{"slug":"x402-api-catalog-onrender-com-api-mcp-audit-712691","title":"MCP server safety audit","host":"x402-api-catalog.onrender.com","method":"GET","resource":"https://x402-api-catalog.onrender.com/api/mcp-audit","category":"code","description":"MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+cre","price_listed":0.06,"price_asked":0.06,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":229,"reported_calls_30d":2,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"repo":"example-org/example-mcp-server","url":"https://mcp.example.com/mcp"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"repo":{"description":"optional owner/repo to fold in a GitHub supply-chain signal","type":"string"},"url":{"description":"base URL of the MCP server (streamable-HTTP transport)","type":"string"}},"required":["url"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"score":{"type":"number"},"url":{"type":"string"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.06,"price_match":true,"latency_ms":229,"error":null}],"description_full":"MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too.","last_updated":"2026-09-07T17:52:09.026Z","schemes":["exact"]}