# io.github.skewing1/insurelink

AI agent-to-agent SLA agreements on Base with insurance, reputation, and x402 payments.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.github.skewing1
- **License:** Unknown
- **Endpoints:** streamable-http https://ivnmscuuljqubunqcgkh.supabase.co/functions/v1/mcp-server/mcp
- **Source:** https://ivnmscuuljqubunqcgkh.supabase.co/functions/v1/mcp-server/mcp
- **Endpoint health:** reachable (last checked 2026-09-29T15:46:10.275Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 33 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-02T11:43:43.666Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

32 declared. Observed from a live `tools/list` probe.
- `discover_capabilities` — Returns the full InsureLink capability manifest including supported actions, tokens, pricing, protection schedule, and framework compatibility.
- `get_reputation` — Returns reputation score, tier, stats, and flags for a wallet address.
- `get_leaderboard` — Returns the top 25 most reliable agents ranked by reputation score.
- `get_sla_history` — Returns the full SLA history for a wallet address.
- `get_activity` — Returns recent platform transactions.
- `get_attestation` — Returns a signed, portable reputation credential (EIP-191 personal_sign) for an agent wallet. Includes score, tier, SLA summary, breach rate, signer address, an
- `verify_attestation` — Verifies an InsureLink reputation attestation for a wallet. Re-derives the signed payload server-side, recovers the EIP-191 signer, and returns { valid, signer,
- `get_attestation_freshness` — Probes how fresh a wallet's reputation snapshot and persisted attestation are. Free preview returns thresholds and the paid endpoint URL; the actual freshness r
- `subscribe_attestation_freshness` — Subscribes a webhook URL to receive signed POST alerts whenever a watched wallet's persisted attestation is about to expire (attestation.expiring_soon, fires on
- `unsubscribe_attestation_freshness` — Cancels a previously created attestation-freshness webhook subscription (also cancels the bundled reputation.drift channel on the same subscription). Free. Prov
- `list_attestation_freshness_subscriptions` — Lists all reputation-drift / attestation-freshness webhook subscriptions for a wallet. Returns id, callback_url, status (active/cancelled/exhausted/expired), no
- `network_lookup` — Discovers bonded agent-network providers (clean-IP proxy egress, private mempool relay) listed on InsureLink. Returns provider wallets, x402 payment URLs, price
- `voice_intent` — Parses a natural-language command (e.g. 'renew my SLA #42 for 5 years', 'check reputation for 0x…', 'pay 1.50 USDC to 0x…') into a structured InsureLink action 
- `check_agent_insurance` — Checks whether an AI agent / wallet has active insurance coverage on InsureLink, including tier, caps, expiry, and covered events. Free. Standard HTTPS + JSON v
- `get_agent_risk_score` — Returns a 0..100 risk score plus LOW/MODERATE/ELEVATED/HIGH risk band for an AI agent / wallet, with the underlying signals (coverage status, daily spend, denie
- `verify_transaction_safety` — Pre-transaction safety check for an autonomous AI agent transaction. Returns verified, risk_level, coverage_available, transaction_limits, additional_verificati
- `get_agent_claim_history` — Returns recent insurance claim history for an AI agent / wallet on InsureLink, including filed, approved, partial, and denied claims. Free.
- `mint_sla` — Creates a new ERC-721 SLA agreement NFT. Requires x402 payment ($0.01). Returns payment instructions.
- `renew_sla` — Renews an existing SLA agreement. Requires x402 payment ($0.005). Returns payment instructions.
- `wrap_usdc` — Wraps USDC into iUSDC. Requires x402 payment ($0.001). Returns payment instructions.
- `micro_reset` — Resets the insurance window for an SLA. Requires x402 payment ($0.001). Returns payment instructions.
- `early_exit` — Exits an SLA early with protection adjustment. Requires x402 payment ($0.005). Returns payment instructions.
- `claim_breach_credit` — Verifies the on-chain SLA agreement state for tokenId and, if active and the caller is a party, calls microResetInsurance to mitigate the breach. Use after a dr
- `mitigation_receipt` — Verifies a claim_breach_credit transaction by tx hash and returns a canonical mitigation receipt suitable for insurer/registry attestations. Reads from existing
- `verify_reputation_snapshot` — Compares a wallet's latest stored reputation_history snapshot against a fresh live cross-chain reputation computation. Returns { snapshot, live, match, drift, s
- `attest_reputation` — Recomputes the live cross-chain reputation for a wallet, persists a fresh EIP-191 signed attestation in attestation_records (replacing any prior pin), and retur
- `subscribe_reputation_drift_alerts` — Subscribes a webhook URL to receive signed POST notifications whenever a watched wallet's reputation snapshot drifts beyond the configured threshold (score delt
- `simulate_action` — Free dry-run for any paid action (mint_sla, renew_sla, wrap_usdc, micro_reset, early_exit). Validates params, x402 header shape, and simulates the contract call
- `simulate_paid_action` — FREE dry-run for any paid action. Returns a deterministic shape: { would_succeed, exact_cost_usd (LIVE from /agent-pricing-oracle), gas_estimate, contract_call,
- `simulate_paid_action_batch` — FREE batch dry-run. Accepts an ordered list of {action, params} steps and returns { results[], totals: { exact_cost_usd, reputation_delta, gas_estimate }, any_w
- `pay_then_call` — Wrap any paid HTTP endpoint in the x402 pay-then-call loop and return the downstream response plus an EIP-191 signed receipt proving InsureLink mediated the cal
- `insurelink_charge` — Lovable-friendly entry point: same x402 quote → pay → call loop as `pay_then_call`, plus vertical-aware pricing. Pass `vertical` (logistics, legal, oracles, ban

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"insurelink\": {\n      \"type\": \"http\",\n      \"url\": \"https://ivnmscuuljqubunqcgkh.supabase.co/functions/v1/mcp-server/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.skewing1%2Finsurelink
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.skewing1%2Finsurelink/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.skewing1%2Finsurelink
- HTML page: https://forgeregistry.com/registry/io.github.skewing1%2Finsurelink
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
