FHI MCP Server Security Audit
Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (2)
- LOWin payment_info
- LOWin sec_material_event_delta
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"fhi-x402-security-tools": {
"url": "https://polished-truth-c514.fhi-llc-1118.workers.dev/mcp"
}
}
}Remote-Endpunkte
https://polished-truth-c514.fhi-llc-1118.workers.dev/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (6)
⚪payment_info
Free guide to the FHI MCP tools, Base-USDC x402 payment flow, and per-tool prices.
Eingabe-Schema
{
"type": "object",
"properties": {}
}🟡domain_change_evidence(domain)
Stateful DNS, CAA, and certificate-transparency monitoring for a public domain. The first call establishes a baseline; later calls return evidence changes and certificate-expiry signals. ($0.01 USDC on Base)
Eingabe-Schema
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"minLength": 1
}
},
"required": [
"domain"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪package_install_preflight(ecosystem, name, version, expectedName)
npm or PyPI install preflight: blocks missing packages, detects near-name typosquats when an expected name is supplied, and checks OSV advisories. ($0.01 USDC on Base)
Eingabe-Schema
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"enum": [
"npm",
"PyPI"
]
},
"name": {
"type": "string",
"minLength": 1
},
"version": {
"type": "string"
},
"expectedName": {
"type": "string"
}
},
"required": [
"ecosystem",
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪sec_material_event_delta(cik, ticker, since)
New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)
Eingabe-Schema
{
"type": "object",
"properties": {
"cik": {
"type": "string"
},
"ticker": {
"type": "string"
},
"since": {
"type": "string",
"minLength": 1
}
},
"required": [
"since"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪mcp_payment_preflight(serverUrl)
MCP server security audit before an agent connects or pays: probes initialize and tools/list, then returns an ALLOW, CAUTION, or BLOCK risk score for command, filesystem, or wallet capabilities; prompt-injection or data-exfiltration signals; permissive JSON-schema inputs; missing HSTS; and a large tool surface. Does not execute tools. ($0.01 USDC on Base)
Eingabe-Schema
{
"type": "object",
"properties": {
"serverUrl": {
"type": "string",
"format": "uri"
}
},
"required": [
"serverUrl"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪mcp_vendor_due_diligence(mcpUrl, ticker, cik, since)
One decision-ready due-diligence dossier before an agent adopts or pays an MCP vendor: live MCP metadata and tool-risk preflight, DNS/CAA/certificate evidence, plus optional SEC material-filing evidence for a public company. Does not execute vendor tools or certify safety. ($0.10 USDC on Base)
Eingabe-Schema
{
"type": "object",
"properties": {
"mcpUrl": {
"type": "string",
"format": "uri"
},
"ticker": {
"type": "string"
},
"cik": {
"type": "string"
},
"since": {
"type": "string"
}
},
"required": [
"mcpUrl"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Nachweis