Server definition
- Hash
- sha256:94f70dd67ef0bcde41127d6f19af43097502f5ba25726c8765e1929ef5ebb1aa
- What it is
- What a remote MCP server returned when asked what it offers: 9 tools
The blob, as servednamed by its sha256
{
"instructions": "Use audit_a2a_agent_card before depending on an unfamiliar A2A agent; it never executes target-agent skills. Use audit_shopify_agentic_storefront for a public Shopify AI-shopping surface; it never executes store mutations. For remote MCP dependencies, use audit_mcp_dependency. Use screen_consequential_action before purchases, payments, cart/checkout mutations, writes, deployments, sends, deletes or execution. UI-capable hosts can render decision cards. Public results never expose GHOSBC private runtime.",
"tools": [
{
"description": "Use before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable badge metadata. It does not send a task to or execute any skill on the target agent.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"card_url": {
"description": "Public HTTPS A2A Agent Card URL, normally /.well-known/agent-card.json.",
"format": "uri",
"type": "string"
}
},
"required": [
"card_url"
],
"type": "object"
},
"name": "audit_a2a_agent_card",
"outputSchema": null
},
{
"description": "Use for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authenticated/private MCP endpoints.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"endpoint_url": {
"description": "Public HTTPS MCP endpoint.",
"format": "uri",
"type": "string"
}
},
"required": [
"endpoint_url"
],
"type": "object"
},
"name": "audit_mcp_dependency",
"outputSchema": null
},
{
"description": "Use to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates carts, checkouts, orders, payments, credentials, or store data.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"store": {
"description": "Public Shopify store domain or HTTPS URL, for example store.myshopify.com.",
"type": "string"
}
},
"required": [
"store"
],
"type": "object"
},
"name": "audit_shopify_agentic_storefront",
"outputSchema": null
},
{
"description": "Use only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "buy_policy_checks",
"outputSchema": null
},
{
"description": "Use before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"payload": {}
},
"required": [
"payload"
],
"type": "object"
},
"name": "sanitize_agent_payload",
"outputSchema": null
},
{
"description": "Use before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"capabilities": {
"items": {
"type": "string"
},
"type": "array"
},
"mode": {
"enum": [
"OPEN",
"GUARDED",
"SEALED"
],
"type": "string"
},
"text": {
"type": "string"
}
},
"required": [
"text"
],
"type": "object"
},
"name": "screen_agent_request",
"outputSchema": null
},
{
"description": "Use immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when explicit bounds fit; REVIEW when bounds are missing; BLOCK when limits are violated. Does not execute the action.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"action": {
"type": "string"
},
"amount": {
"type": "number"
},
"constraints": {
"additionalProperties": false,
"properties": {
"allowed_actions": {
"items": {
"type": "string"
},
"type": "array"
},
"allowed_targets": {
"items": {
"type": "string"
},
"type": "array"
},
"currency": {
"type": "string"
},
"expires_at": {
"format": "date-time",
"type": "string"
},
"max_amount": {
"type": "number"
}
},
"type": "object"
},
"currency": {
"type": "string"
},
"target": {
"type": "string"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "screen_consequential_action",
"outputSchema": null
},
{
"description": "Use before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code verification.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"annotations": {
"type": [
"object",
"null"
]
},
"description": {
"type": "string"
},
"inputSchema": {
"type": [
"object",
"null"
]
},
"name": {
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "screen_mcp_tool_definition",
"outputSchema": null
},
{
"description": "Use immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"response": {}
},
"required": [
"response"
],
"type": "object"
},
"name": "validate_agent_response",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:94f70dd67ef0bcde41127d6f19af43097502f5ba25726c8765e1929ef5ebb1aa | sha256sum