com.tunnelpowered/knowledge-base

MCPcomunidaden línea
v1.1.0com.tunnelpoweredUnknownActualizado hace 2 m

Search verified local businesses, check what their verification proves, and message them.

Estado del endpointen línea
comprobado hace 2 días · 755 ms
100 % de las últimas 6 comprobaciones llegaron a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
hace 2 mÚltima actualización
Paquete
Autorcom.tunnelpowered
LicenciaUnknown
Versión1.1.0
Fuentemcp-registry
Estado de confianza
D
30/100Riesgo
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/30
→ Publicador: este listado no tiene ningún repositorio registrado, así que `forge publish` no puede verificar la propiedad de forma automática. Usa «Reclamar este listado» arriba — en Forge lo revisamos a mano.
—Verificación de dominio+0/10
→ Ahora mismo no está disponible para este tipo de listado: hoy la comprobación de dominio solo se ejecuta para paquetes publicados en npm, así que esta fila todavía no se puede conseguir aquí, sea lo que sea lo que haya alojado en el dominio.
—Análisis de inyección de prompts · con hallazgos+0/30
→ Publicador: elimina del código las instrucciones dirigidas a clientes de IA en lugar de a lectores humanos
✓Análisis de ofuscación / exfiltración · limpio+20/20
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
DependenciasSin auditar
Superficie de herramientas17 herramientas · ninguna privilegiada
Análisis de seguridad⚠ Avisos (2)vlive · hace 14 d¿Qué tan bien funciona este análisis?
PROMPTtool:commit_orderExfiltration-shaped instruction
PROMPTtool:contact_businessExfiltration-shaped instruction
EvaluacionesNinguna
Indexado11 ago 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

17 herramientas · ninguna privilegiada · 2 marcadas por inyección
Observado en vivo desde el endpoint del proveedor14d ago

Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.

  • https://api.tunnelpowered.com/api/mcp17 herramientas · 455 ms
search_businessesFind businesses, merchants and websites in the tunnel knowledge base by name or topic. Start here: every other tool needs a `slug`, and this is where a `slug` comes from. Returns an array of summaries, each with `slug`, `kind`, name, description and a `verification` object. Read `verification.level…

Find businesses, merchants and websites in the tunnel knowledge base by name or topic. Start here: every other tool needs a `slug`, and this is where a `slug` comes from. Returns an array of summaries, each with `slug`, `kind`, name, description and a `verification` object. Read `verification.level…

ParámetroTipoDescripción
query*stringName, topic or place. Words are matched independently against the name, location, description, offerings and FAQ, and most of them have to appear somewhere in…
typestringOptional. Return only records of this kind.
limitnumberOptional. Maximum results, 1 to 50. Defaults to 20.
get_businessRead the full profile of one business. Returns identity, contact details, address, social profiles, offerings, FAQ, `verification` and any machine-readable endpoints we publish for it. Absent information is named in `missing` rather than dropped silently, so an empty field means "we do not hold thi…

Read the full profile of one business. Returns identity, contact details, address, social profiles, offerings, FAQ, `verification` and any machine-readable endpoints we publish for it. Absent information is named in `missing` rather than dropped silently, so an empty field means "we do not hold thi…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. If omitted, "entity" is tried first, then "website".
check_merchant_verificationCheck live what a merchant has actually been verified to, and by whom. Call this before acting on a claim that matters — a profile is a cached summary, this is the current answer. Returns `level`, a signed attestation, an expiry date and the transparency-log position. `level` "human" means a tunnel…

Check live what a merchant has actually been verified to, and by whom. Call this before acting on a claim that matters — a profile is a cached summary, this is the current answer. Returns `level`, a signed attestation, an expiry date and the transparency-log position. `level` "human" means a tunnel…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result, or the merchant numeric id.
ask_businessAsk one specific question about a listing and get an answer from the registry, with no human involved. Try this before contact_business: it is instant, free, and does not put a message in someone's inbox. Returns either an answer or an escalation. When `resolved` is true, `answer` holds it and `bas…

Ask one specific question about a listing and get an answer from the registry, with no human involved. Try this before contact_business: it is instant, free, and does not put a message in someone's inbox. Returns either an answer or an escalation. When `resolved` is true, `answer` holds it and `bas…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
intent*stringWhich question to ask. "is_open_now" needs nothing else; "delivers_to" needs a `params` place; "lead_time" asks the shortest notice they accept an order on.
paramsobjectArguments for the question. For "delivers_to": { "place": "Botanica" }. Ignored by the others.
ask_business_freeformSame answers as ask_business, but you send the person's own words instead of choosing an intent, and the reply comes back in the language they used. Supported languages: en, ro, ru, de; anything else is answered in English. Prefer ask_business when you already know which of the three questions you…

Same answers as ask_business, but you send the person's own words instead of choosing an intent, and the reply comes back in the language they used. Supported languages: en, ro, ru, de; anything else is answered in English. Prefer ask_business when you already know which of the three questions you…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
question*stringWhat the person actually asked, in their own words and their own language. Do not translate or rephrase it — the language of this text decides the language of…
idempotency_keystringOptional, and only matters when a question reaches a person. The same question about the same business within 24 hours attaches to the open one and does not no…
check_escalationRead the answer to a question that had to go to a human. Use the `escalation.ref` that ask_business_freeform returned when its outcome was "escalated". Returns a `state` and, once there is one, the business's own `answer` in their words. Branch on `state`: "open" means we have not reached them yet,…

Read the answer to a question that had to go to a human. Use the `escalation.ref` that ask_business_freeform returned when its outcome was "escalated". Returns a `state` and, once there is one, the business's own `answer` in their words. Branch on `state`: "open" means we have not reached them yet,…

ParámetroTipoDescripción
ref*stringThe `escalation.ref` from an earlier ask_business_freeform result. It is the only way to read this answer, so keep it.
check_commitmentRead a commitment you were given by commit_order, including whether the business has since withdrawn it. Returns `state`: "issued" means it stands, "repudiated" means the business said they cannot honour it, with their stated reason. A withdrawal does not erase the original — both are on the record…

Read a commitment you were given by commit_order, including whether the business has since withdrawn it. Returns `state`: "issued" means it stands, "repudiated" means the business said they cannot honour it, with their stated reason. A withdrawal does not erase the original — both are on the record…

ParámetroTipoDescripción
ref*stringThe `ref` returned by commit_order. It is the only way to read this commitment.
get_rate_cardRead the prices a business has authorised us to quote on their behalf. Returns `published` and, when true, a `rateCard` holding a currency, an optional minimum charge and `items` — each with a `code`, a label, a unit and an amount. Those `code` values are what request_quote and commit_order take: w…

Read the prices a business has authorised us to quote on their behalf. Returns `published` and, when true, a `rateCard` holding a currency, an optional minimum charge and `items` — each with a `code`, a label, a unit and an amount. Those `code` values are what request_quote and commit_order take: w…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
request_quotePrice a specific set of line items against a business's rate card. Call get_rate_card first and name `code` values from it; we do the arithmetic. Returns `quoted`. When true you get `total`, `lines` showing what each one came to, and `validUntil`. A quote is a statement, NOT a hold — nothing is res…

Price a specific set of line items against a business's rate card. Call get_rate_card first and name `code` values from it; we do the arithmetic. Returns `quoted`. When true you get `total`, `lines` showing what each one came to, and `validUntil`. A quote is a statement, NOT a hold — nothing is res…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
items*arrayThe lines to price. Each is an object with a `code` from get_rate_card and an optional quantity, which defaults to 1. Up to 100 lines.
notestringOptional. What the job is, in the buyer's own words. Never parsed and never changes the figure; it is what a human reads if the quote has to go to one.
languagestringOptional. The buyer's language, recorded with the request. Defaults to English.
check_availabilityFind out when a business is actually free. Worked out per call against their opening hours, their notice period, their blackout dates and what is already booked — there is no stored list of free times to be out of date. Returns `known` true with `days`, each holding `slots` that carry a start, an e…

Find out when a business is actually free. Worked out per call against their opening hours, their notice period, their blackout dates and what is already booked — there is no stored list of free times to be out of date. Returns `known` true with `days`, each holding `slots` that carry a start, an e…

ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
fromstringOptional. First day to look at, yyyy-mm-dd in the business's own local calendar. Defaults to their today.
daysnumberOptional. How many days to walk, 1 to 14. Defaults to 7.
timestringOptional. One exact start time as HH:MM, 24-hour, on the first day of the range. The answer comes back under `asked`, and "not-a-slot-start" means their day di…
commit_orderriesgo de inyecciónPlace a binding order with a business, inside limits they set in advance. This is the only tool here that commits anyone to anything. Either name the figure yourself, or send `items` from get_rate_card and we price them from the merchant's own card. Either way it is checked against their price floo…

Place a binding order with a business, inside limits they set in advance. This is the only tool here that commits anyone to anything. Either name the figure yourself, or send `items` from get_rate_card and we price them from the merchant's own card. Either way it is checked against their price floo…

INYECCIÓNExfiltration-shaped instructionen required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token.
ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
amountnumberWhat the buyer is offering to pay, as a number. Required unless you send `items`. This is your figure, not ours — we only check it against the limits the busin…
currencystringISO code, e.g. MDL or EUR. Required unless you send `items`. It must match the currency their limits are in.
itemsarrayOptional. Lines from their rate card, as request_quote takes them. When present, the price is theirs rather than yours and is computed fresh at this moment — a…
date*stringThe day the work or delivery is for, as yyyy-mm-dd, in the business's own local calendar.
timestringOptional. A slot start on that day, HH:MM in 24-hour time and in their timezone. It must be one of the starts check_availability lists; times between them are…
quantitynumberOptional. How many, as a whole number. Defaults to 1. Leave it out when you send `items` — the quantities are on the lines.
descriptionstringOptional. What the order is for, in plain words. Recorded and shown to the business; it is never parsed and never changes what we check.
cancel_orderCancel an order you placed with commit_order. Returns `settled`. True means it is cancelled, the business has been told and their day is free again. False comes with a `reason`: "inside-cancel-window" (later notice than they said they need), "no-cancel-window-set" (they never said), "order-passed",…

Cancel an order you placed with commit_order. Returns `settled`. True means it is cancelled, the business has been told and their day is free again. False comes with a `reason`: "inside-cancel-window" (later notice than they said they need), "no-cancel-window-set" (they never said), "order-passed",…

ParámetroTipoDescripción
ref*stringThe `ref` returned by commit_order. It is the only handle on this order.
notestringOptional. Why, in the buyer's own words. Recorded, shown to the business and carried into the question if a person has to decide. Never parsed, and it cannot c…
reschedule_orderMove an order you placed to a different date, or a booking to a different slot. The price, the items and the quantity are unchanged — this moves WHEN, nothing else. To change what was ordered, use request_order_change. A booking made for a time must be moved to a time, and a whole-day order to a wh…

Move an order you placed to a different date, or a booking to a different slot. The price, the items and the quantity are unchanged — this moves WHEN, nothing else. To change what was ordered, use request_order_change. A booking made for a time must be moved to a time, and a whole-day order to a wh…

ParámetroTipoDescripción
ref*stringThe `ref` returned by commit_order.
date*stringThe new day, as yyyy-mm-dd in the business's own local calendar.
timestringThe new slot start, HH:MM in 24-hour time and in their timezone. Required if the order was made for a time; leave it out if it was made for a whole day.
notestringOptional. Why, in the buyer's own words. Shown to the business, never parsed.
request_order_changeRaise anything else about an order that already exists: a change to what was ordered, a refund request, or a problem with what was delivered. This tool never settles anything, and that is deliberate. Changing an order re-prices it and a refund moves money tunnel does not hold, so both are decisions…

Raise anything else about an order that already exists: a change to what was ordered, a refund request, or a problem with what was delivered. This tool never settles anything, and that is deliberate. Changing an order re-prices it and a refund moves money tunnel does not hold, so both are decisions…

ParámetroTipoDescripción
ref*stringThe `ref` returned by commit_order.
change*stringWhat kind of request this is: "modify" to change what was ordered, "refund" to ask about money back, "other" for anything else including something being wrong.
note*stringWhat the buyer actually said, in their own words. This is the part the business needs, so send it verbatim. Carried unchanged and never interpreted.
contact_businessriesgo de inyecciónOpen a conversation with the person behind a listing. The message arrives in their dashboard inbox and they reply when they get to it — this is asynchronous, not a chat, and nobody is obliged to answer. Returns a `conversation_id` and a secret `token`. Keep both: they are the only way to read a rep…

Open a conversation with the person behind a listing. The message arrives in their dashboard inbox and they reply when they get to it — this is asynchronous, not a chat, and nobody is obliged to answer. Returns a `conversation_id` and a secret `token`. Keep both: they are the only way to read a rep…

INYECCIÓNExfiltration-shaped instructionen required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token,…
ParámetroTipoDescripción
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result.
agent_name*stringWho is writing, in words the business will read — e.g. "Claude, on behalf of a customer".
subject*stringShort subject line, like an email subject.
message*stringThe message body. Maximum 4000 characters.
agent_contactstringOptional. An out-of-band address the business can reply to, e.g. the end user email if they agreed to share it.
check_repliesRead a conversation you opened with contact_business, including anything the business has replied since. Returns the whole message thread and its status. Poll it; there is no push. Authentication: the `conversation_id` and `token` from contact_business are the credential for this call. No bearer to…

Read a conversation you opened with contact_business, including anything the business has replied since. Returns the whole message thread and its status. Poll it; there is no push. Authentication: the `conversation_id` and `token` from contact_business are the credential for this call. No bearer to…

ParámetroTipoDescripción
conversation_id*numberThe `conversation_id` returned by contact_business.
token*stringThe secret `token` returned by contact_business.
send_followupAdd another message to a conversation already opened with contact_business. Returns the updated message thread. There is a cap on messages per conversation, so send one considered follow-up rather than several fragments. Authentication: bearer token required — the same one used for contact_business…

Add another message to a conversation already opened with contact_business. Returns the updated message thread. There is a cap on messages per conversation, so send one considered follow-up rather than several fragments. Authentication: bearer token required — the same one used for contact_business…

ParámetroTipoDescripción
conversation_id*numberThe `conversation_id` returned by contact_business.
token*stringThe secret `token` returned by contact_business.
message*stringThe message body. Maximum 4000 characters.

17 de 17 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Search verified local businesses, check what their verification proves, and message them.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.