databutler-provenance
Live trust signals for domains & packages: age, registrar, typosquat resemblance.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"databutler-provenance": {
"url": "https://databutler.dev/api/mcp/provenance"
}
}
}リモートエンドポイント
https://databutler.dev/api/mcp/provenancestreamable-httpできること
ツール一覧
ツール(2)
🟢domain_provenance(domain)
Who runs this domain? Live RDAP lookup: registration date and age, registrar, nameservers, status, whether the registrant is redacted, plus a typosquat check (edit-distance / brand-substring) against high-value brands. A very recently registered domain resembling a bank or big brand is a classic phishing signal — but report it as a signal, not a conclusion.
入力スキーマ
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "e.g. example.com"
}
},
"required": [
"domain"
]
}🟡package_provenance(ecosystem, name)
Who publishes this package, and is it a typosquat? Live npm or PyPI lookup: first-publish date and age, release count, latest version, maintainers/author, linked repo, plus a typosquat check against popular package names. Use when an agent is about to install or recommend an unfamiliar dependency.
入力スキーマ
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"enum": [
"npm",
"pypi"
],
"description": "npm or pypi"
},
"name": {
"type": "string",
"description": "package name, e.g. express or requests"
}
},
"required": [
"ecosystem",
"name"
]
}コミュニティ
エビデンス