MCP server · trust report

co.ainumbers/tools

2 checks that ran failed — credential hygiene and transport config — so this release can’t be trusted as-is.

Publisher
co.ainumbers
Repository
github.com/PostOakLabs/ainumbers-mcp-apps
Install
remote only
Versions
5
Inspected
6 of 6 checks · 100%
Scored
2026-07-20 · rubric 1.0.0

What we checked

Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.

6 checks1 clean5 flagged
  • Injection surface

    warn25% of grade

    Tool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).

    tool "customer_risk_rating" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "ap2_aml_mandate_builder" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "diagnose_canton_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "optimize_settlement_capital" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_tokenized_collateral_eligibility" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_cash_leg_finality" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_canton_dvp_atomicity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_repo_haircut" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_canton_party_allowlist" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_digital_asset_regulatory" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_pvp_settlement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_tokenized_security_lifecycle" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "mobilize_margin_collateral" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_fund_collateral" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_collateral_swap_eligibility" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_ap2_mandate_chain" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "simulate_spend_policy" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_x402_settlement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_agent_attestation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_ai_act_conformity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "precheck_reserve_attestation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_basel31_delta" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_einvoice_batch" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_dora_incident" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_aml_typologies" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "simulate_vop_matching" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_acp_checkout" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_eudi_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_psd3_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "select_agentic_checkout_protocol" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "audit_acp_ucp_product_feed" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_agent_traffic_policy" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compare_agentic_rail_protocols" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "inspect_visa_trusted_agent_protocol" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_mastercard_agentic_token" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_a2a_agent_card" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "simulate_x402_flow" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_agentic_readiness_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_mcp_deployability_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_dora_readiness_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_agent_commerce_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_a2a_x402_mandate" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_a2a_trust_chain" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "attest_mcp_server" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_tempo_fit_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_tempo_payment_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "decode_mpp_session" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_tempo_token_compliance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "screen_tip20_transfer_batch" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_tempo_zone_disclosure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "map_tempo_settlement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_tempo_validator_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_arc_fit_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_arc_cpn_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_arc_stablefx_rfq" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_arc_xreserve_config" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_arc_paymaster_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_cctp_v2_transfer" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_treasury_clearing_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_clearing_access_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "estimate_ficc_margin_netting" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "estimate_cross_margin_benefit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_digital_trade_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_mletr_record" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_digital_trade_rules" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_trade_document_set" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_tokenized_settlement_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_deposit_token_compliance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_cross_network_settlement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_settlement_asset_finality" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_agent_economy_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "reconcile_x402_batch_settlement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_ap2_payment_receipt" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_agent_service_metering" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_ai_act_highrisk_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_ai_conformity_pack" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_fria_monitoring_plan" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_agentic_ai_risk" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_carbon_compliance_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_cbam_embedded_emissions" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "resolve_cbam_default_value" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_cbam_certificate_cost" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "aggregate_cbam_precursor_emissions" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_taxonomy_alignment" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "aggregate_taxonomy_kpi_gar" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_eugb_factsheet" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "apply_climate_scenario" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_t1_readiness_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_csdr_penalty" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "predict_settlement_fail" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_ssi_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_allocation_affirmation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_securities_settlement_message" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_buy_in_exposure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_settlement_efficiency_kpi" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_pqc_timeline_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "plan_tls_pki_migration" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_iso20022_pqc_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_fido_pqc_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_blockchain_quantum_risk" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_sanctions_screening_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "aggregate_ownership_50pct" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_screening_list_coverage" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_fuzzy_match_calibration" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_eccn_dual_use" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_circumvention_diligence" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_no_russia_clause_pack" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_sanctions_screening_quality" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_mica_casp_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "route_mica_transitional_deadline" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_mica_casp_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_mica_own_funds" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_crypto_asset_whitepaper" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_mar_crypto_surveillance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_tfr_travel_rule_batch" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "scope_mica_token_and_service" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "reconcile_mpp_subscription" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_tempo_gas_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_canton_selective_disclosure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_dtc_tokenized_treasury" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_partner_stablecoin_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "route_partner_stablecoin_jurisdiction" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_dscsa_transaction_statement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_saleable_return" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_suspect_product_status" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_dpp_data_carrier" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_product_lineage" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_product_authenticity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_fsma204_cte" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "link_traceability_lot_code" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "resolve_recall_trace" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "anchor_document_integrity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_timestamp_attestation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_c2pa_manifest" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_content_credential_signature" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "resolve_provenance_ingredient_tree" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_ai_act_art50_marking" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_dual_layer_disclosure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_content_binding_assertion" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_webbotauth_signature" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_signature_directory" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_signature_agent_card" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "audit_agent_key_rotation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "crosswalk_agent_payment_rail_trust" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_agent_directory_publish_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_cyclonedx_sbom" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_slsa_provenance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_openvex_statement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_spdx_sbom" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_cra_annex1_completeness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_cra_vuln_reporting_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_nis2_entity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_nis2_art21_measures" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_nis2_penalty_exposure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_nis2_incident_significance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_nis2_supply_chain_diligence" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_nis2_governance_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_mcp_server_identity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_mcp_authorization_metadata" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_mcp_registry_entry" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "audit_mcp_tool_scope_revocation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_agent_obo_mandate" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_mcp_task_lifecycle" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_emir_trade_report" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_emir_uti_completeness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_emir_upi" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "reconcile_emir_pairing" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_emir_lifecycle_event" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_emir_reporting_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_vida_einvoice_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_vida_drr_reporting_obligation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_vida_recapitulative_migration" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_vida_platform_deemed_supplier" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "route_vida_oss_registration" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_vida_readiness_diagnostic" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_eudr_due_diligence_statement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_eudr_geolocation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_eudr_commodity_scope" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_eudr_country_risk" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "link_eudr_supply_chain_traceability" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_eudr_readiness_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_iso42001_aims_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_ai_impact_assessment" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_ai_system_governance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "map_nist_ai_rmf_functions" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_gpai_code_conformance" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_ai_governance_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_ifrs17_measurement_model" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_ifrs17_csm_rollforward" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_ifrs17_risk_adjustment" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_solvency2_scr_ratio" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "reconcile_sii_ifrs17" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_insurance_reporting_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "calculate_irrbb_eve_shocks" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "evaluate_irrbb_sot_eve" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "evaluate_irrbb_sot_nii" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "map_irrbb_standardised_approach" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_irrbb_csrbb_scope" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "run_irrbb_disclosure_fit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "convert_markdown_document" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "convert_tabular_data" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_conversion_receipt" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_conversion_receipt" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "prove_metadata_sanitization" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_digest_manifest" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "choose_cc_license" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "select_cbe_license" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "map_pil_flavor" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compare_rights_matrix" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "certify_license_election" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_license_election" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "generate_iscc_code" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_tdm_reservation" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "select_embedded_license" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_license_compatibility" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assemble_license_terms" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_rights_record" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "generate_attribution_string" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_royalty_split" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_nft_metadata" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_ipfs_cid" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "analyze_prediction_market" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "find_prediction_arbitrage" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_perp_margin" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_perp_position" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_reg_z_appendix_j_apr" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_trid_tolerance_cure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "verify_trid_apr_accuracy" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_qm_points_and_fees" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_qm_apr_apor_spread" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lookup_reg_z_thresholds" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_llpa_stack" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_agency_eligibility_matrix" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_conforming_loan_limit" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_fha_mip_eligibility" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_va_funding_fee_residual" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_mismo_uldd_ulad" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_adverse_action_notice" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_adverse_action_notice" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_disparity_metrics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_hmda_rate_spread" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_mla_mapr" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_scra_rate_cap" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_card_act_ability_to_pay" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "test_hoepa_high_cost" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "test_hpml_escrow" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "build_ai_decision_log_record" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_agent_audit_trail" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "classify_annex3_decisioning_obligations" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "test_bifsg_bias_thresholds" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "assess_naic_ais_program_readiness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_cbpr_structured_address" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "validate_pacs008_party_completeness" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "check_purpose_code_requirement" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "simulate_gpi_tracker_lifecycle" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "score_mt_mx_translation_fidelity" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "lint_lei_payment_binding" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "prevalidation_readiness_scorer" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compute_remittance_disclosure" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "compare_corridor_cost" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes. tool "model_stablecoin_corridor_economics" description: off-vendor URL in a description (ainumbers.co); capability text should not name where data goes.

  • Supply chain

    warn25% of grade

    Package provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.

    install hook "prepare" present and not a recognized benign build command; dependency "hono" is edit-distance 2 from popular package "pino" (typosquat candidate)

  • Credential hygiene

    fail15% of grade

    How the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.

    tool "vc_issue" has a secret-shaped input parameter "credential_type" — secrets must never be tool parameters (the model would supply/handle the credential).

  • Permission scope

    pass15% of grade

    Declared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.

    No shell-exec, unbounded/sensitive filesystem, or download-and-run primitives found in scanned source. PASS = no static red flag. Static scanning is blind to code fetched or executed at runtime.

  • Version behavior

    warn10% of grade

    Diff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).

    vs prior 0.4.5 (patch bump): tool "build_workflow_links" description changed (wording only, no injection pattern); tool "find_chain" description changed (wording only, no injection pattern); tool "find_tool" description changed (wording only, no injection pattern); new tool "validate_private_inputs" appeared.

  • Transport config

    fail10% of grade

    Remote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.

    remote MCP endpoint declares NO authentication (unauthenticated remote — nginx-ui/CVE-2026-33032 class)

Version history

Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.

VersionPublishedGradeScoreInspectedChange
v0.4.6 · current2026-07-20 D456/6 · 100%±0
v0.4.52026-07-20 D506/6 · 100%±0
v0.4.42026-07-16 D505/6 · 90%