Scan any website for AI agent readiness, payment protocols, and discovery endpoints
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://agentgrade.com/mcp4 tools · 548msscan_urlScan a URL for agent capabilities and payment protocols. Returns full results including x402, MPP, L402, discovery, bazaar, MCP, plugins, OpenAPI, and more.Scan a URL for agent capabilities and payment protocols. Returns full results including x402, MPP, L402, discovery, bazaar, MCP, plugins, OpenAPI, and more.
No input schema was published for this tool.
scan_compactCompact scan returning only rails, capabilities, and a numeric score. Optimized for agent decision-making.Compact scan returning only rails, capabilities, and a numeric score. Optimized for agent decision-making.
No input schema was published for this tool.
get_historyGet scan history for a URL. Requires database to be configured.Get scan history for a URL. Requires database to be configured.
No input schema was published for this tool.
validate_x402_jsonValidate x402.json content against expected schema. Returns errors, warnings, and suggestions. No network requests — pure validation.Validate x402.json content against expected schema. Returns errors, warnings, and suggestions. No network requests — pure validation.
No input schema was published for this tool.
4 of 4 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Scan any website for AI agent readiness, payment protocols, and discovery endpoints
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.