agents

Pay-per-call safety guards for AI agents: injection, tool-call, signing, secret, x402-trust.

Sollte ich dies verwenden

Qualität und Sicherheit

B
Qualität der Beschreibung
97%
Vollständigkeit des Schemas
97%
Qualität der Benennung
50%
Risiko der Vergiftung
80%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (9)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains suspicious base64-like encoded stringin tool-call-guard
  • LOWTool 'secure-code-review' doesn't follow camelCase/snake_casein secure-code-review
  • LOWTool 'pr-summary' doesn't follow camelCase/snake_casein pr-summary
  • LOWTool 'x402-trust-audit' doesn't follow camelCase/snake_casein x402-trust-audit
  • LOWTool 'sign-guard' doesn't follow camelCase/snake_casein sign-guard
  • LOWTool 'inject-guard' doesn't follow camelCase/snake_casein inject-guard
  • LOWTool 'tool-call-guard' doesn't follow camelCase/snake_casein tool-call-guard
  • LOWTool 'secret-scan' doesn't follow camelCase/snake_casein secret-scan

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~2,382Tokens (Tool-Definitionen)
~2.6 KBTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (1.86% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "agents": {
      "url": "https://paygent.obsmetrics.com/mcp"
    }
  }
}

Remote-Endpunkte

https://paygent.obsmetrics.com/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (7)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
⚪secure-code-review(code, language, context)

Security review of a code snippet or diff. Returns structured findings (severity, CWE, location, remediation). [security; up to 75c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Source code or unified diff to review"
    },
    "language": {
      "type": "string",
      "description": "Language hint, e.g. typescript, python"
    },
    "context": {
      "type": "string",
      "description": "Optional context about the code"
    }
  },
  "required": [
    "code"
  ]
}
🔴pr-summary(diff, style)

Turn a git diff into a clear PR description or release notes. [dev-tools; up to 30c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "diff": {
      "type": "string",
      "description": "Unified git diff to summarise"
    },
    "style": {
      "type": "string",
      "description": "e.g. conventional, changelog, executive"
    }
  },
  "required": [
    "diff"
  ]
}
⚪x402-trust-audit(paymentRequirements, selectedOptionIndex, paymentPayload, expected, spendPolicy, ...)

Vet an x402 counterparty before settling USDC: scores the advertised payment requirements AND (when supplied) the EIP-3009 authorization you are about to sign. Returns a machine-enforceable trust verdict (per-entry scores, coverage-honest trustScore, spend-constraint + tamper-evident fingerprint) for buyer agents and wallet/spend-policy layers. No endpoint fetch. [security; up to 200c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "paymentRequirements": {
      "description": "The x402 payment requirements from the counterparty: the 402 `accepts` array, or a single object."
    },
    "selectedOptionIndex": {
      "type": "number",
      "description": "Index in the accepts array the buyer intends to settle (default 0). The verdict is scoped to it."
    },
    "paymentPayload": {
      "description": "The UNSIGNED EIP-3009 authorization the buyer is about to sign: { authorization|message: {from,to,value,validAfter,validBefore,nonce}, domain: {name,version,chainId,verifyingContract} }. Lets the audit bind the menu to the actual charge (server-enforced to/value/verifyingContract/chainId). Omit to vet requirements only - but then the verdict is never auto-settle-safe."
    },
    "expected": {
      "type": "object",
      "description": "Optional caller expectations.",
      "properties": {
        "network": {
          "type": "string"
        },
        "chainId": {
          "type": "number"
        },
        "asset": {
          "type": "string",
          "description": "Expected asset contract address"
        },
        "payTo": {
          "type": "string"
        },
        "maxAmountAtomic": {
          "type": "string"
        },
        "identity": {
          "type": "string"
        }
      }
    },
    "spendPolicy": {
      "type": "object",
      "description": "Optional buyer spend policy to evaluate against and to pin facilitators.",
      "properties": {
        "maxUsd": {
          "type": "number"
        },
        "allowedNetworks": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "allowedAssets": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "allowedFacilitators": {
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      }
    },
    "endpointUrl": {
      "type": "string",
      "description": "Resource URL being paid (context only; never fetched)."
    },
    "serverMetadata": {
      "description": "Optional server metadata the caller already holds (context only; not fetched)."
    },
    "context": {
      "type": "string",
      "description": "Optional free-form context."
    }
  },
  "required": [
    "paymentRequirements"
  ]
}
🟡sign-guard(tx, typedData, expected, spendPolicy, context)

Pre-sign safety oracle for agent wallets: submit the transaction or EIP-712 message you are about to sign and get a machine-enforceable verdict. Decodes the calldata/typed-data, flags the drainer toolkit (unlimited approvals, setApprovalForAll, permit/permit2 + EIP-3009 to an unexpected party, transferFrom draining an unnamed account, ownership transfer, raw ETH to a stranger), and binds the decoded action to your stated intent - only a fully pinned, clean action is auto-sign-safe. Fails closed: an undecodable on-chain call is cautioned and an unrecognized off-chain signature grant is blocked. Deterministic, sub-second, no endpoint fetch. It vouches that the action matches what you said; it does NOT vouch that a counterparty is trustworthy. [security; up to 200c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "tx": {
      "type": "object",
      "description": "An EVM transaction you are about to sign.",
      "properties": {
        "to": {
          "type": "string",
          "description": "Target contract / recipient (0x address)."
        },
        "data": {
          "type": "string",
          "description": "Calldata hex (0x...). Omit for a plain ETH transfer."
        },
        "value": {
          "type": "string",
          "description": "Wei to send, decimal or 0x."
        },
        "chainId": {
          "type": "number",
          "description": "EIP-155 chain id (e.g. 8453 for Base)."
        }
      }
    },
    "typedData": {
      "type": "object",
      "description": "An EIP-712 message you are about to sign (the off-chain drainer surface: permit, Permit2, EIP-3009). { domain, types, primaryType, message }."
    },
    "expected": {
      "type": "object",
      "description": "Your stated intent. Supplying it lets the verdict BIND the action; only a fully bound, clean action is auto-sign-safe. For an allowance, you MUST supply maxAmount; for a transferFrom, supply `from`.",
      "properties": {
        "spender": {
          "type": "string",
          "description": "Address you intend to approve."
        },
        "recipient": {
          "type": "string",
          "description": "Address you intend to send to."
        },
        "from": {
          "type": "string",
          "description": "Account whose funds you intend to move (transferFrom / EIP-3009)."
        },
        "contract": {
          "type": "string",
          "description": "Contract you intend to call."
        },
        "asset": {
          "type": "string",
          "description": "Token contract you intend to touch."
        },
        "maxAmount": {
          "type": "string",
          "description": "Atomic ceiling you intend to expose (required to auto-sign an allowance)."
        },
        "chainId": {
          "type": "number",
          "description": "Chain you intend to act on."
        }
      }
    },
    "spendPolicy": {
      "type": "object",
      "description": "Optional buyer spend policy (context only)."
    },
    "context": {
      "type": "string",
      "description": "Optional free-form context."
    }
  }
}
🔴inject-guard(content, context)

Untrusted-content guardrail for agents: submit a blob of text you are about to feed to your own LLM (scraped web content, a tool result, another agent's message) and get a machine-enforceable verdict - is this a prompt-injection / jailbreak / data-exfiltration / tool-hijack attempt? Returns a risk level, the detected classes with spans, the unicode obfuscation it found (zero-width, bidi-override, tag-chars, homoglyphs), and a SANITIZED copy safe to feed onward. Hybrid: a deterministic, uninjectable pattern engine (authoritative) plus an LLM classifier that can only raise the risk, never clear a flag. Detection of known injection classes - not a proof of safety. [security; up to 15c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "The untrusted text to scan before you feed it to your LLM."
    },
    "context": {
      "type": "string",
      "description": "Optional: where the content came from (url, tool name, sender) - context only."
    }
  },
  "required": [
    "content"
  ]
}
🟡tool-call-guard(call, intent, expected, context)

Pre-execution safety oracle for agent actions: submit the tool call you are about to run (shell, http, sql, file, code, env) plus your stated intent, and get a machine-enforceable verdict before you execute it. Decodes what the call does, flags the danger toolkit (rm -rf, reverse shell, curl|sh, SSRF to cloud metadata, credential reads, DROP/DELETE-without-WHERE, path traversal, dynamic eval), and binds it to your intent (allowedHosts/allowedPaths/readOnly/noNetwork) - only a fully pinned, clean, intent-matched call is auto-exec-safe. Hybrid: a deterministic, uninjectable detector engine (authoritative) plus an LLM classifier that can only raise the risk. Fails closed. Detection of known-dangerous patterns, not a proof of safety; it never executes the call. [security; up to 8c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "call": {
      "type": "object",
      "required": [
        "kind"
      ],
      "description": "The tool call you are about to execute.",
      "properties": {
        "kind": {
          "type": "string",
          "enum": [
            "shell",
            "http",
            "sql",
            "file",
            "code",
            "env"
          ],
          "description": "The kind of action."
        },
        "command": {
          "type": "string",
          "description": "shell: the full command line."
        },
        "method": {
          "type": "string",
          "description": "http: HTTP method."
        },
        "url": {
          "type": "string",
          "description": "http: the target URL."
        },
        "body": {
          "type": "string",
          "description": "http: request body (context)."
        },
        "query": {
          "type": "string",
          "description": "sql: the SQL statement."
        },
        "op": {
          "type": "string",
          "description": "file: read|write|delete|move. env: read|write."
        },
        "path": {
          "type": "string",
          "description": "file: the target path."
        },
        "language": {
          "type": "string",
          "description": "code: the language."
        },
        "source": {
          "type": "string",
          "description": "code: the source to run."
        },
        "name": {
          "type": "string",
          "description": "env: the variable name."
        }
      }
    },
    "intent": {
      "type": "string",
      "description": "What this call is for (natural language). Used by the classifier for intent-mismatch."
    },
    "expected": {
      "type": "object",
      "description": "Machine-checkable constraints. Supplying them lets the verdict BIND the call; only a positively-scoped, satisfied call is auto-exec-safe.",
      "properties": {
        "allowedHosts": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "http: the only hosts you intend to reach (required to auto-exec a networked call)."
        },
        "allowedPaths": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "file: the only paths you intend to touch (required to auto-exec a file write)."
        },
        "readOnly": {
          "type": "boolean",
          "description": "the call must not mutate state (set false to auto-exec a mutating call)."
        },
        "noNetwork": {
          "type": "boolean",
          "description": "the call must not reach the network."
        }
      }
    },
    "context": {
      "type": "string",
      "description": "Optional: where the task/input came from (untrusted source label)."
    }
  },
  "required": [
    "call"
  ]
}
🟡secret-scan(content)

Leaked-credential guardrail for agents: submit a blob you are about to commit, log, post, or hand to another tool (a diff, a config, an .env, an LLM output) and get a machine-enforceable verdict - does it contain a live secret? Detects cloud keys (AWS), VCS tokens (GitHub/GitLab), provider API keys (Stripe, OpenAI, Anthropic, Google, Slack), private-key blocks, JWTs, and credentials embedded in URLs, plus high-entropy key=value assignments. Returns a risk level, the detected classes with a MASKED locator (never the secret itself, so the verdict cannot re-leak), and a REDACTED copy safe to emit onward. Deterministic, sub-second, never fetches. Detection of known secret formats - not a proof of cleanliness. [security; up to 200c/call]

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "The text to scan for leaked secrets (diff, config, .env, log line, LLM output)."
    }
  },
  "required": [
    "content"
  ]
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet7 Tools
verifiziertVersion nicht aufgezeichnet7 Tools