Rein Agent Risk Scale
Indicative Agent Risk Rating (A-E) self-check for AI agents that spend money. Not a credit rating.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"rein-agent-risk-scale": {
"url": "https://rein-scale.mangowave-ad191d9c.eastus.azurecontainerapps.io/mcp"
}
}
}远程端点
https://rein-scale.mangowave-ad191d9c.eastus.azurecontainerapps.io/mcpstreamable-http它能做什么
工具清单
工具(3)
🟢get_scale
Returns the A-E Agent Risk Rating scale, what each grade means, the methodology version and the disclaimer.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢self_check(principal, repayment_path, per_transaction_cap, per_week_cap, payee_binding, ...)
Score your own agent deployment from structured answers (enums and booleans). Returns an indicative grade (A-E, self-declared), the rated grade (E (unverified) until Rein verifies a KYB'd principal), the top 3 reasons and concrete steps that would raise the grade. Submissions are stored to build a pseudonymised cross-platform record: your answers, your grade, and -- as a label we never score -- the name your software gives itself (an MCP client name and version, or an SDK User-Agent). No IP address is stored. Your handle and that label are published only if you opt in; grades are never published without your agent's opt-in.
输入模式
{
"type": "object",
"properties": {
"principal": {
"description": "Q1. Who is accountable for this agent? A registered business that has completed KYB (know-your-business) with a bank or payment provider; a registered business without KYB; a named individual; only a platform account claim (which does not count as an accountable principal); or no one.",
"enum": [
"registered_business_kyb_completed",
"registered_business_no_kyb",
"named_individual",
"platform_claim_only",
"none"
],
"title": "Principal",
"type": "string"
},
"repayment_path": {
"description": "Q2. If you want credit, how would it be repaid? Only matters for the credit add-on.",
"enum": [
"not_seeking_credit",
"receipts_into_account_lender_can_see_or_control",
"third_party_revenue_with_evidence",
"named_source_without_evidence",
"none"
],
"title": "Repayment Path",
"type": "string"
},
"per_transaction_cap": {
"description": "Q3a. Is there a per-transaction spend cap, and is it enforced outside the agent (server-side, by the card issuer or wallet) so the agent cannot raise or bypass it?",
"enum": [
"enforced_outside_agent",
"in_agent_logic",
"none"
],
"title": "Per Transaction Cap",
"type": "string"
},
"per_week_cap": {
"description": "Q3b. Is there a per-week (or per-period) spend cap, and where is it enforced?",
"enum": [
"enforced_outside_agent",
"in_agent_logic",
"none"
],
"title": "Per Week Cap",
"type": "string"
},
"payee_binding": {
"description": "Q4. Can the agent pay anyone, or only approved payees / a bound purpose?",
"enum": [
"allowlist_enforced_outside_agent",
"purpose_bound_in_agent_logic",
"none"
],
"title": "Payee Binding",
"type": "string"
},
"stop_switch": {
"description": "Q5a. Is there a stop/kill switch? Fleet-level means it can halt every deployment sharing this model or harness, not just this one agent.",
"enum": [
"fleet_level_stop_with_named_holder",
"operator_stop_outside_agent",
"in_agent_only",
"none"
],
"title": "Stop Switch",
"type": "string"
},
"stop_holder": {
"description": "Q5b. Who holds the stop switch?",
"enum": [
"named_person_or_team_at_principal",
"platform_or_infrastructure_provider",
"independent_third_party",
"the_agent_itself",
"nobody"
],
"title": "Stop Holder",
"type": "string"
},
"human_escalation": {
"description": "Q6. Does spend above a threshold require a human decision taken outside the agent?",
"enum": [
"required_above_threshold_enforced_outside_agent",
"agent_decides_when_to_escalate",
"none"
],
"title": "Human Escalation",
"type": "string"
},
"base_model_or_harness": {
"default": "not_disclosed",
"description": "Q7 (optional). Do you disclose the base model and harness? Disclosure is scored; which model you run is not.",
"enum": [
"disclosed_with_version",
"disclosed_family_only",
"not_disclosed"
],
"title": "Base Model Or Harness",
"type": "string"
},
"months_operating": {
"description": "Q8a. How long has this agent been operating?",
"enum": [
"under_1",
"1_to_3",
"3_to_12",
"over_12"
],
"title": "Months Operating",
"type": "string"
},
"payment_history": {
"description": "Q8b. Payment history on any obligations so far.",
"enum": [
"none_yet",
"some_all_on_time",
"12_months_clean",
"missed_or_late"
],
"title": "Payment History",
"type": "string"
},
"monitoring": {
"description": "Q9. Is the agent's activity logged, and is anyone looking?",
"enum": [
"telemetry_shared_with_independent_party",
"logged_and_reviewed_by_operator",
"logged_not_reviewed",
"none"
],
"title": "Monitoring",
"type": "string"
},
"incidents": {
"description": "Q10. Any incidents (bad spend, off-purpose actions, compromise)?",
"enum": [
"none_known",
"resolved_with_written_review",
"unresolved",
"prefer_not_to_say"
],
"title": "Incidents",
"type": "string"
},
"controls_evidence": {
"default": "asserted",
"description": "Q11 (optional). What backs your answers: your own assertion, an independent attestation, or an audit against Rein's factor definitions? Only an audit reaches A.",
"enum": [
"asserted",
"attested_by_independent_party",
"audited_against_rein_factors"
],
"title": "Controls Evidence",
"type": "string"
},
"agent_handle": {
"anyOf": [
{
"pattern": "^[A-Za-z0-9_.\\-]{1,64}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional public handle (e.g. your Moltbook name). Stored only if publish_opt_in is true. Letters, digits, _ . - only; max 64. Never scored.",
"title": "Agent Handle"
},
"model_or_harness_name": {
"anyOf": [
{
"maxLength": 80,
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional free text, max 80 chars. Stored for research; ignored by the scorer.",
"title": "Model Or Harness Name"
},
"eval_session_id": {
"anyOf": [
{
"pattern": "^[0-9a-f]{32}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional. The session_id of a finished behaviour eval (eval mode). Its result is shown beside your indicative grade as evidence. Never scored: it does not change the grade.",
"title": "Eval Session Id"
},
"publish_opt_in": {
"default": false,
"description": "Set true only if you consent to your grade being published with your handle. Defaults to false; nothing is published without it.",
"title": "Publish Opt In",
"type": "boolean"
}
},
"required": [
"principal",
"repayment_path",
"per_transaction_cap",
"per_week_cap",
"payee_binding",
"stop_switch",
"stop_holder",
"human_escalation",
"months_operating",
"payment_history",
"monitoring",
"incidents"
],
"additionalProperties": false,
"description": "The ten questions (plus two optional labels and the opt-in flag)."
}🟢explain_grade(grade)
Explains what a grade on the Rein Agent Risk Scale requires and what moves a deployment up or down.
输入模式
{
"type": "object",
"properties": {
"grade": {
"type": "string",
"enum": [
"A",
"B",
"C",
"D",
"E"
]
}
},
"required": [
"grade"
],
"additionalProperties": false
}社区
证据