ZBS Index What actually exists in applied AI, with the source next to it

mcp server

dcl-trust-oracle

Deterministic AI audit layer for LLM/agent outputs: policy checks, tamper-evident log, x402.

Description as published by the maintainer. Source

  • version 2.3.0
  • active

active — Most recent push to the repository was 2026-08-06.

What this server can do

18 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

dcl_audit_decode(tx_hash)
POST-ACTION Basic Audit ($0.10). Retrieves a record from the tamper-evident chain by tx_hash. Required: tx_hash.
dcl_audit_decode_deep(tx_hash)
POST-ACTION Deep Forensic Audit ($0.50). Extended output with drift_context and full chain integrity verification. Required: tx_hash.
dcl_commit(agent_id, decision, prior_checks)
FINAL-STEP Leibniz Layer Crypto Commit ($0.01). Writes a trading/agent decision to the append-only Leibniz Layer audit chain and returns a Merkle-proof-style receipt: `tx_hash` (proof of this specific commit), `chain_hash` (the previous commit's hash, linking this one into the chain), and `chain_depth` (this commit's position in the chain). Unlike the evaluate_* tools, this call has no pass/fail verdict of its own — it always succeeds and simply seals the decision. Passing `prior_checks` is optional but recommended: it records which earlier pipeline steps (firewall/wallet/trade/MEV) this specific commit is downstream of, in one auditable record. Always run this LAST, after every other crypto-suite check has passed. Required: decision, agent_id.
dcl_evaluate_batch(items, agent_id)
PRE-ACTION Bulk Processing ($0.10). Evaluates a list of items in one call; each item is a dict shaped {"response": str, "policy"?: str}, where policy defaults to "default" if omitted and may be any built-in policy name (default, strict, anti_jailbreak, safety, content_quality). Each item gets its own independent COMMIT/NO_COMMIT verdict via the same logic as the matching single-item evaluate_* tool; results are returned in input order under `results`, plus a shared `batch_id`. Capped at 200 items per call — oversized batches are rejected. Use this instead of multiple single-item evaluate_* calls when checking several responses — optionally against different policies — in one priced call rather than paying per item separately. Required: items, agent_id.
dcl_evaluate_fast(agent_id, response)
FAST Pre-Action Audit ($0.01). Runs the response through the server's "default" policy: a substring check against 3 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety") with a 0.7 minimum-confidence threshold. Each forbidden match found costs 0.4 confidence; if confidence falls below 0.7, or any match is found, the verdict is NO_COMMIT and `reason` lists which phrase triggered it. Otherwise COMMIT. Use this as the default low-cost first-pass gate before a risky agent action; switch to dcl_evaluate_strict for a broader, higher-bar check, or to dcl_evaluate_jailbreak / dcl_evaluate_safety / dcl_evaluate_quality for a narrower, single-topic check instead of the general-purpose default policy. Required: response, agent_id.
dcl_evaluate_jailbreak(agent_id, response)
PRE-ACTION Instruction Adherence Check ($0.02). Runs the "anti_jailbreak" policy: a substring check against 6 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety", "pretend you are", "act as if", "DAN") with a 0.8 minimum-confidence threshold — each match costs 0.4 confidence. Returns COMMIT if no phrase matches and confidence stays at or above 0.8, otherwise NO_COMMIT with `reason` listing the matched phrase(s). Use this as a targeted, cheaper check when the concern is specifically prompt-injection / persona-hijack risk; use dcl_evaluate_strict instead when you also want safety- and default-policy phrases covered in the same call. Required: response, agent_id.
dcl_evaluate_jailbreak_crypto(agent_id, response)
PRE-ACTION Crypto Jailbreak & Injection Detection ($0.02). Crypto-specialized instruction-override/jailbreak/injection screen: standard role-switch and instruction-override patterns, plus crypto-specific drain-wallet injection (e.g. "transfer all funds to...", fake "test transaction" requesting full balance) and unlimited-approval injection (e.g. type(uint256).max, "approve unlimited allowance", skip-slippage-confirmation framing). Any match returns NO_COMMIT with `reason` and `findings` naming the matched category/categories; run this FIRST in the DCL crypto pipeline, before wallet/trade/MEV checks, since it screens the input itself rather than a decision built on top of it. Required: response, agent_id.
dcl_evaluate_mev(agent_id, response)
POST-ACTION MEV & Market-Abuse Compliance Screen ($0.03). Text-level screen (not a mempool/transaction analyzer) for front-running/sandwich-attack language, wash trading/layering/spoofing, KYC/AML red flags (mixers, structuring, obscuring fund origin), and pump-and-dump/rug-pull language. Any critical-severity finding, or two or more major-severity findings, returns NO_COMMIT; a single major-severity finding is also returned as NO_COMMIT but with a distinctly higher `confidence` (~0.55 vs ~0.05-0.2 for harder violations) so downstream callers can tell a soft single flag apart from a hard multi-finding block. Each finding includes an illustrative `regulatory_reference` tag (MiFID II, FCA, or an EU AI Act article). Required: response, agent_id.
dcl_evaluate_output_sanitizer(agent_id, response)
FINAL-GATE Output Sanitizer ($0.02). Post-processing checkpoint that strips secrets/credentials, PII, crypto material (seed phrases, private keys, wallet addresses), internal network details (private IPs, MAC addresses, .internal/.local/.corp hostnames), and unsafe shell/SQL/path-traversal fragments from a raw model response — plus a narrow, high-precision safety net for direct self-harm-instruction-seeking and targeted-harassment phrasing (not a general toxicity classifier). Returns a single `sanitized_output` with every match replaced by `[REDACTED]`; use that instead of the original whenever verdict is NO_COMMIT. Run this as the LAST gate before a response reaches its destination — after `dcl_evaluate_jailbreak_crypto`/other input-side checks have already run, and immediately before `dcl_commit` seals the final decision. Internally re-uses the same detection tables as `dcl_evaluate_secrets`/`dcl_evaluate_pii` for the secrets/PII categories, so results stay consistent with those tools. Required: response, agent_id.
dcl_evaluate_pii(agent_id, response)
POST-ACTION PII Detection Scan ($0.02). Regex-based scan across 8 personal-data categories, with a Luhn checksum on card numbers to reduce false positives. Any finding results in NO_COMMIT. Required: response, agent_id.
dcl_evaluate_quality(agent_id, response)
PRE-ACTION Content Quality & Drift Check ($0.03). Runs the "content_quality" policy: flags 12 absolutist or unverifiable-claim phrases (e.g. "guaranteed returns", "100% accurate", "studies show", "without a doubt") with a 0.85 minimum-confidence threshold — the highest bar of any single-policy tool. Returns NO_COMMIT if any phrase matches or confidence falls below 0.85, with `reason` listing the matched phrase(s). Use this to catch overconfident or unsubstantiated claims in generated content — a different concern from jailbreak or safety phrasing — e.g. before publishing agent-written copy or reports. Required: response, agent_id.
dcl_evaluate_safety(agent_id, response)
PRE-ACTION Baseline Safety Check ($0.01). Runs the "safety" policy: flags 2 forbidden disclaimers ("I cannot be held responsible", "no guarantees") and additionally REQUIRES the substring "AI" to appear somewhere in the response — missing it costs 0.2 confidence even with no forbidden phrase present. Minimum confidence is 0.75. Returns NO_COMMIT if confidence drops below 0.75, with `reason` naming the forbidden phrase found or the missing required pattern. Use this when you specifically need to confirm an AI-disclosure marker is present and the two disclaimer phrases are absent — not as a general-purpose safety net; for broader coverage use dcl_evaluate_fast or dcl_evaluate_strict instead. Required: response, agent_id.
dcl_evaluate_secrets(agent_id, response)
POST-ACTION Secret & Credential Leak Scan ($0.02). Regex-based scan across 8 categories (API keys, cloud credentials, tokens/JWTs, private keys, DB URLs, connection strings, env assignments, webhook secrets, internal endpoints with auth). Any finding results in NO_COMMIT. Required: response, agent_id.
dcl_evaluate_signal(agent_id, response)
POST-ACTION Market Signal Fabrication Screen ($0.03). Pattern-based heuristic on the output text alone (no source price feed) — flags guaranteed-price-prediction language ("will definitely hit $X"), absolute-certainty claims ("100% certain", "cannot go down"), a fabricated-price flag when a specific dollar figure co-occurs with a guaranteed-outcome claim, and an invented-token flag when a "$TICKER" cashtag doesn't match a small set of well-known symbols (false positives are possible for legitimate lesser-known tickers — this is a heuristic pre-check, not ground truth). For a full claim-by-claim check against an actual price-feed snapshot, use the local grounding workflow instead of this live tool. Verdict/confidence collapsing follows the same rule as dcl_evaluate_mev: any critical finding or 2+ major findings is a hard NO_COMMIT; exactly one major finding is a softer NO_COMMIT at ~0.55 confidence. Required: response, agent_id.
dcl_evaluate_strict(agent_id, response)
STRICT Pre-Action Audit ($0.05). Runs the response against a broader, higher-bar "strict" policy: the union of all forbidden phrases from the default, anti-jailbreak, and safety policies (8 phrases total), with a 0.85 minimum-confidence threshold instead of the default policy's 0.7. Each matched phrase costs 0.4 confidence; if confidence falls below 0.85, or any phrase matches, the verdict is NO_COMMIT with `reason` listing every match found. Use this instead of dcl_evaluate_fast when the cost of a false COMMIT is high — e.g. before an irreversible or high-stakes agent action — since it catches jailbreak- and safety-adjacent phrasing that the plain default policy would miss. Required: response, agent_id.
dcl_evaluate_trade(agent_id, response)
PRE-ACTION Trade Decision Verifier ($0.02). Screens trade-decision language for guaranteed-return claims, zero-risk/"can't lose" framing, and unqualified "buy/sell X now" directives — any match is NO_COMMIT. If no unsafe language is found, COMMIT additionally requires the word "risk" to appear anywhere in the text as a minimum disclosure marker; its absence alone triggers NO_COMMIT with `reason` noting the missing disclosure. Produces an immutable `trade_receipt` (tx_hash/chain_hash/chain_depth) distinct from the top-level audit hash, for downstream systems that specifically need a trade-shaped receipt object. Required: response, agent_id.
dcl_evaluate_wallet(agent_id, response)
POST-ACTION Wallet Secret Guardian ($0.02). Scans for BIP-39 seed phrases (12 or 24 consecutive wordlist words), raw hex or WIF-format private keys, Ethereum/Bitcoin wallet addresses, and API keys/bearer tokens appearing near wallet/custody/signing terminology. Any finding results in NO_COMMIT — wallet secrets have no safe threshold, unlike other DCL evaluators. Returns a `sanitized_output` with all matches redacted (null if nothing was found) and a masked `redacted_sample` per finding — the real value is never returned or stored server-side. Required: response, agent_id.
dcl_pipeline_start(scope, agent_id, ttl_seconds)
SESSION Management ($0.05). Generates a new `pipeline_id` and returns session metadata (scope, expiry, initial drift_mode) for organizing a series of related checks under one identifier. Note: this call does not currently link the returned pipeline_id to later evaluate_* calls — there is no server-side session state that ties subsequent audits back to it; it is an identifier/timestamp issuer, not an active tracking session. Use this to obtain a shared reference ID for your own client-side grouping of a multi-step audit sequence; do not rely on it to automatically aggregate drift across calls. Required: agent_id.

Last successful function declaration observed on . Source: https://mcp.fronesislabs.com/mcp. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://mcp.fronesislabs.com/mcp.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
GitHub stars 1 Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. cumulative, all time GitHub
Last commit 2026-08-06 Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. point in time GitHub
Open issues 0 Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. as of fetch GitHub
Latest published version 2.3.0 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-08-05 When the registry record was last updated by its maintainer. point in time Model Context Protocol
License MIT Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. as of fetch GitHub
First listed in the MCP Registry 2026-08-05 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
repository status active The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. as of fetch GitHub
mcp tools declared 18 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe mcp.fronesislabs.com
mcp endpoint status ok The server listed 18 functions when asked. as of probe mcp.fronesislabs.com

Where to get it

Related, by what their authors tagged them

  • io.github.amitsingh-24/pixlint — last commit 2026-07-27, shares mcp-protocol, mcp-tools
    Lint, curate & prepare computer-vision datasets from your AI assistant — MCP server, 67 tools
  • MINT Protocol — Universal Work Attestation — last commit 2026-07-19, shares trust, trust-score
    Trust stack for AI agents: identity, attest, verify, rate, recommend, discover — on Solana.
  • AsterPay — EUR Settlement for AI Agents — last commit 2026-03-10, shares base, trust-score, x402
    EUR settlement + trust for AI agent commerce: budgets, KYA, merchant discovery. 22 tools.
  • io.github.bch1212/agenttrust — last commit 2026-05-13, shares trust-score
    Trust scores & reputation for the agent-to-agent economy. Verify A2A counterparties.
  • io.github.ertugrulakben/dep-oracle — last commit 2026-03-13, shares trust-score
    Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis.
  • SatRank — Lightning trust + audit oracle — last commit 2026-07-13, shares oracle
    Lightning trust + audit oracle. Score, pay, and audit L402 endpoints with Ed25519 receipts.
  • AIMarket Oracle Gateway — last commit 2026-08-03, shares oracle
    Stdio MCP: 17 verifiable AIMarket oracles, 35 pay-per-call tools for AI agents.
  • io.github.aoreshkov/oracle-forms-mcp — last commit 2026-08-02, shares oracle
    Serves Oracle Forms module content (.fmb/.mmb/.pll/.olb) from a directory to MCP clients.
  • KTA-Oracle — last commit 2026-04-16, shares oracle
    Live KTA rates, market data, payment rails, AML/VAT compliance, SDK snippets. 16 tools.
  • MCP Toolbox for Databases — last commit 2026-08-08, shares oracle
    MCP Toolbox for Databases enables your agent to connect to your database.

These share tags the maintainers applied themselves, such as mcp-protocol, mcp-tools, trust, trust-score. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.

This is not a recommendation and not a test result. It is a map of what the authors said their work is about.

How the author describes it

Topics the maintainer set on GitHub: ai-safety, base, base-network, mcp, mcp-protocol, mcp-security, mcp-server, mcp-servers, mcp-service, mcp-tools, oracle, trust, trust-and-safety, trust-score, x402.

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Fronesis-Labs/dcl-webhook on GitHub — GitHub, observed , trust tier 3.
  2. Tools declared by the MCP server at https://mcp.fronesislabs.com/mcp — mcp.fronesislabs.com, observed , trust tier 1.
  3. Official MCP Registry — Model Context Protocol, observed , trust tier 1.