com.obeliskgate/trust-tools

trust-tools

Website security ratings, token verification, and tamper-evident ledger heads from Obelisk Gate.

1.0.0
Version
remote
Transport
8
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 8 tools scanned
  • metadata: scanned

No findings.

Tools (8)

  • scan_trust

    Run Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.

  • verify_token

    Verify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.

  • get_org_rating

    Read the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.

  • verify_agent_run_proof

    Verify an Obelisk run proof. Pass run_proof_token, the token Obelisk signs at POST /api/agent-proof/run: the tool checks Obelisk's signature against its published keys, that the named agent is active now with the same key that answered the run challenge, and which delegation hops matched the owner's registry when the token was signed. A bare run_proof envelope is only checked for internal consistency and is never reported as verified, because anyone can build one. Reports the envelope's commitment scheme: a legacy v1 envelope, whose hashes are unsalted, carries the warning unsalted-v1. Does not reveal or infer raw task data.

  • get_agent_proof

    Read an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.

  • transparency_head

    Read the current signed transparency head of Obelisk's tamper-evident receipt ledger. Save headAnchorHash with anchorCount and compare later: the count must never go down, and the head at a saved count must not change. No consistency proofs are published, so this cannot show a later head extends a saved one. Same data as /.well-known/obelisk-transparency.json.

  • gate_status

    Read the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.

  • explain_rating

    Explain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is read.