Server definition
- Hash
- sha256:dd7fd0790340c26da9012637ec698cdff83d30d33238abbdca253ded8333b9ee
- What it is
- What a remote MCP server returned when asked what it offers: 1 tools
The blob, as servednamed by its sha256
{
"instructions": "Dredd judges MCP server invocations BEFORE damage — server identity AND dependency graph (npm/pypi). Call check_mcp_server with the server name (and optional version + tool) to get a signed verdict: BLOCK, ADVISORY, or ALLOW. The dep_graph field in the response tells you whether transitive supply-chain risk (Shai-Hulud class) was checked.",
"tools": [
{
"description": "Pre-flight security verdict for an MCP server invocation. Judges BOTH server-level reputation AND the server's dependency graph (npm/pypi) against the DugganUSA threat-intel corpus (1.13M+ IOCs, Shai-Hulud + typosquat + LOLBin families). Returns BLOCK / ADVISORY / REVIEW / ALLOW with severity, evidence, dep-graph summary, and HMAC-signed response. REVIEW means we hold NO RECORD of this server -- not that it is safe. Treat REVIEW as do-not-proceed-blindly: a brand-new attacker-published server looks exactly like this. ALLOW is only returned when we actually resolved the server and scanned its dependency graph; check known_to_us and dep_graph.scanned to confirm. Use this BEFORE invoking any other MCP server tool, especially ones installed from outside the official MCP Registry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"server": {
"description": "MCP server name (e.g. io.github.foo/bar) or substring",
"type": "string"
},
"tool": {
"description": "Optional name of the specific tool being invoked",
"type": "string"
},
"version": {
"description": "Optional version of the MCP server (semver)",
"type": "string"
}
},
"required": [
"server"
],
"type": "object"
},
"name": "check_mcp_server",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:dd7fd0790340c26da9012637ec698cdff83d30d33238abbdca253ded8333b9ee | sha256sum