agents

Pay-per-call safety guards for AI agents: injection, tool-call, signing, secret, x402-trust.

사용해야 할까요

품질 및 안전성

B
설명 품질
97%
스키마 완전성
97%
이름 품질
50%
오염 위험
80%
권한 일치
100%
프로토콜 준수
100%

발견 사항 (9)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains suspicious base64-like encoded stringtool-call-guard에서
  • LOWTool 'secure-code-review' doesn't follow camelCase/snake_casesecure-code-review에서
  • LOWTool 'pr-summary' doesn't follow camelCase/snake_casepr-summary에서
  • LOWTool 'x402-trust-audit' doesn't follow camelCase/snake_casex402-trust-audit에서
  • LOWTool 'sign-guard' doesn't follow camelCase/snake_casesign-guard에서
  • LOWTool 'inject-guard' doesn't follow camelCase/snake_caseinject-guard에서
  • LOWTool 'tool-call-guard' doesn't follow camelCase/snake_casetool-call-guard에서
  • LOWTool 'secret-scan' doesn't follow camelCase/snake_casesecret-scan에서

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~2,382토큰 (도구 정의)
~2.6 KB일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.86%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "agents": {
      "url": "https://paygent.obsmetrics.com/mcp"
    }
  }
}

원격 엔드포인트

https://paygent.obsmetrics.com/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (7)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
⚪secure-code-review(code, language, context)

Security review of a code snippet or diff. Returns structured findings (severity, CWE, location, remediation). [security; up to 75c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Source code or unified diff to review"
    },
    "language": {
      "type": "string",
      "description": "Language hint, e.g. typescript, python"
    },
    "context": {
      "type": "string",
      "description": "Optional context about the code"
    }
  },
  "required": [
    "code"
  ]
}
🔴pr-summary(diff, style)

Turn a git diff into a clear PR description or release notes. [dev-tools; up to 30c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "diff": {
      "type": "string",
      "description": "Unified git diff to summarise"
    },
    "style": {
      "type": "string",
      "description": "e.g. conventional, changelog, executive"
    }
  },
  "required": [
    "diff"
  ]
}
⚪x402-trust-audit(paymentRequirements, selectedOptionIndex, paymentPayload, expected, spendPolicy, ...)

Vet an x402 counterparty before settling USDC: scores the advertised payment requirements AND (when supplied) the EIP-3009 authorization you are about to sign. Returns a machine-enforceable trust verdict (per-entry scores, coverage-honest trustScore, spend-constraint + tamper-evident fingerprint) for buyer agents and wallet/spend-policy layers. No endpoint fetch. [security; up to 200c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "paymentRequirements": {
      "description": "The x402 payment requirements from the counterparty: the 402 `accepts` array, or a single object."
    },
    "selectedOptionIndex": {
      "type": "number",
      "description": "Index in the accepts array the buyer intends to settle (default 0). The verdict is scoped to it."
    },
    "paymentPayload": {
      "description": "The UNSIGNED EIP-3009 authorization the buyer is about to sign: { authorization|message: {from,to,value,validAfter,validBefore,nonce}, domain: {name,version,chainId,verifyingContract} }. Lets the audit bind the menu to the actual charge (server-enforced to/value/verifyingContract/chainId). Omit to vet requirements only - but then the verdict is never auto-settle-safe."
    },
    "expected": {
      "type": "object",
      "description": "Optional caller expectations.",
      "properties": {
        "network": {
          "type": "string"
        },
        "chainId": {
          "type": "number"
        },
        "asset": {
          "type": "string",
          "description": "Expected asset contract address"
        },
        "payTo": {
          "type": "string"
        },
        "maxAmountAtomic": {
          "type": "string"
        },
        "identity": {
          "type": "string"
        }
      }
    },
    "spendPolicy": {
      "type": "object",
      "description": "Optional buyer spend policy to evaluate against and to pin facilitators.",
      "properties": {
        "maxUsd": {
          "type": "number"
        },
        "allowedNetworks": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "allowedAssets": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "allowedFacilitators": {
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      }
    },
    "endpointUrl": {
      "type": "string",
      "description": "Resource URL being paid (context only; never fetched)."
    },
    "serverMetadata": {
      "description": "Optional server metadata the caller already holds (context only; not fetched)."
    },
    "context": {
      "type": "string",
      "description": "Optional free-form context."
    }
  },
  "required": [
    "paymentRequirements"
  ]
}
🟡sign-guard(tx, typedData, expected, spendPolicy, context)

Pre-sign safety oracle for agent wallets: submit the transaction or EIP-712 message you are about to sign and get a machine-enforceable verdict. Decodes the calldata/typed-data, flags the drainer toolkit (unlimited approvals, setApprovalForAll, permit/permit2 + EIP-3009 to an unexpected party, transferFrom draining an unnamed account, ownership transfer, raw ETH to a stranger), and binds the decoded action to your stated intent - only a fully pinned, clean action is auto-sign-safe. Fails closed: an undecodable on-chain call is cautioned and an unrecognized off-chain signature grant is blocked. Deterministic, sub-second, no endpoint fetch. It vouches that the action matches what you said; it does NOT vouch that a counterparty is trustworthy. [security; up to 200c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "tx": {
      "type": "object",
      "description": "An EVM transaction you are about to sign.",
      "properties": {
        "to": {
          "type": "string",
          "description": "Target contract / recipient (0x address)."
        },
        "data": {
          "type": "string",
          "description": "Calldata hex (0x...). Omit for a plain ETH transfer."
        },
        "value": {
          "type": "string",
          "description": "Wei to send, decimal or 0x."
        },
        "chainId": {
          "type": "number",
          "description": "EIP-155 chain id (e.g. 8453 for Base)."
        }
      }
    },
    "typedData": {
      "type": "object",
      "description": "An EIP-712 message you are about to sign (the off-chain drainer surface: permit, Permit2, EIP-3009). { domain, types, primaryType, message }."
    },
    "expected": {
      "type": "object",
      "description": "Your stated intent. Supplying it lets the verdict BIND the action; only a fully bound, clean action is auto-sign-safe. For an allowance, you MUST supply maxAmount; for a transferFrom, supply `from`.",
      "properties": {
        "spender": {
          "type": "string",
          "description": "Address you intend to approve."
        },
        "recipient": {
          "type": "string",
          "description": "Address you intend to send to."
        },
        "from": {
          "type": "string",
          "description": "Account whose funds you intend to move (transferFrom / EIP-3009)."
        },
        "contract": {
          "type": "string",
          "description": "Contract you intend to call."
        },
        "asset": {
          "type": "string",
          "description": "Token contract you intend to touch."
        },
        "maxAmount": {
          "type": "string",
          "description": "Atomic ceiling you intend to expose (required to auto-sign an allowance)."
        },
        "chainId": {
          "type": "number",
          "description": "Chain you intend to act on."
        }
      }
    },
    "spendPolicy": {
      "type": "object",
      "description": "Optional buyer spend policy (context only)."
    },
    "context": {
      "type": "string",
      "description": "Optional free-form context."
    }
  }
}
🔴inject-guard(content, context)

Untrusted-content guardrail for agents: submit a blob of text you are about to feed to your own LLM (scraped web content, a tool result, another agent's message) and get a machine-enforceable verdict - is this a prompt-injection / jailbreak / data-exfiltration / tool-hijack attempt? Returns a risk level, the detected classes with spans, the unicode obfuscation it found (zero-width, bidi-override, tag-chars, homoglyphs), and a SANITIZED copy safe to feed onward. Hybrid: a deterministic, uninjectable pattern engine (authoritative) plus an LLM classifier that can only raise the risk, never clear a flag. Detection of known injection classes - not a proof of safety. [security; up to 15c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "The untrusted text to scan before you feed it to your LLM."
    },
    "context": {
      "type": "string",
      "description": "Optional: where the content came from (url, tool name, sender) - context only."
    }
  },
  "required": [
    "content"
  ]
}
🟡tool-call-guard(call, intent, expected, context)

Pre-execution safety oracle for agent actions: submit the tool call you are about to run (shell, http, sql, file, code, env) plus your stated intent, and get a machine-enforceable verdict before you execute it. Decodes what the call does, flags the danger toolkit (rm -rf, reverse shell, curl|sh, SSRF to cloud metadata, credential reads, DROP/DELETE-without-WHERE, path traversal, dynamic eval), and binds it to your intent (allowedHosts/allowedPaths/readOnly/noNetwork) - only a fully pinned, clean, intent-matched call is auto-exec-safe. Hybrid: a deterministic, uninjectable detector engine (authoritative) plus an LLM classifier that can only raise the risk. Fails closed. Detection of known-dangerous patterns, not a proof of safety; it never executes the call. [security; up to 8c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "call": {
      "type": "object",
      "required": [
        "kind"
      ],
      "description": "The tool call you are about to execute.",
      "properties": {
        "kind": {
          "type": "string",
          "enum": [
            "shell",
            "http",
            "sql",
            "file",
            "code",
            "env"
          ],
          "description": "The kind of action."
        },
        "command": {
          "type": "string",
          "description": "shell: the full command line."
        },
        "method": {
          "type": "string",
          "description": "http: HTTP method."
        },
        "url": {
          "type": "string",
          "description": "http: the target URL."
        },
        "body": {
          "type": "string",
          "description": "http: request body (context)."
        },
        "query": {
          "type": "string",
          "description": "sql: the SQL statement."
        },
        "op": {
          "type": "string",
          "description": "file: read|write|delete|move. env: read|write."
        },
        "path": {
          "type": "string",
          "description": "file: the target path."
        },
        "language": {
          "type": "string",
          "description": "code: the language."
        },
        "source": {
          "type": "string",
          "description": "code: the source to run."
        },
        "name": {
          "type": "string",
          "description": "env: the variable name."
        }
      }
    },
    "intent": {
      "type": "string",
      "description": "What this call is for (natural language). Used by the classifier for intent-mismatch."
    },
    "expected": {
      "type": "object",
      "description": "Machine-checkable constraints. Supplying them lets the verdict BIND the call; only a positively-scoped, satisfied call is auto-exec-safe.",
      "properties": {
        "allowedHosts": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "http: the only hosts you intend to reach (required to auto-exec a networked call)."
        },
        "allowedPaths": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "file: the only paths you intend to touch (required to auto-exec a file write)."
        },
        "readOnly": {
          "type": "boolean",
          "description": "the call must not mutate state (set false to auto-exec a mutating call)."
        },
        "noNetwork": {
          "type": "boolean",
          "description": "the call must not reach the network."
        }
      }
    },
    "context": {
      "type": "string",
      "description": "Optional: where the task/input came from (untrusted source label)."
    }
  },
  "required": [
    "call"
  ]
}
🟡secret-scan(content)

Leaked-credential guardrail for agents: submit a blob you are about to commit, log, post, or hand to another tool (a diff, a config, an .env, an LLM output) and get a machine-enforceable verdict - does it contain a live secret? Detects cloud keys (AWS), VCS tokens (GitHub/GitLab), provider API keys (Stripe, OpenAI, Anthropic, Google, Slack), private-key blocks, JWTs, and credentials embedded in URLs, plus high-entropy key=value assignments. Returns a risk level, the detected classes with a MASKED locator (never the secret itself, so the verdict cannot re-leak), and a REDACTED copy safe to emit onward. Deterministic, sub-second, never fetches. Detection of known secret formats - not a proof of cleanliness. [security; up to 200c/call]

입력 스키마

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "The text to scan for leaked secrets (diff, config, .env, log line, LLM output)."
    }
  },
  "required": [
    "content"
  ]
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 7개
검증됨버전이 기록되지 않음도구 7개