| Summary | Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls — DROP TABLE, rm -rf, force-push — before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0. | Scan/purge hidden text & score web domains: TLS, DNS, headers, speed. Free scans, $0.01 actions.
The Tools:
-
text_scan_v1 — free
Scans a text string for invisible Unicode characters, homoglyphs, and normalization issues. Returns a risk score, a list of flagged characters, and detected homoglyphs. Never modifies the input text.
-
text_purge_v1 — $0.01 per call
Removes invisible Unicode characters and replaces homoglyphs in a text string, then normalizes the result. Returns the cleaned text plus a before-and-after risk comparison.
-
domain_check_score_v1 — free
Overall score, per-category scores, and how many findings each category raised. Use it to triage: rank a list of domains, confirm one is healthy, or decide whether the full report is worth pulling. It tells you which categories are weak and how many issues they hold, but not what the issues are.
-
domain_check_score_batch_v1 — free
The same triage scores for up to 100 domains in a single call. One score summary per distinct domain: overall score, per-category scores, and how many findings each category raised. Never the findings themselves.
-
domain_check_v1 — $0.01 per call
Full report for one domain: weighted score out of 100, per-category breakdown, and every individual finding with a prioritised remediation order.
-
domain_check_batch_v1 — from $0.005 per domain
The same full report for up to 100 domains in a single call, with one payment for the whole batch instead of one per domain. Both cheaper per domain and much faster than calling
domain_check_v1 in a loop.
|
|---|