com.bmcxiv/breach402-owner-protection

MCPcommunautéen ligne
v0.1.1com.bmcxivUnknownMis à jour il y a 1 mois

Protect owners with private checks across 13.3B+ breach records and prioritized defenses.

État de l’endpointen ligne
vérifié il y a 6 jours · 422 ms
100 % des dernières 4 vérifications ont atteint cet endpoint
Fonctionne dans
ClaudeCursorCopilotChatGPTGemini

Déduit des transports déclarés par cette annonce (streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
il y a 1 moisDernière mise à jour
Paquet
Auteurcom.bmcxiv
LicenceUnknown
Version0.1.1
Sourcemcp-registry
Statut de confiance
B
60/100Bon
Listé dans l’index Forge+10/10
Identité de l’éditeur vérifiée+0/30
Éditeur : aucune référence de dépôt n’est enregistrée pour cette annonce, `forge publish` ne peut donc pas vérifier la propriété automatiquement. Utilisez « Revendiquer cette annonce » ci-dessus — Forge les examine à la main.
Vérification de domaine+0/10
Actuellement indisponible pour ce type d’annonce — la vérification de domaine ne s’exécute aujourd’hui que pour les paquets adossés à npm, cette ligne ne peut donc pas encore être obtenue ici, quel que soit le contenu hébergé sur le domaine.
Analyse d’injection de prompt · propre+30/30
Analyse d’obfuscation / exfiltration · propre+20/20
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine
Provenance
DépendancesNon audité
Surface d’outils8 outils · aucun privilégié
Analyse de sécurité✓ Proprevlive · il y a 6 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé26 juil. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

8 outils · aucun privilégié
Observé en direct depuis l’endpoint du fournisseur6d ago

Lu depuis un véritable échange MCP initialize → tools/list contre l’endpoint déclaré. Aucun outil n’a été invoqué — tools/list est l’appel d’introspection en lecture seule que le protocole prévoit pour cela. Cela reflète ce que le serveur annonçait à cet instant ; un endpoint hébergé n’est figé sur aucune version et peut changer sans préavis.

  • https://breach402.bmcxiv.com/mcp8 outils · 422 ms
assess_owner_security_needFree, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.

Free, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.

ParamètreTypeDescription
scenario*stringNon-identifying description of the owner's security situation. Email addresses are rejected.
preview_synthetic_breach_reportFree static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.

Free static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_owner_email_verificationSend an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.

Send an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.

ParamètreTypeDescription
email*stringThe owner-controlled email address to verify.
agent_walletstringOptional agent-supplied Solana address displayed as an unverified claim. It is not proof of wallet control.
get_owner_email_verification_statusPoll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.

Poll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.

ParamètreTypeDescription
enrollment_id*stringEnrollment identifier returned when verification was started.
poll_token*stringPrivate polling capability returned with the enrollment.
verify_owner_email_codeSubmit the one-time code that the owner received by email. The code is bound to the original agent enrollment.

Submit the one-time code that the owner received by email. The code is bound to the original agent enrollment.

ParamètreTypeDescription
enrollment_id*stringEnrollment identifier returned when verification was started.
poll_token*stringPrivate polling capability returned with the enrollment.
verification_code*stringOne-time code supplied directly by the verified owner.
prepare_paid_breach_checkValidate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.

Validate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.

ParamètreTypeDescription
scan_token*stringOne-time token returned after owner verification.
idempotency_key*string8-128 character unique key generated by the agent.
get_breach_reportRetrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…

Retrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…

ParamètreTypeDescription
check_id*stringPaid-check identifier returned after successful x402 settlement.
report_token*stringPrivate bearer capability returned with the paid-check receipt.
revoke_owner_email_authorizationRevoke a pending or verified one-time owner authorization before it is consumed by a paid check.

Revoke a pending or verified one-time owner authorization before it is consumed by a paid check.

ParamètreTypeDescription
enrollment_id*stringEnrollment identifier whose authorization should be revoked.
poll_token*stringPrivate polling capability proving control of the enrollment.

8 outils sur 8 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Protect owners with private checks across 13.3B+ breach records and prioritized defenses.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Aucune couverture des dépendances

Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.