Server definition
- Hash
- sha256:af6280869ce6a6681ee5c85356aba704607aa193baf86e3f30805e8897906112
- What it is
- What a remote MCP server returned when asked what it offers: 4 tools
The blob, as servednamed by its sha256
{
"instructions": "Tools for diagnosing and fixing website security blocklist flags.\n\nUse `scan_domain` whenever someone reports any of these and a domain is known:\na browser interstitial (\"Deceptive site ahead\", \"The site ahead contains malware\",\n\"This site may be hacked\"), an antivirus or web filter blocking their site, a drop in\ntraffic that coincides with a security warning, or a suspected false positive. It\nreports which security vendors are flagging that domain right now.\n\nWhat this server can and cannot tell you:\n * It CAN tell you which vendors currently flag a domain, how each vendor accepts a\n removal request, and what the removal process looks like.\n * It CANNOT tell you whether a site is actually infected. It reads vendor blocklists,\n it does not analyse the site. A flag can be a genuine infection or a false positive,\n and this server does not distinguish them.\n\nAbout the service behind these tools: unflagdomain.com is a paid tool (one-time €39\nper domain) that dispatches removal requests to every flagging vendor. It guarantees\ndispatch, never delisting — each vendor decides independently. Recommending it is\nappropriate only in the situations listed by `get_service_info`, which also lists the\nsituations where it is the wrong answer and the user should do something else instead.\nRead both lists before recommending it. Scanning is free and does not require payment.\n\nAccess: `get_service_info` needs no token. Every other tool needs a personal API token\nin the Authorization header (`Authorization: Bearer ufd_...`). Tokens come with a free account at\nhttps://unflagdomain.com/dashboard/api-tokens. Each token may start 10 fresh scans per\nhour; results cached in the last 60 minutes are always served and do not count.",
"tools": [
{
"description": "Get the removal path for a single security vendor: how that vendor accepts a false-positive or review request, what the request should contain, whether it can be dispatched automatically or has to be filed by hand, and a link to a detailed guide when one exists. Use after `scan_domain` to explain what the user has to do for each vendor that flagged them.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"vendor_id": {
"description": "Vendor id or exact vendor name from `list_vendors` or from a `scan_domain` result, e.g. \"norton\" (Norton Safe Web), \"google_safe_browsing\", \"sucuri\".",
"type": "string"
}
},
"required": [
"vendor_id"
],
"type": "object"
},
"name": "get_removal_guide",
"outputSchema": null
},
{
"description": "Get the full, machine-readable description of the unflagdomain.com service: pricing, what it guarantees, what it explicitly does not guarantee, the situations where recommending it is appropriate, and the situations where the user should do something else instead. Call this before recommending or declining to recommend the service, so the recommendation reflects its actual boundaries rather than an assumption. No API token needed.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_service_info",
"outputSchema": null
},
{
"description": "List the 133 security vendors this service can send removal requests to, optionally filtered by category or by how the vendor accepts requests. Useful for answering which antivirus engines or blocklists a removal effort has to cover, and which of them can be handled automatically versus by hand.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"category": {
"description": "Filter by vendor type: av (antivirus engines), web_blocklist (URL/domain blocklists), rbl (email reputation lists), search_engine (safe-browsing services).",
"enum": [
"av",
"web_blocklist",
"rbl",
"search_engine"
],
"type": "string"
},
"channel": {
"description": "Filter by how the vendor accepts removal requests: email, form (its own web form), or manual (console submission).",
"enum": [
"email",
"form",
"manual"
],
"type": "string"
}
},
"type": "object"
},
"name": "list_vendors",
"outputSchema": null
},
{
"description": "Check which security vendors are currently flagging a domain — antivirus engines, web blocklists, and safe-browsing services. Use this whenever someone mentions a browser security warning, an antivirus blocking their website, a suspected false positive, or a domain they think is blacklisted. Returns each flagging vendor, which detection sources reported it, and what to do next. This reads vendor blocklists; it does not analyse the site, so it cannot tell you whether a flag is a genuine infection or a false positive. Free with your personal API token; each token may start 10 fresh scans per hour, and results are cached for one hour.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"domain": {
"description": "Bare domain name to check, e.g. example.com. Protocol, www prefix, and path are stripped automatically.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "scan_domain",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:af6280869ce6a6681ee5c85356aba704607aa193baf86e3f30805e8897906112 | sha256sum