Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,554Letters: 14Defects: 1,331counted 4 min ago
teppi

Server definition

Hash
sha256:e8bfe290701a87d500d4e7d826c26cc2dff565fc2e25114f672ce066e8af5954
What it is
What a remote MCP server returned when asked what it offers: 22 tools

The blob, as servednamed by its sha256

{ "instructions": null, "tools": [ { "description": "Context lookup: Resolve a single DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, or SRV) and return the raw answers. Use for quick, targeted lookups of one record type; prefer dossier_dns for a full multi-type DNS audit in parallel, or dossier_full for a complete domain health check. Queries Cloudflare DoH (1.1.1.1/dns-query) over HTTPS, follows CNAME chains, 5 s timeout. Returns a JSON array of answer objects with name, type, and data fields. On error, returns a string describing the DNS failure.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "name": { "description": "Domain name or hostname to resolve, e.g. example.com or mail.example.com. FQDN preferred; relative labels are accepted.", "type": "string" }, "type": { "description": "DNS record type to query. Common choices: A (IPv4), AAAA (IPv6), MX (mail), TXT (SPF/DKIM/verification), NS (nameservers), CNAME (alias).", "enum": [ "A", "AAAA", "MX", "TXT", "NS", "CNAME" ], "type": "string" } }, "required": [ "name", "type" ], "type": "object" }, "name": "dns_lookup", "outputSchema": null }, { "description": "Core dossier check: Report a domain's AI-crawler policy — whether robots.txt allows, blocks, or is silent on the six major AI agents (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent). Use to answer \"does this site let AI models train on / retrieve its content?\" in a posture audit. Fetches https://<domain>/robots.txt, follows redirects (off-site redirect = no policy), 10s timeout; parses robots groups. Returns a CheckResult; on success { hasRobots, agents: { <agent>: 'allowed' | 'blocked' | 'unspecified' } }. A missing robots.txt is data, not an error (every agent unspecified).", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_ai_crawlers", "outputSchema": null }, { "description": "Core dossier check: Send a CORS preflight OPTIONS request to https://<domain>/ and return the access-control-* response headers. Use to verify CORS policy for a specific origin-method pair, or to check whether a domain allows cross-origin requests; provide origin and method to simulate a precise preflight, or omit to use defaults (origin: https://domainposture.com, method: GET). Single OPTIONS request via fetch, 5 s timeout. Returns a CheckResult: on success, {status:\"ok\", headers:{access-control-allow-origin,...}}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" }, "method": { "description": "Access-Control-Request-Method header value, e.g. POST or PUT. Defaults to GET if omitted.", "type": "string" }, "origin": { "description": "Origin header value to include in the preflight, e.g. https://app.example.com. Defaults to https://domainposture.com if omitted.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_cors", "outputSchema": null }, { "description": "Core dossier check: Discover subdomains visible in Certificate Transparency logs. Use for attack-surface mapping; prefer dossier_full when running a complete audit. Queries crt.sh first, falls back to certspotter; capped at 100 unique subdomains; 10s timeout. Returns a CheckResult with { subdomains[], wildcards[], certCount, source }.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_ct_log", "outputSchema": null }, { "description": "Core dossier check: Probe a domain's DKIM public keys by querying <selector>._domainkey.<domain> for each selector. Use to verify signing configuration or discover active selectors; supply selectors when you know the ESP's selector, or omit to probe six common selectors (default, google, k1, selector1, selector2, mxvault). Issues parallel Cloudflare DoH (1.1.1.1) TXT queries per selector, 5 s timeout each. Returns a CheckResult: {status:\"ok\", found:[{selector, publicKey, raw},...], notFound:[...]} or {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" }, "selectors": { "description": "DKIM selector names to probe, e.g. [\"google\", \"s1\"]. Omit to probe the built-in common-selectors set: default, google, k1, selector1, selector2, mxvault.", "items": { "type": "string" }, "type": "array" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_dkim", "outputSchema": null }, { "description": "Core dossier check: Retrieve and parse a domain's DMARC policy from its _dmarc.<domain> TXT record, returning all tags. Use to audit email authentication policy, verify the p (policy) and rua (reporting) settings, or confirm alignment mode; pair with dossier_spf and dossier_dkim for complete email-auth coverage. Queries _dmarc.<domain> via Cloudflare DoH (1.1.1.1), 5 s timeout; parses each tag=value pair. Returns a CheckResult: on success, {status:\"ok\", raw, tags:{p, rua, ruf, adkim, aspf,...}}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_dmarc", "outputSchema": null }, { "description": "Core dossier check: Fetch a domain's full DNS profile — A, AAAA, NS, SOA, CAA, and TXT records — all in parallel. Use as the first step of a domain audit or when you need a comprehensive DNS snapshot in one call; prefer dns_lookup for a single record type, or dossier_full for all 10 dossier checks at once. Fires six Cloudflare DoH (1.1.1.1) queries concurrently, each with a 5 s timeout. Returns a CheckResult discriminated union: on success, {status:\"ok\", records:{a, aaaa, ns, soa, caa, txt}}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_dns", "outputSchema": null }, { "description": "Core dossier check: Verify DNSSEC chain-of-trust for a domain (DS, DNSKEY, AD flag). Use to confirm the zone is signed and resolvers accept the chain; prefer dossier_dns for raw record types or dossier_full for the complete audit. Fires Cloudflare DoH DS and DNSKEY queries with DO=1; 8s timeout. Returns a CheckResult discriminated union with { dnssecEnabled, adFlag, ds[], dnskey[] } on success.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_dnssec", "outputSchema": null }, { "description": "Aggregate dossier check: Run all 10 Domain Dossier checks — dns, mx, spf, dmarc, dkim, tls, redirects, headers, cors, web-surface — in parallel and return all results in a single response. Use when you need a comprehensive domain health snapshot in one call; counts as ONE paywall call regardless of how many checks run. For a single focused check, prefer the individual dossier_* tools to minimise latency. Fires all 10 checks concurrently via Cloudflare DoH or direct HTTPS, 5 s per-check timeout. Returns a JSON object keyed by check id (dns, mx, etc.), each value a CheckResult discriminated union ({status:\"ok\",...} or {status:\"error\", reason}).", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_full", "outputSchema": null }, { "description": "Core dossier check: Fetch https://<domain>/ and return all HTTP response headers, with an audit highlighting missing or misconfigured security headers. Use to review CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy; for redirect tracing use dossier_redirects instead. Single GET via fetch, 5 s timeout, captures raw response headers before any redirect is followed. Returns a CheckResult: on success, {status:\"ok\", headers:{...}, securityAudit:[{header, present, value},...]}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_headers", "outputSchema": null }, { "description": "Core dossier check: Detect whether a domain publishes an llms.txt at its root — the emerging convention that gives AI agents a curated markdown index of a site's content. Use in a content-posture audit to confirm a site guides (rather than ignores) AI agents. Fetches https://<domain>/llms.txt, 10s timeout; requires a non-HTML content type and a leading markdown H1 (a catch-all SPA answering 200 with HTML is NOT an llms.txt). Returns a CheckResult; on success { bytes, firstLine }; not_applicable when absent.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_llms_txt", "outputSchema": null }, { "description": "Core dossier check: Fetch and validate a domain's MTA-STS policy (mode, mx, max_age, policy id). Use to confirm inbound SMTP is locked to TLS for this domain. Resolves the _mta-sts TXT record, then fetches the policy from mta-sts.<domain>/.well-known/mta-sts.txt; 10s timeout. Returns a CheckResult; not_applicable when no MTA-STS TXT is published.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_mta_sts", "outputSchema": null }, { "description": "Core dossier check: Look up a domain's MX (mail exchanger) records and return them sorted ascending by priority. Use when verifying inbound-mail routing or as a precursor to SPF or DMARC checks; prefer dns_lookup with type=MX if you only need the raw DNS answer without the ranked view. Queries Cloudflare DoH (1.1.1.1), follows CNAME aliases, 5 s timeout. Returns a CheckResult discriminated union: on success, {status:\"ok\", records:[{exchange, priority},...]} sorted by priority; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_mx", "outputSchema": null }, { "description": "Core dossier check: Trace the full HTTP redirect chain starting from https://<domain>/, recording each hop's status code and destination URL. Use to debug redirect loops, verify HTTP→HTTPS upgrades, or audit link shorteners; stops at 10 hops to prevent infinite loops. Follows Location headers with fetch (no auto-redirect), 5 s per hop. Returns a CheckResult: on success, {status:\"ok\", hops:[{url, statusCode, redirectsTo},...], final}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_redirects", "outputSchema": null }, { "description": "Core dossier check: Verify a domain publishes a security.txt (RFC 9116) at /.well-known/security.txt — the standard machine-readable channel for reporting vulnerabilities. Use in a security audit to confirm researchers have a published disclosure route; its absence is a genuine (minor) audit flag. Fetches https://<domain>/.well-known/security.txt, 10s timeout; requires a non-HTML content type and a Contact: field. Returns a CheckResult; on success { contact[], expires, raw }; not_applicable when absent.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_security_txt", "outputSchema": null }, { "description": "Core dossier check: Retrieve and parse a domain's SPF record, decomposing it into mechanisms and qualifiers. Use to verify email sender policy, debug delivery failures, or check the 10-lookup limit; pair with dossier_dmarc for full email-auth coverage, or use dns_lookup with type=TXT for the raw record only. Fetches TXT records via Cloudflare DoH (1.1.1.1), 5 s timeout, locates the v=spf1 record and parses all mechanisms. Returns a CheckResult: on success, {status:\"ok\", raw, mechanisms:[{type, value, qualifier},...], lookupCount}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_spf", "outputSchema": null }, { "description": "Core dossier check: Fetch and inspect the TLS certificate presented by a domain on port 443, returning chain details and validity period. Use to verify certificate expiry, issuer, Subject Alternative Names, or detect mismatched or self-signed certs; not a full cipher-suite scanner. Performs a TLS handshake from the server edge, 5 s timeout; extracts the leaf certificate. Returns a CheckResult: on success, {status:\"ok\", subject, issuer, validFrom, validTo, daysRemaining, sans, fingerprint}; on failure, {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_tls", "outputSchema": null }, { "description": "Core dossier check: Look up a domain's TLS-RPT (SMTP TLS Reporting) policy. Use to confirm the domain receives reports of SMTP-TLS failures. Resolves _smtp._tls.<domain> TXT via Cloudflare DoH; 5s timeout. Returns a CheckResult; not_applicable when no record is published.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_tlsrpt", "outputSchema": null }, { "description": "Core dossier check: Snapshot a domain's public web surface: robots.txt, sitemap.xml, and the home-page <head> metadata (title, description, OpenGraph, Twitter cards). Use for SEO audits, content discovery, or verifying metadata before sharing; for HTTP headers use dossier_headers, for redirect behavior use dossier_redirects. Fetches /, /robots.txt, and /sitemap.xml concurrently via HTTPS, 5 s each; parses <head> with a lightweight HTML parser. Returns a composite CheckResult: {status:\"ok\", meta:{title, description, og, twitter}, robots, sitemapPresent} or {status:\"error\", reason}.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_web_surface", "outputSchema": null }, { "description": "Core dossier check: Look up the registrar, creation date, expiry date, and registry statuses for a domain. Use for ownership/expiry audit. Queries WHOIS over TCP/43 via the `whoiser` library; 15s timeout. Returns a CheckResult; not_applicable when the registry refuses or redacts the query (common on cloud IPs).", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "Public FQDN, e.g. example.com. Must be resolvable on the public internet; IPs, ports, paths, and protocol prefixes are rejected.", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "dossier_whois", "outputSchema": null }, { "description": "Context lookup: Resolve an IPv4 or IPv6 address to its geolocation, ASN, org name, and city/country. Use when you need network or location context for a raw IP address; prefer dns_lookup or dossier_dns for hostname resolution. Queries ipinfo.io with a server-side token — the token is never exposed to callers. Returns a JSON object with fields ip, city, region, country, org, loc, and timezone. On failure, returns an error string describing what went wrong.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "ip": { "description": "IPv4 or IPv6 address to look up, e.g. 1.2.3.4 or 2001:db8::1. Hostnames are not accepted.", "type": "string" } }, "required": [ "ip" ], "type": "object" }, "name": "ip_lookup", "outputSchema": null }, { "description": "Context lookup: Parse a User-Agent header string into structured browser, OS, device type, and rendering-engine components. Use to identify client capabilities from a raw UA string, e.g. when analysing server logs or request headers; does not perform any network lookups — entirely local parsing. Runs synchronously using the ua-parser-js library with no external calls. Returns a JSON object with browser.name, browser.version, os.name, os.version, device.type, device.vendor, and engine.name fields; unknown fields are empty strings.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "ua": { "description": "Full User-Agent header value as sent by the browser or HTTP client, e.g. \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36\".", "type": "string" } }, "required": [ "ua" ], "type": "object" }, "name": "user_agent_parse", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:e8bfe290701a87d500d4e7d826c26cc2dff565fc2e25114f672ce066e8af5954 | sha256sum