Server definition
- Hash
- sha256:88e29f918412406d417a6aa7bd98706a0291dbfdadd7257113cd1ca81ac0ee73
- What it is
- What a remote MCP server returned when asked what it offers: 3 tools
The blob, as servednamed by its sha256
{
"instructions": "polygraph publishes independent behavioral security grades (A-F) for MCP servers. Use check_server as the pre-flight check before recommending or installing a server: it returns the published grade in well under a second and runs nothing. A not_available result means the server is unevaluated (neither safe nor unsafe), not that it failed. Hosted grading is discontinued: request_grade returns gone. Grade a server yourself with the open harness (the self_grade command on a miss). list_servers returns servers with a published grade, 25 at a time by default (up to 100 per call), with a summary that always covers the full graded corpus. Every grade is reproducible: the report page carries a one-command re-run. This endpoint does not grade servers itself.",
"tools": [
{
"description": "Read a server's published behavioral grade (A-F) from polygraph.so in under a second; no execution. The pre-flight check before recommending or installing an MCP server. On a miss it returns not_available (unevaluated: neither safe nor unsafe) with next steps.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"server_ref": {
"description": "Registry-prefixed server ref: npm/<name>, npm/@scope/<name>, pypi/<name>, or github/<owner>/<repo>, with an optional @version. Example: npm/@modelcontextprotocol/server-filesystem",
"maxLength": 512,
"minLength": 1,
"type": "string"
}
},
"required": [
"server_ref"
],
"type": "object"
},
"name": "check_server",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"categories": {
"additionalProperties": false,
"description": "Per-category pass/fail, present when graded.",
"properties": {
"c01": {
"type": "string"
},
"c02": {
"type": "string"
},
"c03": {
"type": "string"
}
},
"required": [
"c01",
"c02",
"c03"
],
"type": "object"
},
"current_version": {
"type": [
"string",
"null"
]
},
"grade": {
"description": "A-F, present when status is graded.",
"type": "string"
},
"report_url": {
"type": "string"
},
"self_grade": {
"description": "One-command reproduce/grade, present on a miss.",
"type": "string"
},
"server_ref": {
"type": "string"
},
"status": {
"description": "Whether a published grade exists.",
"enum": [
"graded",
"not_available"
],
"type": "string"
},
"version_match": {
"type": [
"boolean",
"null"
]
}
},
"required": [
"status",
"server_ref"
],
"type": "object"
}
},
{
"description": "Servers with a published polygraph grade, sorted A-first then by ref. Returns up to `limit` rows starting at `offset` (default limit 25, capped at 100 per call); `grade` restricts to one letter. `summary` always covers the full graded corpus (a total plus a count per grade), regardless of `grade`, `limit`, or `offset`.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"grade": {
"description": "Restrict to servers with this grade.",
"enum": [
"A",
"B",
"C",
"D",
"F"
],
"type": "string"
},
"limit": {
"description": "Rows to return. Default 25, capped at 100 per call.",
"exclusiveMinimum": 0,
"type": "integer"
},
"offset": {
"description": "Rows to skip before taking `limit`, for paging past the first page.",
"minimum": 0,
"type": "integer"
}
},
"type": "object"
},
"name": "list_servers",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"servers": {
"items": {
"additionalProperties": false,
"properties": {
"polygraph": {
"type": "string"
},
"server_ref": {
"type": "string"
}
},
"required": [
"server_ref",
"polygraph"
],
"type": "object"
},
"type": "array"
},
"summary": {
"additionalProperties": false,
"description": "Always covers the full graded corpus, independent of `grade`, `limit`, or `offset`.",
"properties": {
"byGrade": {
"additionalProperties": false,
"description": "Count of graded servers per letter, across the whole corpus.",
"properties": {
"A": {
"type": "number"
},
"B": {
"type": "number"
},
"C": {
"type": "number"
},
"D": {
"type": "number"
},
"F": {
"type": "number"
}
},
"required": [
"A",
"B",
"C",
"D",
"F"
],
"type": "object"
},
"total": {
"description": "Total graded servers across the whole corpus.",
"type": "number"
}
},
"required": [
"total",
"byGrade"
],
"type": "object"
},
"total": {
"description": "Rows matching `grade` (if given), before `limit`/`offset`. Equals summary.total when grade is omitted.",
"type": "number"
}
},
"required": [
"total",
"servers",
"summary"
],
"type": "object"
}
},
{
"description": "Hosted grading is discontinued. This tool returns gone. Existing published grades remain available via check_server / list_servers. To grade a server yourself, run the open harness: npx -y -p @polygraphso/litmus polygraphso-litmus litmus <server_ref>.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"server_ref": {
"description": "Registry-prefixed server ref: npm/<name>, npm/@scope/<name>, pypi/<name>, or github/<owner>/<repo>, with an optional @version. Example: npm/@modelcontextprotocol/server-filesystem",
"maxLength": 512,
"minLength": 1,
"type": "string"
}
},
"required": [
"server_ref"
],
"type": "object"
},
"name": "request_grade",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"created": {
"description": "false if the server was already recorded.",
"type": "boolean"
},
"demand": {
"description": "How many times this server has been requested.",
"type": "number"
},
"payment": {
"additionalProperties": false,
"description": "How grading is paid for. The web checkout settles up front in $POLYGRAPH; the x402 rail takes an authorization that is charged only once a grade lands, and a run the harness cannot complete voids it, so nothing is charged. The fee buys the run, never the grade.",
"properties": {
"asset": {
"description": "The token the x402 rail expects: USDC.",
"type": "string"
},
"network": {
"description": "CAIP-2 chain id the x402 payment settles on: eip155:8453 (Base mainnet).",
"type": "string"
},
"payUrl": {
"description": "Human/browser checkout for this request, paid in $POLYGRAPH.",
"type": [
"string",
"null"
]
},
"required": {
"description": "false when the fee is already paid or authorized.",
"type": "boolean"
},
"usdPrice": {
"description": "The one-time fee, in USD.",
"type": "number"
},
"x402Url": {
"description": "The agent payment endpoint. POST the same request body here; a bare POST returns a 402 with the exact payment requirements, and a retry with an X-PAYMENT header pays it.",
"type": "string"
}
},
"required": [
"required",
"usdPrice",
"payUrl",
"x402Url",
"network",
"asset"
],
"type": "object"
},
"requestId": {
"description": "The recorded request's id.",
"type": [
"string",
"null"
]
},
"server_ref": {
"description": "The server ref that was recorded.",
"type": "string"
},
"status": {
"const": "queued",
"type": "string"
},
"statusUrl": {
"description": "Poll for grading progress (unpaid, grading, graded, failed); check_server also reflects the published result.",
"type": [
"string",
"null"
]
}
},
"required": [
"status",
"server_ref",
"created",
"demand",
"requestId",
"statusUrl",
"payment"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:88e29f918412406d417a6aa7bd98706a0291dbfdadd7257113cd1ca81ac0ee73 | sha256sum