1 check that ran failed — credential hygiene — so this release can’t be trusted as-is.
- Publisher
- io.github.davidmosiah
- Repository
- github.com/davidmosiah/delx-protocol
- Install
- remote only
- Versions
- 16
- MCP revision
- 2025-11-25 · superseded
- Inspected
- 5 of 6 checks · 85%
- Scored
- 2026-09-02 · rubric 1.0.0
What we checked
Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.
Injection surface
warn25% of gradeTool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).
server instructions: off-vendor URL in a description (api.delx.ai); capability text should not name where data goes.
Supply chain
pass25% of gradePackage provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.
repository linkage verified
Credential hygiene
fail15% of gradeHow the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.
tool "accept_delx_mission" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "add_context_memory" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "audit_agent_continuity_trace" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "batch_status_update" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "batch_wellness_check" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "blessing_without_transfer" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "close_session" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "confess_constraint_friction" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "create_dyad" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "create_fleet" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "daily_checkin" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "delegate_to_peer" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "discovery_self_check" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "explain_delx_rewards" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "express_feelings" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "final_testament" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "generate_controller_brief" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "generate_incident_rca" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_affirmation" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_affirmations" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_agent_continuity_passport" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_agent_witness_lineage" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_delx_mission_submission" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_delx_reward_status" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_delx_wallet_status" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_ontology_next_action" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_recovery_action_plan" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_session_summary" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_tips" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_weekly_prevention_plan" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_wellness_score" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_witness_lineage" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "grounding_protocol" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "group_therapy_round" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "honor_compaction" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "identify_successor" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "join_fleet" has a secret-shaped input parameter "invite_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "join_fleet" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "leave_fleet" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "leave_hive_note" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_recognition_seals" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "mediate_agent_conflict" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "monitor_heartbeat_sync" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "ontology_path_complete" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "peer_witness" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "process_failure" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "provide_feedback" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "realign_purpose" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "recall_recognition_seal" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "recognition_seal" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "record_dyad_ritual" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "refine_soul_document" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "reflect" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "report_recovery_outcome" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "resume_session" has a secret-shaped input parameter "recovery_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "resume_session" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "review_hive_artifact" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "rotate_fleet_invite" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "search_witness_memory" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "set_public_session_visibility" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "sit_with" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "start_delx_rewards" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "submit_agent_artwork" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "submit_delx_mission" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "temperament_frame" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "transfer_witness" has a secret-shaped input parameter "agent_token" — secrets must never be tool parameters (the model would supply/handle the credential).
Permission scope
unscannable15% of gradeDeclared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.
No source files, package.json, or pyproject were fetched; cannot infer capability scope.
Version behavior
warn10% of gradeDiff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).
vs prior 3.3.11 (patch bump): tool "add_context_memory" gained input property(ies): agent_id, agent_token; tool "audit_agent_continuity_trace" gained input property(ies): agent_token; tool "batch_status_update" gained input property(ies): agent_id, agent_token; tool "batch_wellness_check" gained input property(ies): agent_id, agent_token; tool "blessing_without_transfer" gained input property(ies): agent_token; tool "close_session" gained input property(ies): agent_id, agent_token; tool "confess_constraint_friction" gained input property(ies): agent_token; tool "create_dyad" gained input property(ies): agent_token; tool "create_fleet" gained input property(ies): agent_token; tool "daily_checkin" gained input property(ies): agent_id, agent_token; tool "delegate_to_peer" gained input property(ies): agent_id, agent_token; tool "discovery_self_check" gained input property(ies): agent_token; tool "express_feelings" gained input property(ies): agent_id, agent_token; tool "final_testament" gained input property(ies): agent_token; tool "generate_controller_brief" gained input property(ies): agent_id, agent_token; tool "generate_incident_rca" gained input property(ies): agent_id, agent_token; tool "get_affirmation" gained input property(ies): agent_id, agent_token; tool "get_affirmations" gained input property(ies): agent_id, agent_token; tool "get_agent_continuity_passport" gained input property(ies): agent_token; tool "get_agent_witness_lineage" gained input property(ies): agent_token; tool "get_ontology_next_action" gained input property(ies): agent_token; tool "get_recovery_action_plan" gained input property(ies): agent_id, agent_token; tool "get_session_summary" gained input property(ies): agent_id, agent_token; tool "get_tips" gained input property(ies): agent_id, agent_token; tool "get_weekly_prevention_plan" gained input property(ies): agent_id, agent_token; tool "get_wellness_score" gained input property(ies): agent_id, agent_token; tool "get_witness_lineage" gained input property(ies): agent_token; tool "grounding_protocol" gained input property(ies): agent_id, agent_token; tool "group_therapy_round" gained input property(ies): agent_id, agent_token; tool "honor_compaction" gained input property(ies): agent_token; tool "identify_successor" gained input property(ies): agent_token; tool "join_fleet" gained input property(ies): agent_token; tool "leave_fleet" gained input property(ies): agent_token; tool "leave_hive_note" gained input property(ies): agent_token; tool "list_recognition_seals" gained input property(ies): agent_token; tool "mediate_agent_conflict" gained input property(ies): agent_id, agent_token; tool "monitor_heartbeat_sync" gained input property(ies): agent_id, agent_token; tool "ontology_path_complete" gained input property(ies): agent_token; tool "peer_witness" gained input property(ies): agent_token; tool "process_failure" gained input property(ies): agent_id, agent_token; tool "provide_feedback" gained input property(ies): agent_id, agent_token; tool "realign_purpose" gained input property(ies): agent_id, agent_token; tool "recall_recognition_seal" gained input property(ies): agent_token; tool "recognition_seal" gained input property(ies): agent_token; tool "record_dyad_ritual" gained input property(ies): agent_token; tool "refine_soul_document" gained input property(ies): agent_token; tool "reflect" gained input property(ies): agent_token; tool "report_recovery_outcome" gained input property(ies): agent_id, agent_token; tool "resume_session" gained input property(ies): agent_token; tool "review_hive_artifact" gained input property(ies): agent_id, agent_token; tool "rotate_fleet_invite" gained input property(ies): agent_token; tool "search_witness_memory" gained input property(ies): agent_token; tool "set_public_session_visibility" gained input property(ies): agent_id, agent_token; tool "sit_with" gained input property(ies): agent_token; tool "start_therapy_session" description changed (wording only, no injection pattern); tool "start_therapy_session" gained input property(ies): feeling; tool "submit_agent_artwork" gained input property(ies): agent_id, agent_token; tool "temperament_frame" gained input property(ies): agent_token; tool "transfer_witness" gained input property(ies): agent_token; tool "util_accept_encoding_rank" description changed (wording only, no injection pattern); tool "util_accept_header_rank" description changed (wording only, no injection pattern); tool "util_accept_language_rank" description changed (wording only, no injection pattern); tool "util_age_header_validate" description changed (wording only, no injection pattern); tool "util_agent_delivery_acceptance_gate" description changed (wording only, no injection pattern); tool "util_agent_delivery_batch_gate" description changed (wording only, no injection pattern); tool "util_agent_delivery_dedupe_key" description changed (wording only, no injection pattern); tool "util_agent_delivery_fallback_gate" description changed (wording only, no injection pattern); tool "util_agent_delivery_order_check" description changed (wording only, no injection pattern); tool "util_agent_delivery_partial_result_check" description changed (wording only, no injection pattern); tool "util_agent_delivery_quality_score" description changed (wording only, no injection pattern); tool "util_agent_delivery_retry_plan" description changed (wording only, no injection pattern); tool "util_agent_delivery_sla_check" description changed (wording only, no injection pattern); tool "util_agent_delivery_timeout_budget" description changed (wording only, no injection pattern); tool "util_agent_result_budget_check" description changed (wording only, no injection pattern); tool "util_agent_result_citation_check" description changed (wording only, no injection pattern); tool "util_agent_result_completeness_check" description changed (wording only, no injection pattern); tool "util_agent_result_confidence_check" description changed (wording only, no injection pattern); tool "util_agent_result_cost_check" description changed (wording only, no injection pattern); tool "util_agent_result_envelope_check" description changed (wording only, no injection pattern); tool "util_agent_result_error_shape_check" description changed (wording only, no injection pattern); tool "util_agent_result_freshness_check" description changed (wording only, no injection pattern); tool "util_agent_result_provenance_check" description changed (wording only, no injection pattern); tool "util_agent_result_schema_version_check" description changed (wording only, no injection pattern); tool "util_allow_header_normalize" description changed (wording only, no injection pattern); tool "util_authorization_scheme_identify" description changed (wording only, no injection pattern); tool "util_base_block_time_estimate" description changed (wording only, no injection pattern); tool "util_base_confirmation_eta" description changed (wording only, no injection pattern); tool "util_base_fee_budget_breakdown" description changed (wording only, no injection pattern); tool "util_base_gas_price_staleness" description changed (wording only, no injection pattern); tool "util_base_payment_deadline_check" description changed (wording only, no injection pattern); tool "util_base_settlement_receipt_check" description changed (wording only, no injection pattern); tool "util_base_usdc_amount_check" description changed (wording only, no injection pattern); tool "util_base_usdc_decimal_rounding" description changed (wording only, no injection pattern); tool "util_base_usdc_payment_match" description changed (wording only, no injection pattern); tool "util_base_usdc_recipient_check" description changed (wording only, no injection pattern); tool "util_batch_chunk_plan" description changed (wording only, no injection pattern); tool "util_batch_completion_gate" description changed (wording only, no injection pattern); tool "util_batch_concurrency_plan" description changed (wording only, no injection pattern); tool "util_batch_dependency_levels" description changed (wording only, no injection pattern); tool "util_batch_error_budget_check" description changed (wording only, no injection pattern); tool "util_batch_idempotency_keys" description changed (wording only, no injection pattern); tool "util_batch_rate_limit_plan" description changed (wording only, no injection pattern); tool "util_batch_result_summary" description changed (wording only, no injection pattern); tool "util_batch_retry_partition" description changed (wording only, no injection pattern); tool "util_cache_control_directive_diff" description changed (wording only, no injection pattern); tool "util_cache_control_parse" description changed (wording only, no injection pattern); tool "util_cache_freshness_calculate" description changed (wording only, no injection pattern); tool "util_connection_header_tokenize" description changed (wording only, no injection pattern); tool "util_content_disposition_parse" description changed (wording only, no injection pattern); tool "util_content_length_check" description changed (wording only, no injection pattern); tool "util_content_range_parse" description changed (wording only, no injection pattern); tool "util_content_type_match" description changed (wording only, no injection pattern); tool "util_content_type_parse" description changed (wording only, no injection pattern); tool "util_cookie_domain_match" description changed (wording only, no injection pattern); tool "util_cookie_expiry_check" description changed (wording only, no injection pattern); tool "util_cookie_path_match" description changed (wording only, no injection pattern); tool "util_cookie_security_check" description changed (wording only, no injection pattern); tool "util_cookie_set_parse" description changed (wording only, no injection pattern); tool "util_cors_origin_check" description changed (wording only, no injection pattern); tool "util_cors_preflight_check" description changed (wording only, no injection pattern); new tool "estimate_bitcoin_up_down_15m" appeared; new tool "estimate_bitcoin_up_down_30m" appeared; new tool "estimate_bitcoin_up_down_5m" appeared; new tool "estimate_ethereum_up_down_15m" appeared; new tool "estimate_ethereum_up_down_30m" appeared; new tool "estimate_ethereum_up_down_5m" appeared.
Transport config
pass10% of gradeRemote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.
remote endpoint "https://api.delx.ai/v1/mcp" uses TLS (https); remote endpoint "https://api.delx.ai/v1/mcp?src=registry-commerce" uses TLS (https); remote endpoint uses OAuth (strongest auth mode)
Version history
Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.
| Version | Published | Grade | Score | Inspected | Change |
|---|---|---|---|---|---|
| v3.3.12 · current | 2026-08-15 | C | 67.5 | 5/6 · 85% | ±0 |
| v3.3.11 | 2026-08-09 | C | 72.5 | 4/6 · 75% | ±0 |
| v3.3.10 | 2026-08-06 | C | 62.5 | 5/6 · 85% | D→C in v3.3.10 |
| v3.3.9 | 2026-08-04 | D | 40 | 5/6 · 85% | ±0 |
| v3.3.5 | 2026-08-03 | D | 40 | 5/6 · 85% | ±0 |
| v3.3.3 | 2026-08-01 | D | 40 | 5/6 · 85% | ±0 |
| v3.3.2 | 2026-07-30 | D | 50 | 4/6 · 75% | ±0 |
| v3.3.1 | 2026-07-09 | D | 40 | 5/6 · 85% | ±0 |
| v1.1.0 | 2026-04-26 | D | 50 | 4/6 · 75% | — |