ai.velarion/company-intelligence
REMOTE · VELARION-SCRAPER-PRODUCTION.UP.RAILWAY.APP · SCANNED AUG 3
Exec comp benchmarking, say-on-pay risk, and governance cards for US public companies.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 9 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability37
- AI-judged instruction clarity (fair).Partial
- Context-footprint check failed: tool/resource definitions use about 1700 tokens (~188/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · velarion-scraper-production.up.railway.app
claude mcp add --transport http ai-velarion-company-intelligence https://velarion-scraper-production.up.railway.app/mcp
[mcp_servers.ai-velarion-company-intelligence] url = "https://velarion-scraper-production.up.railway.app/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-velarion-company-intelligence": {
"type": "remote",
"url": "https://velarion-scraper-production.up.railway.app/mcp",
"enabled": true
}
}
} openclaw mcp add ai-velarion-company-intelligence --url https://velarion-scraper-production.up.railway.app/mcp --transport streamable-http
mcp_servers:
ai-velarion-company-intelligence:
url: "https://velarion-scraper-production.up.railway.app/mcp" {
"mcpServers": {
"ai-velarion-company-intelligence": {
"type": "http",
"url": "https://velarion-scraper-production.up.railway.app/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 49
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://velarion-scraper-production.up.railway.app/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.up.railway.app | CN=YE1,O=Let's Encrypt,C=US | 29 Jul 2026 | 27 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 6da79bb561da3efeb0e751ca21abd3999fe |
| SANs: *.up.railway.app, up.railway.app | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of velarion-scraper-production.up.railway.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| railway.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://velarion-scraper-production.up.railway.app/mcp | Verified | 200 | |
| http (plaintext) | http://velarion-scraper-production.up.railway.app/mcp | HTTPS enforced | 301 | https://velarion-scraper-production.up.railway.app/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
benchmark_executive_pay ~118
Benchmark executive pay vs. disclosed peers using Velarion's canonical percentile data. Returns pay percentile, performance (TSR) percentile, P4P gap, and an alignment label based on canonical_metrics columns (ceo_percentile, tsr_percentile, p4p_gap). No LLM. role is currently CEO-only (only CEO percentile is pre-computed in canonical_metrics).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| fiscal_year | — | — | — |
| role | string | — | — |
| ticker | string | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
compare_companies ~92
Compare multiple companies on pay, performance, and governance metrics. Returns a ranked table from Velarion's canonical_metrics — no LLM narrative invention. The data-based summary describes observed patterns in the returned data only. Out-of-coverage tickers are excluded (listed separately). Max 20 tickers.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| fiscal_year | — | — | — |
| tickers | array | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
fulfill_paid_order ~193
Fulfill a paid custom quote by compiling and delivering its artifact. Ownership gate: you may only fulfill a quote your own agent account owns. (The REST buyer rail has always enforced this — routes.py:656 — and this tool did not, which meant any valid token could fulfill, and therefore download, an artifact somebody else had paid for. Latent while every token was owner-issued; a live artifact leak the moment self-serve issuance opened. Closed here.) Settlement gate (fail-closed): if the quote is priced and settlement is not verified on any rail, returns settlement_unverified — compile_and_deliver is NOT called. On verified settlement: calls compile_and_deliver (fulfillment.py:121) — the same path used by Danny and the agent bridge. No forked fulfillment logic.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| quote_id | string | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
generate_governance_alpha_card ~319
Generate a Governance Alpha Card for a company. Composite deterministic card: pay alignment (Velarion's own P4P-style estimate, modeled on public proxy-advisory methodology concepts — not licensed ISS data), governance scorecard, SoP risk band, peer quality, top risks/strengths. Requires the company to be in Velarion's coverage universe with current-period data. Calls generate_alpha_card (lib/agent_merchant/compilers/governance_alpha_card.py:441) after confirming deliverability via evaluate_deliverability (deliverability.py:219), which includes the period-currency gate (_governance_alpha_card_period_gate at :312). FREE-TIER CAP: this is the free sample of a $100 marketplace product (GOVERNANCE-ALPHA-CARD, pricer.py:59). Each agent gets ALPHA_CARD_FREE_DAILY_CAP cards per UTC day; beyond that the tool returns free_tier_cap_reached with the purchase path. Unlimited free issuance of the paid anchor product is the contradiction the catalog's PRICE_INTEGRITY blocker named — the cap is what resolves it. Structured errors returned (not raised) for: - not_in_coverage: ticker unknown - not_deliverable: coverage too thin / stale period - free_tier_cap_reached: daily free allowance spent (buy it, or wait for 00:00 UTC)
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| ticker | string | yes | — |
| year | — | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
list_skus ~153
List the Velarion catalog — every product an agent can see and (where APPROVED_SELLABLE) buy. Returns all APPROVED_SELLABLE SKUs with full detail by default (sku_id, name, price, currency, fulfillment type, latency, caveats, classification). Set include_non_sellable=true to also return NEEDS_OWNER_APPROVAL / UNSELLABLE / KILLED rows, each clearly tagged with its classification and blockers so inventory is never hidden — only de-prioritized. No price is fabricated: unverified prices are surfaced as-is with their classification, never quoted as billable.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| include_non_sellable | boolean | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
lookup_company_compensation ~107
Look up executive compensation for a company in Velarion's coverage universe. Returns CEO/NEO total compensation, pay mix breakdown, and canonical metrics for the requested fiscal year (latest available if omitted). All data sourced from Supabase production tables — no LLM, no invented values. Out-of-coverage tickers return a structured error (not_in_coverage).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| fiscal_year | — | — | — |
| ticker | string | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
place_order ~242
Place an order for a priced product — creates a quote you can pay and then fulfill. This is the missing middle of the buy path: price_product tells you what it costs, place_order creates the actual quote (owned by YOUR agent account), and fulfill_paid_order delivers it once settlement clears. Requires a token with the mcp:buy scope AND a Velarion commerce account — a self-serve token issued at POST /agent/v1/token/self-serve has both. CUSTOM-* cohort products (CUSTOM-PEER-COHORT / CUSTOM-SOP-WINDOW / CUSTOM-GOV-EXTENDED): the ticker list is the comparison cohort, capped at 15 distinct tickers (a 16th is a clean too_many_tickers rejection, never a silent truncation). The subject is the first in-coverage ticker unless subject_ticker names another cohort member. Returns quote_id, the price, and how to pay. Nothing is charged here.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| product_type | string | yes | — |
| scope_params | — | — | — |
| subject_ticker | — | — | — |
| tickers | array | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
predict_say_on_pay_risk ~129
Predict Say-on-Pay risk for a company using Velarion's deterministic risk compilers. Returns trend phrase, peer cohort distribution note, governance friction summary, and overall risk band. No LLM — fully deterministic from canonical_metrics + say_on_pay data. Compilers: compile_sop_trend_phrase, compile_sop_peer_cohort_distribution, compile_governance_friction_summary (lib/agent_merchant/compilers/say_on_pay_risk.py).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| fiscal_year | — | — | — |
| ticker | string | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.
price_product ~272
Price a Velarion product. Handles EVERY catalog SKU in its real state. product_type may be a sku_id (e.g. "SKU-002") OR a custom_artifact_family (e.g. "peer_disclosure_custom_cohort"). Returns the row's classification and, when APPROVED_SELLABLE, the price a buyer is actually charged: - APPROVED_SELLABLE → proposed_price_cents + currency + fulfillment_type + latency + caveats. No price floor touches it (deleted 2026-07-14); the catalog/pricer anchor IS the billed price. - NEEDS_OWNER_APPROVAL → {status: "needs_owner_approval"} structurally — price is known but the row is pending Andy's approval flip. - UNSELLABLE / KILLED → structured error with the reason. custom_band families price via the profit-aware pricer (respecting MERCHANT_MIN_MARGIN); one_off_fixed SKUs price at the canonical catalog price_cents. No fabricated price is ever returned (price_verified gate enforced upstream in classify_sku).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_token | string | — | — |
| buyer_type | — | — | — |
| product_type | string | yes | — |
| scope_params | — | — | — |
| ticker | string | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.