nsgoods-workbench-mcp
Read only x402 catalogue: payability verdicts, prices, drift, host status, signatures. No wallet.
- 1.0.0
- Version
- remote
- Transport
- 8
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 8 tools scanned
- metadata: scanned
No findings.
Tools (8)
payability_verdict
Latest payability observation for one exact resource URL (path and query included), with the meaning of the verdict, remediation if it cannot be paid, and the per-network options seen. last_checked_at is the last time any scan looked at the resource; verdict_since is when the current verdict was first observed in the unbroken run that leads to it. A scan that did not contain the resource does not break the run, so verdict_since can span weeks nobody measured. How current a row is comes from last_checked_at and in_latest_scan, not from verdict_since alone.
find_endpoints
Search the catalogue by host or URL substring. Returns up to `limit` endpoints (max 50) with their latest verdict, plus the total match count. Use this first when you do not know the exact resource URL. Rows with in_latest_scan=false were not in the latest full scan; read last_checked_at for when they were last probed. Optional network filter (for example eip155:8453 or solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp) and sort=price for the cheapest first. last_checked_at is the last time any scan looked at the resource; verdict_since is when the current verdict was first observed in the unbroken run that leads to it. A scan that did not contain the resource does not break the run, so verdict_since can span weeks nobody measured. How current a row is comes from last_checked_at and in_latest_scan, not from verdict_since alone.
catalogue_stats
Size and health of the x402 catalogue as of the latest full scan: resources, hosts, verdict counts, and payable endpoints per network.
host_summary
Summary for a host (no time series): first/last seen, current verdict mix, n_resources, total verdict changes, gone_since if absent from the latest full scan, and a small resources_sample. Sample rows with in_latest_scan=false were not in the latest full scan; read last_checked_at for when they were last probed. n_resources counts every resource ever seen for this host; current_verdict_mix and n_payable_last_full count only the latest full scan. last_checked_at is the last time any scan looked at the resource; verdict_since is when the current verdict was first observed in the unbroken run that leads to it. A scan that did not contain the resource does not break the run, so verdict_since can span weeks nobody measured. How current a row is comes from last_checked_at and in_latest_scan, not from verdict_since alone.
x401_status
Current x401 emitter adoption across the scanned catalogue (from the daily watcher).
drift_status
Verdict changes between the two latest full scans (catalogue wide, or for one host), plus the declared model drift watch.
verify_signature
Offline EIP-191 verify of a signed nsgoods response. Identifies the service from the manifest (or the optional `service` arg), strips exactly that service's post-sign fields, canonicalises (JCS, both ASCII modes), recovers the signer and checks it against the published manifest signers. Reproduction-attestation (JCS/byte-length) and envelope (signer/signature, components) shapes are reported as unsupported_shape, not verified here. Refusals carry a distinct status: malformed_signature (signature is not a 65-byte 0x-prefixed hex string), schema_rejected (the body carries a signed_by/signature pair but fails the required field shape for every service the claimed signer covers; recovery was not attempted, checked is false, reasons lists the failed candidates), signature_mismatch (well-formed but recovers a different address than signed_by under every candidate service recipe of this signer), no_flat_recipe (signed_by is a manifest signer but every s
reports
Published weekly payability reports (from the signed manifest).