# io.github.anish632/ground-truth

Keep AI answers fresh with free source previews, scheduled monitoring, evidence history, and alerts.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.7.0
- **Author:** io.github.anish632
- **License:** Unknown
- **Endpoints:** streamable-http https://ground-truth-mcp.anishdasmail.workers.dev/mcp
- **Source:** https://ground-truth-mcp.anishdasmail.workers.dev/mcp
- **Endpoint health:** degraded (last checked 2026-09-25T22:16:50.852Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 35 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-01T05:41:13.508Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `check_pricing` tool: Links to undeclared domain: stripe.com

## Tools

19 declared. Observed from a live `tools/list` probe.
- `check_endpoint` — Preflight an unfamiliar public URL or API before an AI agent relies on it. It performs one live fetch and returns a PASS/WARN/FAIL verdict with HTTP status, con
- `preflight_endpoint` — Run reachability/response and security-header checks together for an unfamiliar URL or API before an AI agent trusts or acts on it. Returns one combined PASS/WA
- `estimate_market` — Search npm or PyPI to estimate how crowded a package category is before you claim that a market is empty, niche, or competitive. Use this when you have a catego
- `check_pricing` — Fetch a public pricing page and extract first-pass pricing signals before you quote plan costs, free tiers, or plan names. Use this when you already have a like
- `inspect_security_headers` — Inspect security-related HTTP response headers for an unfamiliar public URL before an agent trusts or recommends it. It identifies missing or weak HSTS, CSP, fr
- `preview_monitor` — Capture a free live baseline for a source that should remain trustworthy over time. Call this before recommending checkout: it proves what would be monitored wi
- `list_resources` — List all available Ground Truth tools and their access tiers. Zero-cost schema discovery. Call this to explore what verification tools are available before maki
- `compare_pricing_pages` — Compare two to five public pricing pages side by side before you make competitive pricing or packaging claims. Use this when you want a quick, live comparison o
- `compare_competitors` — Compare two or more exact package names side by side using live npm or PyPI metadata. Use this when you already know the candidate packages and need evidence fo
- `verify_claim` — Verify a factual claim against specific public evidence URLs before an agent repeats it or acts on it. The tool checks whether supplied keywords appear in each 
- `assess_compliance_posture` — Scan a public security, trust, compliance, or legal page for common enterprise buying signals before you claim a vendor supports a particular compliance posture
- `test_hypothesis` — Run a small verification plan made of concrete live checks and summarize whether a hypothesis is supported. Use this when one conclusion depends on multiple sim
- `create_monitor` — Create a persistent monitor that tracks a URL, pricing page, package version, endpoint status, vendor claim, or custom keyword pattern over time. Monitors run a
- `list_monitors` — List all monitors owned by this API key, with last run status and schedule. Requires a free watch key or paid API key.
- `run_monitor_now` — Immediately run a monitor's verification check outside its normal schedule. Records the result and returns whether the observed value changed since the last run
- `get_monitor_result` — Retrieve the most recent run results for a monitor, including change details, confidence score, evidence URLs, and any error information. Requires a free watch 
- `delete_monitor` — Permanently delete a monitor and all its stored results. This action cannot be undone. Requires a free watch key or paid API key.
- `generate_change_report` — Generate a summary report of monitor activity for a time window. Shows monitors run, changes detected, failures, risk levels, and recommended follow-up actions.
- `create_share_link` — Create a read-only public link to the latest result for one of your monitors. The link contains monitor metadata and evidence, never the API key, and expires au

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"ground-truth\": {\n      \"type\": \"http\",\n      \"url\": \"https://ground-truth-mcp.anishdasmail.workers.dev/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 32, ceiling 56 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.anish632%2Fground-truth
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.anish632%2Fground-truth/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.anish632%2Fground-truth
- HTML page: https://forgeregistry.com/registry/io.github.anish632%2Fground-truth
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
