io.github.LarryLemonBot/boundary-guard-x402

MCPCommunitylive
v0.1.0io.github.LarryLemonBotUnknownAktualisiert vor 4 Mon.

MCP tools for x402 readiness, paid-path probes, launch packs, and trust receipts.

Endpunkt-Statuslive
geprüft vor 10 Tagen · 158 ms
100 % der letzten 5 Prüfungen haben diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
vor 4 Mon.Letzte Aktualisierung
Paket
Autorio.github.LarryLemonBot
LizenzUnknown
Version0.1.0
Quellemcp-registry
Trust-Status
B
60/100Gut
✓Im Forge-Index gelistet+10/10
—Publisher-Identität verifiziert+0/30
→ Publisher: für diesen Eintrag ist kein Repository hinterlegt, daher kann `forge publish` die Inhaberschaft nicht automatisch prüfen. Nutze oben „Diesen Eintrag beanspruchen“ — Forge prüft diese Fälle von Hand.
—Domain-Verifizierung+0/10
→ Für diesen Eintragstyp derzeit nicht verfügbar — die Domain-Prüfung läuft heute nur für npm-gestützte Pakete, diese Zeile lässt sich hier also noch nicht erreichen, unabhängig davon, was auf der Domain liegt.
✓Prompt-Injection-Scan · sauber+30/30
✓Obfuskations-/Exfiltrations-Scan · sauber+20/20
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft—
AbhängigkeitenNicht auditiert
Tool-Oberfläche6 Tools · keines privilegiert
Sicherheits-Scan✓ Saubervlive · vor 1 Mon.Wie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert13. Juni 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

6 Tools · keines privilegiert
Live am Endpunkt des Anbieters beobachtet1mo ago

Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.

  • https://x402-resource-scanner.vercel.app/mcp6 Tools · 125 ms
boundary_guard_checkCreate a deterministic, read-only pre-action receipt from request, policy, and optional result evidence. Use before an agent posts, spends, lists, or writes so the decision can be audited; no external action is executed.

Create a deterministic, read-only pre-action receipt from request, policy, and optional result evidence. Use before an agent posts, spends, lists, or writes so the decision can be audited; no external action is executed.

ParameterTypBeschreibung
nextStepstringOptional guidance stored in the receipt.
policyobjectDecision object, e.g. allow/retry/review/block and reason.
request*objectAction metadata the agent is about to perform.
resultobjectOptional result or dry-run summary to hash into evidence.
scan_x402_resourceRead-only scan of a public API/provider URL for x402, OpenAPI, pricing, and agent-discovery metadata. Pass url, and optionally marketplace_url plus expected_resources, to get a readiness score, issues, and fixes; no private endpoints are called.

Read-only scan of a public API/provider URL for x402, OpenAPI, pricing, and agent-discovery metadata. Pass url, and optionally marketplace_url plus expected_resources, to get a readiness score, issues, and fixes; no private endpoints are called.

ParameterTypBeschreibung
expected_resourcesintegerOptional expected resource count.
marketplace_urlstringOptional marketplace/listing URL to compare against public metadata.
url*stringTarget API/provider base URL to scan.
probe_x402_paid_pathProbe a public x402 paid endpoint without signing or paying, then parse the HTTP 402 challenge. Pass target plus optional expected network/asset/price to verify payment metadata and receive a deterministic health receipt.

Probe a public x402 paid endpoint without signing or paying, then parse the HTTP 402 challenge. Pass target plus optional expected network/asset/price to verify payment metadata and receive a deterministic health receipt.

ParameterTypBeschreibung
expectedobjectOptional expected x402 metadata such as network, asset, and priceUsd.
methodstringSafe unpaid probe method. Defaults to GET.
modestringProbe mode for v1. Defaults to unpaid_402.
target*stringSpecific paid endpoint URL to probe without payment.
check_agent_tool_readinessGateCheck readiness: check whether an x402/agent-facing tool is ready for agent routing, marketplace listing, and paid-path monitoring, including public agent discovery surfaces (/llms.txt, /agents.txt, /.well-known/mcp.json, /mcp). Pass target plus optional tier, marketplace_url, expected_resource…

GateCheck readiness: check whether an x402/agent-facing tool is ready for agent routing, marketplace listing, and paid-path monitoring, including public agent discovery surfaces (/llms.txt, /agents.txt, /.well-known/mcp.json, /mcp). Pass target plus optional tier, marketplace_url, expected_resource…

ParameterTypBeschreibung
expectedobjectOptional expected x402 network/asset/price metadata for paid_path probes.
expected_resourcesintegerOptional expected resource count.
marketplace_urlstringOptional marketplace/listing URL to compare against public metadata.
methodstringSafe unpaid probe method when paid_path is supplied. Defaults to GET.
paid_pathstringOptional specific paid endpoint to probe without payment for deep/report tiers.
target*stringTarget API/provider base URL to scan.
tierstringReadiness depth. quick=$1, deep=$5, report=$10. Defaults to quick.
generate_x402_launch_packGenerate marketplace-safe launch assets for an x402/MCP seller: listing copy, buyer FAQ, checklist, approval packet, and claim boundaries. Pass target plus optional product_name, audience, primary_use_case, marketplace_url, and paid_path; service/premium tiers include readiness evidence. Tiers: sin…

Generate marketplace-safe launch assets for an x402/MCP seller: listing copy, buyer FAQ, checklist, approval packet, and claim boundaries. Pass target plus optional product_name, audience, primary_use_case, marketplace_url, and paid_path; service/premium tiers include readiness evidence. Tiers: sin…

ParameterTypBeschreibung
audiencestringPrimary buyer/audience for listing copy.
desired_marketplacesarrayOptional marketplace names to include in launch planning.
expectedobjectOptional expected x402 network/asset/price metadata for paid_path probes.
expected_resourcesintegerOptional expected resource count.
marketplace_urlstringOptional marketplace/listing URL to compare against public metadata.
methodstringSafe unpaid probe method when paid_path is supplied. Defaults to GET.
paid_pathstringOptional paid endpoint to validate via unpaid 402 challenge for service/premium packs.
primary_use_casestringPrimary buyer outcome/use case.
product_namestringBuyer-facing product title.
target*stringTarget API/provider base URL to package for launch.
tierstringLaunch pack depth. single=$9, service=$29, premium=$49. Defaults to single.
generate_trust_receiptGenerate a deterministic trust receipt from sanitized request/policy/result/payment summaries. Do not submit raw auth headers, cookies, API keys, private keys, payment signatures, payment response headers, customer prompts, customer documents, or payer-identifying evidence.

Generate a deterministic trust receipt from sanitized request/policy/result/payment summaries. Do not submit raw auth headers, cookies, API keys, private keys, payment signatures, payment response headers, customer prompts, customer documents, or payer-identifying evidence.

ParameterTypBeschreibung
nextStepstringOptional receipt next-step guidance.
paymentobjectOptional sanitized payment summary or caller-provided hashes only; do not include raw payment signatures, raw payment response headers, private keys, API keys,…
policyobjectSanitized policy or decision summary to hash.
request*objectSanitized request/action summary to hash; omit raw prompts, documents, credentials, cookies, auth headers, signatures, and secrets.
resultobjectSanitized outcome/result summary to hash; omit customer data and secret-like values.

6 von 6 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

MCP tools for x402 readiness, paid-path probes, launch packs, and trust receipts.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Keine Abdeckung der Abhängigkeiten

Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.