Ground Truth - First Call Activation
REMOTE · GROUND-TRUTH-MCP.ANISHDASMAIL.WORKERS.DEV · SCANNED AUG 3
First MCP call: run check_endpoint with url=https://example.com. Paid plan adds monitors.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_monitor). See how to fix → View diagnostics → Fail
- HTTPS not yet verified: we couldn't determine whether a plaintext access path exists. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2086 tokens (~130/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · ground-truth-mcp.anishdasmail.workers.dev
claude mcp add --transport http anish632-ground-truth https://ground-truth-mcp.anishdasmail.workers.dev/mcp
[mcp_servers.anish632-ground-truth] url = "https://ground-truth-mcp.anishdasmail.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"anish632-ground-truth": {
"type": "remote",
"url": "https://ground-truth-mcp.anishdasmail.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add anish632-ground-truth --url https://ground-truth-mcp.anishdasmail.workers.dev/mcp --transport streamable-http
mcp_servers:
anish632-ground-truth:
url: "https://ground-truth-mcp.anishdasmail.workers.dev/mcp" {
"mcpServers": {
"anish632-ground-truth": {
"type": "http",
"url": "https://ground-truth-mcp.anishdasmail.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 −2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://ground-truth-mcp.anishdasmail.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=anishdasmail.workers.dev | CN=YE1,O=Let's Encrypt,C=US | 16 Jun 2026 | 14 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 61c2b75c3c80a003b10051ae11883311088 |
| SANs: *.anishdasmail.workers.dev, anishdasmail.workers.dev | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of ground-truth-mcp.anishdasmail.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ground-truth-mcp.anishdasmail.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://ground-truth-mcp.anishdasmail.workers.dev/mcp | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
assess_compliance_posture Compliance Signal Scan ~113
Scan a public security, trust, compliance, or legal page for common enterprise buying signals before you claim a vendor supports a particular compliance posture. It looks for public references to SOC 2, ISO 27001, GDPR, HIPAA, DPA terms, subprocessors, SSO, SCIM, encryption, and data residency language. This is a signal scanner, not proof of certification or legal sufficiency.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Public trust, security, compliance, or policy URL to scan. |
| Name | Type | Req | Description |
|---|---|---|---|
| cached | boolean | — | True when the page body came from the 5-minute cache. |
| error | string | — | Fetch or parsing error when the page could not be analyzed. |
| matchedSignals | array | — | Signal names that were detected on the page. |
| pageLength | integer | — | Size of the fetched page body in characters. |
| signals | object | — | Boolean scan results for common enterprise compliance and security signals. |
| url | string | yes | Compliance or trust page that was analyzed. |
No examples provided.
check_endpoint Endpoint Reachability Check ~147
Perform one live, unauthenticated fetch against a public URL or API endpoint before you recommend it, document it, or build on top of it. Use this when the question is simply whether an endpoint currently responds and what kind of response it returns. It reports HTTP status, content type, elapsed time, likely auth/rate-limit signals, and a short response sample. A successful result only proves basic reachability at fetch time. Do not use it to validate authenticated flows, POST side effects, JavaScript execution, or deeper business logic.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Public http(s) URL or bare domain to probe. Bare domains like google.com are accepted and normalized to https:// automatically. |
| Name | Type | Req | Description |
|---|---|---|---|
| accessible | boolean | yes | True when the endpoint returned a 2xx HTTP status. |
| authRequired | boolean | — | True when the server responded with 401 or 403, which usually means credentials are required. |
| contentType | string|null | — | Response Content-Type header, if present. |
| error | string | — | Validation or network error when the request could not be completed. |
| inputUrl | string | — | Original user input when normalization changed it, for example when https:// was added. |
| rateLimited | boolean | — | True when the server responded with 429 Too Many Requests. |
| responseTimeMs | integer | — | Elapsed request time in milliseconds. |
| sampleResponse | string | — | First 1,000 characters of the response body for quick inspection. Use this as a debugging hint only; it may be truncated and should not be treated as a complete page capture. |
| status | integer | — | HTTP status code returned by the endpoint, when a response was received. |
| url | string | yes | Normalized URL that was actually fetched. |
No examples provided.
check_pricing Pricing Page Scan ~166
Fetch a public pricing page and extract first-pass pricing signals before you quote plan costs, free tiers, or plan names. Use this when you already have a likely pricing URL and need a quick live scan of visible page text. It returns price-like strings, heuristic plan labels, free or free-trial signals, and cache information. It does not map prices to exact plans, normalize currencies, execute checkout flows, or guarantee that a price applies to a specific region or customer type. JavaScript-rendered, logged-in, or heavily obfuscated pricing details can be missed. Results are cached for 5 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Public pricing or plans URL to analyze. Prefer the specific pricing page, for example https://stripe.com/pricing, rather than a generic homepage. |
| Name | Type | Req | Description |
|---|---|---|---|
| cached | boolean | — | True when the page body came from the 5-minute cache instead of a new fetch. |
| error | string | — | Fetch or parsing error when the pricing page could not be analyzed. |
| hasFreeOption | boolean | — | True when the page contains signals that a free plan or $0 option exists somewhere on the page. This is a page-level signal, not proof that the offer is currently self-serve or globally available. |
| hasFreeTrial | boolean | — | True when the page contains signals that a free trial exists somewhere on the page. |
| pageLength | integer | — | Size of the fetched page body in characters. |
| plansDetected | array | — | Lowercased heuristic plan labels detected from the page text. They are useful hints, not authoritative plan identifiers. |
| pricesFound | array | — | Distinct price-like strings extracted from the page text. These are not linked back to specific plans or billing conditions. |
| url | string | yes | Pricing page that was analyzed. |
No examples provided.
compare_competitors Named Package Comparison ~192
Compare two or more exact package names side by side using live npm or PyPI metadata. Use this when you already know the candidate packages and need evidence for claims such as 'tool A is newer', 'tool B is still maintained', or 'these packages use different licenses'. It returns per-package registry metadata in input order, with field availability varying by registry. Missing or unpublished packages return found=false. Do not use it to discover unknown alternatives, estimate market size, or compare packages across different registries. Registry responses are cached for 5 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| packages | array | yes | Two to ten exact package names from the same registry, for example ['react', 'vue']. Use exact registry names, not search phrases or categories. |
| registry | string | — | Registry that all package names belong to. All compared packages must come from the same registry, and returned metadata fields differ slightly between npm and PyPI. |
| Name | Type | Req | Description |
|---|---|---|---|
| comparisons | array | yes | Per-package lookup results returned in the same order as the input package list. Some fields only exist for npm or only for PyPI, so consumers should treat absent fields as normal. |
| packages | array | yes | Package names that were requested for comparison. |
| registry | string | yes | Registry used for all comparisons. |
No examples provided.
compare_pricing_pages Pricing Page Comparison ~95
Compare two to five public pricing pages side by side before you make competitive pricing or packaging claims. Use this when you want a quick, live comparison of visible prices, free-plan signals, and plan-name hints across vendors. The output is heuristic and page-level: it does not map every price to every plan or normalize regional billing differences.
| Name | Type | Req | Description |
|---|---|---|---|
| pages | array | yes | Two to five named pricing pages to compare side by side. |
| Name | Type | Req | Description |
|---|---|---|---|
| pages | array | yes | Per-page pricing signals returned in input order. |
| summary | object | yes | Aggregate counts across all compared pricing pages. |
No examples provided.
create_monitor Create Monitor ~325
Create a persistent monitor that tracks a URL, pricing page, package version, endpoint status, vendor claim, or custom keyword pattern over time. Monitors run automatically on their configured schedule (hourly/daily/weekly) via the Cloudflare cron trigger, or on demand with run_monitor_now. Results are stored in the Durable Object SQLite database. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| instructions | string | — | Supplementary instructions. For vendor_claim: the URL to check. For custom_prompt: comma-separated keywords. Optional for other types. |
| name | string | yes | Human-readable name for this monitor. |
| notification_destination | string | — | Optional destination reserved for a future alert-delivery integration. |
| schedule | string | — | How often the monitor runs automatically. manual means only via run_monitor_now. |
| target_type | string | yes | What to monitor. url/endpoint: HTTP reachability and status. pricing_page: pricing signals (prices, plans, free tier). package: package version on npm or pypi (target_value as 'npm:pkg-name' or 'pypi… |
| target_value | string | yes | Primary target. For url/endpoint/pricing_page/custom_prompt: a public https URL. For package: 'npm:package-name' or 'pypi:package-name'. For vendor_claim: the claim text to search for. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | Creation timestamp ISO 8601. |
| error | string | — | Error message if creation failed. |
| id | string | yes | Unique monitor ID. |
| name | string | yes | Monitor name. |
| schedule | string | yes | Monitor schedule. |
| target_type | string | yes | Monitor target type. |
| target_value | string | yes | Monitor target value. |
No examples provided.
delete_monitor Delete Monitor ~44
Permanently delete a monitor and all its stored results. This action cannot be undone. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| monitor_id | string | yes | The monitor ID to delete. |
| Name | Type | Req | Description |
|---|---|---|---|
| deleted | boolean | yes | — |
| error | string | — | — |
| monitor_id | string | yes | — |
| results_deleted | number | yes | Number of result records also deleted. |
No examples provided.
estimate_market Package Market Search ~149
Search npm or PyPI to estimate how crowded a package category is before you claim that a market is empty, niche, or competitive. Use this when you have a category or search phrase such as 'edge orm' and want live result counts plus representative matches. Do not use it to compare exact known package names or to infer adoption from downloads; it reflects search results, not market share. Registry responses are cached for 5 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Short registry search phrase to evaluate, for example 'mcp memory server' or 'edge orm'. |
| registry | string | — | Registry to search. Use 'npm' for JavaScript ecosystems and 'pypi' for Python ecosystems. |
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Search phrase that was evaluated. |
| registry | string | yes | Registry that was searched. |
| topResults | array | yes | Representative top search matches that help interpret the market count. |
| totalResults | — | yes | Total number of matching packages reported by the registry search. |
No examples provided.
generate_change_report Generate Change Report ~89
Generate a summary report of monitor activity for a time window. Shows monitors run, changes detected, failures, risk levels, and recommended follow-up actions. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| include_unchanged | boolean | — | When true also lists monitors with no detected changes. |
| period | string | — | Report period. daily covers the past 24 hours, weekly covers the past 7 days. |
| Name | Type | Req | Description |
|---|---|---|---|
| changes | array | yes | — |
| error | string | — | — |
| failures | array | yes | — |
| from | string | yes | — |
| period | string | yes | — |
| recommended_actions | array | yes | — |
| summary | object | yes | — |
| to | string | yes | — |
No examples provided.
get_monitor_result Get Monitor Results ~71
Retrieve the most recent run results for a monitor, including change details, confidence score, evidence URLs, and any error information. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximum number of results to return, newest first. |
| monitor_id | string | yes | The monitor ID to retrieve results for. |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | — |
| monitor_id | string | yes | — |
| results | array | yes | — |
| total | number | yes | — |
No examples provided.
inspect_security_headers Security Header Inspection ~126
Fetch a public URL and inspect security-relevant response headers before you claim that a product or endpoint has a strong browser-facing security baseline. Use this for quick due diligence on public apps and docs sites. It checks for common headers such as HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options. It does not replace a real security review, authenticated testing, or vulnerability scanning.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Public http(s) URL or bare domain to inspect. Bare domains are normalized to https:// automatically. |
| Name | Type | Req | Description |
|---|---|---|---|
| accessible | boolean | yes | True when the endpoint returned an HTTP response. |
| error | string | — | Validation or network error when the request could not be completed. |
| headers | object | — | Tracked response headers and their raw values when present. |
| https | boolean | yes | True when the normalized URL used https. |
| inputUrl | string | — | Original user input when normalization changed it. |
| missingRecommended | array | — | Tracked headers that were not present on the response. |
| presentCount | integer | — | Number of tracked security headers that were present. |
| score | string | — | Heuristic security-header score based on how many tracked headers were present. |
| status | integer | — | HTTP status code returned by the endpoint. |
| url | string | yes | Normalized URL that was fetched. |
No examples provided.
list_monitors List Monitors ~52
List all monitors owned by this API key, with last run status and schedule. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| active_only | boolean | — | When true returns only active monitors. Set false to include paused monitors. |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | — |
| monitors | array | yes | List of monitors belonging to this API key. |
| total | number | yes | Total number of monitors returned. |
No examples provided.
list_resources Server Resource Discovery ~48
List all available Ground Truth tools and their access tiers. Zero-cost schema discovery. Call this to explore what verification tools are available before making a tool call. No quota consumption, no API key required.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| freeTools | array | yes | Tools available in the free tier with no API key required. |
| monitorTools | array | yes | Monitor management tools requiring team API key. |
| paidTools | array | yes | Tools requiring team API key or agentic payment. |
| serverVersion | string | yes | Current server version. |
No examples provided.
run_monitor_now Run Monitor Now ~63
Immediately run a monitor's verification check outside its normal schedule. Records the result and returns whether the observed value changed since the last run. Counts against your monthly quota. Requires a team API key.
| Name | Type | Req | Description |
|---|---|---|---|
| monitor_id | string | yes | The monitor ID returned by create_monitor. |
| Name | Type | Req | Description |
|---|---|---|---|
| changed | boolean | yes | — |
| confidence | number|null | yes | — |
| error | string | — | — |
| evidence | array | yes | — |
| monitor_id | string | yes | — |
| new_value | string|null | yes | — |
| old_value | string|null | yes | — |
| result_id | string | yes | — |
| run_at | string | yes | — |
| status | string | yes | — |
No examples provided.
test_hypothesis Multi-step Hypothesis Test ~200
Run a small verification plan made of concrete live checks and summarize whether a hypothesis is supported. Use this when one conclusion depends on multiple simple checks such as endpoint reachability, npm search counts, or whether a page contains an exact substring. This is a coordination tool, not an open-ended research agent: every test must be explicitly defined in advance, and tests run in order with no branching or early exit. The final verdict is mechanical: all tests passing => SUPPORTED, zero passing => REFUTED, otherwise PARTIALLY SUPPORTED. Use verify_claim when you already have evidence URLs, estimate_market for category sizing, and compare_competitors when you already know exact package names.
| Name | Type | Req | Description |
|---|---|---|---|
| hypothesis | string | yes | Claim to test, for example 'there are fewer than 50 MCP email servers on npm'. |
| tests | array | yes | Ordered list of one to ten checks to run. Each test object uses only the fields required by its type. |
| Name | Type | Req | Description |
|---|---|---|---|
| hypothesis | string | yes | Hypothesis that was evaluated. |
| tests | array | yes | Per-test execution results in input order. |
| verdict | object | yes | High-level verdict for the hypothesis. |
No examples provided.
verify_claim Claim Support Check ~206
Check whether a factual claim is supported by a specific set of public evidence URLs that you already have. For each source, the tool performs a case-insensitive keyword match over the fetched page body, then marks that source as supporting the claim when at least half of the supplied keywords appear. Use this for evidence-backed claim checks on known pages, not for open-ended search, semantic reasoning, or contradiction extraction. The aggregate verdict is driven only by the per-page keyword support ratio. Fetched pages are cached for 5 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| claim | string | yes | Plain-language claim to verify, for example 'AWS Business support includes 24/7 phone support'. |
| evidence_urls | array | yes | One to ten public documentation, pricing, policy, or support URLs that are likely to contain direct evidence for the claim. |
| keywords | array | yes | Keywords or short phrases that should appear on supporting pages. Matching is case-insensitive substring matching, so choose phrases that are likely to appear verbatim. |
| Name | Type | Req | Description |
|---|---|---|---|
| claim | string | yes | Claim that was evaluated. |
| sources | array | yes | Per-source evidence results. |
| verdict | object | yes | Aggregate verdict across all supplied sources. |
No examples provided.