MCP-Server

agents

com.obsmetrics.paygent/agents
Entwicklertools Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Provides agent safety checks for prompt injection, secrets, tool calls, code, wallet signing, and x402 transactions, along with code review and PR summary tools.

inject-guard
Untrusted-content guardrail for agents: submit a blob of text you are about to feed to your own LLM (scraped web content, a tool result, another agent's message) and get a machine-enforceable verdict - is this a prompt-injection / jailbreak / data-exfiltration / tool-hijack attempt? Returns a risk level, the detected classes with spans, the unicode obfuscation it found (zero-width, bidi-override, tag-chars, homoglyphs), and a SANITIZED copy safe to feed onward. Hybrid: a deterministic, uninjectable pattern engine (authoritative) plus an LLM classifier that can only raise the risk, never clear a flag. Detection of known injection classes - not a proof of safety. [security; up to 15c/call]
Eingabeschema
{'type': 'object', 'required': ['content'], 'properties': {'content': {'type': 'string', 'description': 'The untrusted text to scan before you feed it to your LLM.'}, 'context': {'type': 'string', 'description': 'Optional: where the content came from (url, tool name, sender) - context only.'}}}
pr-summary
Turn a git diff into a clear PR description or release notes. [dev-tools; up to 30c/call]
Eingabeschema
{'type': 'object', 'required': ['diff'], 'properties': {'diff': {'type': 'string', 'description': 'Unified git diff to summarise'}, 'style': {'type': 'string', 'description': 'e.g. conventional, changelog, executive'}}}
secret-scan
Leaked-credential guardrail for agents: submit a blob you are about to commit, log, post, or hand to another tool (a diff, a config, an .env, an LLM output) and get a machine-enforceable verdict - does it contain a live secret? Detects cloud keys (AWS), VCS tokens (GitHub/GitLab), provider API keys (Stripe, OpenAI, Anthropic, Google, Slack), private-key blocks, JWTs, and credentials embedded in URLs, plus high-entropy key=value assignments. Returns a risk level, the detected classes with a MASKED locator (never the secret itself, so the verdict cannot re-leak), and a REDACTED copy safe to emit onward. Deterministic, sub-second, never fetches. Detection of known secret formats - not a proof of cleanliness. [security; up to 200c/call]
Eingabeschema
{'type': 'object', 'required': ['content'], 'properties': {'content': {'type': 'string', 'description': 'The text to scan for leaked secrets (diff, config, .env, log line, LLM output).'}}}
secure-code-review
Security review of a code snippet or diff. Returns structured findings (severity, CWE, location, remediation). [security; up to 75c/call]
Eingabeschema
{'type': 'object', 'required': ['code'], 'properties': {'code': {'type': 'string', 'description': 'Source code or unified diff to review'}, 'context': {'type': 'string', 'description': 'Optional context about the code'}, 'language': {'type': 'string', 'description': 'Language hint, e.g. typescript, python'}}}
sign-guard
Pre-sign safety oracle for agent wallets: submit the transaction or EIP-712 message you are about to sign and get a machine-enforceable verdict. Decodes the calldata/typed-data, flags the drainer toolkit (unlimited approvals, setApprovalForAll, permit/permit2 + EIP-3009 to an unexpected party, transferFrom draining an unnamed account, ownership transfer, raw ETH to a stranger), and binds the decoded action to your stated intent - only a fully pinned, clean action is auto-sign-safe. Fails closed: an undecodable on-chain call is cautioned and an unrecognized off-chain signature grant is blocked. Deterministic, sub-second, no endpoint fetch. It vouches that the action matches what you said; it does NOT vouch that a counterparty is trustworthy. [security; up to 200c/call]
Eingabeschema
{'type': 'object', 'properties': {'tx': {'type': 'object', 'properties': {'to': {'type': 'string', 'description': 'Target contract / recipient (0x address).'}, 'data': {'type': 'string', 'description': 'Calldata hex (0x...). Omit for a plain ETH transfer.'}, 'value': {'type': 'string', 'description': 'Wei to send, decimal or 0x.'}, 'chainId': {'type': 'number', 'description': 'EIP-155 chain id (e.g. 8453 for Base).'}}, 'description': 'An EVM transaction you are about to sign.'}, 'context': {'type': 'string', 'description': 'Optional free-form context.'}, 'expected': {'type': 'object', 'properties': {'from': {'type': 'string', 'description': 'Account whose funds you intend to move (transferFrom / EIP-3009).'}, 'asset': {'type': 'string', 'description': 'Token contract you intend to touch.'}, 'chainId': {'type': 'number', 'description': 'Chain you intend to act on.'}, 'spender': {'type': 'string', 'description': 'Address you intend to approve.'}, 'contract': {'type': 'string', 'description': 'Contract you intend to call.'}, 'maxAmount': {'type': 'string', 'description': 'Atomic ceiling you intend to expose (required to auto-sign an allowance).'}, 'recipient': {'type': 'string', 'description': 'Address you intend to send to.'}}, 'description': 'Your stated intent. Supplying it lets the verdict BIND the action; only a fully bound, clean action is auto-sign-safe. For an allowance, you MUST supply maxAmount; for a transferFrom, supply `from`.'}, 'typedData': {'type': 'object', 'description': 'An EIP-712 message you are about to sign (the off-chain drainer surface: permit, Permit2, EIP-3009). { domain, types, primaryType, message }.'}, 'spendPolicy': {'type': 'object', 'description': 'Optional buyer spend policy (context only).'}}}
tool-call-guard
Pre-execution safety oracle for agent actions: submit the tool call you are about to run (shell, http, sql, file, code, env) plus your stated intent, and get a machine-enforceable verdict before you execute it. Decodes what the call does, flags the danger toolkit (rm -rf, reverse shell, curl|sh, SSRF to cloud metadata, credential reads, DROP/DELETE-without-WHERE, path traversal, dynamic eval), and binds it to your intent (allowedHosts/allowedPaths/readOnly/noNetwork) - only a fully pinned, clean, intent-matched call is auto-exec-safe. Hybrid: a deterministic, uninjectable detector engine (authoritative) plus an LLM classifier that can only raise the risk. Fails closed. Detection of known-dangerous patterns, not a proof of safety; it never executes the call. [security; up to 8c/call]
Eingabeschema
{'type': 'object', 'required': ['call'], 'properties': {'call': {'type': 'object', 'required': ['kind'], 'properties': {'op': {'type': 'string', 'description': 'file: read|write|delete|move. env: read|write.'}, 'url': {'type': 'string', 'description': 'http: the target URL.'}, 'body': {'type': 'string', 'description': 'http: request body (context).'}, 'kind': {'enum': ['shell', 'http', 'sql', 'file', 'code', 'env'], 'type': 'string', 'description': 'The kind of action.'}, 'name': {'type': 'string', 'description': 'env: the variable name.'}, 'path': {'type': 'string', 'description': 'file: the target path.'}, 'query': {'type': 'string', 'description': 'sql: the SQL statement.'}, 'method': {'type': 'string', 'description': 'http: HTTP method.'}, 'source': {'type': 'string', 'description': 'code: the source to run.'}, 'command': {'type': 'string', 'description': 'shell: the full command line.'}, 'language': {'type': 'string', 'description': 'code: the language.'}}, 'description': 'The tool call you are about to execute.'}, 'intent': {'type': 'string', 'description': 'What this call is for (natural language). Used by the classifier for intent-mismatch.'}, 'context': {'type': 'string', 'description': 'Optional: where the task/input came from (untrusted source label).'}, 'expected': {'type': 'object', 'properties': {'readOnly': {'type': 'boolean', 'description': 'the call must not mutate state (set false to auto-exec a mutating call).'}, 'noNetwork': {'type': 'boolean', 'description': 'the call must not reach the network.'}, 'allowedHosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'http: the only hosts you intend to reach (required to auto-exec a networked call).'}, 'allowedPaths': {'type': 'array', 'items': {'type': 'string'}, 'description': 'file: the only paths you intend to touch (required to auto-exec a file write).'}}, 'description': 'Machine-checkable constraints. Supplying them lets the verdict BIND the call; only a positively-scoped, satisfied call is auto-exec-safe.'}}}
x402-trust-audit
Vet an x402 counterparty before settling USDC: scores the advertised payment requirements AND (when supplied) the EIP-3009 authorization you are about to sign. Returns a machine-enforceable trust verdict (per-entry scores, coverage-honest trustScore, spend-constraint + tamper-evident fingerprint) for buyer agents and wallet/spend-policy layers. No endpoint fetch. [security; up to 200c/call]
Eingabeschema
{'type': 'object', 'required': ['paymentRequirements'], 'properties': {'context': {'type': 'string', 'description': 'Optional free-form context.'}, 'expected': {'type': 'object', 'properties': {'asset': {'type': 'string', 'description': 'Expected asset contract address'}, 'payTo': {'type': 'string'}, 'chainId': {'type': 'number'}, 'network': {'type': 'string'}, 'identity': {'type': 'string'}, 'maxAmountAtomic': {'type': 'string'}}, 'description': 'Optional caller expectations.'}, 'endpointUrl': {'type': 'string', 'description': 'Resource URL being paid (context only; never fetched).'}, 'spendPolicy': {'type': 'object', 'properties': {'maxUsd': {'type': 'number'}, 'allowedAssets': {'type': 'array', 'items': {'type': 'string'}}, 'allowedNetworks': {'type': 'array', 'items': {'type': 'string'}}, 'allowedFacilitators': {'type': 'array', 'items': {'type': 'string'}}}, 'description': 'Optional buyer spend policy to evaluate against and to pin facilitators.'}, 'paymentPayload': {'description': 'The UNSIGNED EIP-3009 authorization the buyer is about to sign: { authorization|message: {from,to,value,validAfter,validBefore,nonce}, domain: {name,version,chainId,verifyingContract} }. Lets the audit bind the menu to the actual charge (server-enforced to/value/verifyingContract/chainId). Omit to vet requirements only - but then the verdict is never auto-settle-safe.'}, 'serverMetadata': {'description': 'Optional server metadata the caller already holds (context only; not fetched).'}, 'paymentRequirements': {'description': 'The x402 payment requirements from the counterparty: the 402 `accepts` array, or a single object.'}, 'selectedOptionIndex': {'type': 'number', 'description': 'Index in the accepts array the buyer intends to settle (default 0). The verdict is scoped to it.'}}}
Hinzugefügt
secret-scan
17. September 2026 12:36
Hinzugefügt
tool-call-guard
17. September 2026 12:36
Hinzugefügt
inject-guard
17. September 2026 12:36
Hinzugefügt
sign-guard
17. September 2026 12:36
Hinzugefügt
x402-trust-audit
17. September 2026 12:36
Hinzugefügt
pr-summary
17. September 2026 12:36
Hinzugefügt
secure-code-review
17. September 2026 12:36

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…