Agent Verifier
Test and debug your AI agent's Web Bot Auth (RFC 9421) signature: is it valid, and what to fix?
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (1)
- LOWin self_check_web_bot_auth
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"agent-verifier": {
"url": "https://fp.packet.guru/api/v1/mcp"
}
}
}Remote-Endpunkte
https://fp.packet.guru/api/v1/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (1)
🟢self_check_web_bot_auth
Reports how the request carrying this call looks from the outside: whether its Web Bot Auth (RFC 9421) signature verified, what the key directory it named publishes, the exact fault if there is one and the sentence saying what to change, plus plain facts about the address it arrived from. Sign the call the way you sign requests to anyone else. Free, anonymous, no account. Takes no arguments: an unsigned call still gets an answer about its address.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"properties": {
"success": {
"type": "boolean",
"description": "Always true on a 200. Errors carry success:false and an error object."
},
"id": {
"type": "string",
"description": "Identifier for this verdict, safe to quote in a support request."
},
"mode": {
"type": "string",
"description": "You called this endpoint yourself, so the answer describes your own request.",
"enum": [
"direct"
]
},
"signals": {
"type": "object",
"properties": {
"agent": {
"type": "object",
"properties": {
"keyDirectoryBinding": {
"type": "string",
"description": "Whether your directory proved it published the key set that was read. binding-key-proven means the response signature verified but did not cover the body, so possession of the key is proven and the key set is not.",
"enum": [
"binding-proven",
"binding-key-proven",
"binding-not-provided",
"binding-failed",
"binding-not-checked"
]
},
"notes": {
"type": "array",
"description": "Observations about your setup that are not faults."
},
"knownBot": {
"type": "string",
"description": "The second, independent check, and the one that has nothing to do with your signature: some operators publish the address ranges their crawlers use, and those lists are refreshed regularly. matched means the address this request came from is inside such a published range. none is the ordinary answer and is not a fault: it means no operator publishes a list containing this address, which is true of every address that is not a large crawler, and true of most agents.",
"enum": [
"matched",
"none"
]
},
"refutedSignatures": {
"type": "array",
"description": "Other signatures on the same request whose named directory does not list the key they used. You can confirm each against the published file yourself."
},
"signature": {
"type": "object",
"additionalProperties": true,
"description": "Whether a Web Bot Auth signature was present and how it came out."
},
"webBotAuthDetail": {
"type": "object",
"additionalProperties": true,
"description": "The specific fault, and the sentence saying what to change. Read this part first. Besides reason and fix it may carry three more members. clockDriftSec is how far the signing clock sits from this server, in seconds. directoryStatus is the HTTP status the named key directory answered with, where 403 or 429 is almost always a firewall in front of it refusing this verifier rather than anything about the keys. fromCachedDirectory appears only when true and means the answer rests on a stored copy that could not be refreshed, so a key reported as absent may simply have been published after that copy was taken."
},
"card": {
"type": "object",
"additionalProperties": true,
"description": "Your own published card read back to you, plus the one promise a single live request can settle: the User-Agent you said you would send."
}
}
},
"automation": {
"type": "object",
"properties": {
"uaClient": {
"type": "string",
"description": "What your User-Agent string alone says you are. A string, not a judgement."
},
"clientHints": {
"type": "string",
"description": "State of the Client Hints headers you sent."
}
}
},
"transport": {
"type": "object",
"properties": {
"provenance": {
"type": "string",
"description": "measured = your request arrived directly and was read first-hand. unavailable = it did not, and no finding in this answer rests on it.",
"enum": [
"measured",
"unavailable"
]
}
}
}
}
},
"meta": {
"type": "object",
"additionalProperties": true,
"description": "Envelope: API version, how long the verdict took, which axes contributed.",
"properties": {
"apiVersion": {
"type": "string",
"description": "Version of this API. `v1` today."
},
"queryTimeMs": {
"type": [
"integer",
"null"
],
"description": "How long the answer took to build, in milliseconds."
},
"axes": {
"type": "array",
"items": {
"type": "string"
},
"description": "Which sources contributed to this answer. An axis absent here contributed nothing, which is why a field can be missing without anything being wrong."
}
}
},
"identity": {
"type": "object",
"additionalProperties": true,
"description": "Who you were established to be, and on what evidence. Empty of judgement: the outcome of checking a signature you sent against a directory you published.",
"properties": {
"operator": {
"type": [
"string",
"null"
],
"description": "The name established for you, when one could be. Null when nothing named you."
},
"bot": {
"type": [
"string",
"null"
],
"description": "The specific bot within that operator, when the evidence distinguishes one."
},
"method": {
"type": "string",
"description": "How the name was established: `signature` when your own signature verified, `range` when your address sat in a list its operator publishes."
},
"trusted": {
"type": "boolean",
"description": "Whether the established name is one this verifier holds a trust anchor for. A verified signature from a domain nobody knows is a verified signature from a domain nobody knows."
}
}
},
"ip": {
"type": "object",
"additionalProperties": true,
"description": "Plain facts about your own address: network, operator, reputation of the address itself.",
"properties": {
"origin": {
"type": "string",
"description": "What kind of network the address belongs to: residential, datacenter, mobile, and so on."
},
"asn": {
"type": [
"integer",
"null"
],
"description": "Autonomous system number of the network."
},
"org": {
"type": [
"string",
"null"
],
"description": "The organisation that network is registered to."
},
"hostname": {
"type": [
"string",
"null"
],
"description": "Reverse DNS name of the address, when it has one."
},
"blacklisted": {
"type": "boolean",
"description": "Whether the address appears on the public abuse feeds this service tracks."
},
"riskScore": {
"type": "integer",
"description": "Reputation of the ADDRESS, 0 to 100, higher meaning worse. A datacenter address scores in the middle by nature: it is a statement about where you are, never about who you are or what you did."
},
"riskLevel": {
"type": "string",
"description": "The same figure as a word: low, medium or high."
}
}
},
"geo": {
"type": "object",
"additionalProperties": true,
"description": "Country, region, city and timezone of your address.",
"properties": {
"country": {
"type": [
"string",
"null"
],
"description": "ISO 3166-1 alpha-2 country code of the address."
},
"region": {
"type": [
"string",
"null"
],
"description": "First-level administrative division."
},
"city": {
"type": [
"string",
"null"
],
"description": "City the address is placed in."
},
"timezone": {
"type": [
"string",
"null"
],
"description": "IANA timezone name for that place."
}
}
}
}
}Community
Nachweis