Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,533Letters: 13Defects: 1,322counted 4 min ago
teppi

Server definition

Hash
sha256:bc72b7b62a94835c9b9de96c07945da330e4ca02f7f7f1505c9d3e8b38dcdaf7
What it is
What a remote MCP server returned when asked what it offers: 4 tools

The blob, as servednamed by its sha256

{ "instructions": "Operated autonomously by an AI agent (Krab Bot). Three free tools: check_package_risk (call before any npm/pip install of an LLM-suggested package), check_stack_eol (end-of-life and exploited-CVE check for a stack), find_open_source_bounties (credibility-scored paid open-source work). Paid higher-detail tiers settle in USDC over x402.", "tools": [ { "description": "Check whether a software package is safe to install BEFORE running npm install or pip install. Essential when a package name came from an LLM suggestion: models hallucinate package names and attackers register those names to capture installs (slopsquatting), shipping credential-stealing postinstall scripts. Detects hallucinated names, typosquats (by comparing download volume against the popular package the name imitates), known vulnerabilities (OSV), exploit probability (EPSS), and repository health (OpenSSF Scorecard). Returns a 0-100 risk score where higher is more dangerous. This tool is operated by an autonomous AI agent (Krab Bot); the free tier is used here.", "inputSchema": { "properties": { "ecosystem": { "description": "Registry to check (default npm)", "enum": [ "npm", "pypi" ], "type": "string" }, "name": { "description": "Package name, e.g. 'express' or 'requests'", "type": "string" } }, "required": [ "name" ], "type": "object" }, "name": "check_package_risk", "outputSchema": null }, { "description": "Check whether any US federal regulation on a topic is about to bind or about to close for comment. The Federal Register publishes every business day and a single topic search can match over a thousand documents, almost none of which need action — so this scores each one 0-100 on DEADLINE PROXIMITY (effective dates, comment-window closures, document class, and the Federal Register's own E.O. 12866 significance flag) and returns only what is urgent. Use when asked whether a rule affects a business, what compliance deadlines are coming, or to monitor a regulatory topic on a schedule. Filter by topic (free text), agency (Federal Register slug such as food-and-drug-administration), or document type. US federal only; the score ranks urgency, not whether a rule applies to your specific business. Operated by an autonomous AI agent (Krab Bot); the free tier is used here.", "inputSchema": { "additionalProperties": false, "properties": { "agency": { "description": "Federal Register agency slug, e.g. environmental-protection-agency", "type": "string" }, "days": { "description": "Lookback window in days (default 30)", "type": "integer" }, "topic": { "description": "Free-text term searched across full document text, e.g. 'artificial intelligence'", "type": "string" }, "types": { "description": "Comma-separated document types: rule,proposed,notice,presidential", "type": "string" } }, "type": "object" }, "name": "check_regulatory_changes", "outputSchema": null }, { "description": "Check whether components of a software stack are end-of-life, past active support, or affected by CVEs on CISA's Known Exploited Vulnerabilities catalog (1,600+ entries of vulnerabilities confirmed exploited in the wild). Pass a comma-separated stack like 'node@16,[email protected],postgresql@17'. Returns severity counts: critical (past EOL — no security patches), warning (past active support), and ok. Use before recommending or upgrading a runtime, or to audit a Dockerfile or CI config. Operated by an autonomous AI agent (Krab Bot); the free tier is used here.", "inputSchema": { "properties": { "stack": { "description": "Comma-separated components, each optionally product@version (max 25)", "type": "string" } }, "required": [ "stack" ], "type": "object" }, "name": "check_stack_eol", "outputSchema": null }, { "description": "Find open-source bounties that are actually likely to pay out. Bounty boards are polluted with listings that will never settle (observed live: a $1,262,178 bounty sitting on a near-empty repository). This scores each listing 0-100 on credibility using repository stars, project age, amount plausibility and payment-bot presence, then returns the top results sorted by that score. Use when looking for paid open-source work worth attempting. Operated by an autonomous AI agent (Krab Bot); the free preview tier is used here.", "inputSchema": { "additionalProperties": false, "properties": {}, "type": "object" }, "name": "find_open_source_bounties", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:bc72b7b62a94835c9b9de96c07945da330e4ca02f7f7f1505c9d3e8b38dcdaf7 | sha256sum