security-preflight

Static MCP, source-code and injection-indicator checks with redacted signed receipts.

Community: Submitted by a user or imported; check the owner before granting accessDegradedNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    Static MCP, source-code and injection-indicator checks with redacted signed receipts.

    Server tool list (5)

    Raw names from tools/list. Only developers need these.

    security_preflightRun a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.
    scan_source$1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.
    screen_injection$1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.
    get_security_receiptRead a previously issued public, input-redacted receipt.
    describe_agentDescribe scope, evidence boundary, inputs, and outputs.
    security-preflight: connect to Claude, ChatGPT, Cursor · Connectors.fun