Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Ground Truth - First Call Activation

REMOTE · GROUND-TRUTH-MCP.ANISHDASMAIL.WORKERS.DEV · SCANNED AUG 3

First MCP call: run check_endpoint with url=https://example.com. Paid plan adds monitors.

+2 this week 62 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2086 tokens (~130/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · ground-truth-mcp.anishdasmail.workers.dev

# add to Claude Code
claude mcp add --transport http anish632-ground-truth https://ground-truth-mcp.anishdasmail.workers.dev/mcp
# ~/.codex/config.toml
[mcp_servers.anish632-ground-truth]
url = "https://ground-truth-mcp.anishdasmail.workers.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "anish632-ground-truth": {
      "type": "remote",
      "url": "https://ground-truth-mcp.anishdasmail.workers.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add anish632-ground-truth --url https://ground-truth-mcp.anishdasmail.workers.dev/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  anish632-ground-truth:
    url: "https://ground-truth-mcp.anishdasmail.workers.dev/mcp"
// mcp.json
{
  "mcpServers": {
    "anish632-ground-truth": {
      "type": "http",
      "url": "https://ground-truth-mcp.anishdasmail.workers.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 −2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://ground-truth-mcp.anishdasmail.workers.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=anishdasmail.workers.dev CN=YE1,O=Let's Encrypt,C=US 16 Jun 2026 14 Sept 2026 ECDSA 256 ECDSA-SHA384 61c2b75c3c80a003b10051ae11883311088
SANs: *.anishdasmail.workers.dev, anishdasmail.workers.dev
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of ground-truth-mcp.anishdasmail.workers.dev. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
workers.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://ground-truth-mcp.anishdasmail.workers.dev/mcp Verified 200
http (plaintext) http://ground-truth-mcp.anishdasmail.workers.dev/mcp Inconclusive 406
MCP tools — 16 exposed · ~2,086 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
assess_compliance_posture ~113

Scan a public security, trust, compliance, or legal page for common enterprise buying signals before you claim a vendor supports a particular compliance posture. It looks for public references to SOC 2, ISO 27001, GDPR, HIPAA, DPA terms, subprocessors, SSO, SCIM, encryption, and data residency language. This is a signal scanner, not proof of certification or legal sufficiency.

NameTypeReqDescription
urlstringyesPublic trust, security, compliance, or policy URL to scan.
NameTypeReqDescription
cachedbooleanTrue when the page body came from the 5-minute cache.
errorstringFetch or parsing error when the page could not be analyzed.
matchedSignalsarraySignal names that were detected on the page.
pageLengthintegerSize of the fetched page body in characters.
signalsobjectBoolean scan results for common enterprise compliance and security signals.
urlstringyesCompliance or trust page that was analyzed.

No examples provided.

check_endpoint ~147

Perform one live, unauthenticated fetch against a public URL or API endpoint before you recommend it, document it, or build on top of it. Use this when the question is simply whether an endpoint currently responds and what kind of response it returns. It reports HTTP status, content type, elapsed time, likely auth/rate-limit signals, and a short response sample. A successful result only proves basic reachability at fetch time. Do not use it to validate authenticated flows, POST side effects, JavaScript execution, or deeper business logic.

NameTypeReqDescription
urlstringyesPublic http(s) URL or bare domain to probe. Bare domains like google.com are accepted and normalized to https:// automatically.
NameTypeReqDescription
accessiblebooleanyesTrue when the endpoint returned a 2xx HTTP status.
authRequiredbooleanTrue when the server responded with 401 or 403, which usually means credentials are required.
contentTypestring|nullResponse Content-Type header, if present.
errorstringValidation or network error when the request could not be completed.
inputUrlstringOriginal user input when normalization changed it, for example when https:// was added.
rateLimitedbooleanTrue when the server responded with 429 Too Many Requests.
responseTimeMsintegerElapsed request time in milliseconds.
sampleResponsestringFirst 1,000 characters of the response body for quick inspection. Use this as a debugging hint only; it may be truncated and should not be treated as a complete page capture.
statusintegerHTTP status code returned by the endpoint, when a response was received.
urlstringyesNormalized URL that was actually fetched.

No examples provided.

check_pricing ~166

Fetch a public pricing page and extract first-pass pricing signals before you quote plan costs, free tiers, or plan names. Use this when you already have a likely pricing URL and need a quick live scan of visible page text. It returns price-like strings, heuristic plan labels, free or free-trial signals, and cache information. It does not map prices to exact plans, normalize currencies, execute checkout flows, or guarantee that a price applies to a specific region or customer type. JavaScript-rendered, logged-in, or heavily obfuscated pricing details can be missed. Results are cached for 5 minutes.

NameTypeReqDescription
urlstringyesPublic pricing or plans URL to analyze. Prefer the specific pricing page, for example https://stripe.com/pricing, rather than a generic homepage.
NameTypeReqDescription
cachedbooleanTrue when the page body came from the 5-minute cache instead of a new fetch.
errorstringFetch or parsing error when the pricing page could not be analyzed.
hasFreeOptionbooleanTrue when the page contains signals that a free plan or $0 option exists somewhere on the page. This is a page-level signal, not proof that the offer is currently self-serve or globally available.
hasFreeTrialbooleanTrue when the page contains signals that a free trial exists somewhere on the page.
pageLengthintegerSize of the fetched page body in characters.
plansDetectedarrayLowercased heuristic plan labels detected from the page text. They are useful hints, not authoritative plan identifiers.
pricesFoundarrayDistinct price-like strings extracted from the page text. These are not linked back to specific plans or billing conditions.
urlstringyesPricing page that was analyzed.

No examples provided.

compare_competitors ~192

Compare two or more exact package names side by side using live npm or PyPI metadata. Use this when you already know the candidate packages and need evidence for claims such as 'tool A is newer', 'tool B is still maintained', or 'these packages use different licenses'. It returns per-package registry metadata in input order, with field availability varying by registry. Missing or unpublished packages return found=false. Do not use it to discover unknown alternatives, estimate market size, or compare packages across different registries. Registry responses are cached for 5 minutes.

NameTypeReqDescription
packagesarrayyesTwo to ten exact package names from the same registry, for example ['react', 'vue']. Use exact registry names, not search phrases or categories.
registrystringRegistry that all package names belong to. All compared packages must come from the same registry, and returned metadata fields differ slightly between npm and PyPI.
NameTypeReqDescription
comparisonsarrayyesPer-package lookup results returned in the same order as the input package list. Some fields only exist for npm or only for PyPI, so consumers should treat absent fields as normal.
packagesarrayyesPackage names that were requested for comparison.
registrystringyesRegistry used for all comparisons.

No examples provided.

compare_pricing_pages ~95

Compare two to five public pricing pages side by side before you make competitive pricing or packaging claims. Use this when you want a quick, live comparison of visible prices, free-plan signals, and plan-name hints across vendors. The output is heuristic and page-level: it does not map every price to every plan or normalize regional billing differences.

NameTypeReqDescription
pagesarrayyesTwo to five named pricing pages to compare side by side.
NameTypeReqDescription
pagesarrayyesPer-page pricing signals returned in input order.
summaryobjectyesAggregate counts across all compared pricing pages.

No examples provided.

create_monitor ~325

Create a persistent monitor that tracks a URL, pricing page, package version, endpoint status, vendor claim, or custom keyword pattern over time. Monitors run automatically on their configured schedule (hourly/daily/weekly) via the Cloudflare cron trigger, or on demand with run_monitor_now. Results are stored in the Durable Object SQLite database. Requires a team API key.

NameTypeReqDescription
instructionsstringSupplementary instructions. For vendor_claim: the URL to check. For custom_prompt: comma-separated keywords. Optional for other types.
namestringyesHuman-readable name for this monitor.
notification_destinationstringOptional destination reserved for a future alert-delivery integration.
schedulestringHow often the monitor runs automatically. manual means only via run_monitor_now.
target_typestringyesWhat to monitor. url/endpoint: HTTP reachability and status. pricing_page: pricing signals (prices, plans, free tier). package: package version on npm or pypi (target_value as 'npm:pkg-name' or 'pypi…
target_valuestringyesPrimary target. For url/endpoint/pricing_page/custom_prompt: a public https URL. For package: 'npm:package-name' or 'pypi:package-name'. For vendor_claim: the claim text to search for.
NameTypeReqDescription
created_atstringyesCreation timestamp ISO 8601.
errorstringError message if creation failed.
idstringyesUnique monitor ID.
namestringyesMonitor name.
schedulestringyesMonitor schedule.
target_typestringyesMonitor target type.
target_valuestringyesMonitor target value.

No examples provided.

delete_monitor ~44

Permanently delete a monitor and all its stored results. This action cannot be undone. Requires a team API key.

NameTypeReqDescription
monitor_idstringyesThe monitor ID to delete.
NameTypeReqDescription
deletedbooleanyes
errorstring
monitor_idstringyes
results_deletednumberyesNumber of result records also deleted.

No examples provided.

estimate_market ~149

Search npm or PyPI to estimate how crowded a package category is before you claim that a market is empty, niche, or competitive. Use this when you have a category or search phrase such as 'edge orm' and want live result counts plus representative matches. Do not use it to compare exact known package names or to infer adoption from downloads; it reflects search results, not market share. Registry responses are cached for 5 minutes.

NameTypeReqDescription
querystringyesShort registry search phrase to evaluate, for example 'mcp memory server' or 'edge orm'.
registrystringRegistry to search. Use 'npm' for JavaScript ecosystems and 'pypi' for Python ecosystems.
NameTypeReqDescription
querystringyesSearch phrase that was evaluated.
registrystringyesRegistry that was searched.
topResultsarrayyesRepresentative top search matches that help interpret the market count.
totalResultsyesTotal number of matching packages reported by the registry search.

No examples provided.

generate_change_report ~89

Generate a summary report of monitor activity for a time window. Shows monitors run, changes detected, failures, risk levels, and recommended follow-up actions. Requires a team API key.

NameTypeReqDescription
include_unchangedbooleanWhen true also lists monitors with no detected changes.
periodstringReport period. daily covers the past 24 hours, weekly covers the past 7 days.
NameTypeReqDescription
changesarrayyes
errorstring
failuresarrayyes
fromstringyes
periodstringyes
recommended_actionsarrayyes
summaryobjectyes
tostringyes

No examples provided.

get_monitor_result ~71

Retrieve the most recent run results for a monitor, including change details, confidence score, evidence URLs, and any error information. Requires a team API key.

NameTypeReqDescription
limitintegerMaximum number of results to return, newest first.
monitor_idstringyesThe monitor ID to retrieve results for.
NameTypeReqDescription
errorstring
monitor_idstringyes
resultsarrayyes
totalnumberyes

No examples provided.

inspect_security_headers ~126

Fetch a public URL and inspect security-relevant response headers before you claim that a product or endpoint has a strong browser-facing security baseline. Use this for quick due diligence on public apps and docs sites. It checks for common headers such as HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options. It does not replace a real security review, authenticated testing, or vulnerability scanning.

NameTypeReqDescription
urlstringyesPublic http(s) URL or bare domain to inspect. Bare domains are normalized to https:// automatically.
NameTypeReqDescription
accessiblebooleanyesTrue when the endpoint returned an HTTP response.
errorstringValidation or network error when the request could not be completed.
headersobjectTracked response headers and their raw values when present.
httpsbooleanyesTrue when the normalized URL used https.
inputUrlstringOriginal user input when normalization changed it.
missingRecommendedarrayTracked headers that were not present on the response.
presentCountintegerNumber of tracked security headers that were present.
scorestringHeuristic security-header score based on how many tracked headers were present.
statusintegerHTTP status code returned by the endpoint.
urlstringyesNormalized URL that was fetched.

No examples provided.

list_monitors ~52

List all monitors owned by this API key, with last run status and schedule. Requires a team API key.

NameTypeReqDescription
active_onlybooleanWhen true returns only active monitors. Set false to include paused monitors.
NameTypeReqDescription
errorstring
monitorsarrayyesList of monitors belonging to this API key.
totalnumberyesTotal number of monitors returned.

No examples provided.

list_resources ~48

List all available Ground Truth tools and their access tiers. Zero-cost schema discovery. Call this to explore what verification tools are available before making a tool call. No quota consumption, no API key required.

Input schema present but exposes no named parameters.

NameTypeReqDescription
freeToolsarrayyesTools available in the free tier with no API key required.
monitorToolsarrayyesMonitor management tools requiring team API key.
paidToolsarrayyesTools requiring team API key or agentic payment.
serverVersionstringyesCurrent server version.

No examples provided.

run_monitor_now ~63

Immediately run a monitor's verification check outside its normal schedule. Records the result and returns whether the observed value changed since the last run. Counts against your monthly quota. Requires a team API key.

NameTypeReqDescription
monitor_idstringyesThe monitor ID returned by create_monitor.
NameTypeReqDescription
changedbooleanyes
confidencenumber|nullyes
errorstring
evidencearrayyes
monitor_idstringyes
new_valuestring|nullyes
old_valuestring|nullyes
result_idstringyes
run_atstringyes
statusstringyes

No examples provided.

test_hypothesis ~200

Run a small verification plan made of concrete live checks and summarize whether a hypothesis is supported. Use this when one conclusion depends on multiple simple checks such as endpoint reachability, npm search counts, or whether a page contains an exact substring. This is a coordination tool, not an open-ended research agent: every test must be explicitly defined in advance, and tests run in order with no branching or early exit. The final verdict is mechanical: all tests passing => SUPPORTED, zero passing => REFUTED, otherwise PARTIALLY SUPPORTED. Use verify_claim when you already have evidence URLs, estimate_market for category sizing, and compare_competitors when you already know exact package names.

NameTypeReqDescription
hypothesisstringyesClaim to test, for example 'there are fewer than 50 MCP email servers on npm'.
testsarrayyesOrdered list of one to ten checks to run. Each test object uses only the fields required by its type.
NameTypeReqDescription
hypothesisstringyesHypothesis that was evaluated.
testsarrayyesPer-test execution results in input order.
verdictobjectyesHigh-level verdict for the hypothesis.

No examples provided.

verify_claim ~206

Check whether a factual claim is supported by a specific set of public evidence URLs that you already have. For each source, the tool performs a case-insensitive keyword match over the fetched page body, then marks that source as supporting the claim when at least half of the supplied keywords appear. Use this for evidence-backed claim checks on known pages, not for open-ended search, semantic reasoning, or contradiction extraction. The aggregate verdict is driven only by the per-page keyword support ratio. Fetched pages are cached for 5 minutes.

NameTypeReqDescription
claimstringyesPlain-language claim to verify, for example 'AWS Business support includes 24/7 phone support'.
evidence_urlsarrayyesOne to ten public documentation, pricing, policy, or support URLs that are likely to contain direct evidence for the claim.
keywordsarrayyesKeywords or short phrases that should appear on supporting pages. Matching is case-insensitive substring matching, so choose phrases that are likely to appear verbatim.
NameTypeReqDescription
claimstringyesClaim that was evaluated.
sourcesarrayyesPer-source evidence results.
verdictobjectyesAggregate verdict across all supplied sources.

No examples provided.