databutler-provenance

Live trust signals for domains & packages: age, registrar, typosquat resemblance.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~262token 数(工具定义)
~507 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.20%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "databutler-provenance": {
      "url": "https://databutler.dev/api/mcp/provenance"
    }
  }
}

远程端点

https://databutler.dev/api/mcp/provenancestreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢domain_provenance(domain)

Who runs this domain? Live RDAP lookup: registration date and age, registrar, nameservers, status, whether the registrant is redacted, plus a typosquat check (edit-distance / brand-substring) against high-value brands. A very recently registered domain resembling a bank or big brand is a classic phishing signal — but report it as a signal, not a conclusion.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "e.g. example.com"
    }
  },
  "required": [
    "domain"
  ]
}
🟡package_provenance(ecosystem, name)

Who publishes this package, and is it a typosquat? Live npm or PyPI lookup: first-publish date and age, release count, latest version, maintainers/author, linked repo, plus a typosquat check against popular package names. Use when an agent is about to install or recommend an unfamiliar dependency.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi"
      ],
      "description": "npm or pypi"
    },
    "name": {
      "type": "string",
      "description": "package name, e.g. express or requests"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具