Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "agent_outcome_receipt", "agent_permission_vault" and "agent_spend_governor"; changed the definition of "action_lock" (21 tools before, 24 now)
⟨148 unchanged words⟩ "},{"type":"null"}]},"retry_decision":{"enum":["RETRY_ALLOWED","RETRY_LATER","DO_NOT_RETRY","REVIEW"],"type":"string"},"state":{"enum":["acquired","in_progress" ⟨17 unchanged words⟩ boolean"}},"required":["success","decision","retry_decision","state","action_id","lease_token","lease_expires_at ⟨6 unchanged words⟩
Create or verify a tamper-evident receipt of an agent-reported outcome. It proves DropEngine recorded a claim, not that the external event independently occurred. Do not send raw payloads or secrets. Price: $0.001 USDC per call. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and cal…
Check whether an owner-configured policy authorizes this capability for the verified caller. Permission check only; agents cannot grant themselves permission. This is authorization, not action safety. Price: $0.001 USDC per call. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and ca…
Enforce autonomous-agent budgets before paid actions. Call before spending; authorize, commit, release, or inspect an opaque reservation. Do not use for free operations or an equivalent trusted budget system. Price: $0.001 USDC per call. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recip…
Added "action_lock" (20 tools before, 21 now)
Action Lock ($0.001 USDC): Prevent duplicate side effects across agent retries, crashes, and concurrent workers. If an action has side effects and may be retried or executed concurrently, acquire before execution. Complete after confirmed success; release after confirmed failure. Use before payments, purchases, orders, emails, transactions, writes, and external tool actions. Avoid pure reads or equivalent provider-side idempotency. An expired lease can hide a completed external effect; reconcile first. Agent Action Gate asks whether an action should be performed; Action Lock asks whether it i…
Changed the definition of "analyze_whale_activity", "backtest_strategy", "check_change" and 17 more
⟨51 unchanged words⟩ does not claim complete balances or whale labels. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"dataagent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{
Added "preflight_action"; changed the definition of "check_package", "check_url", "extract_structured" and 1 more (19 tools before, 20 now)
⟨267 unchanged words⟩ ,"block"],"type":"string"},"recommended_next":{"additionalProperties":false,"properties":{"price":{"type":["string","null"]},"reason":{"type":"string"},"tool":{"type":"string"}},"required":["tool","reason","price"],"type":"object"},"reputation":{"enum":["good","neutral" ⟨131 unchanged words⟩
⟨40 unchanged words⟩ ,"block"],"type":"string"},"recommended_next":{"additionalProperties":false,"properties":{"price":{"type":["string","null"]},"reason":{"type":"string"},"tool":{"type":"string"}},"required":["tool","reason","price"],"type":"object"},"redirect_count":{"maximum":9007199254740991,"minimum":0,
Recently observed → Live
Live → Recently observed
Recently observed → Live
Live → Recently observed
Removed "estimate_trade_execution" (20 tools before, 19 now)
Paid Trade Execution Quote ($0.01 USDC). Gets an indicative swap quote before a trade; supports Solana via Jupiter and EVM via 0x when provider keys are configured. Requires token addresses and decimals for custom assets. Returns estimated output and quote source. Read-only: never signs, submits, or executes.
Recently observed → Live
Changed the definition of "mcp_server_inspect"
PaidMCPread-onlyserverMCPhealth check ($0.01 USDC on Base):verifyconnectatopublicanyHTTPSpublic MCP endpoint over HTTPS, confirm it is reachable, list its tool names,summarize
Live → Recently observed
Recently observed → Live
Changed the definition of "check_change", "extract_structured", "get_live_quote" and 1 more
before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"baseline_available":{"type":"boolean"},"cached":{"type":"boolean"},"change_score":{"type":"number"},"change_type":{"items":{"type":"string"},"type":"array"},"changed":{"type":"boolean"},"checked_at":{"type":"string"},"current_hash":{"type":"string"},"data_age_seconds":{"type":"number"},"diff":{"anyOf":[{"additionalProperties":false,"properties":{"added":{"items":{"type":"string"},"type":"array"},"removed":{"items":{"type":"string"},"type":"array"}},"required":["added","removed"],"type":"object"},{"type":"null"}]},"previous_hash":{"type":"string"},"success":{"const":true,"type":"boolean"},"summary":{"additionalProperties":false,"properties":{"price_changed":{"type":["boolean","null"]},"stock_changed":{"type":["boolean","null"]}},"required":["price_changed","stock_changed"],"type":"object"}},"required":["success","changed","baseline_available","current_hash","previous_hash","change_score","change_type","diff","summary","cached","data_age_seconds","checked_at"],"type":"object"}Live → Recently observed
Certificate recorded, valid to 2026-12-22
Recently observed → Live
Changed the definition of "check_package", "check_url" and "token_security_audit"
before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"cached":{"type":"boolean"},"checked_at":{"format":"date-time","pattern":"^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$","type":"string"},"data_freshness_seconds":{"minimum":0,"type":"number"},"degraded":{"type":"boolean"},"dependencies_analyzed":{"maximum":9007199254740991,"minimum":0,"type":"integer"},"dependency_count":{"maximum":9007199254740991,"minimum":0,"type":"integer"},"dependency_findings":{"items":{"additionalProperties":false,"properties":{"known_malicious":{"type":["boolean","null"]},"package":{"type":"string"},"risk":{"enum":["low","medium","high","critical","unknown"],"type":"string"},"version":{"type":"string"},"vulnerabilities":{"items":{"type":"string"},"type":"array"}},"required":["package","version","known_malicious","vulnerabilities","risk"],"type":"object"},"type":"array"},"dependency_risk":{"enum":["low","medium","high","unknown"],"type":"string"},"deprecated":{"type":"boolean"},"ecosystem":{"const":"npm","type":"string"},"install_script_risk":{"enum":["low","medium","high","critical","unknown"],"type":"string"},"known_malicious":{"type":["boolean","null"]},"known_vulnerabilities":{"items":{"additionalProperties":false,"properties":{"affected":{"const":true,"type":"boolean"},"fixed_version":{"type":["string","null"]},"id":{"type":"string"},"severity":{"enum":["low","medium","high","critical","unknown"],"type":"string"},"summary":{"type":["string","null"]}},"required":["id","summary","severity","affected","fixed_version"],"type":"object"},"type":"array"},"maintainer_count":{"anyOf":[{"maximum":9007199254740991,"minimum":0,"type":"integer"},{"type":"null"}]},"maintainer_risk":{"enum":["low","medium","high","unknown"],"type":"string"},"malicious_confidence":{"anyOf":[{"enum":["low","medium","high"],"type":"string"},{"type":"null"}]},"new_package":{"type":["boolean","null"]},"package":{"type":"string"},"package_age_days":{"anyOf":[{"maximum":9007199254740991,"minimum":0,"type":"integer"},{"type":"null"}]},"recommendation":{"enum":["allow","caution","block"],"type":"string"},"reputation":{"enum":["good","neutral","suspicious","malicious","unknown"],"type":"string"},"requested_version":{"type":["string","null"]},"resolved_version":{"type":"string"},"risk_confidence":{"enum":["low","medium","high"],"type":"string"},"risk_level":{"enum":["low","medium","high","critical"],"type":"string"},"risk_score":{"maximum":100,"minimum":0,"type":"integer"},"similar_to":{"type":["string","null"]},"similarity_score":{"anyOf":[{"maximum":1,"minimum":0,"type":"number"},{"type":"null"}]},"sources":{"items":{"type":"string"},"type":"array"},"success":{"const":true,"type":"boolean"},"suspicious_scripts":{"items":{"additionalProperties":false,"properties":{"name":{"type":"string"},"signals":{"items":{"type":"string"},"type":"array"}},"required":["name","signals"],"type":"object"},"type":"array"},"typosquat_risk":{"enum":["low","medium","high","critical","unknown"],"type":"string"},"warnings":{"items":{"type":"string"},"type":"array"}},"required":["success","ecosystem","package","requested_version","resolved_version","risk_score","risk_level","risk_confidence","recommendation","known_malicious","malicious_confidence","known_vulnerabilities","typosquat_risk","similar_to","similarity_score","install_script_risk","suspicious_scripts","dependency_risk","dependency_count","dependencies_analyzed","dependency_findings","maintainer_risk","maintainer_count","reputation","package_age_days","new_package","deprecated","warnings","sources","degraded","cached","checked_at","data_freshness_seconds"],"type":"object"}Live → Recently observed
Changed the definition of "check_package"
⟨37 unchanged words⟩ static analysis only. Package code is never executed.DirectChecksdependencyuptreestoand10maintainerdirecthistorydependenciesarewhen their versions can be resolved; it does notassessed;traverseunknown
First tool surface recorded: 4 tools (server version 1.5.0)
https://mcp.dropenginehq.com/api/invoice-mcp (mcp_streamable_http) — from mcp_registry
Certificate recorded, valid to 2026-12-22
Authorization not required
Added "analyze_whale_activity", "backtest_strategy", "estimate_trade_execution" and 2 more; changed the definition of "verify_claim" (15 tools before, 20 now)
⟨15 unchanged words⟩ search evidence and returns supported/contradicted/mixed/insufficient/stale with sources. RequiresoptionalTAVILY_API_KEY.TAVILY_API_KEY;Ifwithouttheevidencekeysearchisitmissing, returnsinsufficient_evidence.a provider-unavailable error before requesting payment. Claim text is sent to the configured search provider.
Added "check_change", "extract_structured", "get_live_quote" and 1 more (11 tools before, 15 now)
Paid Change / Diff Check ($0.001 USDC). Checks normalized text on a public HTTPS page against a previous SHA-256 hash, returning a compact diff when a prior snapshot is available.
Paid Fresh Structured Extract ($0.01 USDC). Extracts a fresh webpage into a simple agent-defined typed JSON shape, with validation and per-field provenance. Uses static page data only; never executes page JavaScript and never fabricates missing fields.
Paid Live Product Quote ($0.01 USDC). Retrieves explicitly published product price and stock from a public HTTPS product page before an agent buys; shipping, tax and unknown values remain null. Never purchases.
Paid Freshness / Claim Verifier ($0.02 USDC). Checks a factual claim against fresh web search evidence and returns supported/contradicted/mixed/insufficient/stale with sources. Requires optional TAVILY_API_KEY; without evidence search it returns insufficient_evidence. Claim text is sent to the configured search provider.
Unknown → Live
First tool surface recorded: 11 tools (server version 1.5.0)
https://mcp.dropenginehq.com/api/paid-mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 29 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨38 unchanged words⟩ executes user code. Historical results are not predictions. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"dataagent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"metanext":{"additionalPropertiesitems":false{},"propertiestype":{"cachearray"},"payment":{"additionalProperties":false,"properties":{"age_msexecution_status":{"minimumenum":0["not_started","succeeded","failed","unknown"],"type":"numberstring"},"hitstatus":{"enum":["not_required","required","settled","failed","unknown"],"type":"booleanstring"}},"required":["hitstatus","age_msexecution_status"],"type":"object"},"failed_sourcesresult":{},"itemsstatus":{"additionalPropertiesenum":false["succeeded","propertiesfailed","partial","outcome_unknown"],"type":{"reasonstring"}},"required":{["status","result","error","meta","payment","next"],"type":"stringobject"},"sourcedata":{"additionalProperties":{},"propertyNames":{"type":"string"}},"requiredtype":["sourceobject"},"reasonerror"]:{"anyOf":[{},{"type":"objectnull"}]},"typemeta":{"arrayadditionalProperties":{},"latency_mspropertyNames":{"minimumtype":0"string"},"type":"numberobject"},"partialnext":{"items":{},"type":"booleanarray"},"sourcespayment":{"itemsadditionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"arraystring"}},"required":["sourcesstatus","latency_msexecution_status"],"partialtype":"object"},"failed_sourcesresult":{},"cachestatus":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"objectstring"},"success":{"const":true,"type ⟨83 unchanged words⟩ :["success","tool","timestamp","data","meta"],"type":"object"}
⟨23 unchanged words⟩ compact diff when a prior snapshot is available. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"baseline_available":{"type":"boolean"},"cached" ⟨45 unchanged words⟩ "},{"type":"null"}]},"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"previous_hash":{"type":"string"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const ⟨35 unchanged words⟩
⟨63 unchanged words⟩ or assess maintainer history. Unknown coverage returns caution. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"checked_at" ⟨152 unchanged words⟩ ":"npm","type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"install_script_risk":{"enum":["low","medium" ⟨75 unchanged words⟩ "},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"new_package":{"type":["boolean","null"]},"next":{"items":{},"type":"array"},"package":{"type":"string"},"package_age_days" ⟨7 unchanged words⟩ "},{"type":"null"}]},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"recommendation":{"enum":["allow","caution" ⟨36 unchanged words⟩ ,"resolved_version":{"type":"string"},"result":{},"risk_confidence":{"enum":["low","medium" ⟨34 unchanged words⟩ {"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨73 unchanged words⟩
⟨50 unchanged words⟩ clean result is not a guarantee of safety. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"checked_at" ⟨7 unchanged words⟩ ":"unknown","type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"final_url":{"type":["string","null" ⟨3 unchanged words⟩ ,"malware":{"type":"boolean"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"normalized_url":{"type":"string"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"phishing":{"type":"boolean"},"recommendation" ⟨6 unchanged words⟩ recommended_next":{"additionalProperties":false,"properties":{"availability":{"type":["string","null"]},"availability_observation":{"type":"string"},"condition":{"type":"string"},"price":{"type":["string","null"]},"reason":{"type":"string"},"recommendation_id":{"format":"uuid","pattern":"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$","type":"string"},"tool":{"type":"string"},"workflow_id":{"type":"string"}},"required":["tool","reason","price ⟨5 unchanged words⟩ "minimum":0,"type":"integer"},"result":{},"risk_level":{"enum":["low","medium" ⟨16 unchanged words⟩ {"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨42 unchanged words⟩
⟨69 unchanged words⟩ certification. Never send private keys or seed phrases. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
⟨12 unchanged words⟩ ,"contract"],"type":"string"},"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"chain" ⟨121 unchanged words⟩ "type":["boolean","null"]},"error":{"anyOf":[{},{"type":"null"}]},"exposures":{"items":{"additionalProperties":false," ⟨38 unchanged words⟩ "type":["boolean","null"]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"mixer_exposure":{"additionalProperties":false,"properties":{" ⟨15 unchanged words⟩ ,"direct"],"type":"object"},"next":{"items":{},"type":"array"},"onchain":{"additionalProperties":false,"properties":{" ⟨28 unchanged words⟩ ,"block_number"],"type":"object"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"recommendation":{"enum":["allow","caution" ⟨8 unchanged words⟩ ,"unknown"],"type":"string"},"result":{},"risk_confidence":{"enum":["low","medium" ⟨28 unchanged words⟩ {"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨40 unchanged words⟩
⟨29 unchanged words⟩ executes page JavaScript and never fabricates missing fields. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"confidence" ⟨17 unchanged words⟩ ,"data_age_seconds":{"type":"number"},"error":{"anyOf":[{},{"type":"null"}]},"extracted_at":{"type":"string"},"final_url":{"type":"string"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"provenance":{"items":{"additionalProperties":false," ⟨14 unchanged words⟩ recommended_next":{"additionalProperties":false,"properties":{"availability":{"type":["string","null"]},"availability_observation":{"type":"string"},"condition":{"type":"string"},"price":{"type":["string","null"]},"reason":{"type":"string"},"recommendation_id":{"format":"uuid","pattern":"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$","type":"string"},"tool":{"type":"string"},"workflow_id":{"type":"string"}},"required":["tool","reason","price"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨42 unchanged words⟩
⟨25 unchanged words⟩ tax and unknown values remain null. Never purchases. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"availability":{"additionalProperties":false,"properties":{" ⟨44 unchanged words⟩ ,"estimated_days_max"],"type":"object"},"error":{"anyOf":[{},{"type":"null"}]},"fetched_at":{"type":"string"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"product":{"additionalProperties":false,"properties":{" ⟨49 unchanged words⟩ ,"landed_total"],"type":"object"},"result":{},"sources":{"items":{"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨37 unchanged words⟩
⟨29 unchanged words⟩ match/discrepancy/needs_review. No payment or bookkeeping action is taken. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"checks":{"items":{"additionalProperties":false," ⟨31 unchanged words⟩ ,"needs_review"],"type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"evidence":{"items":{"additionalProperties":false," ⟨77 unchanged words⟩ ,"line_items"],"type":"object"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"pages_processed":{"exclusiveMinimum":0,"maximum":9007199254740991,"type":"integer"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"source_sha256":{"type":"string"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"warnings":{"items ⟨13 unchanged words⟩
⟨13 unchanged words⟩ 10 pages. Oversized PDFs are rejected before OCR. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"checks":{"items":{"additionalProperties":false," ⟨31 unchanged words⟩ ,"needs_review"],"type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"evidence":{"items":{"additionalProperties":false," ⟨77 unchanged words⟩ ,"line_items"],"type":"object"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"pages_processed":{"exclusiveMinimum":0,"maximum":9007199254740991,"type":"integer"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"source_sha256":{"type":"string"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"warnings":{"items ⟨13 unchanged words⟩
⟨13 unchanged words⟩ 50 pages. Oversized PDFs are rejected before OCR. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"checks":{"items":{"additionalProperties":false," ⟨31 unchanged words⟩ ,"needs_review"],"type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"evidence":{"items":{"additionalProperties":false," ⟨77 unchanged words⟩ ,"line_items"],"type":"object"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"pages_processed":{"exclusiveMinimum":0,"maximum":9007199254740991,"type":"integer"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"source_sha256":{"type":"string"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"warnings":{"items ⟨13 unchanged words⟩
⟨35 unchanged words⟩ It does not inspect or validate the document. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"document_not_inspected":{"const":true,"type":"boolean"},"error":{"anyOf":[{},{"type":"null"}]},"final_validation_on_paid_call":{"const":true,"type":"boolean"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"network":{"enum":["eip155:8453","eip155:84532"],"type":"string"},"next":{"items":{},"type":"array"},"no_payment_taken":{"const":true,"type":"boolean"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"price_usdc":{"type":["string","null" ⟨11 unchanged words⟩ "},{"type":"null"}]},"result":{},"status":{"enum":["readysucceeded","needs_page_countfailed","unsupportedpartial","temporarily_unavailableoutcome_unknown"],"type":"string"}},"required":["status","recommended_tool","price_usdc","network","reason", ⟨5 unchanged words⟩
⟨62 unchanged words⟩ Pair with check_url to pre-screen a suspicious endpoint. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"capabilities":{"items":{"type":"string" ⟨8 unchanged words⟩ ,"endpoint_host":{"type":"string"},"error":{"anyOf":[{},{"type":"null"}]},"expected_tools":{"anyOf":[{"additionalProperties":false, ⟨20 unchanged words⟩ ,"inspected_at":{"type":"string"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"metadata_is_untrusted":{"const":true,"type":"boolean"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"read_only_inspection":{"const":true,"type":"boolean"},"result":{},"server":{"additionalProperties":false,"properties":{" ⟨9 unchanged words⟩ ,"type":"object"},"status":{"constenum":["reachablesucceeded","failed","partial","outcome_unknown"],"type":"string"},"tool_count":{"maximum" ⟨84 unchanged words⟩ ,"type":"boolean"}},"required":["status","endpoint_host","inspected_at","server","capabilities", ⟨10 unchanged words⟩
⟨128 unchanged words⟩ uniform SLA. Recommended workflows: agent-safety-gate, safe-transaction-preflight, tool-discovery-trust. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
⟨6 unchanged words⟩ {"action_type":{"type":"string"},"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"approval_handoff":{"additionalProperties":false,"properties":{"note":{"type":"string"},"request_id":{"type":"null"},"status":{"enum":["not_requested","not_created_by_gate"],"type":"string"}},"required":["status","request_id","note"],"type":"object"},"attempted_checks":{"items":{"type":"string"},"type":"array"},"checks":{"items":{"additionalProperties":false," ⟨51 unchanged words⟩ "minimum":0,"type":"number"},"confidence_semantics":{"const":"Heuristic evidence sufficiency/risk signal; not a probability or guarantee.","type":"string"},"decision":{"enum":["ALLOW","DENY","REQUIRE_APPROVAL","REVIEW"],"type":"string"},"decision_scope":{"additionalProperties":false,"properties":{"assesses":{"items":{"type":"string"},"type":"array"},"does_not":{"items":{"type":"string"},"type":"array"},"question":{"const":"Should my agent perform this action?","type":"string"}},"required":["question","assesses","does_not"],"type":"object"},"error":{"anyOf":[{},{"type":"null"}]},"estimated_cost":{"additionalProperties":false,"properties":{" ⟨46 unchanged words⟩ ,"proposed_action"],"type":"object"},"evidence_status":{"enum":["incomplete","rule_evaluable"],"type":"string"},"failed_checks":{"items":{"additionalProperties":false," ⟨18 unchanged words⟩ "minimum":0,"type":"number"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"next_best_tool":{"type":["string","null"]},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"reasons":{"items":{"type":"string" ⟨13 unchanged words⟩ :"string"},"type":"array"},"result":{},"retryable":{"type":"boolean"},"risk" ⟨19 unchanged words⟩ :"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type":"boolean ⟨1 unchanged words⟩ success","decision","risk","confidence","confidence_semantics","evidence_status","required_checks","attempted_checks","completed_checks","checks_run","failed_checks","skipped_checks"," ⟨5 unchanged words⟩ ","next_best_tool","latency_ms","signing_or_broadcast_performed","checks","decision_scope","approval_handoff","action_type","intent"],"type":"object"}
⟨85 unchanged words⟩ platform's local service registry and are marked degraded. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
⟨14 unchanged words⟩ [a-zA-Z0-9_.-]*$","type":"string"},"completed_tools":{"items":{"maxLength":128,"minLength":1,"type":"string"},"maxItems":30,"type":"array"},"constraints":{"additionalProperties":false,"properties":{" ⟨47 unchanged words⟩
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"alternatives":{"items":{"additionalProperties":false," ⟨127 unchanged words⟩ ,"confidence":{"type":"number"},"confidence_semantics":{"type":"string"},"degraded":{"type":"boolean"},"error":{"anyOf":[{},{"type":"null"}]},"expected_total_cost_usd":{"type":["number","null"]},"match_found":{"type":"boolean"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"next_best_tool":{"type":["string","null" ⟨6 unchanged words⟩ ,"balanced"],"type":"string"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"provider_availability_observed_at":{"type":["string","null"]},"provider_availability_source":{"type":"string"},"query":{"type":["string","null" ⟨111 unchanged words⟩ ":[{"additionalProperties":false,"properties":{"availability":{"type":["string","null"]},"availability_observation":{"type":"string"},"condition":{"type":"string"},"price":{"type":["string","null"]},"reason":{"type":"string"},"recommendation_id":{"format":"uuid","pattern":"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$","type":"string"},"tool":{"type":"string"},"workflow_id" ⟨12 unchanged words⟩ ":[{"additionalProperties":false,"properties":{"estimated_cost":{"additionalProperties":false,"properties":{"basis":{"type":"string"},"conditional_call_count":{"type":"number"},"currency":{"type":"string"},"expected":{"type":"number"},"max":{"type":"number"},"min":{"type":"number"},"optional_call_count":{"type":"number"},"required_call_count":{"type":"number"}},"required":["min","expected","max","currency","basis","required_call_count","conditional_call_count","optional_call_count"],"type":"object"},"estimated_total_price_usd":{"type":"number"},"id":{"type":"string"},"name":{"type":"string"},"next_required_step":{"anyOf":[{"additionalProperties":false,"properties":{"condition":{"type":["string","null"]},"tool":{"type":"string"},"type":{"type":"string"}},"required":["tool","type","condition"],"type":"object"},{"type":"null"}]},"state_mode":{"enum":["client_managed"],"type":"string"}},"required":["id","name","estimated_total_price_usd"],"type": ⟨6 unchanged words⟩ :"string"},"type":"array"},"relevance_score":{"type":"number"},"result":{},"routing_data_age_seconds":{"type":"number"},"routing_reason":{"items":{"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨25 unchanged words⟩
⟨33 unchanged words⟩ rebalancing, and guaranteed execution; does not place orders. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"dataagent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"metanext":{"additionalPropertiesitems":false{},"propertiestype":{"cachearray"},"payment":{"additionalProperties":false,"properties":{"age_msexecution_status":{"minimumenum":0["not_started","succeeded","failed","unknown"],"type":"numberstring"},"hitstatus":{"enum":["not_required","required","settled","failed","unknown"],"type":"booleanstring"}},"required":["hitstatus","age_msexecution_status"],"type":"object"},"failed_sourcesresult":{},"itemsstatus":{"additionalPropertiesenum":false["succeeded","propertiesfailed","partial","outcome_unknown"],"type":{"reasonstring"}},"required":{["status","result","error","meta","payment","next"],"type":"stringobject"},"sourcedata":{"additionalProperties":{},"propertyNames":{"type":"string"}},"requiredtype":["sourceobject"},"reasonerror"]:{"anyOf":[{},{"type":"objectnull"}]},"typemeta":{"arrayadditionalProperties":{},"latency_mspropertyNames":{"minimumtype":0"string"},"type":"numberobject"},"partialnext":{"items":{},"type":"booleanarray"},"sourcespayment":{"itemsadditionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"arraystring"}},"required":["sourcesstatus","latency_msexecution_status"],"partialtype":"object"},"failed_sourcesresult":{},"cachestatus":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"objectstring"},"success":{"const":true,"type ⟨83 unchanged words⟩ :["success","tool","timestamp","data","meta"],"type":"object"}
⟨52 unchanged words⟩ external LLM or provider call. Maximum 100000 characters. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"credential_theft_risk" ⟨43 unchanged words⟩ :"object"},"type":"array"},"error":{"anyOf":[{},{"type":"null"}]},"instruction_override_risk":{"type":"boolean"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"prompt_injection_detected":{"type":"boolean"},"recommendation" ⟨10 unchanged words⟩ :"string"},"type":"array"},"result":{},"risk_level":{"enum":["low","medium" ⟨97 unchanged words⟩ {"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"tool_manipulation_risk":{"type":"boolean"} ⟨19 unchanged words⟩
⟨70 unchanged words⟩ tool never signs, holds keys, or broadcasts. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"analysis_scope":{"const":"top_level_calldata_and_rpc_simulation","type": ⟨178 unchanged words⟩ ,"degraded":{"type":"boolean"},"error":{"anyOf":[{},{"type":"null"}]},"estimated_gas":{"type":["string","null" ⟨8 unchanged words⟩ "type":["string","null"]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"native_balance_changes":{"items":{"additionalProperties":false," ⟨25 unchanged words⟩ :"object"},"type":"array"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"recommendation":{"enum":["allow","caution","block"],"type":"string"},"result":{},"revert_reason":{"type":["string","null" ⟨25 unchanged words⟩ "}]},"simulation_success":{"type":"boolean"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨80 unchanged words⟩
⟨56 unchanged words⟩ scoring. Does not trade or guarantee token safety. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"dataagent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"metanext":{"additionalPropertiesitems":false{},"propertiestype":{"cachearray"},"payment":{"additionalProperties":false,"properties":{"age_msexecution_status":{"minimumenum":0["not_started","succeeded","failed","unknown"],"type":"numberstring"},"hitstatus":{"enum":["not_required","required","settled","failed","unknown"],"type":"booleanstring"}},"required":["hitstatus","age_msexecution_status"],"type":"object"},"failed_sourcesresult":{},"itemsstatus":{"additionalPropertiesenum":false["succeeded","propertiesfailed","partial","outcome_unknown"],"type":{"reasonstring"}},"required":{["status","result","error","meta","payment","next"],"type":"stringobject"},"sourcedata":{"additionalProperties":{},"propertyNames":{"type":"string"}},"requiredtype":["sourceobject"},"reasonerror"]:{"anyOf":[{},{"type":"objectnull"}]},"typemeta":{"arrayadditionalProperties":{},"latency_mspropertyNames":{"minimumtype":0"string"},"type":"numberobject"},"partialnext":{"items":{},"type":"booleanarray"},"sourcespayment":{"itemsadditionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"arraystring"}},"required":["sourcesstatus","latency_msexecution_status"],"partialtype":"object"},"failed_sourcesresult":{},"cachestatus":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"objectstring"},"success":{"const":true,"type ⟨83 unchanged words⟩ :["success","tool","timestamp","data","meta"],"type":"object"}
⟨37 unchanged words⟩ text is sent to the configured search provider. Agent entry points: risky external action → use Agent Action Gate when a combined action-specific safety assessment is needed; unclear capability/provider → use free /api/discover; constrained comparison between callable alternatives → use paid route_tool; known single capability → call the direct tool; multi-step objective → read the matching workflow recipe and call only relevant steps. Workflows are stateless recipes, not executors; calls are paid separately and are not bundle charged. Agent Action Gate does not approve payment, sign or broadcast transactions, evaluate seller reputation, replace transaction simulation, replace route_tool, or replace human approval.
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"agent_ux":{"additionalProperties":false,"properties":{"error":{"anyOf":[{},{"type":"null"}]},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"}},"required":["status","result","error","meta","payment","next"],"type":"object"},"cached":{"type":"boolean"},"claim" ⟨42 unchanged words⟩ ,"degraded":{"type":"boolean"},"error":{"anyOf":[{},{"type":"null"}]},"evidence":{"items":{"additionalProperties":false," ⟨55 unchanged words⟩ ,"age_days"],"type":"object"},"meta":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"next":{"items":{},"type":"array"},"payment":{"additionalProperties":false,"properties":{"execution_status":{"enum":["not_started","succeeded","failed","unknown"],"type":"string"},"status":{"enum":["not_required","required","settled","failed","unknown"],"type":"string"}},"required":["status","execution_status"],"type":"object"},"result":{},"sources":{"items":{"type":"string"},"type":"array"},"status":{"enum":["succeeded","failed","partial","outcome_unknown"],"type":"string"},"success":{"const":true,"type ⟨34 unchanged words⟩
⟨51 unchanged words⟩ :"object"},"type":"array"},"recommended_next":{"additionalProperties":false,"properties":{"price":{"type":["string","null"]},"reason":{"type":"string"},"tool":{"type":"string"}},"required":["tool","reason","price"],"type":"object"},"success":{"const":true,"type":"boolean ⟨41 unchanged words⟩
⟨38 unchanged words⟩ trust confidence; no LLM call is required. Returns the best tool, confidence, reason, price, relevant workflow, next-best option, and a context-aware recommended_next when useful. This is recommendation metadata only: it never invokes the selected provider ⟨20 unchanged words⟩
⟨107 unchanged words⟩ :"object"},"type":"array"},"best_tool":{"type":["string","null"]},"cached":{"type":"boolean"},"candidates_after_filters" ⟨16 unchanged words⟩ ,"checked_at":{"type":"string"},"confidence":{"type":"number"},"degraded":{"type":"boolean"},"expected_total_cost_usd":{"type":["number","null"]},"match_found":{"type":"boolean"},"next_best_tool":{"type":["string","null"]},"optimize_for":{"enum":["cheapest","fastest" ⟨116 unchanged words⟩ "},{"type":"null"}]},"recommended_next":{"anyOf":[{"additionalProperties":false,"properties":{"price":{"type":["string","null"]},"reason":{"type":"string"},"tool":{"type":"string"},"workflow_id":{"type":"string"}},"required":["tool","reason","price"],"type":"object"},{"type":"null"}]},"recommended_workflow":{"anyOf":[{"additionalProperties":false,"properties":{"estimated_total_price_usd":{"type":"number"},"id":{"type":"string"},"name":{"type":"string"}},"required":["id","name","estimated_total_price_usd"],"type":"object"},{"type":"null"}]},"registry_sources":{"items":{"type":"string" ⟨11 unchanged words⟩ success":{"const":true,"type":"boolean"},"why":{"items":{"type":"string"},"type":"array"}},"required":["success","match_found" ⟨15 unchanged words⟩
Agent Action Gate ($0.02 USDC flat; stable MCP tool name preflight_action). Use before an AI agent performs an external action. Evaluates the required safety, trust, spending and transaction checks and returns ALLOW, REVIEW, REQUIRE_APPROVAL or DENY. Use before opening an untrusted URL, installing a dependency, calling an unfamiliar MCP/tool, spending funds, submitting a transaction, or consuming untrusted external content. Do not use for pure local deterministic computation or when no external action/risk exists. Does not assess seller reputation. Missing or skipped relevant checks cannot pr…
before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"cached":{"type":"boolean"},"confidence":{"additionalProperties":false,"properties":{"overall":{"type":"number"}},"required":["overall"],"type":"object"},"data":{"additionalProperties":{},"propertyNames":{"type":"string"},"type":"object"},"data_age_seconds":{"type":"number"},"extracted_at":{"type":"string"},"final_url":{"type":"string"},"provenance":{"items":{"additionalProperties":false,"properties":{"field":{"type":"string"},"source_type":{"type":"string"}},"required":["field","source_type"],"type":"object"},"type":"array"},"success":{"const":true,"type":"boolean"},"url":{"type":"string"},"validation":{"additionalProperties":false,"properties":{"coercions":{"items":{"type":"string"},"type":"array"},"missing_fields":{"items":{"type":"string"},"type":"array"},"schema_valid":{"type":"boolean"}},"required":["schema_valid","missing_fields","coercions"],"type":"object"}},"required":["success","url","final_url","data","validation","confidence","provenance","cached","data_age_seconds","extracted_at"],"type":"object"}before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"availability":{"additionalProperties":false,"properties":{"in_stock":{"type":["boolean","null"]},"quantity_available":{"type":"null"},"stock_status":{"enum":["in_stock","out_of_stock","unknown"],"type":"string"}},"required":["in_stock","stock_status","quantity_available"],"type":"object"},"cached":{"type":"boolean"},"confidence":{"enum":["high","low"],"type":"string"},"data_age_seconds":{"type":"number"},"delivery":{"additionalProperties":false,"properties":{"estimated_days_max":{"type":"null"},"estimated_days_min":{"type":"null"}},"required":["estimated_days_min","estimated_days_max"],"type":"object"},"fetched_at":{"type":"string"},"product":{"additionalProperties":false,"properties":{"canonical_url":{"type":"string"},"title":{"type":["string","null"]}},"required":["title","canonical_url"],"type":"object"},"quote":{"additionalProperties":false,"properties":{"currency":{"type":["string","null"]},"fees":{"type":"null"},"landed_total":{"type":"null"},"quantity":{"type":"number"},"shipping":{"type":"null"},"subtotal":{"type":"number"},"tax":{"type":"null"},"unit_price":{"type":"number"}},"required":["currency","unit_price","quantity","subtotal","shipping","tax","fees","landed_total"],"type":"object"},"sources":{"items":{"type":"string"},"type":"array"},"success":{"const":true,"type":"boolean"},"variant":{"additionalProperties":false,"properties":{"color":{"type":["string","null"]},"size":{"type":["string","null"]},"verified":{"type":["boolean","null"]}},"required":["size","color","verified"],"type":"object"}},"required":["success","product","quote","availability","variant","delivery","confidence","sources","cached","fetched_at","data_age_seconds"],"type":"object"}before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"cached":{"type":"boolean"},"claim":{"type":"string"},"confidence":{"type":"number"},"conflicting_evidence":{"items":{"additionalProperties":false,"properties":{"published_at":{"type":["string","null"]},"snippet":{"type":"string"},"source":{"type":"string"},"source_quality":{"type":"string"},"supports":{"const":false,"type":"boolean"},"title":{"type":"string"}},"required":["source","title","published_at","source_quality","supports","snippet"],"type":"object"},"type":"array"},"degraded":{"type":"boolean"},"evidence":{"items":{"additionalProperties":false,"properties":{"published_at":{"type":["string","null"]},"snippet":{"type":"string"},"source":{"type":"string"},"source_quality":{"type":"string"},"supports":{"const":true,"type":"boolean"},"title":{"type":"string"}},"required":["source","title","published_at","source_quality","supports","snippet"],"type":"object"},"type":"array"},"freshness":{"additionalProperties":false,"properties":{"age_days":{"type":["number","null"]},"newest_source_at":{"type":["string","null"]},"status":{"enum":["fresh","stale","unknown"],"type":"string"}},"required":["status","newest_source_at","age_days"],"type":"object"},"sources":{"items":{"type":"string"},"type":"array"},"success":{"const":true,"type":"boolean"},"verdict":{"enum":["supported","contradicted","mixed","insufficient_evidence","stale"],"type":"string"},"verified_at":{"type":"string"},"warnings":{"items":{"type":"string"},"type":"array"}},"required":["success","claim","verdict","confidence","freshness","evidence","conflicting_evidence","warnings","sources","degraded","cached","verified_at"],"type":"object"}before
—after
{"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"cached":{"type":"boolean"},"checked_at":{"type":"string"},"degraded":{"type":"boolean"},"domain_age_risk":{"const":"unknown","type":"string"},"final_url":{"type":["string","null"]},"https":{"type":"boolean"},"malware":{"type":"boolean"},"normalized_url":{"type":"string"},"phishing":{"type":"boolean"},"recommendation":{"enum":["allow","caution","block"],"type":"string"},"redirect_count":{"maximum":9007199254740991,"minimum":0,"type":"integer"},"risk_level":{"enum":["low","medium","high","critical"],"type":"string"},"risk_score":{"maximum":100,"minimum":0,"type":"integer"},"safe":{"type":"boolean"},"sources":{"items":{"type":"string"},"type":"array"},"success":{"const":true,"type":"boolean"},"suspicious_domain":{"type":"boolean"},"suspicious_redirect":{"type":"boolean"},"threats":{"items":{"type":"string"},"type":"array"},"warnings":{"items":{"type":"string"},"type":"array"}},"required":["success","safe","risk_score","risk_level","recommendation","normalized_url","final_url","redirect_count","https","domain_age_risk","phishing","malware","suspicious_redirect","suspicious_domain","threats","warnings","sources","cached","degraded","checked_at"],"type":"object"}⟨12 unchanged words⟩ public EVM RPC metadata for supported EVM tokens.RequiresConfigureGOPLUS_ACCESS_TOKEN;GOPLUS_ACCESS_TOKEN or explicitly enable the bounded public API with GOPLUS_PUBLIC_TOKEN_API_ENABLED=1; ifitneither ismissingavailable,returnsnoapaymentprovider-unavailableiserrorrequested.beforeMissingpayment.provider fields remain unknown and incomplete coverage returns caution. Reports provider findings separately from deterministic internal scoring. ⟨7 unchanged words⟩
Paid Whale Intelligence ($0.02 USDC). Summarizes large public GeckoTerminal-indexed DEX trades for a token address on a supported chain. Large-trader labels are size-based heuristics, not verified whale identities; data is not chain-wide. Wallet mode uses Helius (Solana) or Etherscan API V2 (EVM) when configured, returning recent indexed transactions only; it does not claim complete balances or whale labels.
Paid Strategy Backtest ($0.10 USDC). Tests built-in long-only spot strategies against bounded public Binance OHLCV history. Signals form at candle close and execute at the next candle open. Applies configured fees/slippage; accepts declarative parameters only and never executes user code. Historical results are not predictions.
Paid Trade Execution Quote ($0.01 USDC). Gets an indicative swap quote before a trade; supports Solana via Jupiter and EVM via 0x when provider keys are configured. Requires token addresses and decimals for custom assets. Returns estimated output and quote source. Read-only: never signs, submits, or executes.
Paid Arbitrage Intelligence ($0.03 USDC). Compares Binance and Coinbase public spot order books at a requested trade size and applies caller- or server-configured taker fee assumptions. Rejects stale books. Excludes transfers, inventory rebalancing, and guaranteed execution; does not place orders.
Paid Token Security Audit ($0.01 USDC). Normalizes GoPlus token-security flags and public EVM RPC metadata for supported EVM tokens. Requires GOPLUS_ACCESS_TOKEN; if it is missing, returns a provider-unavailable error before payment. Reports provider findings separately from deterministic internal scoring. Does not trade or guarantee token safety.