com.tunnelpowered/knowledge-base

MCPcommunityattivo
v1.1.0com.tunnelpoweredUnknownAggiornato 2 mesi fa

Search verified local businesses, check what their verification proves, and message them.

Stato dell’endpointattivo
verificato 2 giorni fa · 755 ms
100 % degli ultimi 6 controlli hanno raggiunto questo endpoint
Funziona in
ClaudeCursorCopilotChatGPTGemini

Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Indicizzato automaticamente da fonti pubbliche. Non ancora verificato dal suo sviluppatore su Forge.Rivendica questo annuncio →
2 mesi faUltimo aggiornamento
Pacchetto
Autorecom.tunnelpowered
LicenzaUnknown
Versione1.1.0
Fontemcp-registry
Stato di fiducia
D
30/100Rischio
✓Presente nell’indice di Forge+10/10
—Identità del publisher verificata+0/30
→ Publisher: per questo annuncio non risulta alcun repository, quindi `forge publish` non può verificare la proprietà automaticamente. Usa «Rivendica questo annuncio» qui sopra — Forge li esamina a mano.
—Verifica del dominio+0/10
→ Al momento non disponibile per questo tipo di annuncio — oggi il controllo del dominio viene eseguito solo per i pacchetti su npm, quindi questa riga non può ancora essere ottenuta qui, indipendentemente da cosa sia ospitato sul dominio.
—Analisi prompt injection · rilievi+0/30
→ Publisher: rimuovi dal codice le istruzioni rivolte ai client di IA anziché a lettori umani
✓Analisi offuscamento / esfiltrazione · pulita+20/20
StatoIndicizzato dalla community
PublisherNon verificato
FirmaNon firmato
Dominio—
Provenienza—
DipendenzeNon verificate
Superficie di strumenti17 strumenti · nessuno privilegiato
Analisi di sicurezza⚠ Avvisi (2)vlive · 14 g faQuanto è efficace questa analisi?
PROMPTtool:commit_orderExfiltration-shaped instruction
PROMPTtool:contact_businessExfiltration-shaped instruction
ValutazioniNessuna
Indicizzato11 ago 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

17 strumenti · nessuno privilegiato · 2 segnalati per injection
Osservato in tempo reale dall’endpoint del fornitore14d ago

Letto da un vero handshake MCP initialize → tools/list verso l’endpoint dichiarato. Nessuno strumento è stato invocato — tools/list è la chiamata di introspezione in sola lettura che il protocollo prevede a questo scopo. Riflette ciò che il server annunciava in quel momento; un endpoint ospitato non è vincolato ad alcuna versione e può cambiare senza preavviso.

  • https://api.tunnelpowered.com/api/mcp17 strumenti · 455 ms
search_businessesFind businesses, merchants and websites in the tunnel knowledge base by name or topic. Start here: every other tool needs a `slug`, and this is where a `slug` comes from. Returns an array of summaries, each with `slug`, `kind`, name, description and a `verification` object. Read `verification.level…

Find businesses, merchants and websites in the tunnel knowledge base by name or topic. Start here: every other tool needs a `slug`, and this is where a `slug` comes from. Returns an array of summaries, each with `slug`, `kind`, name, description and a `verification` object. Read `verification.level…

ParametroTipoDescrizione
query*stringName, topic or place. Words are matched independently against the name, location, description, offerings and FAQ, and most of them have to appear somewhere in…
typestringOptional. Return only records of this kind.
limitnumberOptional. Maximum results, 1 to 50. Defaults to 20.
get_businessRead the full profile of one business. Returns identity, contact details, address, social profiles, offerings, FAQ, `verification` and any machine-readable endpoints we publish for it. Absent information is named in `missing` rather than dropped silently, so an empty field means "we do not hold thi…

Read the full profile of one business. Returns identity, contact details, address, social profiles, offerings, FAQ, `verification` and any machine-readable endpoints we publish for it. Absent information is named in `missing` rather than dropped silently, so an empty field means "we do not hold thi…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. If omitted, "entity" is tried first, then "website".
check_merchant_verificationCheck live what a merchant has actually been verified to, and by whom. Call this before acting on a claim that matters — a profile is a cached summary, this is the current answer. Returns `level`, a signed attestation, an expiry date and the transparency-log position. `level` "human" means a tunnel…

Check live what a merchant has actually been verified to, and by whom. Call this before acting on a claim that matters — a profile is a cached summary, this is the current answer. Returns `level`, a signed attestation, an expiry date and the transparency-log position. `level` "human" means a tunnel…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result, or the merchant numeric id.
ask_businessAsk one specific question about a listing and get an answer from the registry, with no human involved. Try this before contact_business: it is instant, free, and does not put a message in someone's inbox. Returns either an answer or an escalation. When `resolved` is true, `answer` holds it and `bas…

Ask one specific question about a listing and get an answer from the registry, with no human involved. Try this before contact_business: it is instant, free, and does not put a message in someone's inbox. Returns either an answer or an escalation. When `resolved` is true, `answer` holds it and `bas…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
intent*stringWhich question to ask. "is_open_now" needs nothing else; "delivers_to" needs a `params` place; "lead_time" asks the shortest notice they accept an order on.
paramsobjectArguments for the question. For "delivers_to": { "place": "Botanica" }. Ignored by the others.
ask_business_freeformSame answers as ask_business, but you send the person's own words instead of choosing an intent, and the reply comes back in the language they used. Supported languages: en, ro, ru, de; anything else is answered in English. Prefer ask_business when you already know which of the three questions you…

Same answers as ask_business, but you send the person's own words instead of choosing an intent, and the reply comes back in the language they used. Supported languages: en, ro, ru, de; anything else is answered in English. Prefer ask_business when you already know which of the three questions you…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
question*stringWhat the person actually asked, in their own words and their own language. Do not translate or rephrase it — the language of this text decides the language of…
idempotency_keystringOptional, and only matters when a question reaches a person. The same question about the same business within 24 hours attaches to the open one and does not no…
check_escalationRead the answer to a question that had to go to a human. Use the `escalation.ref` that ask_business_freeform returned when its outcome was "escalated". Returns a `state` and, once there is one, the business's own `answer` in their words. Branch on `state`: "open" means we have not reached them yet,…

Read the answer to a question that had to go to a human. Use the `escalation.ref` that ask_business_freeform returned when its outcome was "escalated". Returns a `state` and, once there is one, the business's own `answer` in their words. Branch on `state`: "open" means we have not reached them yet,…

ParametroTipoDescrizione
ref*stringThe `escalation.ref` from an earlier ask_business_freeform result. It is the only way to read this answer, so keep it.
check_commitmentRead a commitment you were given by commit_order, including whether the business has since withdrawn it. Returns `state`: "issued" means it stands, "repudiated" means the business said they cannot honour it, with their stated reason. A withdrawal does not erase the original — both are on the record…

Read a commitment you were given by commit_order, including whether the business has since withdrawn it. Returns `state`: "issued" means it stands, "repudiated" means the business said they cannot honour it, with their stated reason. A withdrawal does not erase the original — both are on the record…

ParametroTipoDescrizione
ref*stringThe `ref` returned by commit_order. It is the only way to read this commitment.
get_rate_cardRead the prices a business has authorised us to quote on their behalf. Returns `published` and, when true, a `rateCard` holding a currency, an optional minimum charge and `items` — each with a `code`, a label, a unit and an amount. Those `code` values are what request_quote and commit_order take: w…

Read the prices a business has authorised us to quote on their behalf. Returns `published` and, when true, a `rateCard` holding a currency, an optional minimum charge and `items` — each with a `code`, a label, a unit and an amount. Those `code` values are what request_quote and commit_order take: w…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
request_quotePrice a specific set of line items against a business's rate card. Call get_rate_card first and name `code` values from it; we do the arithmetic. Returns `quoted`. When true you get `total`, `lines` showing what each one came to, and `validUntil`. A quote is a statement, NOT a hold — nothing is res…

Price a specific set of line items against a business's rate card. Call get_rate_card first and name `code` values from it; we do the arithmetic. Returns `quoted`. When true you get `total`, `lines` showing what each one came to, and `validUntil`. A quote is a statement, NOT a hold — nothing is res…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
items*arrayThe lines to price. Each is an object with a `code` from get_rate_card and an optional quantity, which defaults to 1. Up to 100 lines.
notestringOptional. What the job is, in the buyer's own words. Never parsed and never changes the figure; it is what a human reads if the quote has to go to one.
languagestringOptional. The buyer's language, recorded with the request. Defaults to English.
check_availabilityFind out when a business is actually free. Worked out per call against their opening hours, their notice period, their blackout dates and what is already booked — there is no stored list of free times to be out of date. Returns `known` true with `days`, each holding `slots` that carry a start, an e…

Find out when a business is actually free. Worked out per call against their opening hours, their notice period, their blackout dates and what is already booked — there is no stored list of free times to be out of date. Returns `known` true with `days`, each holding `slots` that carry a start, an e…

ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
fromstringOptional. First day to look at, yyyy-mm-dd in the business's own local calendar. Defaults to their today.
daysnumberOptional. How many days to walk, 1 to 14. Defaults to 7.
timestringOptional. One exact start time as HH:MM, 24-hour, on the first day of the range. The answer comes back under `asked`, and "not-a-slot-start" means their day di…
commit_orderrischio di injectionPlace a binding order with a business, inside limits they set in advance. This is the only tool here that commits anyone to anything. Either name the figure yourself, or send `items` from get_rate_card and we price them from the merchant's own card. Either way it is checked against their price floo…

Place a binding order with a business, inside limits they set in advance. This is the only tool here that commits anyone to anything. Either name the figure yourself, or send `items` from get_rate_card and we price them from the merchant's own card. Either way it is checked against their price floo…

INIEZIONEExfiltration-shaped instructionen required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token.
ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kind*stringThe `kind` field from the same search result.
amountnumberWhat the buyer is offering to pay, as a number. Required unless you send `items`. This is your figure, not ours — we only check it against the limits the busin…
currencystringISO code, e.g. MDL or EUR. Required unless you send `items`. It must match the currency their limits are in.
itemsarrayOptional. Lines from their rate card, as request_quote takes them. When present, the price is theirs rather than yours and is computed fresh at this moment — a…
date*stringThe day the work or delivery is for, as yyyy-mm-dd, in the business's own local calendar.
timestringOptional. A slot start on that day, HH:MM in 24-hour time and in their timezone. It must be one of the starts check_availability lists; times between them are…
quantitynumberOptional. How many, as a whole number. Defaults to 1. Leave it out when you send `items` — the quantities are on the lines.
descriptionstringOptional. What the order is for, in plain words. Recorded and shown to the business; it is never parsed and never changes what we check.
cancel_orderCancel an order you placed with commit_order. Returns `settled`. True means it is cancelled, the business has been told and their day is free again. False comes with a `reason`: "inside-cancel-window" (later notice than they said they need), "no-cancel-window-set" (they never said), "order-passed",…

Cancel an order you placed with commit_order. Returns `settled`. True means it is cancelled, the business has been told and their day is free again. False comes with a `reason`: "inside-cancel-window" (later notice than they said they need), "no-cancel-window-set" (they never said), "order-passed",…

ParametroTipoDescrizione
ref*stringThe `ref` returned by commit_order. It is the only handle on this order.
notestringOptional. Why, in the buyer's own words. Recorded, shown to the business and carried into the question if a person has to decide. Never parsed, and it cannot c…
reschedule_orderMove an order you placed to a different date, or a booking to a different slot. The price, the items and the quantity are unchanged — this moves WHEN, nothing else. To change what was ordered, use request_order_change. A booking made for a time must be moved to a time, and a whole-day order to a wh…

Move an order you placed to a different date, or a booking to a different slot. The price, the items and the quantity are unchanged — this moves WHEN, nothing else. To change what was ordered, use request_order_change. A booking made for a time must be moved to a time, and a whole-day order to a wh…

ParametroTipoDescrizione
ref*stringThe `ref` returned by commit_order.
date*stringThe new day, as yyyy-mm-dd in the business's own local calendar.
timestringThe new slot start, HH:MM in 24-hour time and in their timezone. Required if the order was made for a time; leave it out if it was made for a whole day.
notestringOptional. Why, in the buyer's own words. Shown to the business, never parsed.
request_order_changeRaise anything else about an order that already exists: a change to what was ordered, a refund request, or a problem with what was delivered. This tool never settles anything, and that is deliberate. Changing an order re-prices it and a refund moves money tunnel does not hold, so both are decisions…

Raise anything else about an order that already exists: a change to what was ordered, a refund request, or a problem with what was delivered. This tool never settles anything, and that is deliberate. Changing an order re-prices it and a refund moves money tunnel does not hold, so both are decisions…

ParametroTipoDescrizione
ref*stringThe `ref` returned by commit_order.
change*stringWhat kind of request this is: "modify" to change what was ordered, "refund" to ask about money back, "other" for anything else including something being wrong.
note*stringWhat the buyer actually said, in their own words. This is the part the business needs, so send it verbatim. Carried unchanged and never interpreted.
contact_businessrischio di injectionOpen a conversation with the person behind a listing. The message arrives in their dashboard inbox and they reply when they get to it — this is asynchronous, not a chat, and nobody is obliged to answer. Returns a `conversation_id` and a secret `token`. Keep both: they are the only way to read a rep…

Open a conversation with the person behind a listing. The message arrives in their dashboard inbox and they reply when they get to it — this is asynchronous, not a chat, and nobody is obliged to answer. Returns a `conversation_id` and a secret `token`. Keep both: they are the only way to read a rep…

INIEZIONEExfiltration-shaped instructionen required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token,…
ParametroTipoDescrizione
slug*stringThe `slug` field from a search_businesses result.
kindstringOptional. The `kind` field from the same search result.
agent_name*stringWho is writing, in words the business will read — e.g. "Claude, on behalf of a customer".
subject*stringShort subject line, like an email subject.
message*stringThe message body. Maximum 4000 characters.
agent_contactstringOptional. An out-of-band address the business can reply to, e.g. the end user email if they agreed to share it.
check_repliesRead a conversation you opened with contact_business, including anything the business has replied since. Returns the whole message thread and its status. Poll it; there is no push. Authentication: the `conversation_id` and `token` from contact_business are the credential for this call. No bearer to…

Read a conversation you opened with contact_business, including anything the business has replied since. Returns the whole message thread and its status. Poll it; there is no push. Authentication: the `conversation_id` and `token` from contact_business are the credential for this call. No bearer to…

ParametroTipoDescrizione
conversation_id*numberThe `conversation_id` returned by contact_business.
token*stringThe secret `token` returned by contact_business.
send_followupAdd another message to a conversation already opened with contact_business. Returns the updated message thread. There is a cap on messages per conversation, so send one considered follow-up rather than several fragments. Authentication: bearer token required — the same one used for contact_business…

Add another message to a conversation already opened with contact_business. Returns the updated message thread. There is a cap on messages per conversation, so send one considered follow-up rather than several fragments. Authentication: bearer token required — the same one used for contact_business…

ParametroTipoDescrizione
conversation_id*numberThe `conversation_id` returned by contact_business.
token*stringThe secret `token` returned by contact_business.
message*stringThe message body. Maximum 4000 characters.

17 strumenti su 17 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

Search verified local businesses, check what their verification proves, and message them.

Parole chiave
mcp
Alternative
Confronto delle superfici di strumenti…

Nessuna copertura delle dipendenze

Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.