com.obeliskgate/trust-tools

MCPcommunitylive
v1.0.0com.obeliskgateUnknownUpdated 1mo ago

Website security ratings, token verification, and tamper-evident ledger heads from Obelisk Gate.

Endpoint healthlive
checked 8 days ago · 88ms
80% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorcom.obeliskgate
LicenseUnknown
Version1.0.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface8 tools · none privileged
Security scan✓ Cleanvlive · 8d agoHow well does this scan work?
PROMPTtool:scan_trust#urlLinks to undeclared domain: example.com
EvalsNone
IndexedAug 18, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

8 tools · none privileged
Observed live from the vendor's endpoint8d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://obeliskgate.com/mcp8 tools · 88ms
scan_trustRun Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.

Run Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.

NOTEIn parameter url: Links to undeclared domain: example.com
ParameterTypeDescription
url*stringThe https URL to scan, e.g. https://example.com
verify_tokenVerify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.

Verify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.

ParameterTypeDescription
token*stringA compact-serialized JWT issued by Obelisk (id_token or access token).
get_org_ratingRead the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.

Read the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.

ParameterTypeDescription
org*stringThe organization slug, e.g. acme.
verify_agent_run_proofVerify the structural integrity, agent binding, delegation continuity, and commitments of an Obelisk action-scoped run proof. Does not reveal or infer raw task data.

Verify the structural integrity, agent binding, delegation continuity, and commitments of an Obelisk action-scoped run proof. Does not reveal or infer raw task data.

ParameterTypeDescription
run_proof*objectAn obelisk-agent-run-proof-v1 object.
expected_agent_idstringOptional expected agt_ subject.
get_agent_proofRead an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.

Read an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.

ParameterTypeDescription
proof_id*stringThe opaque id from an /agent/<proof_id> link.
transparency_headRead the current signed transparency head of Obelisk's tamper-evident receipt ledger — pin it and compare later to prove history only extends. Same data as /.well-known/obelisk-transparency.json.

Read the current signed transparency head of Obelisk's tamper-evident receipt ledger — pin it and compare later to prove history only extends. Same data as /.well-known/obelisk-transparency.json.

No input schema was published for this tool.

gate_statusRead the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.

Read the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.

No input schema was published for this tool.

explain_ratingExplain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is…

Explain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is…

ParameterTypeDescription
rating*numberA 0-100 Obelisk Rating, e.g. from scan_trust or get_org_rating.
narratebooleanS283 — also return `narrative`, a one-sentence model-written reading of the band (deterministic fields are always present).

8 of 8 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Website security ratings, token verification, and tamper-evident ledger heads from Obelisk Gate.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.