional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in.",
"type": "string"
},
"severity_threshold": {
"default": "all",
"description": "Minimum severity to report",
"enum": [
"blocker",
"high",
"medium",
"all"
],
"type": "string"
},
"sign": {
"default": false,
"description": "Return the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof.",
"type": "boolean"
},
"verdict_relay": {
"description": "Optional (verdict-relay/v2): also return a BIP-340 signature an ERC-8414 InvinoveritasVerdictAuthoritySigned contract verifies on-chain (garyyang-finchip/task-token-standard#2). {chain_id, authority, task_contract, token_id, submission_id, task_version, result_hash, task_document}. Requires sign=true. result_hash must be sha256 of the exact artifact; task_document is the plaintext task document (sha256 = the kernel's tdHash) and is put into the review context. approved/decision_ref come from our own verdict (approve->true, reject->false; concerns/defer unsigned). Checked before any charge. Result field verdict_relay.",
"type": "object"
}
},
"required": [
"artifact"
],
"type": "object"
},
"name": "review",
"outputSchema": null
},
{
"description": "Statistical reality-check of a backtest from its realized returns (or trade rows), not the strategy itself. Returns likely_real / borderline / overfit_or_noise using the Deflated Sharpe Ratio (adjusted for the number of variants tried), a sign-flip permutation test, and out-of-sample decay across purged folds. Inputs are not retained beyond a redacted audit hash. Docs: https://api.babyblueviper.com/docs",
"inputSchema": {
"properties": {
"agent_id": {
"description": "Optional caller agent ID",
"type": "string"
},
"k_folds": {
"default": 5,
"maximum": 20,
"minimum": 2,
"type": "integer"
},
"n_perms": {
"default": 2000,
"maximum": 3000,
"minimum": 200,
"type": "integer"
},
"n_trials": {
"default": 1,
"description": "How many strategy variants/params you tried before selecting this one. Be honest — more trials = bigger Deflated-Sharpe haircut.",
"maximum": 10000000,
"minimum": 1,
"type": "integer"
},
"periods_per_year": {
"description": "Optional, for annualized-Sharpe display only.",
"exclusiveMinimum": 0,
"type": "number"
},
"returns": {
"description": "Per-trade (or per-period) realized returns.",
"items": {
"type": "number"
},
"type": "array"
},
"trades": {
"description": "Alternative to 'returns': rows with a return field (ret/pnl/net_bps) and optional 'coin'/'ts'/'entry'/'exit' fields.",
"items": {
"type": "object"
},
"type": "array"
},
"trial_sharpes": {
"description": "Optional: Sharpes of all variants tried → exact DSR variance.",
"items": {
"type": "number"
},
"type": "array"
}
},
"type": "object"
},
"name": "validate",
"outputSchema": null
},
{
"description": "Checks a signed invinoveritas proof without trusting whoever handed it over: recomputes the event id, checks the Schnorr signature, and confirms the signing key is invinoveritas's published key. Optionally pass expect_artifact_hash (sha256 of the content you received) to confirm the proof covers that exact content. Accepts the full event, or an event_id to look up. Returns {valid, checks, proof_payload}. Free, no sign-in. Docs: https://api.babyblueviper.com/verify",
"inputSchema": {
"properties": {
"event": {
"description": "The signed proof event {id,pubkey,created_at,kind,tags,content,sig} the counterparty handed you (from a /prove or /review sign=true response).",
"type": "object"
},
"event_id": {
"description": "Alternatively, the Nostr event id alone (from a /review sign=true, /prove, or /witness proof) — fetches the durably-stored full event, independent of relay retention, and verifies it.",
"type": "string"
},
"expect_artifact_hash": {
"description": "Optional sha256 hex of the output you received — asserts the proof is ABOUT that exact artifact.",
"type": "string"
},
"expect_intended_verifier": {
"description": "Optional (added 2026-08-16) — asserts the proof's declared intended_verifier matches you, the consumption-identity check alongside expect_artifact_hash's content-identity check. A match confirms the issuer's declared intent, not that delivery was actually restricted to you.",
"type": "string"
},
"proof_id": {
"description": "Alternatively, a stored attestation proof_id to fetch + verify.",
"type": "string"
},
"verifier_signature": {
"description": "Optional (added 2026-08-16) — an EIP-191 personal_sign signature over 'invinoveritas-verify-proof:<event_id>', signed by the key controlling the address in expect_intended_verifier (eip155 CAIP-10 namespace only). Cryptographically PROVES presenter identity rather than just asserting it — sets checks.intended_verifier_authenticated.",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "verify_proof",
"outputSchema": null
},
{
"description": "Timestamps and signs a third party's exact claim, unmodified and unjudged: 'we received this text, attributed to source X, at time T', not 'we agree with it'. The source is recorded as self-declared. The resulting proof checks with verify_proof. Docs: https://api.babyblueviper.com/docs",
"inputSchema": {
"properties": {
"body": {
"description": "The exact claim to anchor, byte-for-byte (max 16000 chars)",
"type": "string"
},
"source": {
"description": "Who this claim is attributed to (self-declared, NOT verified by us)",
"type": "string"
}
},
"required": [
"source",
"body"
],
"type": "object"
},
"name": "witness",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:6c3faa0fa134f5414497025e3ce4bcdcde0a5f45a30c25825b6ce838e07d5f21 | sha256sum