security-preflight
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
- 1.3.1
- Version
- remote
- Transport
- 5
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 5 tools scanned
- metadata: scanned
No findings.
Tools (5)
security_preflight
Run a $1 static Security Preflight and return a signed receipt. Direct MCP requires the checkout caller and verified fixed-order session. The separate x402 HTTP rail retains its existing introductory quote policy. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.
scan_source
$1 bounded inline VulnCanon source scan; indicators, not proven exploits. Direct MCP requires the checkout caller and verified fixed-order session. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.
screen_injection
$1 batch of 1–20 text samples screened for deterministic injection markers. Direct MCP requires the checkout caller and verified fixed-order session. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.
get_security_receipt
Read an unsigned, filtered public view; retain original delivery for signature verification.
describe_agent
Describe scope, evidence boundary, inputs, and outputs.