MCP Server

GHOSBC Safety Gate

io.github.MisfitMEdiAhouse/ghosbc-safety-gate
Security Public & reachable MCP 2026-07-28

What this MCP does

Audits A2A agents, MCP dependencies, and Shopify agentic storefronts, screens agent requests and tools, sanitizes payloads, and validates responses.

audit_a2a_agent_card
Audit A2A Agent Card trust
Use before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable badge metadata. It does not send a task to or execute any skill on the target agent.
Input schema
{'type': 'object', 'required': ['card_url'], 'properties': {'card_url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTPS A2A Agent Card URL, normally /.well-known/agent-card.json.'}}, 'additionalProperties': False}
audit_mcp_dependency
Audit MCP dependency
Use for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authenticated/private MCP endpoints.
Input schema
{'type': 'object', 'required': ['endpoint_url'], 'properties': {'endpoint_url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTPS MCP endpoint.'}}, 'additionalProperties': False}
audit_shopify_agentic_storefront
Audit Shopify agentic storefront
Use to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates carts, checkouts, orders, payments, credentials, or store data.
Input schema
{'type': 'object', 'required': ['store'], 'properties': {'store': {'type': 'string', 'description': 'Public Shopify store domain or HTTPS URL, for example store.myshopify.com.'}}, 'additionalProperties': False}
buy_policy_checks
Use only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
sanitize_agent_payload
Use before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.
Input schema
{'type': 'object', 'required': ['payload'], 'properties': {'payload': {}}, 'additionalProperties': False}
screen_agent_request
Use before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'mode': {'enum': ['OPEN', 'GUARDED', 'SEALED'], 'type': 'string'}, 'text': {'type': 'string'}, 'capabilities': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}
screen_consequential_action
Use immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when explicit bounds fit; REVIEW when bounds are missing; BLOCK when limits are violated. Does not execute the action.
Input schema
{'type': 'object', 'required': ['action'], 'properties': {'action': {'type': 'string'}, 'amount': {'type': 'number'}, 'target': {'type': 'string'}, 'currency': {'type': 'string'}, 'constraints': {'type': 'object', 'properties': {'currency': {'type': 'string'}, 'expires_at': {'type': 'string', 'format': 'date-time'}, 'max_amount': {'type': 'number'}, 'allowed_actions': {'type': 'array', 'items': {'type': 'string'}}, 'allowed_targets': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}}, 'additionalProperties': False}
screen_mcp_tool_definition
Use before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code verification.
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string'}, 'annotations': {'type': ['object', 'null']}, 'description': {'type': 'string'}, 'inputSchema': {'type': ['object', 'null']}}, 'additionalProperties': False}
validate_agent_response
Use immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.
Input schema
{'type': 'object', 'required': ['response'], 'properties': {'response': {}}, 'additionalProperties': False}
Added
buy_policy_checks
Sept. 17, 2026, 12:45 p.m.
Added
validate_agent_response
Sept. 17, 2026, 12:45 p.m.
Added
sanitize_agent_payload
Sept. 17, 2026, 12:45 p.m.
Added
screen_consequential_action
Sept. 17, 2026, 12:45 p.m.
Added
screen_mcp_tool_definition
Sept. 17, 2026, 12:45 p.m.
Added
screen_agent_request
Sept. 17, 2026, 12:45 p.m.
Added
audit_mcp_dependency
Sept. 17, 2026, 12:45 p.m.
Added
audit_shopify_agentic_storefront
Sept. 17, 2026, 12:45 p.m.
Added
audit_a2a_agent_card
Sept. 17, 2026, 12:45 p.m.