Protect owners with private checks across 13.3B+ breach records and prioritized defenses.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://breach402.bmcxiv.com/mcp8 tools · 422msassess_owner_security_needFree, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.Free, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.
| Parameter | Type | Description |
|---|---|---|
| scenario* | string | Non-identifying description of the owner's security situation. Email addresses are rejected. |
preview_synthetic_breach_reportFree static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.Free static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.
No input schema was published for this tool.
create_owner_email_verificationSend an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.Send an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.
| Parameter | Type | Description |
|---|---|---|
| email* | string | The owner-controlled email address to verify. |
| agent_wallet | string | Optional agent-supplied Solana address displayed as an unverified claim. It is not proof of wallet control. |
get_owner_email_verification_statusPoll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.Poll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.
| Parameter | Type | Description |
|---|---|---|
| enrollment_id* | string | Enrollment identifier returned when verification was started. |
| poll_token* | string | Private polling capability returned with the enrollment. |
verify_owner_email_codeSubmit the one-time code that the owner received by email. The code is bound to the original agent enrollment.Submit the one-time code that the owner received by email. The code is bound to the original agent enrollment.
| Parameter | Type | Description |
|---|---|---|
| enrollment_id* | string | Enrollment identifier returned when verification was started. |
| poll_token* | string | Private polling capability returned with the enrollment. |
| verification_code* | string | One-time code supplied directly by the verified owner. |
prepare_paid_breach_checkValidate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.Validate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.
| Parameter | Type | Description |
|---|---|---|
| scan_token* | string | One-time token returned after owner verification. |
| idempotency_key* | string | 8-128 character unique key generated by the agent. |
get_breach_reportRetrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…Retrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…
| Parameter | Type | Description |
|---|---|---|
| check_id* | string | Paid-check identifier returned after successful x402 settlement. |
| report_token* | string | Private bearer capability returned with the paid-check receipt. |
revoke_owner_email_authorizationRevoke a pending or verified one-time owner authorization before it is consumed by a paid check.Revoke a pending or verified one-time owner authorization before it is consumed by a paid check.
| Parameter | Type | Description |
|---|---|---|
| enrollment_id* | string | Enrollment identifier whose authorization should be revoked. |
| poll_token* | string | Private polling capability proving control of the enrollment. |
8 of 8 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Protect owners with private checks across 13.3B+ breach records and prioritized defenses.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.