com.ecocitizenz/trust-mcp

ECZ-ID Trust MCP

Read-only ECZ-ID Business Passport state lookup via the public ECZ-ID Resolver. Reports state only.

0.2.0
Version
remote
Transport
7
Tools

Security review

Review passed

Reviewed 20h ago.

  • tools: 7 tools scanned
  • metadata: scanned

No findings.

Tools (7)

  • resolve_identity

    Resolve an ECZ-ID through the public ECZ-ID Resolver and return the exact canonical state with checked_at, Resolver proof link, re-check action and the local-policy caveat. Never asserts safety, approval or compliance.

  • get_current_state

    Return the narrow current Resolver-derived state for an ECZ-ID (state, checked_at, Resolver link). No risk/safety/compliance inference.

  • get_resolver_link

    Return the deterministic public Resolver proof/re-check URL for an ECZ-ID. No network call.

  • explain_status

    Deterministically render the exact ECZ-ID status using the claims-safe renderer (VERIFIED is an ECZ-ID state, not a Microsoft certification). Absence of evidence renders the approved neutral wording — never "unsafe". No LLM.

  • find_product

    Given narrow context flags, return ONE best next ECZ-ID product action (free/community routes win where correct; neutral context routes to free public verification).

  • get_install_instructions

    Return deterministic official install/discovery routes for an ECZ-ID product or surface (canonical URLs only; planned Microsoft surfaces carry no URLs).

  • create_request_to_resolve

    AUTHENTICATED: create a neutral, shareable request for independently re-checkable ECZ-ID evidence. Requires a Microsoft Entra bearer token with the RequestToResolve.Create scope (or app role). It never verifies a target, never sends messages, and absence of evidence is never rendered as unsafe.