ZBS Index What actually exists in applied AI, with the source next to it

mcp server

agents

Pay-per-call safety guards for AI agents: injection, tool-call, signing, secret, x402-trust.

Description as published by the maintainer. Source

  • version 0.0.8
  • active

active — Registry entry last updated 2026-06-16.

What this server can do

7 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

inject-guard(content, context)
Untrusted-content guardrail for agents: submit a blob of text you are about to feed to your own LLM (scraped web content, a tool result, another agent's message) and get a machine-enforceable verdict - is this a prompt-injection / jailbreak / data-exfiltration / tool-hijack attempt? Returns a risk level, the detected classes with spans, the unicode obfuscation it found (zero-width, bidi-override, tag-chars, homoglyphs), and a SANITIZED copy safe to feed onward. Hybrid: a deterministic, uninjectable pattern engine (authoritative) plus an LLM classifier that can only raise the risk, never clear a flag. Detection of known injection classes - not a proof of safety. [security; up to 15c/call] Required: content.
pr-summary(diff, style)
Turn a git diff into a clear PR description or release notes. [dev-tools; up to 30c/call] Required: diff.
secret-scan(content)
Leaked-credential guardrail for agents: submit a blob you are about to commit, log, post, or hand to another tool (a diff, a config, an .env, an LLM output) and get a machine-enforceable verdict - does it contain a live secret? Detects cloud keys (AWS), VCS tokens (GitHub/GitLab), provider API keys (Stripe, OpenAI, Anthropic, Google, Slack), private-key blocks, JWTs, and credentials embedded in URLs, plus high-entropy key=value assignments. Returns a risk level, the detected classes with a MASKED locator (never the secret itself, so the verdict cannot re-leak), and a REDACTED copy safe to emit onward. Deterministic, sub-second, never fetches. Detection of known secret formats - not a proof of cleanliness. [security; up to 200c/call] Required: content.
secure-code-review(code, context, language)
Security review of a code snippet or diff. Returns structured findings (severity, CWE, location, remediation). [security; up to 75c/call] Required: code.
sign-guard(tx, context, expected, typedData, spendPolicy)
Pre-sign safety oracle for agent wallets: submit the transaction or EIP-712 message you are about to sign and get a machine-enforceable verdict. Decodes the calldata/typed-data, flags the drainer toolkit (unlimited approvals, setApprovalForAll, permit/permit2 + EIP-3009 to an unexpected party, transferFrom draining an unnamed account, ownership transfer, raw ETH to a stranger), and binds the decoded action to your stated intent - only a fully pinned, clean action is auto-sign-safe. Fails closed: an undecodable on-chain call is cautioned and an unrecognized off-chain signature grant is blocked. Deterministic, sub-second, no endpoint fetch. It vouches that the action matches what you said; it does NOT vouch that a counterparty is trustworthy. [security; up to 200c/call]
tool-call-guard(call, intent, context, expected)
Pre-execution safety oracle for agent actions: submit the tool call you are about to run (shell, http, sql, file, code, env) plus your stated intent, and get a machine-enforceable verdict before you execute it. Decodes what the call does, flags the danger toolkit (rm -rf, reverse shell, curl|sh, SSRF to cloud metadata, credential reads, DROP/DELETE-without-WHERE, path traversal, dynamic eval), and binds it to your intent (allowedHosts/allowedPaths/readOnly/noNetwork) - only a fully pinned, clean, intent-matched call is auto-exec-safe. Hybrid: a deterministic, uninjectable detector engine (authoritative) plus an LLM classifier that can only raise the risk. Fails closed. Detection of known-dangerous patterns, not a proof of safety; it never executes the call. [security; up to 8c/call] Required: call.
x402-trust-audit(context, expected, endpointUrl, spendPolicy, paymentPayload, serverMetadata, paymentRequirements, selectedOptionIndex)
Vet an x402 counterparty before settling USDC: scores the advertised payment requirements AND (when supplied) the EIP-3009 authorization you are about to sign. Returns a machine-enforceable trust verdict (per-entry scores, coverage-honest trustScore, spend-constraint + tamper-evident fingerprint) for buyer agents and wallet/spend-policy layers. No endpoint fetch. [security; up to 200c/call] Required: paymentRequirements.

Last successful function declaration observed on . Source: https://paygent.obsmetrics.com/mcp. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://paygent.obsmetrics.com/mcp.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
Latest published version 0.0.8 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-06-16 When the registry record was last updated by its maintainer. point in time Model Context Protocol
First listed in the MCP Registry 2026-06-16 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
mcp tools declared 7 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe paygent.obsmetrics.com
mcp endpoint status ok The server listed 7 functions when asked. as of probe paygent.obsmetrics.com

Where to get it

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Tools declared by the MCP server at https://paygent.obsmetrics.com/mcp — paygent.obsmetrics.com, observed , trust tier 1.
  2. Official MCP Registry — Model Context Protocol, observed , trust tier 1.