io.github.troothllc/trooth-network

Trooth

Machine-Readable Company Profiles: search, read and compare any company's Trust Profile.

1.1.5
Version
remote
Transport
8
Tools

Security review

Partly reviewed

Reviewed 30m ago.

  • tools: 8 tools scanned
  • metadata: scanned
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    trooth_my_company_record

Tools (8)

  • trooth_ai_data_use_disclosures

    Read what one company on the Trooth Network has declared about AI and customer data: whether it trains models on customer data, whether AI is in the product, and which approaches. The company is named by its domain or its Trooth slug, matched exactly. Each row is the company's own declaration and is labeled so. Also says whether Trooth observed a supporting policy clause; not observed means Trooth has not read one, never that the company does not train on customer data. Read only.

  • trooth_ask

    Answer a question about Trooth itself (what the Trooth Network is, what one company record carries, pricing, how witnessing works) from Trooth's fixed, curated knowledge base. Makes no outside request. A question the knowledge base does not cover returns out_of_scope; for a company's record use trooth_public_trust_profile.

  • trooth_compare_companies

    Compare two to 4 companies on the Trooth Network section by section, named by their domains or Trooth slugs separated by commas: each section's state for each company and the rows it published, side by side, with who said them. sections narrows it, e.g. security,privacy,ai. A section a company left empty is shown as not published, never filled in from another. Nothing is weighed or ordered; each cell is the company's own record. Read only.

  • trooth_my_company_record

    Needs an OAuth access token for this server from the authorization server its protected-resource metadata names, for a person who has signed in to trooth.co; no scope is required, and every other tool here needs no token. Reads the company record of the Trooth workspace the signed-in person belongs to: its name, its slug and the address of its public page. The workspace comes from the token's subject and never from an argument, so this tool takes no arguments. Read only.

  • trooth_outside_in_read

    Fetch https://<domain>/ and /.well-known/security.txt once, when called, from Trooth's server and report whether HTTPS answered, which of five response headers (HSTS, CSP, nosniff, frame protection, referrer policy) are present, and whether security.txt is published, absent or unread. IP literals and names resolving to private, loopback or link-local addresses are refused; redirects are reported, not followed; each request stops after 4 seconds. Observations, not witnessed evidence, not a grade.

  • trooth_public_trust_profile

    Read one company's published record on the Trooth Network, given its domain or Trooth slug, matched exactly (a URL is reduced to its host), never by a similar name; a name several companies share returns their candidates, not a pick. Returns its complete Trust Profile: every section with its state and who said it. A record is keyed by its domain and does not by itself say which legal entity, subsidiary or product the domain belongs to. Returns a status and a provenance label. Read only.

  • trooth_search_companies

    Search the companies published on the Trooth Network by name, domain, tagline or category, optionally within one industry. Returns up to 10 entries, each with its name and tagline in the company's own words, whether Trooth witnessed it, and the identifier that reads its record with trooth_public_trust_profile. No match is an honest absence on the Network, never a judgment about a company. Read only.

  • trooth_verify

    Check the two signatures on a Trust Ledger Token (tlt2. or tlt. form, or its JTI) against Trooth's own token ledger. Returns valid, invalid (a signature does not check out), expired or revoked, or unclaimed when no token matches. Trooth's signature covers the signing event, not the claim bytes and not the truth of the claims; the issuing company's signature covers the payload.