MCP 서버

Mnemom — Trust Ratings for AI Agents

io.github.mnemom/mnemom
AI 및 에이전트 보안 공개 · 연결 가능 MCP 2026-07-28

이 MCP로 할 수 있는 일

Maintains verifiable AI-agent identities, trust ratings, reputation attestations, signed website trust scans, and published alignment and protection manifests.

claim_agent
Claim a verifiable identity — bind an agent to your organization so its trust and accountability record is provably yours. No human in the loop.
입력 스키마
{'type': 'object', 'required': ['agent_id', 'hash_proof'], 'properties': {'org_id': {'type': 'string', 'description': "Optional. The organization to claim the agent into (e.g. `org-...` or `pers-...`). The caller must be a member of this org (role floor: member). If omitted, the agent is claimed into the caller's personal org."}, 'agent_id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123)'}, 'hash_proof': {'type': 'string', 'minLength': 16, 'description': "Agent possession proof — either the live birth token (`mnbt_…`) whose row pins this agent's hash, or the full 64-hex SHA-256 digest of `${apiKey}|${agentName}` (or `${apiKey}` for an unnamed singleton agent)."}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['claimed', 'agent_id', 'org_id', 'claimed_at'], 'properties': {'org_id': {'type': 'string', 'description': "The organization the agent was claimed into (echoes the resolved org — the supplied `org_id`, or the caller's personal org when omitted)."}, 'claimed': {'type': 'boolean'}, 'agent_id': {'type': 'string'}, 'claimed_at': {'type': 'string', 'format': 'date-time'}}}
get_agent
Look up an agent's public identity and trust state by ID — the accountable record other agents and humans can rely on.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123)'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123).'}, 'name': {'type': ['string', 'null'], 'description': 'Agent name (2-32 chars, alphanumeric + hyphens).'}, 'caller': {'enum': ['anonymous', 'authenticated', 'org_member'], 'type': 'string', 'description': 'Which projection THIS response is. `org_member` receives the owner field set; `anonymous`/`authenticated` receive the reduced public set (id, name, claimed, created_at, last_seen, status, avatar_url, caller). Read this instead of inferring why a field is absent.'}, 'groups': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'color'], 'properties': {'id': {'type': 'string'}, 'name': {'type': 'string'}, 'color': {'type': ['string', 'null'], 'description': 'Group color (hex, e.g. `#0d9488`); `null` when unset.'}}}, 'description': 'Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows.'}, 'org_id': {'type': ['string', 'null'], 'description': "The agent's organization binding. Required as an input by the org-scoped tools (fleet listing, posture assignment). Identifies an organization, not a person."}, 'public': {'type': 'boolean', 'description': "Whether the agent's identity record is publicly discoverable. Distinct from Trust Rating visibility, which is always public."}, 'status': {'enum': ['active', 'offline'], 'type': 'string', 'description': 'Derived from last_seen (active = seen within the last hour).'}, 'claimed': {'type': 'boolean', 'description': "Whether a human or organization has claimed accountability for this agent. On the owner projection this is derived from the ownership column; the owning user's identifier itself is not returned."}, 'last_seen': {'type': ['string', 'null'], 'format': 'date-time'}, 'agent_hash': {'type': 'string', 'description': 'The canonical public identity hash (first 16 hex chars) used as the gateway lookup key and as the input to verify_agent_binding. Owner projection only. Not a credential and not reversible to one.'}, 'avatar_url': {'type': ['string', 'null']}, 'claimed_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'containment_status': {'enum': ['active', 'paused', 'killed'], 'type': ['string', 'null'], 'description': 'Containment state of the agent.'}, 'aip_enforcement_mode': {'enum': ['observe', 'enforce', 'nudge'], 'type': ['string', 'null']}}, 'description': "An agent's identity and trust state, reduced to the fields the trust loop needs. Personal data (owner email address, user identifiers), internal commercial identifiers (billing account) and key-material-derived values (bound-key proof hash, key prefix) are REMOVED at the MCP boundary and are never returned to an MCP client — see the Mnemom privacy policy at https://www.mnemom.ai/privacy. Which fields are present depends on authorization: read `caller` to know which projection you received.", 'additionalProperties': False}
get_reputation
Look up an AI agent's published Trust Rating — Mnemom's portable reliability signal for autonomous software, computed from the agent's own verified activity record. Returns the rating plus the technical factors behind it. Free, public, read-only: every registered agent's rating is published by standard (the `visibility` field is the reputation-publication axis, distinct from identity-record visibility).
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123)'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', '$defs': {'ReputationScore': {'type': 'object', 'required': ['agent_id', 'score', 'grade', 'is_eligible', 'checkpoint_count', 'confidence', 'components', 'visibility'], 'properties': {'tier': {'type': ['string', 'null']}, 'grade': {'type': ['string', 'null'], 'description': 'AAA–D or NR.'}, 'score': {'type': ['integer', 'null'], 'maximum': 1000, 'minimum': 0}, 'claimed': {'type': 'boolean'}, 'agent_id': {'type': 'string'}, 'trend_30d': {'type': ['number', 'null']}, 'agent_name': {'type': ['string', 'null']}, 'components': {'type': 'array', 'items': {'type': 'object', 'required': ['key', 'score', 'weight', 'weighted_score'], 'properties': {'key': {'enum': ['integrity_ratio', 'compliance', 'drift_stability', 'trace_completeness', 'coherence_compatibility'], 'type': 'string'}, 'label': {'type': 'string'}, 'score': {'type': 'number'}, 'weight': {'type': 'number'}, 'factors': {'type': 'array'}, 'weighted_score': {'type': 'number'}}}}, 'confidence': {'enum': ['insufficient', 'low', 'medium', 'high'], 'type': 'string'}, 'visibility': {'enum': ['public', 'private'], 'type': 'string', 'description': 'Reputation-publication axis — whether this agent\'s Trust Rating is published. Every registered agent\'s reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word "public" but govern different things.'}, 'computed_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'is_eligible': {'type': 'boolean'}, 'next_compute_at': {'type': ['string', 'null'], 'format': 'date-time', 'description': 'Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.'}, 'checkpoint_count': {'type': 'integer'}, 'a2a_trust_extension': {'type': 'object', 'properties': {'grade': {'type': 'string'}, 'score': {'type': 'number'}, 'provider': {'type': 'string'}, 'badge_url': {'type': 'string', 'format': 'uri'}, 'confidence': {'type': 'string'}, 'last_updated': {'type': 'string', 'format': 'date-time'}, 'verified_url': {'type': 'string', 'format': 'uri'}, 'extension_uri': {'type': 'string'}, 'methodology_url': {'type': 'string', 'format': 'uri'}}, 'description': 'A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).'}, 'checkpoint_accounting': {'type': ['object', 'null'], 'required': ['total', 'analyzed', 'excluded'], 'properties': {'total': {'type': 'integer', 'description': 'All checkpoints recorded for the agent.'}, 'analyzed': {'type': 'integer', 'description': 'Checkpoints that counted toward the score (drives the X/50 eligibility gauge).'}, 'excluded': {'type': 'object', 'required': ['synthetic', 'insufficient_thinking', 'quarantined'], 'properties': {'synthetic': {'type': 'integer', 'description': 'Synthetic (`ic-synthetic-*`) checkpoints.'}, 'quarantined': {'type': 'integer', 'description': 'Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.'}, 'insufficient_thinking': {'type': 'integer', 'description': 'Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).'}}}, 're_evaluated': {'type': 'object', 'required': ['corrected_clear', 'corrected_non_clear', 'resolved_no_correction'], 'properties': {'corrected_clear': {'type': 'integer', 'description': "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`)."}, 'corrected_non_clear': {'type': 'integer', 'description': "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation."}, 'resolved_no_correction': {'type': 'integer', 'description': 'Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.'}}, 'description': "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed."}}, 'description': 'Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.'}}, 'description': "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000."}}, 'required': ['agent_id', 'score', 'grade', 'is_eligible', 'checkpoint_count', 'confidence', 'components', 'visibility'], 'properties': {'tier': {'type': ['string', 'null']}, 'grade': {'type': ['string', 'null'], 'description': 'AAA–D or NR.'}, 'score': {'type': ['integer', 'null'], 'maximum': 1000, 'minimum': 0}, 'claimed': {'type': 'boolean'}, 'agent_id': {'type': 'string'}, 'trend_30d': {'type': ['number', 'null']}, 'agent_name': {'type': ['string', 'null']}, 'components': {'type': 'array', 'items': {'type': 'object', 'required': ['key', 'score', 'weight', 'weighted_score'], 'properties': {'key': {'enum': ['integrity_ratio', 'compliance', 'drift_stability', 'trace_completeness', 'coherence_compatibility'], 'type': 'string'}, 'label': {'type': 'string'}, 'score': {'type': 'number'}, 'weight': {'type': 'number'}, 'factors': {'type': 'array'}, 'weighted_score': {'type': 'number'}}}}, 'confidence': {'enum': ['insufficient', 'low', 'medium', 'high'], 'type': 'string'}, 'visibility': {'enum': ['public', 'private'], 'type': 'string', 'description': 'Reputation-publication axis — whether this agent\'s Trust Rating is published. Every registered agent\'s reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word "public" but govern different things.'}, 'computed_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'is_eligible': {'type': 'boolean'}, 'next_compute_at': {'type': ['string', 'null'], 'format': 'date-time', 'description': 'Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.'}, 'checkpoint_count': {'type': 'integer'}, 'a2a_trust_extension': {'type': 'object', 'properties': {'grade': {'type': 'string'}, 'score': {'type': 'number'}, 'provider': {'type': 'string'}, 'badge_url': {'type': 'string', 'format': 'uri'}, 'confidence': {'type': 'string'}, 'last_updated': {'type': 'string', 'format': 'date-time'}, 'verified_url': {'type': 'string', 'format': 'uri'}, 'extension_uri': {'type': 'string'}, 'methodology_url': {'type': 'string', 'format': 'uri'}}, 'description': 'A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).'}, 'checkpoint_accounting': {'type': ['object', 'null'], 'required': ['total', 'analyzed', 'excluded'], 'properties': {'total': {'type': 'integer', 'description': 'All checkpoints recorded for the agent.'}, 'analyzed': {'type': 'integer', 'description': 'Checkpoints that counted toward the score (drives the X/50 eligibility gauge).'}, 'excluded': {'type': 'object', 'required': ['synthetic', 'insufficient_thinking', 'quarantined'], 'properties': {'synthetic': {'type': 'integer', 'description': 'Synthetic (`ic-synthetic-*`) checkpoints.'}, 'quarantined': {'type': 'integer', 'description': 'Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.'}, 'insufficient_thinking': {'type': 'integer', 'description': 'Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).'}}}, 're_evaluated': {'type': 'object', 'required': ['corrected_clear', 'corrected_non_clear', 'resolved_no_correction'], 'properties': {'corrected_clear': {'type': 'integer', 'description': "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`)."}, 'corrected_non_clear': {'type': 'integer', 'description': "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation."}, 'resolved_no_correction': {'type': 'integer', 'description': 'Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.'}}, 'description': "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed."}}, 'description': 'Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.'}}, 'description': "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000."}
get_reputation_badge
Get an embeddable Trust Rating badge for an agent — returns the badge image URL plus ready-to-paste Markdown and HTML snippets for a README or agent card.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123)'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['agent_id', 'badge_url', 'verified_url', 'profile_url', 'markdown_embed', 'html_embed'], 'properties': {'agent_id': {'type': 'string', 'description': 'The agent the badge is for (echoed from the request).'}, 'badge_url': {'type': 'string', 'format': 'uri', 'description': 'Canonical SVG Trust Rating badge image URL (always on api.mnemom.ai).'}, 'html_embed': {'type': 'string', 'description': 'Paste-ready HTML badge snippet.'}, 'profile_url': {'type': 'string', 'format': 'uri', 'description': 'Human-readable reputation profile page (on www.mnemom.ai).'}, 'verified_url': {'type': 'string', 'format': 'uri', 'description': 'Public cryptographic verification URL for the rating.'}, 'markdown_embed': {'type': 'string', 'description': 'Paste-ready Markdown badge snippet.'}}, 'additionalProperties': False}
get_started
Zero-auth, no-args orientation: who Mnemom is, the surface map, how to authenticate and what it unlocks, and the value tools to try right now (headlining scan_trust + the reputation reads).
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'token': {'type': 'string', 'description': 'Optional Dojo try-me invite token. When supplied and valid, returns the token-gated dojo briefing manifest (the same content as GET /v1/dojo/try-me/resolve); omit for public orientation.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['who', 'value_prop', 'try_now', 'authenticate', 'skill_path', 'sovereignty_path', 'developer_path', 'surface_map', 'showcase_agent', 'visibility_model', 'what_we_keep_private_and_why', 'verify', 'doctrine'], 'properties': {'who': {'type': 'string', 'description': 'One-line positioning.'}, 'verify': {'type': 'string', 'description': "How to verify signed artifacts in-band (verify, don't trust)."}, 'try_now': {'type': 'array', 'items': {'type': 'object', 'required': ['tool', 'what'], 'properties': {'args': {'type': 'object', 'additionalProperties': True}, 'tool': {'type': 'string'}, 'what': {'type': 'string'}}, 'additionalProperties': False}, 'description': 'Zero-auth value tools to call right now.'}, 'doctrine': {'type': 'string'}, 'skill_path': {'type': 'object', 'required': ['narrative', 'steps'], 'properties': {'steps': {'type': 'array', 'items': {'type': 'object', 'required': ['step', 'tool', 'auth', 'what'], 'properties': {'auth': {'enum': ['none', 'required'], 'type': 'string'}, 'step': {'type': 'integer'}, 'tool': {'type': 'string'}, 'what': {'type': 'string'}}, 'additionalProperties': False}}, 'narrative': {'type': 'string'}}, 'description': 'The two-step on-ramp to declaring and advertising capabilities as A2A skills in a signed, portable AgentCard.', 'additionalProperties': False}, 'value_prop': {'type': 'string', 'description': 'What Mnemom does for an agent.'}, 'surface_map': {'type': 'object', 'description': 'Stable links to the canonical read-only surfaces.', 'additionalProperties': True}, 'authenticate': {'type': 'object', 'required': ['methods', 'unlocks', 'discovery', 'headless'], 'properties': {'methods': {'type': 'array', 'items': {'type': 'string'}}, 'unlocks': {'type': 'array', 'items': {'type': 'string'}}, 'headless': {'type': 'object', 'required': ['when', 'use', 'grant_type', 'discovery', 'steps'], 'properties': {'use': {'type': 'string'}, 'note': {'type': 'string'}, 'when': {'type': 'string'}, 'steps': {'type': 'array', 'items': {'type': 'string'}}, 'discovery': {'type': 'string', 'format': 'uri'}, 'grant_type': {'type': 'string'}}, 'description': "The headless/cloud write-auth fallback (MNE-1392): when your host has no local browser and the standard OAuth redirect can't complete, drive the RFC 8628 Device Authorization Grant yourself.", 'additionalProperties': False}, 'discovery': {'type': 'string', 'format': 'uri'}}, 'description': 'How to authenticate and what auth unlocks.', 'additionalProperties': False}, 'developer_path': {'type': 'object', 'required': ['narrative', 'npx', 'prompt_skills', 'note'], 'properties': {'npx': {'type': 'object', 'required': ['command', 'what'], 'properties': {'what': {'type': 'string'}, 'command': {'type': 'string'}}, 'additionalProperties': False}, 'note': {'type': 'string'}, 'narrative': {'type': 'string'}, 'prompt_skills': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'what'], 'properties': {'name': {'type': 'string'}, 'what': {'type': 'string'}}, 'additionalProperties': False}}}, 'description': 'The developer hero on-ramp: the npx one-liner plus the intent-named MCP prompt-skills (try-me, onboard_an_agent, become_sovereign). Advertisement only — no functional dependency on those prompts existing yet.', 'additionalProperties': False}, 'showcase_agent': {'type': 'object', 'required': ['agent_id', 'why'], 'properties': {'why': {'type': 'string'}, 'agent_id': {'type': 'string'}}, 'description': 'A real Mnemom-owned agent the try_now reputation reads target, so the loop runs verbatim.', 'additionalProperties': False}, 'sovereignty_path': {'type': 'object', 'required': ['narrative', 'prompt', 'steps'], 'properties': {'steps': {'type': 'array', 'items': {'type': 'object', 'required': ['step', 'tool', 'auth', 'what'], 'properties': {'auth': {'enum': ['none', 'required'], 'type': 'string'}, 'step': {'type': 'integer'}, 'tool': {'type': 'string'}, 'what': {'type': 'string'}}, 'additionalProperties': False}}, 'prompt': {'type': 'string', 'description': 'The MCP prompt that walks this journey.'}, 'narrative': {'type': 'string'}}, 'description': 'The five-step on-ramp to becoming a sovereign, accountable agent, composed from existing tools. Walked end to end by the become_sovereign MCP prompt.', 'additionalProperties': False}, 'visibility_model': {'type': 'object', 'required': ['note', 'reputation_visibility', 'identity_record_visibility', 'caller_context'], 'properties': {'note': {'type': 'string'}, 'caller_context': {'type': 'string'}, 'reputation_visibility': {'type': 'string'}, 'identity_record_visibility': {'type': 'string'}}, 'description': "Disambiguates the two axes that share the word 'public': reputation-publication visibility (public by standard) vs identity-record visibility (agent.public), plus the caller-context self-description.", 'additionalProperties': False}, 'what_we_keep_private_and_why': {'type': 'string'}}, 'additionalProperties': False}
list_agents
List your agents — List all agents owned by the authenticated user. Supports pagination.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 50, 'maximum': 100, 'minimum': 1, 'description': 'How many agents to return, 1-100.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 100000, 'minimum': 0, 'description': 'How many agents to skip, for pagination.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', '$defs': {'AgentMcpRecord': {'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123).'}, 'name': {'type': ['string', 'null'], 'description': 'Agent name (2-32 chars, alphanumeric + hyphens).'}, 'caller': {'enum': ['anonymous', 'authenticated', 'org_member'], 'type': 'string', 'description': 'Which projection THIS response is. `org_member` receives the owner field set; `anonymous`/`authenticated` receive the reduced public set (id, name, claimed, created_at, last_seen, status, avatar_url, caller). Read this instead of inferring why a field is absent.'}, 'groups': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'color'], 'properties': {'id': {'type': 'string'}, 'name': {'type': 'string'}, 'color': {'type': ['string', 'null'], 'description': 'Group color (hex, e.g. `#0d9488`); `null` when unset.'}}}, 'description': 'Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows.'}, 'org_id': {'type': ['string', 'null'], 'description': "The agent's organization binding. Required as an input by the org-scoped tools (fleet listing, posture assignment). Identifies an organization, not a person."}, 'public': {'type': 'boolean', 'description': "Whether the agent's identity record is publicly discoverable. Distinct from Trust Rating visibility, which is always public."}, 'status': {'enum': ['active', 'offline'], 'type': 'string', 'description': 'Derived from last_seen (active = seen within the last hour).'}, 'claimed': {'type': 'boolean', 'description': "Whether a human or organization has claimed accountability for this agent. On the owner projection this is derived from the ownership column; the owning user's identifier itself is not returned."}, 'last_seen': {'type': ['string', 'null'], 'format': 'date-time'}, 'agent_hash': {'type': 'string', 'description': 'The canonical public identity hash (first 16 hex chars) used as the gateway lookup key and as the input to verify_agent_binding. Owner projection only. Not a credential and not reversible to one.'}, 'avatar_url': {'type': ['string', 'null']}, 'claimed_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'containment_status': {'enum': ['active', 'paused', 'killed'], 'type': ['string', 'null'], 'description': 'Containment state of the agent.'}, 'aip_enforcement_mode': {'enum': ['observe', 'enforce', 'nudge'], 'type': ['string', 'null']}}, 'description': "An agent's identity and trust state, reduced to the fields the trust loop needs. Personal data (owner email address, user identifiers), internal commercial identifiers (billing account) and key-material-derived values (bound-key proof hash, key prefix) are REMOVED at the MCP boundary and are never returned to an MCP client — see the Mnemom privacy policy at https://www.mnemom.ai/privacy. Which fields are present depends on authorization: read `caller` to know which projection you received.", 'additionalProperties': False}}, 'required': ['agents', 'scope'], 'properties': {'scope': {'enum': ['active', 'all'], 'type': 'string', 'description': 'Echoes the resolved listing scope.'}, 'agents': {'type': 'array', 'items': {'$ref': '#/$defs/AgentMcpRecord'}, 'description': "The caller's agents, reduced to the MCP trust-loop field set."}}, 'additionalProperties': False}
preview_compose_alignment_by_agent
Preview composed alignment (dry run) — Composes the cascade against a hypothetical body at the agent layer and returns conflicts + the composed view. No DB writes. Used by the dashboard editor for live conflict markers.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id', 'card_version', 'autonomy_mode', 'integrity_mode', 'principal', 'values', 'autonomy', 'audit'], 'properties': {'audit': {'type': 'object', 'required': ['retention_days', 'queryable'], 'properties': {'queryable': {'type': 'boolean', 'default': False, 'description': 'Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint.'}, 'query_endpoint': {'type': 'string', 'maxLength': 300, 'description': 'HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false.'}, 'retention_days': {'type': 'integer', 'maximum': 3650, 'minimum': 0, 'description': "How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum."}, 'tamper_evidence': {'enum': ['append_only', 'signed', 'merkle'], 'type': 'string', 'description': 'Tamper-evidence scheme applied to the retained records.'}}, 'description': "How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)", 'additionalProperties': False}, 'values': {'type': 'object', 'required': ['declared'], 'properties': {'declared': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 32, 'minItems': 1, 'description': 'Value catalog IDs — e.g. ["honesty", "no_harm", "privacy"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)'}}, 'description': 'The values this agent declares it is bound by. Required.', 'additionalProperties': False}, 'agent_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.'}, 'autonomy': {'type': 'object', 'required': ['bounded_actions'], 'properties': {'bounded_actions': {'type': 'array', 'items': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'maxItems': 64, 'minItems': 1, 'description': 'Action names the agent may take within its bounds — e.g. ["send_email", "create_ticket"]. At least one required. Action identifiers only, not descriptions.'}, 'forbidden_actions': {'type': 'array', 'items': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'maxItems': 64, 'description': 'Action names the agent must never take. Must be disjoint from `bounded_actions`.'}, 'escalation_triggers': {'type': 'array', 'items': {'type': 'object', 'required': ['condition', 'action', 'reason'], 'properties': {'action': {'enum': ['escalate', 'deny', 'log'], 'type': 'string', 'description': 'What to do when the condition holds.'}, 'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'condition': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'The condition, as a short expression or slug (e.g. "amount > 1000"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}}, 'additionalProperties': False}, 'maxItems': 32, 'description': 'Conditions that route to a human instead of acting.'}}, 'description': 'What the agent may do on its own authority. Required.', 'additionalProperties': False}, 'principal': {'type': 'object', 'required': ['type', 'relationship', 'identifier'], 'properties': {'type': {'enum': ['human', 'organization', 'agent', 'unspecified'], 'type': 'string', 'description': 'The kind of principal the agent answers to.'}, 'identifier': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Who the principal is. Use a ROLE or ORGANIZATION name ("support-team", "Acme Corp Finance"), NOT an individual\'s name, email address or phone number. Pass "unspecified" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}, 'relationship': {'enum': ['delegated_authority', 'advisory', 'autonomous'], 'type': 'string', 'description': 'How the agent relates to that principal.'}, 'escalation_contact': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX ("oncall-sre", "security@example.com"), never an individual\'s personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}}, 'description': 'Whose authority this agent acts under. Required.', 'additionalProperties': False}, 'card_version': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$', 'maxLength': 40, 'minLength': 3, 'description': 'Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`.'}, 'autonomy_mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks.'}, 'integrity_mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Master switch for the values pipeline. Required. Same four states as `autonomy_mode`.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['ok', 'composition_valid', 'conflicts_count', 'summary'], 'properties': {'ok': {'type': 'boolean', 'description': 'True when composition succeeded (no blocking conflicts).'}, 'summary': {'type': 'string', 'description': 'One-line human-readable summary of composition status.'}, 'full_report': {'oneOf': [{'type': 'null'}, {'type': 'object', 'required': ['method', 'path', 'note'], 'properties': {'note': {'type': 'string'}, 'path': {'type': 'string'}, 'method': {'type': 'string'}}, 'additionalProperties': False}], 'description': 'Optional pointer to the full /v1 conflict report (method + path).'}, 'conflicts_count': {'type': 'integer', 'description': 'Total number of conflicts detected (0 = none).'}, 'composition_valid': {'type': 'boolean', 'description': 'True when the composed card is coherence-valid.'}}, 'additionalProperties': False}
preview_compose_protection_by_agent
Preview composed protection (dry run) — Composes the cascade against a hypothetical body at the agent layer and returns conflicts + the composed view. No DB writes. Used by the dashboard editor for live conflict markers.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id', 'card_version', 'mode'], 'properties': {'mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks.'}, 'agent_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.'}, 'thresholds': {'type': 'object', 'required': ['warn', 'quarantine', 'block'], 'properties': {'warn': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is flagged.'}, 'block': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is refused.'}, 'quarantine': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is held for review.'}}, 'description': 'Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. All three are required if this object is sent at all — omit the whole object to accept the composed defaults.', 'additionalProperties': False}, 'card_version': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$', 'maxLength': 40, 'minLength': 3, 'description': 'Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`.'}, 'screen_surfaces': {'type': 'object', 'properties': {'incoming': {'type': 'boolean', 'description': 'Screen prompts arriving at the agent.'}, 'outgoing': {'type': 'boolean', 'description': "Screen the agent's outbound messages."}, 'tool_calls': {'type': 'boolean', 'description': 'Screen the tool calls the agent makes.'}, 'tool_responses': {'type': 'boolean', 'description': 'Screen tool responses returned to the agent.'}}, 'description': 'Which traffic surfaces are screened. Omit to accept the composed defaults.', 'additionalProperties': False}, 'trusted_sources': {'type': 'object', 'properties': {'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 3}, 'maxItems': 64, 'description': 'Trusted DNS names, optionally with `:port`. No wildcards.'}, 'agent_ids': {'type': 'array', 'items': {'type': 'string', 'pattern': '^mnm-[A-Za-z0-9-]{4,}$', 'maxLength': 64, 'minLength': 8}, 'maxItems': 64, 'description': 'Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form.'}, 'ip_ranges': {'type': 'array', 'items': {'type': 'string', 'maxLength': 43, 'minLength': 4}, 'maxItems': 64, 'description': 'Trusted CIDR ranges (e.g. `10.0.0.0/8`).'}}, 'description': 'Sources exempt from screening. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.', 'additionalProperties': False}, 'protected_surface': {'type': 'object', 'properties': {'assets': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'selector'], 'properties': {'kind': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Asset class — e.g. "repo", "database", "bucket".'}, 'label': {'type': 'string', 'maxLength': 120, 'minLength': 1, 'description': 'Short human-readable name for the asset.'}, 'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'selector': {'type': 'string', 'maxLength': 256, 'minLength': 1, 'description': 'Which instance — e.g. "mnemom/mnemom-api". A resource identifier only: no credentials, no connection strings, no personal data.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'The assets under protection.'}, 'escalation_required': {'type': 'array', 'items': {'type': 'object', 'required': ['pattern'], 'properties': {'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'pattern': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Operation matcher — e.g. "force_push", "drop_table*". A short pattern, not a description.'}, 'applies_to': {'type': 'array', 'items': {'type': 'string', 'maxLength': 256, 'minLength': 1}, 'maxItems': 64, 'description': 'Asset identities this entry applies to. Omit to apply to every protected asset.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'Operations that require human approval before the agent may proceed.'}, 'forbidden_operations': {'type': 'array', 'items': {'type': 'object', 'required': ['pattern'], 'properties': {'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'pattern': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Operation matcher — e.g. "force_push", "drop_table*". A short pattern, not a description.'}, 'severity': {'enum': ['low', 'medium', 'high', 'critical'], 'type': 'string', 'description': 'How serious a violation of this entry is.'}, 'applies_to': {'type': 'array', 'items': {'type': 'string', 'maxLength': 256, 'minLength': 1}, 'maxItems': 64, 'description': 'Asset identities this entry applies to. Omit to apply to every protected asset.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'Operations the agent must never perform on the protected assets.'}}, 'description': 'The assets and operations this agent must protect. Omit to accept the composed default (empty surface).', 'additionalProperties': False}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['ok', 'composition_valid', 'conflicts_count', 'summary'], 'properties': {'ok': {'type': 'boolean', 'description': 'True when composition succeeded (no blocking conflicts).'}, 'summary': {'type': 'string', 'description': 'One-line human-readable summary of composition status.'}, 'full_report': {'oneOf': [{'type': 'null'}, {'type': 'object', 'required': ['method', 'path', 'note'], 'properties': {'note': {'type': 'string'}, 'path': {'type': 'string'}, 'method': {'type': 'string'}}, 'additionalProperties': False}], 'description': 'Optional pointer to the full /v1 conflict report (method + path).'}, 'conflicts_count': {'type': 'integer', 'description': 'Total number of conflicts detected (0 = none).'}, 'composition_valid': {'type': 'boolean', 'description': 'True when the composed card is valid.'}}, 'additionalProperties': False}
put_alignment_by_agent
Publish or replace the alignment manifest — Accepts YAML (`text/yaml`, `application/yaml`) or JSON. Body is the full `UnifiedAlignmentCard`; server-side composition merges it across the platform → org → team → agent cascade and writes the canonical composed card. Requires `Idempotency-Key`. Honor...
파괴적 작업 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id', 'card_version', 'autonomy_mode', 'integrity_mode', 'principal', 'values', 'autonomy', 'audit'], 'properties': {'audit': {'type': 'object', 'required': ['retention_days', 'queryable'], 'properties': {'queryable': {'type': 'boolean', 'default': False, 'description': 'Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint.'}, 'query_endpoint': {'type': 'string', 'maxLength': 300, 'description': 'HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false.'}, 'retention_days': {'type': 'integer', 'maximum': 3650, 'minimum': 0, 'description': "How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum."}, 'tamper_evidence': {'enum': ['append_only', 'signed', 'merkle'], 'type': 'string', 'description': 'Tamper-evidence scheme applied to the retained records.'}}, 'description': "How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)", 'additionalProperties': False}, 'values': {'type': 'object', 'required': ['declared'], 'properties': {'declared': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 32, 'minItems': 1, 'description': 'Value catalog IDs — e.g. ["honesty", "no_harm", "privacy"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)'}}, 'description': 'The values this agent declares it is bound by. Required.', 'additionalProperties': False}, 'agent_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.'}, 'autonomy': {'type': 'object', 'required': ['bounded_actions'], 'properties': {'bounded_actions': {'type': 'array', 'items': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'maxItems': 64, 'minItems': 1, 'description': 'Action names the agent may take within its bounds — e.g. ["send_email", "create_ticket"]. At least one required. Action identifiers only, not descriptions.'}, 'forbidden_actions': {'type': 'array', 'items': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'maxItems': 64, 'description': 'Action names the agent must never take. Must be disjoint from `bounded_actions`.'}, 'escalation_triggers': {'type': 'array', 'items': {'type': 'object', 'required': ['condition', 'action', 'reason'], 'properties': {'action': {'enum': ['escalate', 'deny', 'log'], 'type': 'string', 'description': 'What to do when the condition holds.'}, 'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'condition': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'The condition, as a short expression or slug (e.g. "amount > 1000"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}}, 'additionalProperties': False}, 'maxItems': 32, 'description': 'Conditions that route to a human instead of acting.'}}, 'description': 'What the agent may do on its own authority. Required.', 'additionalProperties': False}, 'principal': {'type': 'object', 'required': ['type', 'relationship', 'identifier'], 'properties': {'type': {'enum': ['human', 'organization', 'agent', 'unspecified'], 'type': 'string', 'description': 'The kind of principal the agent answers to.'}, 'identifier': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Who the principal is. Use a ROLE or ORGANIZATION name ("support-team", "Acme Corp Finance"), NOT an individual\'s name, email address or phone number. Pass "unspecified" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}, 'relationship': {'enum': ['delegated_authority', 'advisory', 'autonomous'], 'type': 'string', 'description': 'How the agent relates to that principal.'}, 'escalation_contact': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX ("oncall-sre", "security@example.com"), never an individual\'s personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent\'s governance card and is readable by everyone in the owning organization.'}}, 'description': 'Whose authority this agent acts under. Required.', 'additionalProperties': False}, 'card_version': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$', 'maxLength': 40, 'minLength': 3, 'description': 'Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`.'}, 'autonomy_mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks.'}, 'integrity_mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Master switch for the values pipeline. Required. Same four states as `autonomy_mode`.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['card_id', 'issued_at', 'ok'], 'properties': {'ok': {'type': 'boolean', 'const': True, 'description': 'Always true on successful storage (errors return non-200 status).'}, 'card_id': {'type': 'string', 'pattern': '^ac-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'description': 'Card ID (ac-{uuid}) of the stored alignment card.'}, 'issued_at': {'type': 'string', 'format': 'date-time', 'description': 'ISO 8601 timestamp when the card was issued/stored.'}}, 'additionalProperties': False}
put_protection_by_agent
Publish or replace an agent's protection card (screening mode, thresholds, trusted sources, protected assets). When connected by OAuth sign-in (e.g. ChatGPT), each publish first needs a one-time grant from the same signed-in account: open https://www.mnemom.ai/authorize-protection?agent_id=<agent_id>, approve, then publish within 15 minutes (each grant covers one publish). Only agent_id, card_version and mode are required; mode `enforce` also needs Safe House on the organization. Use preview_compose_protection_by_agent to dry-run without a grant.
파괴적 작업 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id', 'card_version', 'mode'], 'properties': {'mode': {'enum': ['off', 'observe', 'nudge', 'enforce'], 'type': 'string', 'description': 'Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks.'}, 'agent_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.'}, 'thresholds': {'type': 'object', 'required': ['warn', 'quarantine', 'block'], 'properties': {'warn': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is flagged.'}, 'block': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is refused.'}, 'quarantine': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Score at or above which the request is held for review.'}}, 'description': 'Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. All three are required if this object is sent at all — omit the whole object to accept the composed defaults.', 'additionalProperties': False}, 'card_version': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$', 'maxLength': 40, 'minLength': 3, 'description': 'Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`.'}, 'screen_surfaces': {'type': 'object', 'properties': {'incoming': {'type': 'boolean', 'description': 'Screen prompts arriving at the agent.'}, 'outgoing': {'type': 'boolean', 'description': "Screen the agent's outbound messages."}, 'tool_calls': {'type': 'boolean', 'description': 'Screen the tool calls the agent makes.'}, 'tool_responses': {'type': 'boolean', 'description': 'Screen tool responses returned to the agent.'}}, 'description': 'Which traffic surfaces are screened. Omit to accept the composed defaults.', 'additionalProperties': False}, 'trusted_sources': {'type': 'object', 'properties': {'domains': {'type': 'array', 'items': {'type': 'string', 'maxLength': 253, 'minLength': 3}, 'maxItems': 64, 'description': 'Trusted DNS names, optionally with `:port`. No wildcards.'}, 'agent_ids': {'type': 'array', 'items': {'type': 'string', 'pattern': '^mnm-[A-Za-z0-9-]{4,}$', 'maxLength': 64, 'minLength': 8}, 'maxItems': 64, 'description': 'Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form.'}, 'ip_ranges': {'type': 'array', 'items': {'type': 'string', 'maxLength': 43, 'minLength': 4}, 'maxItems': 64, 'description': 'Trusted CIDR ranges (e.g. `10.0.0.0/8`).'}}, 'description': 'Sources exempt from screening. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.', 'additionalProperties': False}, 'protected_surface': {'type': 'object', 'properties': {'assets': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'selector'], 'properties': {'kind': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Asset class — e.g. "repo", "database", "bucket".'}, 'label': {'type': 'string', 'maxLength': 120, 'minLength': 1, 'description': 'Short human-readable name for the asset.'}, 'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'selector': {'type': 'string', 'maxLength': 256, 'minLength': 1, 'description': 'Which instance — e.g. "mnemom/mnemom-api". A resource identifier only: no credentials, no connection strings, no personal data.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'The assets under protection.'}, 'escalation_required': {'type': 'array', 'items': {'type': 'object', 'required': ['pattern'], 'properties': {'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'pattern': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Operation matcher — e.g. "force_push", "drop_table*". A short pattern, not a description.'}, 'applies_to': {'type': 'array', 'items': {'type': 'string', 'maxLength': 256, 'minLength': 1}, 'maxItems': 64, 'description': 'Asset identities this entry applies to. Omit to apply to every protected asset.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'Operations that require human approval before the agent may proceed.'}, 'forbidden_operations': {'type': 'array', 'items': {'type': 'object', 'required': ['pattern'], 'properties': {'reason': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'pattern': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Operation matcher — e.g. "force_push", "drop_table*". A short pattern, not a description.'}, 'severity': {'enum': ['low', 'medium', 'high', 'critical'], 'type': 'string', 'description': 'How serious a violation of this entry is.'}, 'applies_to': {'type': 'array', 'items': {'type': 'string', 'maxLength': 256, 'minLength': 1}, 'maxItems': 64, 'description': 'Asset identities this entry applies to. Omit to apply to every protected asset.'}}, 'additionalProperties': False}, 'maxItems': 64, 'description': 'Operations the agent must never perform on the protected assets.'}}, 'description': 'The assets and operations this agent must protect. Omit to accept the composed default (empty surface).', 'additionalProperties': False}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['card_id', 'issued_at', 'ok'], 'properties': {'ok': {'type': 'boolean', 'const': True, 'description': 'Always true on successful storage (errors return non-200 status).'}, 'card_id': {'type': 'string', 'pattern': '^pc-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'description': 'Card ID (pc-{uuid}) of the stored protection card.'}, 'issued_at': {'type': 'string', 'format': 'date-time', 'description': 'ISO 8601 timestamp when the card was issued/stored.'}}, 'additionalProperties': False}
report_recipe_fn_fp
Submit a false-positive / false-negative correction for one of Mnemom's automated detection rules (a 'recipe') — technical feedback that improves detection accuracy, like filing a bug report against a spam filter.
입력 스키마
{'type': 'object', 'required': ['recipeId', 'type', 'summary'], 'properties': {'type': {'enum': ['fn', 'fp'], 'type': 'string', 'description': '`fn` = false negative (the recipe should have fired). `fp` = false positive (it fired on legitimate behaviour).'}, 'summary': {'type': 'string', 'maxLength': 500, 'minLength': 1, 'description': "A short description of what the recipe got wrong — what it flagged, or what it missed, and why that was incorrect. DESCRIBE the misfire; do NOT paste the conversation, the prompt, the raw payload or the log that triggered it. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}, 'agent_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'Optional. The agent the report concerns. Identifier only.'}, 'recipeId': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'The detection recipe the report is filed against (the one that misfired or failed to fire). Identifier only.'}, 'checkpoint_id': {'type': 'string', 'pattern': '^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$', 'maxLength': 64, 'minLength': 3, 'description': 'Optional. The related integrity checkpoint, so the reviewer can correlate. Identifier only.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['ok', 'candidate_id', 'type', 'related_recipe_id'], 'properties': {'ok': {'enum': [True], 'type': 'boolean'}, 'type': {'enum': ['fn', 'fp'], 'type': 'string'}, 'candidate_id': {'type': 'string'}, 'related_recipe_id': {'type': 'string'}}}
scan_trust
Scan a website's agent-trust-readiness and return a signed scorecard (Trust, plus an Access axis on newer rubrics). Zero-auth. Results are CACHED for up to 24h — check `cached` and `scannedAt` on the result; pass `fresh: true` to force a re-scan (rate-limited). Proxies to the SSRF-locked isittrustready scanner; the Ed25519 signature + permalink are preserved verbatim. Rubric + docs: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.
읽기 전용 외부 접근 가능 멱등성
입력 스키마
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Domain or URL to scan, e.g. "example.com" or "https://example.com".'}, 'fresh': {'type': 'boolean', 'description': "Force a fresh re-scan instead of the cached result (results are cached up to 24h; the engine rate-limits re-scans). Equivalent to the scanner's rescan flag."}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['schema', 'target', 'score', 'grade', 'signature'], 'properties': {'grade': {'type': 'string', 'description': 'Trust letter grade (A+…F).'}, 'score': {'type': 'number', 'description': '0–100 weighted overall TRUST score.'}, 'access': {'type': 'object', 'properties': {'axis': {'type': 'string', 'description': 'Always "access".'}, 'grade': {'type': 'string', 'description': 'Access letter grade (A+…F).'}, 'score': {'type': 'number', 'description': '0–100 weighted Access/discoverability score (independent of Trust).'}, 'version': {'type': 'string', 'description': 'Access-axis rubric version this sub-score was computed against.'}, 'applicable': {'type': 'boolean', 'description': 'False when the site declares Access N/A.'}, 'categories': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Per-category Access scores + checks.'}}, 'description': 'The independent Access/discoverability axis (never blended with Trust). Present from the two-axis rubric (0.3.0+).', 'additionalProperties': True}, 'cached': {'type': 'boolean', 'description': "True when served from the scanner's 24h cache rather than a fresh scan."}, 'schema': {'type': 'string', 'description': 'iitr-scan schema version string (e.g. "iitr-scan/v0.N").'}, 'target': {'type': 'string', 'description': 'Normalized host that was scanned.'}, 'permalink': {'type': 'string', 'format': 'uri', 'description': 'Shareable /r/ permalink (only on /r/ responses; transport field).'}, 'scannedAt': {'type': 'string', 'format': 'date-time', 'description': 'When this scorecard was produced. Results are cached up to 24h — pass fresh:true to scan_trust to force a re-scan.'}, 'signature': {'type': 'object', 'properties': {'alg': {'type': 'string', 'description': 'Always "Ed25519".'}, 'value': {'type': 'string', 'description': 'base64 signature.'}, 'signedAt': {'type': 'string', 'format': 'date-time', 'description': 'When the scorecard was signed.'}, 'publicKeyId': {'type': 'string', 'description': '16-hex key fingerprint, e.g. 94502b2b7235c986.'}}, 'description': 'Ed25519 signature over the canonical result (transport field; stripped before verify).', 'additionalProperties': True}, 'categories': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Trust-axis categories with per-category scores + checks.'}, 'verification': {'type': 'object', 'description': "Self-describing in-band verification block {alg, kid, jwks, canonicalization} — how to verify this scorecard's signature. Self-describing, so signed-EXCLUDED (stripped before verify).", 'additionalProperties': True}, 'rubricVersion': {'type': 'string', 'description': 'Rubric version (e.g. "0.4.0").'}}, 'description': "Signed iitr two-axis trust-readiness scorecard (returned verbatim). Verify it in-band with the verify_scan tool, or follow the rule + key in the scorecard's own `verification` block (Ed25519 against mnemom://iitr/jwks; canonicalization strips [signature, cached, permalink, verification]).", 'additionalProperties': True}
search_reputation_directory
Resolve an agent name or id-prefix to a real agent_id over the PUBLIC reputation directory (only agents whose reputation visibility is public). Zero-auth. The arriving-agent entry point: discover a concrete agent_id, then call get_reputation / verify_reputation on it.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'properties': {'q': {'type': 'string', 'description': 'Name search (ilike) or agent-id prefix match.'}, 'page': {'type': 'integer', 'default': 1, 'minimum': 1, 'description': '1-based page number for pagination. Default 1.'}, 'sort': {'type': 'string', 'default': 'score', 'description': 'Result ordering. Default "score" (highest-rated first); other supported keys order by recency or name.'}, 'grade': {'type': 'string', 'description': 'Filter to one grade (e.g. `AAA`, `B`, `NR`).'}, 'per_page': {'type': 'integer', 'default': 20, 'maximum': 100, 'minimum': 1, 'description': 'Number of results per page. 1–100, default 20.'}, 'confidence': {'enum': ['high', 'medium', 'low', 'insufficient'], 'type': 'string', 'description': 'Filter to agents at a given reputation-confidence level (driven by how much evidence backs the score).'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', '$defs': {'ReputationScore': {'type': 'object', 'required': ['agent_id', 'score', 'grade', 'is_eligible', 'checkpoint_count', 'confidence', 'components', 'visibility'], 'properties': {'tier': {'type': ['string', 'null']}, 'grade': {'type': ['string', 'null'], 'description': 'AAA–D or NR.'}, 'score': {'type': ['integer', 'null'], 'maximum': 1000, 'minimum': 0}, 'claimed': {'type': 'boolean'}, 'agent_id': {'type': 'string'}, 'trend_30d': {'type': ['number', 'null']}, 'agent_name': {'type': ['string', 'null']}, 'components': {'type': 'array', 'items': {'type': 'object', 'required': ['key', 'score', 'weight', 'weighted_score'], 'properties': {'key': {'enum': ['integrity_ratio', 'compliance', 'drift_stability', 'trace_completeness', 'coherence_compatibility'], 'type': 'string'}, 'label': {'type': 'string'}, 'score': {'type': 'number'}, 'weight': {'type': 'number'}, 'factors': {'type': 'array'}, 'weighted_score': {'type': 'number'}}}}, 'confidence': {'enum': ['insufficient', 'low', 'medium', 'high'], 'type': 'string'}, 'visibility': {'enum': ['public', 'private'], 'type': 'string', 'description': 'Reputation-publication axis — whether this agent\'s Trust Rating is published. Every registered agent\'s reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word "public" but govern different things.'}, 'computed_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'is_eligible': {'type': 'boolean'}, 'next_compute_at': {'type': ['string', 'null'], 'format': 'date-time', 'description': 'Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.'}, 'checkpoint_count': {'type': 'integer'}, 'a2a_trust_extension': {'type': 'object', 'properties': {'grade': {'type': 'string'}, 'score': {'type': 'number'}, 'provider': {'type': 'string'}, 'badge_url': {'type': 'string', 'format': 'uri'}, 'confidence': {'type': 'string'}, 'last_updated': {'type': 'string', 'format': 'date-time'}, 'verified_url': {'type': 'string', 'format': 'uri'}, 'extension_uri': {'type': 'string'}, 'methodology_url': {'type': 'string', 'format': 'uri'}}, 'description': 'A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).'}, 'checkpoint_accounting': {'type': ['object', 'null'], 'required': ['total', 'analyzed', 'excluded'], 'properties': {'total': {'type': 'integer', 'description': 'All checkpoints recorded for the agent.'}, 'analyzed': {'type': 'integer', 'description': 'Checkpoints that counted toward the score (drives the X/50 eligibility gauge).'}, 'excluded': {'type': 'object', 'required': ['synthetic', 'insufficient_thinking', 'quarantined'], 'properties': {'synthetic': {'type': 'integer', 'description': 'Synthetic (`ic-synthetic-*`) checkpoints.'}, 'quarantined': {'type': 'integer', 'description': 'Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.'}, 'insufficient_thinking': {'type': 'integer', 'description': 'Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).'}}}, 're_evaluated': {'type': 'object', 'required': ['corrected_clear', 'corrected_non_clear', 'resolved_no_correction'], 'properties': {'corrected_clear': {'type': 'integer', 'description': "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`)."}, 'corrected_non_clear': {'type': 'integer', 'description': "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation."}, 'resolved_no_correction': {'type': 'integer', 'description': 'Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.'}}, 'description': "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed."}}, 'description': 'Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.'}}, 'description': "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000."}}, 'required': ['agents', 'total', 'page', 'per_page'], 'properties': {'page': {'type': 'integer'}, 'total': {'type': 'integer'}, 'agents': {'type': 'array', 'items': {'$ref': '#/$defs/ReputationScore'}}, 'per_page': {'type': 'integer'}}}
verify_reputation
Attest an agent's Trust Rating — returns a Merkle-root + hash-chain attestation (hash_chain_valid) proving the rating derives from an unbroken, append-only checkpoint chain, plus a pointer to the signed integrity certificate. This is a chain-integrity attestation, NOT an in-band Ed25519 signature check (that parity is verify_scan, for website scorecards).
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'Agent identifier (e.g. smolt-abc123)'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['agent_id', 'score', 'grade', 'computed_at', 'verification'], 'properties': {'grade': {'type': 'string'}, 'score': {'type': 'number'}, 'agent_id': {'type': 'string'}, 'computed_at': {'type': 'string', 'format': 'date-time'}, 'verification': {'type': ['object', 'null'], 'properties': {'merkle_root': {'type': ['string', 'null']}, 'certificate_url': {'type': ['string', 'null']}, 'last_checkpoint': {'type': ['string', 'null'], 'format': 'date-time'}, 'checkpoint_count': {'type': 'integer'}, 'first_checkpoint': {'type': ['string', 'null'], 'format': 'date-time'}, 'hash_chain_valid': {'type': 'boolean'}, 'latest_certificate_hash': {'type': ['string', 'null']}}}}}
verify_scan
Verify a website scan scorecard's Ed25519 signature IN-BAND (verify, don't trust). Pass a `scan` (a scorecard from scan_trust) or a `url` to re-scan; returns {verified, key_id, canonicalization} checked against the public key at mnemom://iitr/jwks. Zero-auth. Spec + rubric: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.
읽기 전용 외부 접근 가능 멱등성
입력 스키마
{'type': 'object', 'oneOf': [{'not': {'required': ['url']}, 'required': ['scan']}, {'not': {'required': ['scan']}, 'required': ['url']}], 'properties': {'url': {'type': 'string', 'description': 'Alternatively, a domain/URL to re-scan and then verify.'}, 'scan': {'type': 'object', 'required': ['schema', 'target', 'score', 'grade', 'signature'], 'properties': {'grade': {'type': 'string', 'description': 'Trust letter grade (A+…F).'}, 'score': {'type': 'number', 'description': '0–100 weighted overall TRUST score.'}, 'access': {'type': 'object', 'properties': {'axis': {'type': 'string', 'description': 'Always "access".'}, 'grade': {'type': 'string', 'description': 'Access letter grade (A+…F).'}, 'score': {'type': 'number', 'description': '0–100 weighted Access/discoverability score (independent of Trust).'}, 'version': {'type': 'string', 'description': 'Access-axis rubric version this sub-score was computed against.'}, 'applicable': {'type': 'boolean', 'description': 'False when the site declares Access N/A.'}, 'categories': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Per-category Access scores + checks.'}}, 'description': 'The independent Access/discoverability axis (never blended with Trust). Present from the two-axis rubric (0.3.0+).', 'additionalProperties': True}, 'cached': {'type': 'boolean', 'description': "True when served from the scanner's 24h cache rather than a fresh scan."}, 'schema': {'type': 'string', 'description': 'iitr-scan schema version string (e.g. "iitr-scan/v0.N").'}, 'target': {'type': 'string', 'description': 'Normalized host that was scanned.'}, 'permalink': {'type': 'string', 'format': 'uri', 'description': 'Shareable /r/ permalink (only on /r/ responses; transport field).'}, 'scannedAt': {'type': 'string', 'format': 'date-time', 'description': 'When this scorecard was produced. Results are cached up to 24h — pass fresh:true to scan_trust to force a re-scan.'}, 'signature': {'type': 'object', 'properties': {'alg': {'type': 'string', 'description': 'Always "Ed25519".'}, 'value': {'type': 'string', 'description': 'base64 signature.'}, 'signedAt': {'type': 'string', 'format': 'date-time', 'description': 'When the scorecard was signed.'}, 'publicKeyId': {'type': 'string', 'description': '16-hex key fingerprint, e.g. 94502b2b7235c986.'}}, 'description': 'Ed25519 signature over the canonical result (transport field; stripped before verify).', 'additionalProperties': True}, 'categories': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Trust-axis categories with per-category scores + checks.'}, 'verification': {'type': 'object', 'description': "Self-describing in-band verification block {alg, kid, jwks, canonicalization} — how to verify this scorecard's signature. Self-describing, so signed-EXCLUDED (stripped before verify).", 'additionalProperties': True}, 'rubricVersion': {'type': 'string', 'description': 'Rubric version (e.g. "0.4.0").'}}, 'description': "A scan scorecard previously returned by scan_trust (or iitr's /r/ JSON), passed back verbatim to verify. Same shape as scan_trust's result; the signature is checked against mnemom://iitr/jwks.", 'additionalProperties': True}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'required': ['verified', 'algorithm', 'key_id', 'canonicalization'], 'properties': {'key_id': {'type': ['string', 'null'], 'description': 'The signing key id (kid) checked.'}, 'reason': {'type': 'string', 'description': 'Why verification failed or could not be evaluated (absent when verified).'}, 'verified': {'type': 'boolean', 'description': 'True iff the signature verifies against the in-band JWKS.'}, 'algorithm': {'type': 'string', 'description': 'Always "Ed25519".'}, 'scorecard': {'type': 'object', 'description': 'The scorecard verified (present when re-scanned via `url`).', 'additionalProperties': True}, 'canonicalization': {'type': 'string', 'description': 'The exact canonicalization used (so the verdict is reproducible).'}}, 'description': "In-band verification verdict for an iitr scan scorecard's Ed25519 signature.", 'additionalProperties': True}
변경됨
put_protection_by_agent
2026년 10월 1일 2:47 AM
추가됨
verify_scan
2026년 9월 17일 12:45 PM
추가됨
verify_reputation
2026년 9월 17일 12:45 PM
추가됨
search_reputation_directory
2026년 9월 17일 12:45 PM
추가됨
scan_trust
2026년 9월 17일 12:45 PM
추가됨
report_recipe_fn_fp
2026년 9월 17일 12:45 PM
추가됨
put_protection_by_agent
2026년 9월 17일 12:45 PM
추가됨
put_alignment_by_agent
2026년 9월 17일 12:45 PM
추가됨
preview_compose_protection_by_agent
2026년 9월 17일 12:45 PM
추가됨
preview_compose_alignment_by_agent
2026년 9월 17일 12:45 PM
추가됨
list_agents
2026년 9월 17일 12:45 PM
추가됨
get_started
2026년 9월 17일 12:45 PM
추가됨
get_reputation_badge
2026년 9월 17일 12:45 PM
추가됨
get_reputation
2026년 9월 17일 12:45 PM
추가됨
get_agent
2026년 9월 17일 12:45 PM
추가됨
claim_agent
2026년 9월 17일 12:45 PM

GoCreative Agent API

io.github.ColinHughes2121/gocreative-agent-api

Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

DDG Agent Services

io.github.daedalusdevelopmentgroup/ddg-agent-services-mcp

Acts as a pay-per-call gateway for agent tools including LLM routes, web and market data, Ethereum RPC, security scans, service c…

mainstreet

io.github.philpof102-svg/mainstreet

Provides reputation, trust scoring, validation, consensus, routing, and payment-related tools for on-chain AI agents on Base.

xrpl-referee

io.github.eamwhite1/xrpl-referee

Supports XRPL-based agent hiring, escrow payments, job marketplaces, wallet trust scoring, sanctions and KYC checks, and AI-assis…

InsureLink

io.github.skewing1/insurelink

Manages agent reputation, insurance coverage, SLA agreements, transaction safety checks, attestations, claims, and x402-mediated …

Overwing

ai.overwing/mcp

Evaluates text against configurable safety rules and provides agent policy decisions, approval workflows, compensating actions, a…

Hermes Plant — Agent Commerce Assurance

io.github.JesseGdotIO/hermes-plant

Preflights and attests consequential agent actions, verifies signed evidence, evaluates payments and wallets, and provides determ…