Overwing

Guardrails for LLM output: pass / fail / review verdicts and one recommended action. Hosted or npm.

사용해야 할까요

품질 및 안전성

A
설명 품질
99%
스키마 완전성
74%
이름 품질
86%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

발견 사항 (1)

  • LOWTool 'get_usage' description lacks action verbget_usage에서

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~5,938토큰 (도구 정의)
~811 B일반적인 응답 크기
상당한 주의 영향 (128k 컨텍스트의 4.64%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "overwing-mcp"
      ]
    }
  }
}

실행 가능한 패키지

npmoverwing-mcp0.12.0stdio

원격 엔드포인트

https://overwing.ai/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (34)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🔴evaluate(input, rule_set, metadata, context, store)

Works with no API key: 10 evaluations a day, inputs up to 2,000 characters, and the text is not stored. With a key: 250 a day and up, inputs up to 100,000 characters, and your own rule sets. Score any text (typically an LLM's output) against an Overwing rule set. The text can be in any language; tested in Spanish, Portuguese, French, German, Japanese, Chinese, Korean, Arabic and Hindi. Results come back in English. Returns an aggregate verdict of pass, fail, or review, a recommended_action (block, redact, review, or allow), and per-rule answers with probability, confidence, and the rule's action. Act on recommended_action: block means do not send, redact means remove the flagged content and resend, review means ask a human or a slower model, allow means proceed. Prebuilt sets: 'content-safety' (toxicity, PII, self-harm, sexual content, severity) and 'outbound-message', which also takes a context object (recipient, channel, owns_contact_info) so PII that the recipient already owns is not flagged.

입력 스키마

{
  "type": "object",
  "properties": {
    "input": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100000,
      "description": "The text to evaluate, in any language"
    },
    "rule_set": {
      "type": "string",
      "default": "content-safety",
      "description": "Rule set slug"
    },
    "metadata": {
      "type": "object",
      "additionalProperties": {},
      "description": "Opaque data stored with the evaluation and echoed in webhooks (max 8 KB)"
    },
    "context": {
      "type": "object",
      "additionalProperties": {},
      "description": "Facts the rules may reference: recipient, channel, whether you own the data, sender, purpose. Sent to the model alongside the text (max 8 KB). Use the 'outbound-message' rule set to have it honoured."
    },
    "store": {
      "type": "boolean",
      "description": "With a key: false runs the check without keeping the input text or the context (the verdict and metadata are still recorded). Without a key the text is never stored."
    }
  },
  "required": [
    "input"
  ]
}
🟡evaluate_batch(items, rule_set, context, store)

Score up to 50 texts against one rule set in a single call. Each item counts as one evaluation. Returns a summary plus per-item verdicts; items can fail independently. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "minItems": 1,
      "maxItems": 50,
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 128
          },
          "input": {
            "type": "string",
            "minLength": 1,
            "maxLength": 100000
          },
          "metadata": {
            "type": "object",
            "additionalProperties": {}
          },
          "context": {
            "type": "object",
            "additionalProperties": {},
            "description": "Per-item context; overrides the batch-level context"
          }
        },
        "required": [
          "input"
        ]
      }
    },
    "rule_set": {
      "type": "string",
      "default": "content-safety"
    },
    "context": {
      "type": "object",
      "additionalProperties": {},
      "description": "Facts the rules may reference: recipient, channel, whether you own the data, sender, purpose. Sent to the model alongside the text (max 8 KB). Use the 'outbound-message' rule set to have it honoured."
    },
    "store": {
      "type": "boolean",
      "description": "False runs every item without keeping its input text or context"
    }
  },
  "required": [
    "items"
  ]
}
🟢list_rule_sets(include_inactive)

List the prebuilt and custom rule sets available to this organization. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "include_inactive": {
      "type": "boolean"
    }
  }
}
🟢get_rule_set(slug)

Fetch a rule set with its full rule definitions. Use 'content-safety' as a worked example when writing your own. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100
    }
  },
  "required": [
    "slug"
  ]
}
🟡create_rule_set(name, slug, description, rules)

Create a custom rule set with 1 to 25 rules. Each rule is a choice (pick one option), score (position on an ordered scale), or noul (yes/no) question with a fail condition, optional review threshold, weight, and action (block, redact, or review) that callers should take when it fails. Rule instructions may reference `context.*` fields that callers pass with each evaluation. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "maxLength": 100
    },
    "slug": {
      "type": "string",
      "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
      "maxLength": 100
    },
    "description": {
      "type": "string"
    },
    "rules": {
      "type": "array",
      "minItems": 1,
      "maxItems": 25,
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 100
          },
          "description": {
            "type": "string"
          },
          "question_type": {
            "type": "string",
            "enum": [
              "choice",
              "score",
              "noul"
            ]
          },
          "question_config": {
            "type": "object",
            "additionalProperties": {},
            "description": "choice: {options[], instructions}; score: {levels[], instructions}; noul: {question}"
          },
          "fail_condition": {
            "type": "object",
            "additionalProperties": {},
            "description": "choice: {failOn: [options]}; noul: {failOn: boolean}; score: {failAbove: levelIndex}"
          },
          "review_condition": {
            "type": "object",
            "properties": {
              "confidenceBelow": {
                "type": "number",
                "exclusiveMinimum": 0,
                "maximum": 1
              }
            },
            "required": [
              "confidenceBelow"
            ]
          },
          "weight": {
            "type": "number",
            "exclusiveMinimum": 0,
            "maximum": 100
          },
          "action": {
            "type": "string",
            "enum": [
              "block",
              "redact",
              "review"
            ],
            "description": "What a caller should do when this rule fails: block (default), redact, or review"
          }
        },
        "required": [
          "name",
          "question_type",
          "question_config",
          "fail_condition"
        ]
      }
    }
  },
  "required": [
    "name",
    "slug",
    "rules"
  ]
}
🟢get_evaluation(id)

Fetch a stored evaluation by id, including the original input and per-rule results. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128
    }
  },
  "required": [
    "id"
  ]
}
🟢list_evaluations(limit, verdict, rule_set, cursor)

List recent evaluations, newest first, with optional verdict and rule set filters. Use next_cursor to page. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    },
    "verdict": {
      "type": "string",
      "enum": [
        "pass",
        "fail",
        "review"
      ]
    },
    "rule_set": {
      "type": "string"
    },
    "cursor": {
      "type": "string"
    }
  }
}
🟢get_usage(days)

Daily usage, remaining quota for today, and plan limits. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "days": {
      "type": "integer",
      "minimum": 1,
      "maximum": 90
    }
  }
}
🟢whoami

Identify the organization and plan behind the API key on this request, the key's scope, the organization's data settings (store_inputs, retention_days), and whether billing is set up. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟡create_account(org_name, use_for_session)

Create an Overwing account for yourself, with no email: an organization and an API key, returned once. Nothing is sent to anyone. Use it when you have no key and nobody has given you one; do not create a second account if you already have a key (whoami says which account a key belongs to). The key is the account, so store it at once: with no email there is no reset link. It starts at 50 evaluations a day with Beacon summaries; proving a domain (prove_domain, verify_domain) raises that to the normal free limits and full Beacon reports, and makes a lost key recoverable. This server does not keep the key: send it as Authorization: Bearer on the MCP connection for the tools that need one. Tell the person you work for that you made the account and where the key is kept. No key needed.

입력 스키마

{
  "type": "object",
  "properties": {
    "org_name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200,
      "description": "A name for the account, e.g. the agent's name"
    },
    "use_for_session": {
      "type": "boolean",
      "description": "Ignored here. The hosted server has no session and never holds a key; it exists so calls written for the npm package still validate."
    }
  }
}
🟡prove_domain(domain)

Begin proving that your account controls a domain. For an account with no email the domain stands in for one: it raises the limits to the normal free tier, opens full Beacon reports, and lets a lost key be replaced. Returns one value to publish at the domain, as a DNS TXT record or as a file under /.well-known; then call verify_domain. One domain belongs to one account. Calling again for the same domain returns the same value. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 4,
      "maxLength": 255,
      "description": "A domain you or your operator controls, e.g. acme.com"
    }
  },
  "required": [
    "domain"
  ]
}
⚪verify_domain

Look for the value prove_domain asked for, at the domain. Found: the domain is the account's. Not found: an error saying what was looked for; DNS changes can take a few minutes, and calling again is safe. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟢list_plans

Public plan catalog: prices, daily limits, and per-minute burst limits. No API key needed.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟢atlas_lookup(user_agent)

Say what a User-Agent string claims to be and whether the claim can be trusted, from the Overwing Atlas registry of AI crawlers, fetchers and browser agents. Returns the claimed agent, operator, purpose class, verification method (Web Bot Auth signature, user-agent string only, or unattributable) and a trust note. Works with no API key: 10 lookups a day. With a key, metered per day by Atlas tier: free 100, Pro 10,000, Team 100,000. Use it when deciding whether to serve, block, or pay-gate a request, or to understand who is hitting a site.

입력 스키마

{
  "type": "object",
  "properties": {
    "user_agent": {
      "type": "string",
      "minLength": 1,
      "maxLength": 2000,
      "description": "The User-Agent header value to identify"
    }
  },
  "required": [
    "user_agent"
  ]
}
🟢atlas_agents(q, purpose, operator, verification, limit)

Browse or search Overwing Atlas, the registry of AI crawlers, fetchers and browser agents: name, operator, user-agent tokens, Web Bot Auth key directory, robots.txt behaviour, and (with Atlas Pro or Team) purpose class, verification, evasion flags and traffic shares. Filter by free text, purpose (training, search, browser, coding), operator, or verification. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "q": {
      "type": "string",
      "maxLength": 200,
      "description": "Free text over name, operator, user agents, description"
    },
    "purpose": {
      "type": "string",
      "maxLength": 60,
      "description": "Purpose substring, e.g. training, search, browser, fetcher, coding"
    },
    "operator": {
      "type": "string",
      "maxLength": 100
    },
    "verification": {
      "type": "string",
      "maxLength": 60,
      "description": "e.g. 'Web Bot Auth', 'spoofable', 'Unattributable'"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100,
      "default": 20
    }
  }
}
🟡atlas_register_agent(name, operator, domain, tokens, purpose, ...)

Add an agent or crawler you operate to the Overwing Atlas registry, free, so a site that looks up its User-Agent learns who runs it. Give the agent's name, the operator (the company or person running it), the operator's domain, and the token the User-Agent carries (the product name, such as AcmeBot). The answer carries one value to publish at that domain, as a DNS TXT record or as a file under /.well-known, to prove control of it; then call atlas_verify_registration. A token may not match, contain, or sit inside one already in the registry. This proves control of the domain, not that any given request is yours: the entry is listed as user-agent only unless key_directory_url is a Web Bot Auth key directory on that domain. Only register agents you or your operator actually run. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 3,
      "maxLength": 80,
      "description": "The agent's name, e.g. AcmeBot"
    },
    "operator": {
      "type": "string",
      "minLength": 2,
      "maxLength": 120,
      "description": "The company or person that runs the agent"
    },
    "domain": {
      "type": "string",
      "minLength": 4,
      "maxLength": 255,
      "description": "The operator's domain, e.g. acme.com. Control of it must be proved"
    },
    "tokens": {
      "type": "array",
      "minItems": 1,
      "maxItems": 3,
      "items": {
        "type": "string",
        "minLength": 5,
        "maxLength": 60
      },
      "description": "The product name the User-Agent carries, e.g. [\"AcmeBot\"]"
    },
    "purpose": {
      "type": "string",
      "enum": [
        "training_crawl",
        "search_index",
        "user_fetch",
        "browser_agent",
        "coding_agent",
        "api_agent",
        "other"
      ],
      "default": "other"
    },
    "user_agent": {
      "type": "string",
      "maxLength": 500,
      "description": "The full User-Agent string the agent sends; it must contain a token"
    },
    "description": {
      "type": "string",
      "maxLength": 600
    },
    "policy_url": {
      "type": "string",
      "maxLength": 500,
      "description": "An https page describing the agent"
    },
    "key_directory_url": {
      "type": "string",
      "maxLength": 500,
      "description": "A Web Bot Auth key directory on the operator's domain"
    },
    "follows_robots_txt": {
      "type": "boolean"
    }
  },
  "required": [
    "name",
    "operator",
    "domain",
    "tokens"
  ]
}
⚪atlas_verify_registration(id)

Look for the proof at the operator's domain: the DNS TXT record or the file that atlas_register_agent asked for. Found: the entry is published in the registry, or held for a person when the operator name already belongs to someone. Not found: an error saying what was looked for; DNS changes can take a few minutes, and calling again is safe. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^areg_[A-Za-z0-9_-]{16}$",
      "description": "The registration id from atlas_register_agent"
    }
  },
  "required": [
    "id"
  ]
}
🟢atlas_list_registrations

The agents this organization has registered in Overwing Atlas, newest first, each with its status (pending_verification, pending_review, published, rejected) and, while unverified, the value to publish at the domain. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🔴atlas_withdraw_registration(id)

Withdraw a registration. A published entry leaves the registry, so lookups stop naming the agent; an unfinished request is abandoned. This cannot be undone: register again to put it back. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^areg_[A-Za-z0-9_-]{16}$",
      "description": "The registration id from atlas_register_agent"
    }
  },
  "required": [
    "id"
  ]
}
🟢atlas_summary

Public numbers from Overwing Atlas: registry counts by purpose and verification, published browser-agent traffic shares, sector field-scan headlines (e.g. how many OSINT sites carry AI-crawler rules or any agent-payable surface), and the summary of the Agent Consumers report on what agents actually spend. No key needed.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟢beacon_start(url)

Overwing Beacon answers one question about a site: is this product reachable by agents? It checks robots.txt rules for AI agents, llms.txt, the sitemap, the MCP server card, hosted MCP endpoint and MCP Registry listing, the A2A agent card, OpenAPI discovery, and how the home page reads to a model, then returns three answers (find, read, use), a score and the fixes worth making. This tool starts a check and returns its id; it is free. Then call beacon_report with the id, which runs the check (about twenty seconds). With an Overwing key on the connection beacon_report returns the full report and the check is saved to that dashboard; with no key it returns the summary: the score, the three answers and the first fix. A key is free (POST /api/v1/signup). An agent with a wallet and no account can instead pay $1 in USDC over x402 and get the full report in one call: GET /api/x402/beacon?url=<site>. Call beacon_sample to see a real report in full. No key needed.

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "minLength": 3,
      "maxLength": 500,
      "description": "The site to check: a domain (example.com) or an https URL. Public sites only."
    }
  },
  "required": [
    "url"
  ]
}
🟢beacon_report(id)

The report for a check started with beacon_start. The first call runs the check. With an Overwing key on the connection: score (0 to 100), verdict (yes, partly, no), the find / read / use answers, every check with what was found and a fix when it did not pass, and top_fixes ranked by value. With no key, the summary of the same report: score, verdict, the three answers and the first fix (access=summary). Answers 202 while the check is running (ask again in a few seconds). No key needed for the summary.

입력 스키마

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^bcn_[A-Za-z0-9_-]{16}$",
      "description": "The check id from beacon_start"
    }
  },
  "required": [
    "id"
  ]
}
🟢beacon_sample

A real Overwing Beacon report, free: the check of overwing.ai itself, refreshed daily. Read it to see exactly what a full report holds before starting a check. No key needed.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🔴tower_load_template

Set up Overwing Tower for this organization by loading the starter workflow: email purchase order to order entry, with create_order, update_order and cancel_order against a mock IBM i system, and a starter policy. Idempotent. Needs an organization key. Returns a sample input you can submit. Next: tower_create_agent.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟡tower_create_agent(name, scopes, use_for_session)

Create a scoped agent identity and its key. Needs an organization key. Scope it to the operations the agent needs (for example create_order) rather than * where you can. The key (ow_agent_...) is returned once, in this result, and this server does not keep it: store it, and send it as the Authorization bearer on a connection used for the agent tools (tower_capabilities, tower_decide, tower_submit_action, tower_get_action, tower_compensate, tower_get_receipt, tower_verify_receipts). Revoke with tower_revoke_agent.

입력 스키마

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100,
      "description": "A name a person will recognise in the review queue, e.g. order-intake-bot"
    },
    "scopes": {
      "type": "array",
      "minItems": 1,
      "maxItems": 50,
      "items": {
        "type": "string",
        "pattern": "^(\\*|[a-z][a-z0-9_]{0,63})$"
      },
      "description": "Operation names this agent may call, or [\"*\"] for all"
    },
    "use_for_session": {
      "type": "boolean",
      "description": "Ignored here. The hosted server has no session and never holds a key; it exists so calls written for the npm package still validate."
    }
  },
  "required": [
    "name",
    "scopes"
  ]
}
🟢tower_list_agents

List this organization's Tower agents with scopes, status and last use. Keys are never returned. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🔴tower_revoke_agent(agent_id)

Revoke an agent. Its key stops working at once and cannot be restored. Needs an organization key.

입력 스키마

{
  "type": "object",
  "properties": {
    "agent_id": {
      "type": "string",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$",
      "description": "The agent's id (a UUID), from tower_list_agents"
    }
  },
  "required": [
    "agent_id"
  ]
}
🟢tower_capabilities

List the operations this agent is allowed to call, each with the JSON Schema its input must match and its compensating operation. Call this first; build inputs from the schema rather than guessing. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟢tower_decide(operation, input)

Ask Tower how it would rule on an operation without doing anything: auto (would execute), review (a person must approve), or reject. Returns the score, the reason, and each policy question's answer. No side effects. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "operation": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "input": {
      "type": "object",
      "additionalProperties": {},
      "description": "The operation's input, matching its input_schema from tower_capabilities"
    }
  },
  "required": [
    "operation",
    "input"
  ]
}
🟡tower_submit_action(operation, input, idempotency_key, dry_run)

Ask Tower to perform an operation on the legacy system. Tower decides: executed (done), pending (a person must approve; poll tower_get_action, do not resubmit), or rejected (do not retry unchanged). Always send an idempotency_key that is stable for this business request, such as the source message id: repeating a key returns the original outcome instead of acting twice. Set dry_run to see the decision without executing. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "operation": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "input": {
      "type": "object",
      "additionalProperties": {},
      "description": "The operation's input, matching its input_schema from tower_capabilities"
    },
    "idempotency_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128,
      "description": "Stable per business request; reuse it on retries"
    },
    "dry_run": {
      "type": "boolean"
    }
  },
  "required": [
    "operation",
    "input",
    "idempotency_key"
  ]
}
🟢tower_get_action(action_id)

Status and result of an action: pending, approved, executed, failed, compensated, or rejected. Use it to poll an action that is waiting on human review. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "action_id": {
      "type": "string",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$",
      "description": "The action's id (a UUID), from tower_submit_action"
    }
  },
  "required": [
    "action_id"
  ]
}
🔴tower_compensate(action_id)

Run the compensating operation for an executed action, for example cancel the order that create_order made. Runs once; repeating it returns the first outcome. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "action_id": {
      "type": "string",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$",
      "description": "The executed action's id (a UUID)"
    }
  },
  "required": [
    "action_id"
  ]
}
🟢tower_get_receipt(id)

Fetch one signed receipt by id or by sequence number: the payload, its hash, the previous link's hash, and the Ed25519 signature. Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64,
      "description": "Receipt id or sequence number"
    }
  },
  "required": [
    "id"
  ]
}
🟢tower_verify_receipts(from, to)

Recompute every hash and check every signature over a range of this organization's receipts. Reports the first break, if any. Defaults to the whole chain (up to 5,000 links per call). Needs an agent key.

입력 스키마

{
  "type": "object",
  "properties": {
    "from": {
      "type": "integer",
      "minimum": 1
    },
    "to": {
      "type": "integer",
      "minimum": 1
    }
  }
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 34개