# com.mcp-revenue-empire/japan-public-ledgers

Tamper-evident daily ledgers of 12 Japanese public-data domains, with cross-ledger entity search.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.2
- **Author:** com.mcp-revenue-empire
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.mcp-revenue-empire.com/mcp
- **Source:** https://mcp.mcp-revenue-empire.com/mcp
- **Endpoint health:** reachable (last checked 2026-09-05T15:33:33.957Z, 3 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-05T15:33:33.957Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

172 declared. Observed from a live `tools/list` probe.
- `verify_receipt` — Verify a provenance receipt (F-037): recomputes the HMAC signature, checks the intra-receipt chain linkage, and — when the receipt carries an external anchor re
- `agent_memory_store` — Store a memory for an AI agent (key-value, with TTL and metadata)
- `agent_memory_get` — Retrieve a stored memory by key
- `agent_memory_search` — Search memories by prefix, tags, or type
- `agent_memory_delete` — Delete a memory or all memories in a namespace
- `agent_audit_record` — Record an agent action for audit and compliance
- `agent_audit_query` — Query agent actions with filters
- `agent_audit_report` — Generate audit report (json/markdown/soc2 format)
- `agent_tempmail_create` — Create a temporary email address (auto-expires)
- `agent_tempmail_list` — List received messages in a mailbox
- `agent_tempmail_get` — Get full message content with extracted verification links/codes
- `agent_tempmail_wait` — Wait for an incoming message (long polling, max 60s)
- `agent_captcha_verify_domain` — Verify ownership of a domain before using CAPTCHA solving
- `agent_captcha_solve` — Solve a CAPTCHA for a domain you own or have explicit permission to access
- `agent_proxy_fetch` — Fetch a URL via a rotating proxy (region/type selectable). robots.txt enforced.
- `agent_proxy_session` — Create a sticky proxy session (same IP for multiple requests)
- `agent_trust_score` — Get trust score for a wallet, agent card URL, or domain
- `agent_trust_feedback` — Submit feedback about an agent/wallet (positive or negative)
- `agent_trust_batch` — Get trust scores for multiple subjects in one call (max 100)
- `agent_webhook_create` — Create a webhook endpoint that relays requests to your agent
- `agent_webhook_poll` — Poll for new webhook requests (long polling, max 60s)
- `agent_webhook_replay` — Replay a stored webhook request
- `agent_webhook_list_requests` — List requests received by a webhook endpoint
- `agent_identity_register` — Register an agent and get a unique identity ID + issuer-signed badge. agent_name/metadata are self-reported and unverified.
- `agent_identity_badge` — Get the issuer-signed badge and signed fields for an identity
- `agent_identity_lookup` — Look up an identity. Returns signatureValid (issuer+integrity only, NOT an authenticity/safety signal) and a disclaimer.
- `agent_identity_record` — Append a hash-chained activity record (owner only). Optional provenance (repo/version/config) is self-reported.
- `agent_identity_activities` — List activity records for an identity, newest first (owner only)
- `subsidy_watch_search` — Search the current state of subsidy programs. Each hit includes firstSeenAt and ledgerVerified (hash-chain integrity).
- `subsidy_watch_get` — Get a subsidy program detail plus full event timeline. Returns firstSeenAt and ledgerVerified.
- `subsidy_watch_timeline` — Time-ordered events only for a program (the differentiator: when it appeared, changed, closed). Includes firstSeenAt and ledgerVerified.
- `subsidy_watch_recent_changes` — Recent appearance / change / close events across all programs since the given ISO8601 timestamp. Each item includes firstSeenAt and ledgerVerified.
- `subsidy_watch_verify_ledger` — Verify the hash-chain integrity of a program (tamper detection). Returns chainValid, brokenAt (if any), checked event count, firstSeenAt and ledgerVerified.
- `pubcom_watch_search` — Search e-Gov public-comment notices. Each hit includes firstSeenAt and ledgerVerified (hash-chain integrity).
- `pubcom_watch_get` — Get a public-comment notice detail plus full event timeline. Returns firstSeenAt and ledgerVerified.
- `pubcom_watch_timeline` — Time-ordered events only for a notice (the differentiator: when it opened, deadline moved, closed, or result was published). Includes firstSeenAt and ledgerVeri
- `pubcom_watch_recent_changes` — Recent appearance / deadline-move / close / result-published events across all notices since the given ISO8601 timestamp. Each item includes firstSeenAt and led
- `pubcom_watch_verify_ledger` — Verify the hash-chain integrity of a notice (tamper detection). Returns chainValid, brokenAt (if any), checked event count, firstSeenAt and ledgerVerified.
- `grant_watch_search` — Search Japanese research-grant calls-for-proposals. Each hit includes firstSeenAt and ledgerVerified (hash-chain integrity).
- `grant_watch_get` — Get a grant call detail plus full event timeline. Returns firstSeenAt and ledgerVerified.
- …and 132 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"japan-public-ledgers\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.mcp-revenue-empire.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 33, ceiling 57 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.mcp-revenue-empire%2Fjapan-public-ledgers
- Install plan: https://forgeregistry.com/api/v1/packages/com.mcp-revenue-empire%2Fjapan-public-ledgers/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.mcp-revenue-empire%2Fjapan-public-ledgers
- HTML page: https://forgeregistry.com/registry/com.mcp-revenue-empire%2Fjapan-public-ledgers
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
