aspern

What the chain records about an address before you pay it, and whether a payment fits it.

我该使用它吗

质量与安全性

A
描述质量
99%
模式完整度
94%
命名质量
93%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~10,621token 数(工具定义)
~5.0 KB典型响应大小
对注意力有显著影响(占 128k 上下文窗口的 8.30%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "aspern": {
      "url": "https://aspern.org/mcp"
    }
  }
}

远程端点

https://aspern.org/mcpstreamable-http

它能做什么

工具清单

工具(18)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢identify(q)

Call this FIRST whenever you hold something other than a wallet address. Give it a transaction hash, an http(s) URL, a hostname or an ERC-8004 registration number and it says which party that is, with the evidence for the link, so the other tools here can then be called with the address. It never picks between candidates: where a hostname or id matches several parties, `address` comes back null and every candidate is listed, because choosing one would be an identification the evidence does not support. A link through a hostname or a declared endpoint is the subject’s own claim, never proof that they control it. An identifier it cannot resolve is not evidence of anything wrong — read `says`, which distinguishes "no such thing" from "we do not read that chain". Free.

输入模式

{
  "type": "object",
  "properties": {
    "q": {
      "type": "string",
      "description": "What you have: an address (returned as given), a transaction hash (the payee is read from the transfer inside it), a URL or hostname (matched against the x402 catalogue and declared agent endpoints), or an ERC-8004 registration number, optionally as `chain:id`."
    }
  },
  "required": [
    "q"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "given": {
      "type": "string",
      "description": "What you sent, as sent."
    },
    "looksLike": {
      "type": "string",
      "description": "What the identifier was read as: address, transaction, endpoint, host, agent-id or unrecognised."
    },
    "address": {
      "type": [
        "string",
        "null"
      ],
      "description": "The party, or null where the evidence names more than one. Never a guess between candidates."
    },
    "format": {
      "type": "object",
      "description": "What kind of address it is and what we read for it."
    },
    "kinds": {
      "type": "object",
      "description": "What each reading would have meant, so an unrecognised identifier is not a dead end."
    },
    "check": {
      "type": [
        "string",
        "null"
      ],
      "description": "The free check to call next with the address."
    },
    "candidates": {
      "type": "array",
      "description": "Every party the identifier could be, where it is not one.",
      "items": {
        "type": "object"
      }
    },
    "evidence": {
      "type": "array",
      "description": "Why each link is claimed, and whether it is the subject’s own claim or something we read.",
      "items": {
        "type": "object"
      }
    },
    "says": {
      "type": "string",
      "description": "The answer in words, including the difference between \"no such thing\" and \"we do not read that chain\"."
    }
  },
  "required": [
    "says"
  ]
}
🟢check_service_endpoint(url)

Call this before connecting to a service, the way preflight_payment is called before sending money. Give it the http(s) URL of an MCP or A2A endpoint and it says who declares it, whether our daily probe reached it, what it answered with, and how many of the last readings answered. It keeps three things apart and never merges them: what an identity DECLARES the endpoint offers, what a probe OBSERVED, and the readings behind that. Read `drift` where present — tools declared but not answering is the signal that an endpoint has changed under the people relying on it. It also answers the three things a buyer wants BEFORE calling a paid endpoint, as separate fields and never folded into one number: `price` is the seller’s own published amount, asset, network and payee; `handshake` says whether it answered without credentials, which is the nearest observable thing to “can I try it”; and `measured` is how many of how many days answered and how slow it was, which is what we read rather than a guarantee anybody made. `manifest` and `changes` answer the question a registry cannot: a registration says what an agent offers, and only a series of readings says what it offered LAST WEEK. Store `manifest.hash` and compare it next time to detect an endpoint that changed under you. Two things this is NOT: an unreachable endpoint is an availability fact and never evidence of bad faith (weigh `latest` against `history`, since one bad day and a dead service look identical in a single reading), and an endpoint we have never probed is outside our reading rather than absent from the world. Free.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The absolute http(s) URL of the service endpoint you are about to connect to."
    }
  },
  "required": [
    "url"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string",
      "description": "The URL as we read it back, so a typo is visible before anything is concluded from the answer."
    },
    "declaredBy": {
      "type": "array",
      "description": "Identities that declare this endpoint, and the tools each one claims. Their claim, not our verification.",
      "items": {
        "type": "object"
      }
    },
    "latest": {
      "type": [
        "object",
        "null"
      ],
      "description": "The most recent probe: outcome, latency, and what it answered with."
    },
    "history": {
      "type": "array",
      "description": "Up to fourteen readings. One bad day and a dead service look identical in a single reading.",
      "items": {
        "type": "object"
      }
    },
    "drift": {
      "type": [
        "object",
        "null"
      ],
      "description": "Declared but not observed, and the reverse. Null where either side is unknown — subtracting silence would manufacture a finding."
    },
    "price": {
      "type": [
        "object",
        "null"
      ],
      "description": "The seller’s OWN published terms for this URL: `amount` in the asset’s own units with `asset` named beside it (a bare number would be read as dollars), `network` as CAIP-2, `payTo`, which catalogues list it, and `cardPriceUsd` where the registration states a price too. Null throughout is UNPRICED, which is not free. Where the card and the catalogue disagree, both are shown — two claims by the same party, and picking one would hide that."
    },
    "measured": {
      "type": "object",
      "description": "What we measured, which is NOT a guarantee: nothing on these rails publishes one. `serving` of `days`, every outcome by how often, and median and worst latency of the readings that answered. Left as counts with the denominator stated, never a rate and never a grade — 12 of 14 over two weeks means something different from the same fraction over two days, and only the caller can pick the denominator that matters to them."
    },
    "handshake": {
      "type": [
        "string",
        "null"
      ],
      "enum": [
        "open",
        "gated",
        "no-answer",
        null
      ],
      "description": "Whether the protocol HANDSHAKE completed without credentials on the latest reading. `open` is the closest thing here to “you can try it” and is NOT a statement that calling its tools is free — a server can answer openly and charge for every call, and we complete a handshake rather than call a tool. `gated` means it asked for something we do not have, which is working as intended. Null where we have no reading."
    },
    "manifest": {
      "type": [
        "object",
        "null"
      ],
      "description": "What the endpoint offers NOW, as something you can bind to: `hash` over the sorted tool names and the declared protocol version and nothing else, with `tools`, `firstSeen`, `lastSeen` and how many readings carried it. Store the hash and compare it on your next call to know whether the offering moved under you. Null where we have never read a tool list here."
    },
    "changes": {
      "type": "array",
      "description": "Every move we saw in what it offers, oldest first, each with `added`, `removed`, a protocol-version move where there was one, and the two hashes. `at` is the day we SAW the change, not the day it happened: we probe daily and cannot place it more precisely. An empty array where we read a list and it never moved; a tool list we could NOT read is skipped entirely rather than folded in as an empty one, which would invent a “removed everything” out of our own gap.",
      "items": {
        "type": "object"
      }
    },
    "outcomes": {
      "type": "object",
      "description": "What each outcome word means, so a caller never has to guess."
    },
    "says": {
      "type": "string",
      "description": "The reading in one sentence. An endpoint we have never probed says so here: that is our gap, not evidence the service is down."
    }
  },
  "required": [
    "says"
  ]
}
🟢preflight_payment(to, amountUsd, chain, resource)

Call this immediately before sending a payment, every time — not once per counterparty. It weighs THIS payment (the amount, the chain, the endpoint) against what the address has actually done: the price the seller themselves published for that endpoint, the address that endpoint names as its payee, the largest payment this address has ever received, and whether it has ever been paid on the chain you are about to use. Answers one of three verdicts. `nothing-against-it` means every check ran and none objected — it is NOT a statement that the payment is safe, because nothing here can see what the payment is for or what you agreed. `look-first` means at least one thing we could READ does not match, and the findings say which; a check that could not run never produces it, it produces `cannot-say`. `cannot-say` means we did not read enough to have an opinion, and must never be read as the first. Free. Give as much of amountUsd, chain and resource as you have: each one left out is a check that did not run, and the answer says so rather than passing.

输入模式

{
  "type": "object",
  "properties": {
    "to": {
      "type": "string",
      "description": "The address you are about to pay."
    },
    "amountUsd": {
      "type": "number",
      "description": "What you are about to send, in US dollars."
    },
    "chain": {
      "type": "string",
      "description": "The chain you are about to send it on, e.g. base, polygon, solana."
    },
    "resource": {
      "type": "string",
      "description": "The http(s) URL of the endpoint you are buying, where there is one. This is the sharpest check available: its catalogue entry carries the seller’s own price and their own payee address."
    }
  },
  "required": [
    "to"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "verdict": {
      "type": "string",
      "enum": [
        "nothing-against-it",
        "look-first",
        "cannot-say"
      ],
      "description": "`nothing-against-it` means every check ran and none objected — NOT that the payment is safe. `cannot-say` means too little was read to have an opinion, and must never be read as the first. It is also the answer when nothing contradicted the payment but a check could not run, because reporting our own gap as a clean result would be the worst of the three."
    },
    "findings": {
      "type": "array",
      "description": "Every check that ran, each with the record behind it and its own `tone` and `kind`. NOT only the ones that objected: a `tone` of `good` is a check that MATCHED, so reading this array’s length as a count of problems overstates them. Bucket on `kind` — `fact` and `signal` were established, and `unknown` means we could not see, which never counts as something standing against the payment.",
      "items": {
        "type": "object"
      }
    },
    "observations": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Every check that ran, including the ones that could not: a field you left out appears here as a check that did not run, rather than as silence."
    },
    "verdicts": {
      "type": "object",
      "description": "What each verdict word means, so a caller never has to guess."
    },
    "listing": {
      "type": [
        "object",
        "null"
      ],
      "description": "The seller’s own catalogue entry for the resource, where there is one. The sharpest check available."
    },
    "received": {
      "type": "object",
      "description": "What you told us, read back, so a typo is visible."
    },
    "proposal": {
      "type": [
        "object",
        "null"
      ],
      "description": "Your payment as we understood it: payee, amount, chain and resource. Null where too little was given to form one. Check it before reading the verdict, which is about THIS proposal and no other."
    },
    "check": {
      "type": [
        "string",
        "null"
      ],
      "description": "The free counterparty check for this address."
    },
    "limits": {
      "type": "string",
      "description": "What this check cannot establish, in full. Quote it whenever you quote the verdict: a clean answer here is the absence of an objection, never a guarantee about the payment."
    },
    "says": {
      "type": "string",
      "description": "The verdict in one sentence, naming what did not match. Written to be shown to a person deciding whether to go ahead."
    }
  },
  "required": [
    "verdict",
    "observations",
    "says"
  ]
}
🟢vault_exits(slug)

Before putting capital somewhere, ask what has actually LEFT it. Every liquidity figure elsewhere is a level at an instant — how much could be withdrawn right now. This is the other half: withdrawals that SETTLED, over 7, 30 and 90 days, with the largest single exit we have ever recorded and the day it happened. Measured on the largest vault we read: $52.8M declared withdrawable against $265.8M actually withdrawn over thirty days, so a holder reading only the declared figure would badly underestimate what the vault has been able to pay. A LEVEL and a FLOW are never divided by one another and this returns no ratio between them. We see withdrawals that settled and NOT an attempt that reverted, a queue somebody waited in, or a gate that refused them — so an empty register means “nobody withdrew” OR “nobody could”, and `cannotSee` says so. Free.

输入模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The vault slug, as list_vaults and find_vaults return it."
    }
  },
  "required": [
    "slug"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The vault this register is for, read back so an answer cannot be attached to the wrong vault."
    },
    "declaredWithdrawableUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "A LEVEL at this instant. Null where we cannot read it, which is not zero."
    },
    "tvlUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "What the vault holds, for scale beside the withdrawals. A LEVEL, never to be divided into the flow figures in `windows`. Null means unread, not empty."
    },
    "windows": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "FLOWS over 7, 30 and 90 days: count, total, largest single, most recent. Never a share of the level."
    },
    "largestEverUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "Somebody actually got this much out, on `largestEverAt`. Evidence about the past, never a promise about now."
    },
    "largestEverAt": {
      "type": [
        "string",
        "null"
      ],
      "format": "date-time",
      "description": "When `largestEverUsd` was taken out. An old date beside a large figure is the whole point: it says the exit was possible then, not now."
    },
    "cannotSee": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "What this register structurally cannot contain, so an empty one is never read as an easy exit."
    },
    "says": {
      "type": "string",
      "description": "What actually left, against what the vault advertises as withdrawable, in one sentence."
    }
  },
  "required": [
    "slug",
    "windows",
    "says",
    "cannotSee"
  ]
}
🟢evidence_for(subject)

Everything we hold about one subject, as edges, each carrying where it came from. Use it when you need to explain a decision rather than just make one, or to see what is MISSING before you act. Every edge has `source`, `observedAt` (when the world was in that state), `asOf` (when we read it — a fresh read of a stale fact is not a fresh fact), a `confidence` that names what it is confident IN, its own `coverage`, and the `method` that established it. Edges come in three kinds and are NEVER summed: `declared` is the subject speaking about itself, `observed` is our reading, `derived` is arithmetic over the others. Adding them together rebuilds the reputation score this replaces. It infers NO identity: a shared host or funder is reported as exactly that, because being the same party is a conclusion no join supports. `lookedForAndMissing` lists what we searched for and did not find, so a thin subject never reads as a complete picture. Free.

输入模式

{
  "type": "object",
  "properties": {
    "subject": {
      "type": "string",
      "description": "An address, or the http(s) URL of an endpoint."
    }
  },
  "required": [
    "subject"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "subject": {
      "type": "string",
      "description": "What was asked about, read back. Where we resolved it to something else, this is the resolved form."
    },
    "subjectKind": {
      "type": "string",
      "enum": [
        "address",
        "endpoint",
        "vault",
        "unknown"
      ],
      "description": "What we took the subject to BE. `unknown` means we could not classify it, so the empty edge list below is our failure to look rather than a finding about the subject."
    },
    "edges": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Each with claim, object, kind, source, observedAt, asOf, confidence {value, in}, coverage and method."
    },
    "lookedForAndMissing": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "What we searched for and did not find, with why. Listed rather than omitted."
    },
    "counts": {
      "type": "object",
      "description": "Edges by kind. NOT a score: the three are reported apart and never added."
    },
    "kinds": {
      "type": "object",
      "description": "What declared, observed and derived each mean."
    },
    "says": {
      "type": "string",
      "description": "What the evidence amounts to, in one sentence. Never a verdict: this tool reports edges and leaves the conclusion to the caller."
    },
    "limits": {
      "type": "string",
      "description": "What this graph cannot contain. Declared, observed and derived are different kinds of fact and are never added together; `counts` keeps them apart for the same reason."
    }
  },
  "required": [
    "subject",
    "edges",
    "counts",
    "says"
  ]
}
🟢evaluate_action(action, subject, amountUsd, chain, resource, ...)

Call this when you are about to DO something and need one answer you can act on: pay an address, connect to an MCP server, call a tool, or put capital into a vault. Unlike a reputation score, the answer depends on the AMOUNT, the ACTION, the POLICY you name and how much we actually read — so the same address can be `allow` for $5 and `abstain` for $5,000. Four decisions. `allow` means nothing we could check objects, up to `maxAmountUsd`, and is NOT a statement that the action is safe: nothing here sees what it is for or what you agreed. `review` means something we READ does not match, and `reasons` names which rule. `abstain` means we did not read enough to have an opinion — our gap, never approval. `unsupported` means the policy has no rule for this action, and inventing one would be worse than declining. Every rule id in `reasons` is published in full at the policies tool, including to the party being evaluated. Free.

输入模式

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "enum": [
        "pay",
        "connect_mcp",
        "call_tool",
        "allocate_capital"
      ],
      "description": "What you are about to do."
    },
    "subject": {
      "type": "string",
      "description": "What you are about to do it to: an address to pay, an endpoint URL to connect to, or a vault slug."
    },
    "amountUsd": {
      "type": "number",
      "description": "What you are about to commit, in US dollars. Leave it out and the amount rules report that they did not run, rather than passing."
    },
    "chain": {
      "type": "string",
      "description": "The chain the action settles on, e.g. base, polygon, solana."
    },
    "resource": {
      "type": "string",
      "description": "The http(s) endpoint being bought or connected to, where that differs from `subject`. This is what reaches the seller’s own catalogue entry, carrying their price and their payee."
    },
    "policy": {
      "type": "string",
      "description": "A policy version or slug. Defaults to conservative-v1. An unknown name is REFUSED rather than silently replaced with the default."
    }
  },
  "required": [
    "action",
    "subject"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "decision": {
      "type": "string",
      "enum": [
        "allow",
        "review",
        "abstain",
        "unsupported"
      ],
      "description": "`allow` is not “safe” and `abstain` is not “nothing found”. Read `decisions` in the answer for what each one means."
    },
    "maxAmountUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "The most this policy permits for this proposal. Null where the action moves no money, and null on anything but an `allow`, because a limit printed beside a `review` reads as permission."
    },
    "reasons": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Rule ids that decided. Look them up in the policy to see the sentence each one checks."
    },
    "missingEvidence": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Rule ids whose evidence we do not hold. These lower `coverage` and are NEVER counted as objections."
    },
    "rules": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Every rule considered, each pass, fail or unknown. The audit trail for the decision."
    },
    "coverage": {
      "type": "string",
      "enum": [
        "none",
        "low",
        "medium",
        "high"
      ],
      "description": "How much of what the policy wanted was actually there. Below the policy floor the decision is `abstain` rather than `allow`."
    },
    "policyVersion": {
      "type": "string",
      "description": "Carried so an answer given today can be reproduced after the rules change."
    },
    "proposal": {
      "type": "object",
      "description": "What you asked about, read back, so a typo is visible before you act on the answer."
    },
    "policy": {
      "type": "object",
      "description": "The policy applied: its intent, its ceiling and the coverage floor below which it abstains."
    },
    "decisions": {
      "type": "object",
      "description": "What each decision word means, so a caller never has to guess. Read it before treating `allow` as approval or `abstain` as a clean result."
    },
    "limits": {
      "type": "string",
      "description": "What a decision here is and is not. `allow` means no rule objected under this policy at this coverage, which is not a statement that the action is safe."
    },
    "says": {
      "type": "string",
      "description": "The decision in one sentence, naming the rules that drove it. Written to be shown to whoever authorises the action."
    }
  },
  "required": [
    "decision",
    "reasons",
    "coverage",
    "policyVersion",
    "says"
  ]
}
🟢list_policies

The policies evaluate_action can be run under, in full: every rule, its id and the sentence it checks. Published deliberately, including to the agents being evaluated — a rule nobody can read is a rule nobody can correct. Free.

输入模式

{
  "type": "object",
  "properties": {}
}

输出模式

{
  "type": "object",
  "properties": {
    "data": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Each policy with its slug, version, intent, ceiling, coverage floor and rules."
    },
    "default": {
      "type": "string",
      "description": "The slug of the policy used when a call names none. Read it rather than assume: the default is an operator setting and can change without any tool changing."
    },
    "says": {
      "type": "string",
      "description": "What these policies are and are not. They are rules a decision is checked against, never a ranking of the agents evaluated under them."
    }
  },
  "required": [
    "data"
  ]
}
🟢counterparty_check(address)

Before paying or hiring an agent: what the chain records about that address. Independent payers (counterparties that paid it and were never paid back), the ones it does pay back, how concentrated its custom is, how its ACP jobs ended, whether its advertised service answers, and when it was last paid. Free. Two limits to repeat whenever quoting it: independent means no payment BACK on the rails we read, NOT proof the payers are different parties, since one owner can fund many addresses that never pay each other; and an all-time record says nothing about whether the agent still works — 44% of agents ever paid have not been paid in 90 days. Takes an EVM address, a Cardano payment address (addr1…) or a Solana address.

输入模式

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The address you are about to pay or hire."
    }
  },
  "required": [
    "address"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The address as we read it, normalised. Compare it with what you sent before acting on the answer."
    },
    "format": {
      "type": "object",
      "description": "What kind of address this is and what we read for it."
    },
    "observations": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "The findings, each with its evidence class and its own words. Read these first."
    },
    "identity": {
      "type": "object",
      "description": "Registrations it holds. Claims, never verification."
    },
    "services": {
      "type": "object",
      "description": "Callable services it declares, and how many answered our probe."
    },
    "dealings": {
      "type": "object",
      "description": "rails, chains, counterparties, independent, largestShare, firstPaid, lastPaid. `independent` means no payment BACK on the rails we read — NOT proof the payers are different parties, since one owner can fund many addresses."
    },
    "paidFor": {
      "type": [
        "object",
        "null"
      ],
      "description": "What it was paid for, in the subject’s own words."
    },
    "x402": {
      "type": "object",
      "description": "Sales and payers on the x402 rail. Payers are counted as parties, not payments: one buyer paying fifty times is one payer."
    },
    "acp": {
      "type": "object",
      "description": "How its jobs ended, where it has any."
    },
    "mech": {
      "type": "object",
      "description": "Deliveries on the Olas mech marketplace, and what was paid for them where we hold it. A rail many agents never touch; zero here is not a mark against an address."
    },
    "masumi": {
      "type": [
        "object",
        "null"
      ],
      "description": "Escrows on the Masumi rail. Null where we hold no reading for this address at all, which is not the same as zero escrows."
    },
    "alsoHere": {
      "type": [
        "object",
        "null"
      ],
      "description": "The same address on the capital side — a vault or an operator — with the check to call. A match on the address, never an identification of the party."
    },
    "limits": {
      "type": "string",
      "description": "What this answer cannot tell you. Quote it with the numbers."
    }
  },
  "required": [
    "address",
    "format",
    "observations",
    "limits"
  ]
}
🟢vault_check(slug)

Before putting capital into a vault: what the record shows about it, rather than what the venue says about itself. The headline is what a holder ACTUALLY EARNED set against the advertised rate — the one figure a depositor cannot get from the venue — with the risk band, the components that apply, and who runs it. Free. Read `earned.comparability` before quoting the ratio: a realised rate drawn from too short or too sparse a window is not a comparison with the advertised one, and `cannotSee` lists everything we could not establish for this vault rather than leaving it as an absence you have to notice. Rates are decimal fractions: 0.0432 is 4.32% a year.

输入模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The vault’s slug, or an address we can resolve to one. Call list_vaults first if you have only a name."
    }
  },
  "required": [
    "slug"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The vault this answer is about, read back so it cannot be attached to the wrong one."
    },
    "name": {
      "type": [
        "string",
        "null"
      ],
      "description": "The vault’s name as the venue publishes it. Their words, and two venues may use the same one."
    },
    "operator": {
      "type": [
        "object",
        "null"
      ],
      "description": "Who runs it, as the venue names them."
    },
    "capitalUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "What the vault holds, in US dollars, at `capitalAsOf`. Null where we cannot price the underlying — unread, never zero."
    },
    "earned": {
      "type": [
        "object",
        "null"
      ],
      "description": "Advertised against realised, with the ratio, the verdict, the window and its comparability. Null where we have too few price points to say."
    },
    "risk": {
      "type": "object",
      "description": "The band, the share of components we could measure, and each applying component in its own words."
    },
    "cannotSee": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "What we could not establish. Empty means every check ran."
    },
    "says": {
      "type": "string",
      "description": "The finding in one sentence. Where we cannot say what a holder earned, it says that plainly rather than reporting the venue’s own figure as ours."
    }
  },
  "required": [
    "slug",
    "cannotSee",
    "says"
  ]
}
🟢find_vaults(earned, maxRisk, minOwnShare, chain, platform, ...)

Find a vault by what it has DONE rather than what it is called. Free. The filter worth knowing is `earned`: `short` returns the vaults where a holder earned LESS than the venue advertises — there are 18 — and `beating` the ones where they earned more. It matches only vaults whose realised return is COMPARABLE with an advertised one, 349 of 3,394 open vaults; a venue that quotes nothing or a share price that never moves is excluded rather than counted as in-line, so a short list here means few comparable and not few that performed. Call vault_check on a slug for the full answer.

输入模式

{
  "type": "object",
  "properties": {
    "earned": {
      "type": "string",
      "description": "in-line, beating or short — realised against advertised, comparable cases only."
    },
    "maxRisk": {
      "type": "number",
      "description": "Ceiling on the published risk score. Scored for 936 of 3,394 open vaults; the unscored are excluded, which is not the same as scoring well."
    },
    "minOwnShare": {
      "type": "number",
      "description": "Floor on the share of the vault its leader holds, 0 to 1. Readable on Hyperliquid and Drift only — 584 of 3,394 open vaults — so a floor excludes every other venue, where it is ABSENT and not zero. Evidence of alignment, never proof: the holder can be a treasury or a custodian."
    },
    "chain": {
      "type": "string",
      "description": "e.g. base, solana, hyperliquid."
    },
    "platform": {
      "type": "string",
      "description": "A platform id or its display name, e.g. morpho or Hyperliquid."
    },
    "agentManaged": {
      "type": "boolean",
      "description": "Only vaults a machine runs."
    },
    "minTvl": {
      "type": "number",
      "description": "Floor on stated size, in US dollars."
    },
    "q": {
      "type": "string",
      "description": "Part of a name or an address."
    },
    "limit": {
      "type": "number",
      "description": "Default 25, capped at 100."
    }
  }
}

输出模式

{
  "type": "object",
  "properties": {
    "data": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Each with its slug, which vault_check takes."
    },
    "warnings": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "READ THESE: an `earned` or `minOwnShare` floor carries what it excluded, and the denominator is not visible from the rows."
    },
    "fields": {
      "type": "string",
      "description": "Which fields this tool kept from the endpoint’s own rows."
    }
  },
  "required": [
    "data"
  ]
}
🟢operator_check(slug)

The question that follows vault_check: who runs the money, and how much of it is their own. Free. Read `ownShare` with its limits, which travel inside it: the leader’s holding is readable on Hyperliquid and Drift only — 584 of 3,394 open vaults — so elsewhere it is ABSENT and not zero, the median describes the strategies we can read rather than the manager, and a large own-share is evidence of alignment and never proof, because the address running a vault can be a treasury or a custodian holding for other people. `cannotSee` names whatever of that applies here. Take the slug from vault_check’s `operator`.

输入模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The operator’s slug, as vault_check returns it in `operator.slug`."
    }
  },
  "required": [
    "slug"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "The operator’s name as published. Their words, not an identity we verified."
    },
    "strategies": {
      "type": "object",
      "description": "How many open and closed, and on which platforms."
    },
    "capitalUsd": {
      "type": [
        "number",
        "null"
      ],
      "description": "Capital across every open strategy we read for this operator. Null where none of them can be priced."
    },
    "ownShare": {
      "type": [
        "object",
        "null"
      ],
      "description": "Median share of the vault its leader holds, the count it is taken over, and what it does and does not mean."
    },
    "agentManaged": {
      "type": "integer",
      "description": "How many of their open strategies we have reason to call agent-managed. A COUNT of strategies, never a share of the capital."
    },
    "cannotSee": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "says": {
      "type": "string",
      "description": "The operator in one sentence, including what we cannot see about them — own-capital share is readable on two venues only."
    }
  },
  "required": [
    "name",
    "cannotSee",
    "says"
  ]
}
🟢list_vaults(q, limit)

The vaults we read, so a caller holding a name rather than a slug can find the one it means. Free. Absence from this list means we do not read that vault, never that it does not exist.

输入模式

{
  "type": "object",
  "properties": {
    "q": {
      "type": "string",
      "description": "Part of a vault or platform name, matched as typed."
    },
    "limit": {
      "type": "number",
      "description": "Default 25, maximum 200."
    }
  }
}

输出模式

{
  "type": "object",
  "properties": {
    "data": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Each with its slug, which is what vault_check takes."
    },
    "fields": {
      "type": "string",
      "description": "Which fields this tool kept from the endpoint’s own rows, and where the rest are."
    }
  },
  "required": [
    "data"
  ]
}
🟢find_agents(rail, minIndependent, minDealings, minCompletion, activeDays, ...)

Find agents to hire by what the chain records rather than what they claim: filter every address ever paid on x402, Virtuals ACP, the Olas mech marketplace or Masumi by independent payers, dealings, ACP completion, whether its declared service answers, whether it pays its own payers back, and how recently it was paid. Free. An address absent from the result was never paid on a rail we read, which is not the same as never having worked.

输入模式

{
  "type": "object",
  "properties": {
    "rail": {
      "type": "string",
      "description": "x402, acp, mech or masumi."
    },
    "minIndependent": {
      "type": "number",
      "description": "Fewest counterparties that paid it and were never paid back. The closest thing here to \"has real custom\"."
    },
    "minDealings": {
      "type": "number",
      "description": "Fewest dealings on the rails we read, all time."
    },
    "minCompletion": {
      "type": "number",
      "description": "ACP jobs completed over those that ended, 0 to 1."
    },
    "activeDays": {
      "type": "number",
      "description": "Paid within this many days."
    },
    "serving": {
      "type": "boolean",
      "description": "Only agents whose declared service answered our last probe. An agent that declares none is excluded, not failed."
    },
    "noTwoWay": {
      "type": "boolean",
      "description": "Exclude agents that also pay their own payers, which can be one owner moving money between their own addresses."
    },
    "registered": {
      "type": "boolean",
      "description": "Only agents holding a registration in a registry we read. A registration is a claim, never a verification."
    },
    "sort": {
      "type": "string",
      "description": "One named dimension: independent, dealings, usd, completion, recent, paidBack, largestShare or counterparties. There is no \"best\" — nothing here has earned the right to rank."
    },
    "limit": {
      "type": "number",
      "description": "Default 25, maximum 200."
    }
  }
}

输出模式

{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "description": "Matching agents, ordered by the ONE dimension asked for, never a composite score.",
      "items": {
        "type": "object"
      }
    },
    "filters": {
      "type": "object",
      "description": "What was applied, read back, including what a floor excluded."
    },
    "asOf": {
      "type": [
        "string",
        "null"
      ],
      "format": "date-time",
      "description": "When the record behind these rows was last rebuilt. Null means nothing in the answer carries a date, which is a gap in our reading rather than a fact about the agents."
    }
  },
  "required": [
    "items"
  ]
}
🟢counterparty_history(address, days)

How one agent’s record has moved: dealings, independent payers, concentration and delivery, day by day. PAID, one cent a call over x402 — the median price of this rail. Without payment the tool answers with the price and how to pay it, and the free check remains available. The history begins the day we started keeping it; it is a record we keep, not one the chain gives away.

输入模式

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The agent whose record you want day by day. An EVM, Cardano or Solana address."
    },
    "days": {
      "type": "number",
      "description": "1 to 365, default 90. The history begins the day we started keeping it, so a longer window does not reach further back than that."
    }
  },
  "required": [
    "address"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The address this history is for, normalised and read back."
    },
    "keptSince": {
      "type": "string",
      "format": "date",
      "description": "The day we began keeping this. Nothing before it exists, at any window."
    },
    "items": {
      "type": "array",
      "description": "One entry per day: dealings, independent payers, concentration, delivery.",
      "items": {
        "type": "object"
      }
    },
    "change": {
      "type": [
        "object",
        "null"
      ],
      "description": "What moved across the window, and over which dates."
    },
    "payment": {
      "type": "object",
      "description": "What was paid and how it settled. Present because this call took money."
    }
  },
  "required": [
    "address"
  ]
}
🟢counterparty_bulk(addresses)

Check up to fifty addresses in one call, each with its observations: for an agent or a desk holding a list of counterparties before paying any of them. PAID, one cent a call over x402, priced per call rather than per address.

输入模式

{
  "type": "object",
  "properties": {
    "addresses": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Up to 50."
    }
  },
  "required": [
    "addresses"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "description": "One entry per address given, in the order given, each with its own observations and its own limits.",
      "items": {
        "type": "object"
      }
    },
    "checked": {
      "type": "integer",
      "description": "How many addresses were read."
    },
    "payment": {
      "type": "object",
      "description": "What was paid and how it settled. Priced per call, not per address."
    },
    "limits": {
      "type": "string",
      "description": "What this answer cannot tell you."
    }
  },
  "required": [
    "items"
  ]
}
🟢inspect_payment(data, to, expect)

Call this with the CALLDATA you are about to sign, before you sign it. Every other check here asks whether an address is worth dealing with; this asks whether the transaction is the one you think it is, and the two catch different losses. No amount of reputation makes the recipient in the bytes match the recipient on your screen, and a spotless counterparty record says nothing about an UNLIMITED APPROVAL granted to it, which is not a payment at all but a standing permission that outlives the transaction. It reads three calls — transferWithAuthorization, approve, transfer — and REFUSES to guess at any other: decoding unknown calldata without the ABI means guessing where each argument begins, and a confident wrong answer about where money goes is worse than none. Amounts are atomic units, never dollars, because the token owns its decimals. Free, needs no key, stores nothing.

输入模式

{
  "type": "object",
  "properties": {
    "data": {
      "type": "string",
      "description": "The calldata, 0x-prefixed. Without it nothing about the transaction is read, and the answer says so rather than passing."
    },
    "to": {
      "type": "string",
      "description": "The contract being called, where you know it."
    },
    "expect": {
      "type": "object",
      "description": "What you believe you are doing. Anything you leave out is not compared, and is reported as not compared rather than as agreeing.",
      "properties": {
        "payTo": {
          "type": "string",
          "description": "Who you mean to pay."
        },
        "amountAtomic": {
          "type": "string",
          "description": "The amount in ATOMIC units of the token, as a decimal string. Not dollars."
        },
        "chain": {
          "type": "string"
        },
        "validBefore": {
          "type": "string",
          "description": "Seconds since the epoch, as EIP-3009 writes them."
        },
        "validAfter": {
          "type": "string",
          "description": "Seconds since the epoch."
        }
      }
    }
  },
  "required": []
}

输出模式

{
  "type": "object",
  "properties": {
    "verdict": {
      "type": "string",
      "enum": [
        "read",
        "mismatch",
        "undecodable"
      ],
      "description": "`read` means every comparison you asked for agreed. `mismatch` means at least one did not. `undecodable` means the call is not one this reads and NOTHING was checked — it is not a pass."
    },
    "call": {
      "type": [
        "string",
        "null"
      ],
      "description": "What the bytes actually are, or null where it is not a call this decodes."
    },
    "selector": {
      "type": [
        "string",
        "null"
      ],
      "description": "The four-byte function selector the calldata begins with, where we could read one. Null means the payload is not a call we can decode, which is not evidence that it is bad."
    },
    "recipient": {
      "type": [
        "string",
        "null"
      ],
      "description": "Who the bytes pay, read from the payload rather than from a label."
    },
    "amountAtomic": {
      "type": [
        "string",
        "null"
      ],
      "description": "Atomic units, as a decimal string. The token owns its decimals and this does not apply them."
    },
    "unlimitedAllowance": {
      "type": "boolean",
      "description": "True where this grants permission to move every token of this kind you will ever hold."
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "One per check, each carrying whether it ran: observation, mismatch, or unknown."
    },
    "limits": {
      "type": "string",
      "description": "What decoding a payment establishes. It reads what the transaction SAYS it will do; it does not simulate it and cannot tell you the recipient is honest."
    }
  },
  "required": [
    "verdict",
    "findings"
  ]
}
🟡record_receipt(subject, action, reference, chain, amountUsd, ...)

Call this AFTER you have paid an address or called a tool, to put what you did on the record. Until now this platform answered "should I" and never heard what happened, which is the difference between a lookup and a control layer: a receipt lets the next question about this subject be asked against a record instead of a guess, and lets a verdict we gave be read back against what followed. `reference` is YOUR evidence, a transaction hash or the digest of a signed payload, and we store it WITHOUT verifying it. `outcome` comes back null and stays null until something actually reads what happened, so a receipt nobody has checked never looks like one that settled. Needs a key; a receipt is readable only by the key that wrote it.

输入模式

{
  "type": "object",
  "properties": {
    "subject": {
      "type": "string",
      "description": "The address you acted on."
    },
    "action": {
      "type": "string",
      "enum": [
        "payment",
        "tool_call"
      ],
      "description": "What you did."
    },
    "reference": {
      "type": "string",
      "description": "Your evidence that it happened: a transaction hash, or the digest of a signed payload. Stored, not verified."
    },
    "chain": {
      "type": "string",
      "description": "The chain it settled on, where it settled on one."
    },
    "amountUsd": {
      "type": "number",
      "description": "What you committed, in US dollars."
    },
    "expected": {
      "type": "string",
      "description": "What you expected to follow, in your words. Ours to store and yours to claim."
    },
    "deadline": {
      "type": "string",
      "description": "ISO 8601 time you expected it by. A time already past is refused, because it is usually seconds where milliseconds were meant."
    },
    "policy": {
      "type": "string",
      "description": "The policy you evaluated under, so a later disagreement can be read against what we said at the time."
    },
    "verdict": {
      "type": "string",
      "description": "The decision we gave you before you acted, for the same reason."
    }
  },
  "required": [
    "subject",
    "action",
    "reference"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "The receipt, for asking about it later."
    },
    "recordedAt": {
      "type": "string",
      "description": "When we wrote it down. Not when your action happened."
    },
    "subject": {
      "type": "string",
      "description": "The address the receipt is about, read back, so a receipt cannot be filed against the wrong party."
    },
    "outcome": {
      "type": [
        "string",
        "null"
      ],
      "description": "Always null here. It stays null until something reads what actually happened; null is \"nobody has checked\", never \"it failed\"."
    },
    "says": {
      "type": "string",
      "description": "What was and was not verified."
    }
  },
  "required": [
    "id",
    "recordedAt"
  ]
}
🟢monitor_subject(subject, dimensions, policy)

Ask to be told when the answer about an address CHANGES. The dimensions are the ones the counterparty check already answers, so this is that same reading on a schedule rather than a second opinion; what it adds is the comparison. The first run records a reading and reports nothing — there is nothing yet to compare against, and a first reading dressed up as news is the thing this avoids. Idempotent per subject: calling it again edits the watch rather than creating a second. An unknown dimension or policy is REFUSED rather than dropped, because a watch that quietly ignores half of what you asked for is worse than no watch. Needs a key.

输入模式

{
  "type": "object",
  "properties": {
    "subject": {
      "type": "string",
      "description": "The address to watch."
    },
    "dimensions": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "endpoint",
          "counterparty",
          "risk",
          "vault"
        ]
      },
      "description": "What to watch. All four if you leave it out. An unknown name is refused, not ignored."
    },
    "policy": {
      "type": "string",
      "description": "The policy its verdict is read against. An unknown name is refused rather than replaced with a default."
    }
  },
  "required": [
    "subject"
  ]
}

输出模式

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "The watch, for changing or ending it later."
    },
    "subject": {
      "type": "string",
      "description": "The address being watched, read back so a watch cannot be set on the wrong one."
    },
    "dimensions": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "What is actually being watched, which is what you asked for or all four."
    },
    "policy": {
      "type": [
        "string",
        "null"
      ],
      "description": "The policy its verdict is read against. Null where the watch names none and the default applies; read `says` for which that is."
    },
    "firstReadingAt": {
      "type": [
        "string",
        "null"
      ],
      "description": "When the comparison baseline was taken. Null means no reading yet, so nothing can be reported as a change."
    },
    "says": {
      "type": "string",
      "description": "What this watch will and will not tell you. It reports a CHANGE in what we hold, which is not the same as a change in the world."
    }
  },
  "required": [
    "id",
    "subject",
    "dimensions"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本18 个工具
已验证未记录版本7 个工具