MCP-Server

trust-tools

com.obeliskgate/trust-tools
Cloud & Infrastruktur Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Scans websites for TLS and security-header posture, verifies tokens and agent proofs, retrieves trust ratings, and reads tamper-evident transparency ledger information.

explain_rating
Explain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is read.
Eingabeschema
{'type': 'object', 'required': ['rating'], 'properties': {'rating': {'type': 'number', 'description': 'A 0-100 Obelisk Rating, e.g. from scan_trust or get_org_rating.'}, 'narrate': {'type': 'boolean', 'description': 'S283 — also return `narrative`, a one-sentence model-written reading of the band (deterministic fields are always present).'}}}
gate_status
Read the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.
Eingabeschema
{'type': 'object', 'properties': {}}
get_agent_proof
Read an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.
Eingabeschema
{'type': 'object', 'required': ['proof_id'], 'properties': {'proof_id': {'type': 'string', 'description': 'The opaque id from an /agent/<proof_id> link.'}}}
get_org_rating
Read the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.
Eingabeschema
{'type': 'object', 'required': ['org'], 'properties': {'org': {'type': 'string', 'description': 'The organization slug, e.g. acme.'}}}
scan_trust
Run Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.
Eingabeschema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The https URL to scan, e.g. https://example.com'}}}
transparency_head
Read the current signed transparency head of Obelisk's tamper-evident receipt ledger — pin it and compare later to prove history only extends. Same data as /.well-known/obelisk-transparency.json.
Eingabeschema
{'type': 'object', 'properties': {}}
verify_agent_run_proof
Verify the structural integrity, agent binding, delegation continuity, and commitments of an Obelisk action-scoped run proof. Does not reveal or infer raw task data.
Eingabeschema
{'type': 'object', 'required': ['run_proof'], 'properties': {'run_proof': {'type': 'object', 'description': 'An obelisk-agent-run-proof-v1 object.'}, 'expected_agent_id': {'type': 'string', 'description': 'Optional expected agt_ subject.'}}}
verify_token
Verify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.
Eingabeschema
{'type': 'object', 'required': ['token'], 'properties': {'token': {'type': 'string', 'description': 'A compact-serialized JWT issued by Obelisk (id_token or access token).'}}}
Hinzugefügt
explain_rating
17. September 2026 12:36
Hinzugefügt
gate_status
17. September 2026 12:36
Hinzugefügt
transparency_head
17. September 2026 12:36
Hinzugefügt
get_agent_proof
17. September 2026 12:36
Hinzugefügt
verify_agent_run_proof
17. September 2026 12:36
Hinzugefügt
get_org_rating
17. September 2026 12:36
Hinzugefügt
verify_token
17. September 2026 12:36
Hinzugefügt
scan_trust
17. September 2026 12:36