MCP Verification Gate: check an MCP server or an A2A agent before you connect or delegate

Check an A2A agent before you delegate, or an MCP server's measured conduct. Free, no key.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
88%
Qualität der Benennung
90%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~1,994Tokens (Tool-Definitionen)
~2.4 KBTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (1.56% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "hs-verify-gate": {
      "url": "https://hs-verify-gate.oga-surf-project.workers.dev/mcp"
    }
  }
}

Remote-Endpunkte

https://hs-verify-gate.oga-surf-project.workers.dev/mcpstreamable-http
https://gate.horizonshield.dev/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (6)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢get_conditions

Return the five conditions this gate measures, what it explicitly does not verify, and the tier definitions. Takes no arguments and returns identical output every time. Read this before running a check so you know what a verdict does and does not claim.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "conditions": {
      "type": [
        "array",
        "object"
      ]
    },
    "not_verified": {
      "type": [
        "array",
        "object",
        "string"
      ]
    },
    "tiers": {
      "type": [
        "array",
        "object"
      ]
    }
  },
  "description": "Deterministic. Takes no arguments, looks nothing up, and returns the same document every time. It therefore declares no read-state field, and a structural probe will score it as unable to hold the difference between a failed read and an empty one. That score is correct and is left standing: this tool has no read to fail. Adding a state field it can never use would make the number look better and mean less.",
  "additionalProperties": true
}
🟢check_conformance(endpoint, allow_tool_call)

Measure a public MCP endpoint against five conditions: it speaks MCP, it publishes an A2A agent card, it declares who pays it, identical input returns identical output, and the verdict itself can be recomputed by anyone. Free, no key. Conformance and disclosure only; this says nothing about whether any figure the checked server returns is correct. By default no tool on the checked server is called, so determinism comes back as not measured rather than guessed. Set allow_tool_call true only for a server you control.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string",
      "description": "https URL of the MCP endpoint to measure"
    },
    "allow_tool_call": {
      "type": "boolean",
      "description": "Consent to executing one tool on the checked server, twice, with empty arguments. Only set this for a server you own. Default false."
    }
  },
  "required": [
    "endpoint"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string"
    },
    "reachable": {
      "description": "Three-valued on purpose (gate58). true = measured and answered. false = measured and did not answer. null = NOT MEASURED. null is never to be read as a failing endpoint; it means this gate has nothing to say."
    },
    "pass": {
      "type": [
        "boolean",
        "null"
      ]
    },
    "conditions": {
      "type": [
        "array",
        "object"
      ]
    },
    "record_sha256": {
      "type": "string",
      "description": "Hash of this verdict with record_sha256 and recompute_note removed. Recompute it yourself; verify_verdict does the same arithmetic."
    },
    "recompute_note": {
      "type": "string"
    }
  },
  "additionalProperties": true
}
🟢verify_verdict(record)

Take a verdict this gate issued and recompute its record_sha256 independently. Removes record_sha256 and recompute_note, serialises the remainder in key order, and hashes it. Returns whether the verdict was altered after it was issued. You do not have to trust the party that issued the verdict, including this one.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "record": {
      "type": "object",
      "description": "The full verdict object as returned by check_conformance or GET /self"
    }
  },
  "required": [
    "record"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "verified": {
      "type": [
        "boolean",
        "null"
      ],
      "description": "true = the verdict hashes to its own record_sha256, so it was not altered after issue. false = it was altered. This is a finding about the record, not an error."
    },
    "method": {
      "type": "string"
    },
    "note": {
      "type": "string"
    }
  },
  "additionalProperties": true
}
🟢lookup_server(endpoint)

Look up what this register already holds about an MCP endpoint: whether it is watched, how often it is re-measured, how many measurements exist, when the first and latest were taken, and the latest verdict with the record_sha256 you can recompute yourself. Reads stored measurements only. It contacts nothing and measures nothing, so use check_conformance for a fresh reading. An endpoint that is absent is reported as absent and that is NOT a negative verdict: it means nobody has measured it here, not that it failed.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string",
      "description": "https URL of the MCP endpoint to look up, exactly as it appears on the register"
    }
  },
  "required": [
    "endpoint"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string"
    },
    "on_register": {
      "type": "boolean",
      "description": "true = this endpoint is on the register. false = the register was READ and this endpoint is not on it. If the register could not be read at all, this field is not returned: the call comes back as a tool error (isError), because absence and not-knowing are different answers."
    },
    "register_size": {
      "type": "number"
    },
    "standing": {
      "type": [
        "string",
        "null"
      ]
    },
    "latest": {
      "type": [
        "object",
        "null"
      ]
    },
    "means": {
      "type": [
        "string",
        "object"
      ]
    },
    "does_not_mean": {
      "type": [
        "string",
        "object"
      ]
    }
  },
  "additionalProperties": true
}
🟢is_verified(endpoint)

A single machine-first answer for an agent deciding whether to trust an MCP endpoint BEFORE it connects. Returns verified (true only when the latest scheduled measurement passed every measured condition; null otherwise, never false), a state enum saying which case it is, measured_at, and a record_sha256 with a recompute_url so you can check the verdict without trusting this gate. Reads the stored register only: it contacts nothing and measures nothing. Absent and pending are reported honestly and are NOT negative verdicts. For a fresh measurement rather than the stored one, use check_conformance.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string",
      "description": "https URL of the MCP endpoint to look up, exactly as it appears on the register"
    }
  },
  "required": [
    "endpoint"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string"
    },
    "verified": {
      "type": [
        "boolean",
        "null"
      ],
      "description": "true = latest measurement passed all measured conditions. null = not established here (see state). Never false: unmeasured or not-yet-passing is not a failure."
    },
    "state": {
      "type": "string",
      "enum": [
        "verified",
        "pending",
        "held",
        "watched",
        "absent"
      ],
      "description": "verified = passed all measured conditions. pending = measured but not passing every one (often only because determinism needs the owner's consent). held = could not be reached. watched = on the list, not yet measured. absent = no row here at all."
    },
    "on_register": {
      "type": "boolean"
    },
    "measured_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "record_sha256": {
      "type": [
        "string",
        "null"
      ],
      "description": "Hash of the latest verdict. Recompute it via recompute_url; no trust in this gate required."
    },
    "recompute_url": {
      "type": "string"
    },
    "conditions": {
      "type": [
        "object",
        "null"
      ]
    }
  },
  "description": "A one-glance answer for an agent deciding whether to trust an MCP endpoint BEFORE connecting. Reads the register only; measures nothing. verified is true ONLY when the latest scheduled measurement passed every measured condition; it is null in every other case (pending, held, watched, absent), and never false, because this gate calls nothing a failure. The state enum says which case it is, so a consumer can tell 'not verified here' apart from 'the lookup failed' (that returns as a tool error, isError) and from 'measured and passing'.",
  "additionalProperties": true
}
🟢preflight_agent(agent)

Call this before handing work to an A2A agent you have not used before. Fetches the agent's public card (https://<agent>/.well-known/agent-card.json, one request), reports whether it declares the A2A Conduct Extension, who it says pays it (the compensation declaration, as declared and not verified), whether the card carries a signature, the endpoints it asks to be measured on, and this register's stored reading for each (verified is true only when the latest scheduled measurement passed; null otherwise, never false), plus where to file your own witness walk. Measures nothing new and returns counts and pointers, never a score. An agent that does not declare the extension is reported as such, which is not a negative verdict.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "agent": {
      "type": "string",
      "description": "https origin of the agent (https://agent.example) or the full URL of its agent card"
    }
  },
  "required": [
    "agent"
  ],
  "additionalProperties": false
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet6 Tools
verifiziertVersion nicht aufgezeichnet6 Tools
verifiziertVersion nicht aufgezeichnet5 Tools
verifiziertVersion nicht aufgezeichnet5 Tools
verifiziertVersion nicht aufgezeichnet5 Tools
verifiziertVersion nicht aufgezeichnet5 Tools