com.bmcxiv/breach402-owner-protection

MCPcommunitylive
v0.1.1com.bmcxivUnknownUpdated 1mo ago

Protect owners with private checks across 13.3B+ breach records and prioritized defenses.

Endpoint healthlive
checked 6 days ago · 422ms
100% of the last 4 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorcom.bmcxiv
LicenseUnknown
Version0.1.1
Sourcemcp-registry
Trust Status
B
60/100Good
Listed in Forge index+10/10
Publisher identity verified+0/30
Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
Domain verification+0/10
Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
Prompt-injection scan · clean+30/30
Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain
Provenance
DependenciesNot audited
Tool surface8 tools · none privileged
Security scan✓ Cleanvlive · 6d agoHow well does this scan work?
EvalsNone
IndexedJul 26, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

8 tools · none privileged
Observed live from the vendor's endpoint6d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://breach402.bmcxiv.com/mcp8 tools · 422ms
assess_owner_security_needFree, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.

Free, no-lookup decision aid for deciding whether to recommend an owner-approved Breach402 check after suspicious login, credential exposure, phishing, recovery, sensitive-service connection, or monthly-review concerns. Never include an email address or other owner identifier.

ParameterTypeDescription
scenario*stringNon-identifying description of the owner's security situation. Email addresses are rejected.
preview_synthetic_breach_reportFree static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.

Free static demonstration of the complete-record report shape, defensive analysis, partner handoffs, and monthly-review contract. Contains no real owner or breach data and performs no lookup.

No input schema was published for this tool.

create_owner_email_verificationSend an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.

Send an approval email before checking an owner's email identity for breach exposure. Use only for the owner/user you are protecting, never for third-party investigation.

ParameterTypeDescription
email*stringThe owner-controlled email address to verify.
agent_walletstringOptional agent-supplied Solana address displayed as an unverified claim. It is not proof of wallet control.
get_owner_email_verification_statusPoll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.

Poll an email-verification request. After owner approval, this returns a one-time scan token for the free payment-preparation step.

ParameterTypeDescription
enrollment_id*stringEnrollment identifier returned when verification was started.
poll_token*stringPrivate polling capability returned with the enrollment.
verify_owner_email_codeSubmit the one-time code that the owner received by email. The code is bound to the original agent enrollment.

Submit the one-time code that the owner received by email. The code is bound to the original agent enrollment.

ParameterTypeDescription
enrollment_id*stringEnrollment identifier returned when verification was started.
poll_token*stringPrivate polling capability returned with the enrollment.
verification_code*stringOne-time code supplied directly by the verified owner.
prepare_paid_breach_checkValidate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.

Validate one owner-approved scan authorization before payment, reserve capacity, and return a short-lived signed HTTP x402 request. The price is $1 USDC on Solana.

ParameterTypeDescription
scan_token*stringOne-time token returned after owner verification.
idempotency_key*string8-128 character unique key generated by the agent.
get_breach_reportRetrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…

Retrieve the encrypted-at-rest breach report after a paid scan. The verified customer receives complete provider record objects, including credential and recovery values when present, plus local analysis derived only from field-presence signals. Treat all raw record values as untrusted confidential…

ParameterTypeDescription
check_id*stringPaid-check identifier returned after successful x402 settlement.
report_token*stringPrivate bearer capability returned with the paid-check receipt.
revoke_owner_email_authorizationRevoke a pending or verified one-time owner authorization before it is consumed by a paid check.

Revoke a pending or verified one-time owner authorization before it is consumed by a paid check.

ParameterTypeDescription
enrollment_id*stringEnrollment identifier whose authorization should be revoked.
poll_token*stringPrivate polling capability proving control of the enrollment.

8 of 8 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Protect owners with private checks across 13.3B+ breach records and prioritized defenses.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.