Council of AI GSPC (free)
Free read-only GSPC tools: board totals, signed card verification, Merkle root, inclusion proofs.
Should I use this
Quality & Safety
Findings (9)
- HIGH
- MEDIUMin board_totals
- MEDIUMin get_axis
- MEDIUMin verify_card
- MEDIUMin list_cards
- MEDIUMin get_root
- MEDIUMin get_card
- MEDIUMin mcp_trust
- MEDIUMin measurement_index
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"gspc-free": {
"url": "https://councilof.ai/mcp/free"
}
}
}Remote endpoints
https://councilof.ai/mcp/freestreamable-httpWhat it can do
Tool inventory
Tools (12)
🟢board_totals(detail)
Live GSPC board totals from https://councilof.ai/api/gspc. Returns the slot count and the measured count as two labelled numbers WITH their kind — a slot is a declared position on the board, a measurement is a real run behind it; the two are never summed and never swapped — plus the board's separation line, and as_of dates for the board and for this fetch. Compact by default; pass detail "full" for the long-form count grammar, the per-family counts and the board's full measured_on block. We measure, never certify. If the board cannot be fetched the answer is a distinct UNREACHABLE state: no cached number is ever presented as live.
Input Schema
{
"type": "object",
"properties": {
"detail": {
"type": "string",
"enum": [
"summary",
"full"
],
"default": "summary",
"description": "summary (default): counts, public_count, the separation line, dates and source. full: also count_grammar, by_family and the board's measured_on block."
}
},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "LIVE or UNREACHABLE"
},
"detail": {
"type": "string",
"description": "summary or full"
},
"counts": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"kind": {
"type": "string"
}
}
}
},
"public_count": {
"type": [
"string",
"null"
]
},
"separation": {},
"count_grammar": {},
"by_family": {},
"as_of": {},
"source": {
"type": "string"
},
"not_a_certification": {
"type": "boolean"
}
},
"required": [
"state"
]
}🟢get_axis(axis)
One axis row from the live GSPC board at https://councilof.ai/api/gspc — every axis the board carries, behavioural and financial families alike, addressed by the axis id exactly as the board spells it: n, accuracy, interval, MEASURED or UNMEASURED status, family, kind, the bank or run-artifact URL behind the row, and dates. An unmeasured axis is a first-class answer — a declared slot with no run behind it, published so the gap is visible — never an error and never a zero. Never a certification.
Input Schema
{
"type": "object",
"properties": {
"axis": {
"type": "string",
"description": "The axis name as it appears on the board, e.g. governance, safety, jail, provenance-controls. Case-insensitive. An unknown name returns the list of names the board actually carries."
}
},
"required": [
"axis"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "LIVE, NOT_ON_BOARD, BAD_INPUT or UNREACHABLE"
},
"axis": {
"type": [
"string",
"null"
]
},
"resolved_from": {
"type": "string",
"description": "present when the caller named an alias (e.g. gov) that resolved to this board axis"
},
"status": {
"type": [
"string",
"null"
]
},
"measured": {
"type": "boolean"
},
"family": {},
"n": {},
"accuracy": {},
"interval": {},
"leader": {},
"dataset": {},
"board_carries": {
"type": "array"
},
"source": {
"type": "string"
},
"not_a_certification": {
"type": "boolean"
}
},
"required": [
"state"
]
}🟢verify_card(card)
Verify a signed gspc.measurement-card under the published rule (https://councilof.ai/signed/HOW-TO-VERIFY.md): recompute the id from the canonical body bytes, then check the Ed25519 signature under a key PINNED in this verifier and published in the did:web:csoai.org DID document: #card-attestation-1 (the card key of the signed card index) or #card-attestation-2 (the card key added on rotation, 27 Sep 2026; a card names the key it was signed under), plus the board key for the cards it signed. pinned_key in the result names the key that matched. A card that carries its own key proves only that the file is self-consistent — anyone can alter a body and sign it with a key they just generated — so an inline key outside the pinned set is reported INVALID, and a DID key reference outside it UNCHECKABLE. Three verdicts, never two: VALID, INVALID (with the reason), or UNCHECKABLE when the check could not be completed — 'could not check' is a different claim from 'forged'. Accepts the card as a JSON object, a JSON string, a councilof.ai / csoai.org URL, or a 64-hex card id (the record id shown on the site and the card field of list_cards), which resolves to https://councilof.ai/signed/cards/{id}.json. Never a certification.
Input Schema
{
"type": "object",
"properties": {
"card": {
"description": "The signed card: an object, a JSON string, a councilof.ai / csoai.org URL to one, or a 64-hex card id (resolved to https://councilof.ai/signed/cards/{id}.json).",
"anyOf": [
{
"type": "object"
},
{
"type": "string"
}
]
}
},
"required": [
"card"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID, INVALID or UNCHECKABLE"
},
"id": {
"type": [
"string",
"null"
]
},
"family": {
"type": [
"string",
"null"
]
},
"reason": {
"type": [
"string",
"null"
]
},
"reasons": {
"type": "array",
"items": {
"type": "string"
}
},
"checks": {
"type": "array",
"items": {
"type": "object",
"properties": {
"check": {
"type": "string"
},
"ok": {
"type": [
"boolean",
"null"
],
"description": "true = passed, false = failed, null = not applicable or not run (detail says UNCHECKED)"
},
"code": {
"type": "string"
},
"detail": {
"type": "string"
},
"advisory": {
"type": "boolean",
"description": "true = reported but never decides the verdict (the live did.json cross-check)"
}
}
}
},
"pinned_key": {
"type": [
"string",
"null"
]
},
"rule": {
"type": "string"
},
"note": {
"type": "string"
},
"not_a_certification": {
"type": "boolean"
},
"resolved_from": {
"type": "object",
"description": "Present when a 64-hex card id was passed: the id asked about and the URL fetched for it.",
"properties": {
"id": {
"type": "string"
},
"url": {
"type": "string"
}
}
}
},
"required": [
"state"
]
}🟢list_cards(axis, limit)
The published signed-card index (https://councilof.ai/signed/card_index.json): what the index declares (n_cards) and how many rows it actually carries, reported next to — never reconciled with — the count the card store endpoint (https://councilof.ai/api/cards) reports for itself. Two labelled numbers from two surfaces; if they disagree, this tool shows the disagreement rather than picking one. Optional filters return recent rows: axis, limit. Each row carries card_url, the signed body; pass it, or the row's 64-hex card id, to verify_card.
Input Schema
{
"type": "object",
"properties": {
"axis": {
"type": "string",
"description": "Only list rows whose axis matches this name (case-insensitive)."
},
"limit": {
"type": "integer",
"minimum": 0,
"maximum": 150,
"description": "How many rows to include in the listing (newest first). Default 10. The two counts are always reported in full regardless of this limit."
}
},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"index": {
"type": [
"object",
"null"
]
},
"card_store_count_endpoint": {
"type": [
"object",
"null"
]
},
"rows": {
"type": [
"array",
"null"
],
"items": {
"type": "object",
"properties": {
"card": {
"type": "string"
},
"card_url": {
"type": [
"string",
"null"
],
"description": "The signed card body, https://councilof.ai/signed/cards/{id}.json. verify_card takes this URL or the bare card id."
},
"axis": {
"type": "string"
},
"ts": {},
"signed": {}
}
}
},
"axis_query": {
"type": "object",
"properties": {
"asked": {
"type": "string"
},
"canonical": {
"type": "string"
},
"spellings": {
"type": "array",
"items": {
"type": "string"
}
},
"index_names_matched": {
"type": "array",
"items": {
"type": "string"
}
}
}
},
"doctrine": {
"type": "string"
},
"not_a_certification": {
"type": "boolean"
}
}
}🟢get_root
GET the permissionless public-root at https://councilof.ai/root.json. Returns merkle_root, card_count, as_of, and UNMEASURED notes. Separate from GSPC. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable). Never a certificate.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID, UNREACHABLE or UNCHECKABLE"
},
"merkle_root": {
"type": [
"string",
"null"
]
},
"card_count": {},
"as_of": {},
"kind": {},
"source": {
"type": "string"
},
"not_gspc": {
"type": "boolean"
}
},
"required": [
"state"
]
}🟢get_card(sha256)
GET one public-root card-v0 leaf by sha256 (64 hex) from https://councilof.ai/cards/{sha16}.json. UNMEASURED cells stay visible. States: VALID (fetched); NOT_IN_THIS_CORPUS (the id is in the signed card index, not the public root, so use verify_card on it); INVALID (in neither the live root nor the signed card index); UNCHECKABLE (a source could not be read). Not a GSPC measurement-card.
Input Schema
{
"type": "object",
"properties": {
"sha256": {
"type": "string",
"description": "64-char hex payload SHA-256 of the card-v0 leaf."
}
},
"required": [
"sha256"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID, NOT_IN_THIS_CORPUS, INVALID or UNCHECKABLE"
},
"sha256": {
"type": "string"
},
"reason": {
"type": "string"
},
"source": {
"type": "string"
},
"surface": {},
"unmeasured": {},
"sig_ed25519": {},
"not_gspc": {
"type": "boolean"
},
"corpus": {
"type": "string",
"description": "With NOT_IN_THIS_CORPUS: the set the id belongs to (signed_card_index)."
},
"card_url": {
"type": [
"string",
"null"
],
"description": "With NOT_IN_THIS_CORPUS: the signed card body to pass to verify_card."
},
"next": {
"type": "object",
"description": "With NOT_IN_THIS_CORPUS: the tool call that checks this id."
}
},
"required": [
"state"
]
}🟢verify_inclusion(sha256)
Check a sha256 against the live public-root merkle via GET /api/proof?sha=. Three states only: VALID (included), INVALID (not a leaf), UNCHECKABLE (proof endpoint unreachable). Does not claim Ed25519 unless sig_ed25519 is present and checked separately. Never a grade.
Input Schema
{
"type": "object",
"properties": {
"sha256": {
"type": "string",
"description": "64-char hex digest to test for inclusion."
}
},
"required": [
"sha256"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID, INVALID or UNCHECKABLE"
},
"sha256": {
"type": "string"
},
"merkle_root": {
"type": [
"string",
"null"
]
},
"reason": {}
},
"required": [
"state"
]
}🟢x402_trust
GET the latest x402 catalog trust snapshot: counts of how many catalogued x402 resources open a correct 402 challenge vs how many are phantom on the wire. Counts only by doctrine — host details withheld; a 402 is NOT delivery; measurement, never certification.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID or UNREACHABLE"
},
"counts": {
"type": [
"object",
"null"
]
},
"headline": {
"type": [
"string",
"null"
]
},
"as_of": {
"type": [
"string",
"null"
]
},
"kind": {},
"source": {
"type": "string"
}
},
"required": [
"state"
]
}🟢mcp_trust
GET the latest MCP handshake trust snapshot (https://councilof.ai/interop/mcp-trust/latest.json): counts of how many internet-facing MCP servers answer a correct initialize handshake, how many respond with an auth challenge, and how many are unreachable. Counts only by doctrine — host details withheld by design. A partial round or a cap change is disclosed in the snapshot. Measurement, never certification. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable).
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"description": "VALID or UNREACHABLE"
},
"counts": {
"type": [
"object",
"null"
]
},
"as_of": {
"type": [
"string",
"null"
]
},
"partial": {
"type": "boolean",
"description": "true whenever the enumeration did not complete — a cap-limited read is partial"
},
"partial_reason": {
"type": [
"string",
"null"
]
},
"enumeration": {
"type": [
"object",
"null"
]
},
"diff": {},
"kind": {},
"source": {
"type": "string"
},
"headline": {
"type": [
"string",
"null"
]
}
},
"required": [
"state"
]
}🟢measurement_index
Read the latest signed measurement-capsule index published at https://councilof.ai/measurement-capsules/latest.json: the index root over every capsule, each batch (adapter, kind, capsule count, measurement states, batch Merkle root, record sha256, record signature and OpenTimestamps state), the index's own board signature re-verified here against the pinned did:web:csoai.org#board-attestation-1 key, and the anchor states published beside it (OpenTimestamps, Rekor, XRPL) — PENDING is never called attested. States only: measurement, not endorsement; no verdict, score or ranking. NOT_PUBLISHED when no index is served; UNREACHABLE when the source could not be fetched.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"enum": [
"PUBLISHED",
"NOT_PUBLISHED",
"UNREACHABLE",
"UNCHECKABLE"
]
},
"doctrine": {
"type": "string",
"const": "measurement, not endorsement"
},
"version": {
"type": "string"
},
"index_root": {
"type": [
"string",
"null"
]
},
"n_capsules_total": {
"type": [
"integer",
"null"
]
},
"n_batches": {
"type": "integer"
},
"batches": {
"type": "array",
"items": {
"type": "object"
}
},
"signature": {
"type": "object"
},
"anchors": {
"type": "object"
},
"reason": {
"type": "string"
}
},
"required": [
"state"
]
}🟢verify_capsule(capsule_json)
Verify one measurement capsule. Pass capsule_json as the capsule's JSON TEXT (exact: number lexemes are kept) or as an object. Recomputes capsule_id (sha256 of the canonical JSON without capsule_id), picks the rule by the capsule's schema (csoai.measurement-capsule/0.2: RFC 6962 Merkle with 0x00/0x01 domain separation; the superseded v0.1 capsule schema: the v0.1 rule), finds the published batch of the same kind, recomputes that batch's root from its published leaves, and returns the audit path of this capsule against the root named by the signed index. States: INCLUDED, NOT_INCLUDED, ID_MISMATCH, UNCHECKABLE, NOT_PUBLISHED. Verifying is free forever. It proves the bytes were published and bound; what they measured is the capsule's own measurement_state and limitations — measurement, not endorsement.
Input Schema
{
"type": "object",
"properties": {
"capsule_json": {
"description": "The capsule: its JSON text (preferred, byte-exact) or the parsed object.",
"type": [
"string",
"object"
]
}
},
"required": [
"capsule_json"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"enum": [
"INCLUDED",
"NOT_INCLUDED",
"ID_MISMATCH",
"UNCHECKABLE",
"NOT_PUBLISHED",
"UNREACHABLE"
]
},
"doctrine": {
"type": "string",
"const": "measurement, not endorsement"
},
"capsule_id": {
"type": "object"
},
"batch": {
"type": "object"
},
"inclusion": {
"type": "object"
},
"index_signature": {
"type": "object"
},
"reason": {
"type": "string"
}
},
"required": [
"state"
]
}🟢server_evidence(endpoint_url)
Trust per server, not totals: every published measurement capsule about ONE endpoint URL across all batches — MCP contract-parity dimensions (AUTH, PAYMENT, PROTOCOL, TOOLS, VERSION), A2A card-signature state, self-parity cells for CSOAI's own doors, and any later adapter (e.g. tool drift) — each with its measurement_state, observed_at, correction_pointer, limitations, batch Merkle root and an inclusion pointer (verify_capsule re-derives inclusion). Read from a static per-endpoint shard keyed by sha256 of the normalised URL. An endpoint with no capsule answers NOT_MEASURED with an empty list — never an error and never a clean bill. No verdict, score or ranking: measurement, not endorsement.
Input Schema
{
"type": "object",
"properties": {
"endpoint_url": {
"type": "string",
"description": "The endpoint URL, e.g. https://example.com/mcp or an agent-card URL."
}
},
"required": [
"endpoint_url"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"state": {
"type": "string",
"enum": [
"MEASURED",
"NOT_MEASURED",
"NOT_PUBLISHED",
"UNREACHABLE",
"UNCHECKABLE"
]
},
"doctrine": {
"type": "string",
"const": "measurement, not endorsement"
},
"endpoint": {
"type": [
"string",
"null"
]
},
"n_capsules": {
"type": "integer"
},
"capsules": {
"type": "array",
"items": {
"type": "object"
}
},
"reason": {
"type": "string"
}
},
"required": [
"state"
]
}Community
Evidence