
security-preflight
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Community: Submitted by a user or imported; check the owner before granting accessDegradedNo sign-inGlobalFreeRead-only
What it can do
What data it sees
Do you need an account
No: the server works without sign-in
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Server tool list (5)
Raw names from tools/list. Only developers need these.
| security_preflight | Run a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action. |
| scan_source | $1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt. |
| screen_injection | $1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase. |
| get_security_receipt | Read a previously issued public, input-redacted receipt. |
| describe_agent | Describe scope, evidence boundary, inputs, and outputs. |