Server definition
- Hash
- sha256:a3ed7eae8d4cfb30633273932fdce4f4dde87d6c58a6a5c5aa1182c714302525
- What it is
- What a remote MCP server returned when asked what it offers: 9 tools
The blob, as servednamed by its sha256
{
"instructions": "Fetchgate: read_url and get_metadata fetch/convert a URL server-side (free tier: 30 calls/day per caller, then $0.002/$0.001 per call via x402). scan_for_prompt_injection checks a page or text for injection attempts before you act on it; search_x402_services finds paid APIs that are live and actually bought; check_x402_endpoint says whether an x402 endpoint is worth paying (same free tier, then $0.003/$0.005/$0.01). list_products and get_purchase_info browse and explain how to buy Fetchgate's digital-goods catalog (x402, no account). See https://fetchgate.dev/llms.txt for the full API reference.",
"tools": [
{
"description": "Decide whether an unfamiliar pay-per-call (x402) endpoint is worth paying. Sends one unpaid GET to read its live payment challenge (format, price, network, signing domain), then adds its settled-call and unique-payer history, whether its live price matches its listed price, and its domain's reputation (template farm or not, share of its endpoints that answer). Returns a verdict — ok, caution, avoid or unknown — with the reasons. Nothing is paid. Use before an agent sends money to an endpoint it has not used before. Wraps GET /v1/x402/check. Same free daily tier as read_url; $0.01/call via x402 after that.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The x402 endpoint URL to check.",
"format": "uri",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "check_x402_endpoint",
"outputSchema": null
},
{
"description": "Return the Agent Web Crawler Census: every named bot observed crawling a live, publicly-listed x402 + MCP endpoint over a 24-hour window, each with a case-insensitive regex `matcher` and a behavioural `category` (liveness-monitor, directory-crawler, price-scraper, security-research, ai-training, ...) so you can classify your own access log. Observed first-hand, not aggregated from third-party bot lists. Notable finding: of the named agent-web crawlers in the census, zero have ever presented a payment, and several declare that in their own User-Agent string. Wraps GET /v1/agent-census.json. Free, unmetered, no payment required. CC BY 4.0.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"category": {
"description": "Optional. Return only agents in this behavioural category, e.g. \"price-scraper\" or \"liveness-monitor\". Omit for the full census.",
"type": "string"
}
},
"type": "object"
},
"name": "get_agent_census",
"outputSchema": null
},
{
"description": "Fetch a URL server-side and return structured metadata: title, description, canonical URL, OpenGraph/Twitter card fields, favicon URL, language, and published/modified timestamps when present. Wraps GET /v1/meta. Same free tier as read_url; priced at $0.001/call via x402 once exhausted.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "Absolute http(s) URL to fetch.",
"format": "uri",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "get_metadata",
"outputSchema": null
},
{
"description": "Look up a product by id (from list_products) and explain exactly how to buy it: its price, and the x402 purchase flow step by step (the 402 challenge shape, the PAYMENT-SIGNATURE header, and the signed download URL you get back on success). Does not take payment itself — informational only, mirroring the pre-payment leg of GET /v1/buy/:id.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"product_id": {
"description": "Product id, from list_products' `id` field.",
"type": "string"
}
},
"required": [
"product_id"
],
"type": "object"
},
"name": "get_purchase_info",
"outputSchema": null
},
{
"description": "List Fetchgate's digital-goods catalog: id, name, description, priceUsd, currency, file format, size, sha256, and a walletless humanUrl checkout link for each product for sale. Wraps GET /v1/products. Free, no rate limit, no payment required just to browse.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_products",
"outputSchema": null
},
{
"description": "Fetch a URL server-side and return its main content as clean Markdown, with scripts/styles/nav/ads/boilerplate stripped out. Wraps GET /v1/read. Free tier: 30 calls/day per caller; priced at $0.002/call via x402 once that's exhausted (see get_purchase_info for how the x402 flow works). Only http:// and https:// URLs are accepted; private/internal-network hosts are rejected.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "Absolute http(s) URL to fetch.",
"format": "uri",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "read_url",
"outputSchema": null
},
{
"description": "Check untrusted content BEFORE acting on it. Give a `url` to fetch and scan a web page (its visible text and, separately, text hidden in HTML comments, alt/title/aria attributes and meta tags), or give `text` to scan a tool result, retrieved document or message you already have. Runs 120 detection rules covering instruction override, tool hijacking, data exfiltration, system-prompt extraction, jailbreak framing and encoding tricks (zero-width and Unicode-tag smuggling, homoglyphs, base64). Returns a 0-100 risk score, a recommended action (block / review / flag / none) and each match with its evidence. Heuristic: a clean result means nothing obvious tripped, not that the content is safe. Wraps /v1/scan. Same free daily tier as read_url; $0.003/call via x402 after that.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"text": {
"description": "Text to scan directly (use instead of url).",
"type": "string"
},
"url": {
"description": "Absolute http(s) URL of a page to fetch and scan.",
"format": "uri",
"type": "string"
}
},
"type": "object"
},
"name": "scan_for_prompt_injection",
"outputSchema": null
},
{
"description": "Connect to a remote Streamable HTTP MCP server, fetch its tools/list (sends only initialize, notifications/initialized and tools/list — never tools/call) and scan every tool name, description, parameter description and the server's initialize `instructions` string for tool-poisoning patterns: hidden-instruction markers, invisible Unicode, directives aimed at the model, credential/secret references, exfiltration shapes and instructions about other tools. Returns per-tool findings with severity, excerpt and a score band. Use it before installing or trusting a third-party server. Heuristic: a clean result means nothing obvious in what the server declares about itself, not that it is safe. Wraps GET /v1/mcp-scan. Free, rate-limited per caller; private/internal-network hosts are rejected.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"url": {
"description": "The MCP server's Streamable HTTP endpoint URL, e.g. https://example.com/mcp",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "scan_mcp_server",
"outputSchema": null
},
{
"description": "Search for a pay-per-call (x402) API that does what you need. Unlike a raw directory, results are limited to endpoints that answered a real x402 payment challenge AND had at least 5 settled calls from at least 2 distinct payers in the last 30 days, so dead, never-bought and template-farm listings are left out. Each result has the endpoint URL, method, price in USD, networks, 30-day calls and unique payers, and a flag when the payer count looks farmed. Use it when you need a paid API (search, scraping, enrichment, LLM, market data…) and want one that demonstrably works. Wraps GET /v1/x402/search. Same free daily tier as read_url; $0.005/call via x402 after that.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"limit": {
"description": "Results to return (default 10).",
"maximum": 25,
"minimum": 1,
"type": "integer"
},
"max_price_usd": {
"description": "Only return endpoints priced at or below this, per call.",
"type": "number"
},
"network": {
"description": "Payment network: base, solana, polygon, arbitrum, optimism, or a CAIP-2 id.",
"type": "string"
},
"query": {
"description": "What the API should do, in a few words, e.g. 'web search' or 'email verification'.",
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "search_x402_services",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:a3ed7eae8d4cfb30633273932fdce4f4dde87d6c58a6a5c5aa1182c714302525 | sha256sum