com.lvlltd/skill-market
REMOTE · LVLLTD.COM · SCANNED AUG 9
x402 skill catalog on lvlltd.com — search, quote, pay with Base USDC, unlock sealed packs.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 31 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability27
- 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
- AI-judged instruction clarity (poor).Fail
- Tool/resource definitions use about 1688 tokens (~52/item across 32 items; 31 tools + 1 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage72
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 16% of tool parameters carry a description.Partial
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Unverified: 1 category
A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · lvlltd.com
claude mcp add --transport http com-lvlltd-skill-market https://lvlltd.com/api/mcp
[mcp_servers.com-lvlltd-skill-market] url = "https://lvlltd.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-lvlltd-skill-market": {
"type": "remote",
"url": "https://lvlltd.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-lvlltd-skill-market --url https://lvlltd.com/api/mcp --transport streamable-http
mcp_servers:
com-lvlltd-skill-market:
url: "https://lvlltd.com/api/mcp" {
"mcpServers": {
"com-lvlltd-skill-market": {
"type": "http",
"url": "https://lvlltd.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 9 Aug 26 52
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 9 Aug 2026 · Probed https://lvlltd.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=lvlltd.com | CN=WE1,O=Google Trust Services,C=US | 15 Jul 2026 | 13 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 1c7b0b6f333cf4f713caf0edf3806b84 |
| SANs: lvlltd.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC secure
Validation of lvlltd.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| lvlltd.com. | present | 2371 | 13 | Verified |
| lvlltd.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), interest-cohort=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://lvlltd.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://lvlltd.com/api/mcp | HTTPS enforced | 301 | https://lvlltd.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
challenge_file ~99
File economic challenge against any sealed cid with counter-proof. Without payment returns 402 stake challenge.
| Name | Type | Req | Description |
|---|---|---|---|
| challenger_id | string | – | – |
| claim | string | – | – |
| counter_proof_type | string | – | – |
| dev | boolean | – | – |
| stake_usd | number | – | – |
| target_cid | string | yes | – |
| target_kind | string | – | – |
| tx_hash | string | – | or use dev:true for smoke |
No output schema declared.
No examples provided.
check_access ~54
Resolve skill access: one_time_unlock (perpetual) > catalog_sub > bundle_renew > meter. Never confuses live access with sealed ownership.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
| wallet | string | yes | – |
No output schema declared.
No examples provided.
esp_cycle ~54
Full ESP cycle for a skill (evaluate/settle/prove descriptors). Free. Never invents quality.
| Name | Type | Req | Description |
|---|---|---|---|
| phase | string | – | optional evaluate|settle|prove|cycle |
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
esp_discover ~29
ESP protocol root — free-eval → settle → prove invariants + completion layer URLs. Free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_commerce_signals ~42
Rank skills by confirmed unlock demand. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| skill_id | string | – | – |
| sort | string | – | – |
No output schema declared.
No examples provided.
get_eval_score ~28
Public eval suite pass rate if suite exists. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
get_payment_challenge ~37
Live x402 402 challenge for a skill. Does not unlock. Pay then purchase_skill.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
get_security_scan ~35
Published security scan for a skill (real findings or clean-with-honesty). Free.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
get_skill_details ~29
Public skill details + outline/sample/challenge links. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
graph_advance ~77
Advance capability graph: tick|free_eval|settle|prove|replan|fail_node|kill.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| graph_id | string | yes | – |
| node_id | string | – | – |
| reason | string | – | – |
| skill_id | string | – | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.
graph_create ~56
Create ESP capability graph from intent (free-eval canaries → settle → prove). Free create.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_usd_max | number | – | – |
| intent_text | string | yes | – |
| risk_tier_max | string | – | – |
No output schema declared.
No examples provided.
install ~51
Alias of install_skill_payload — after purchase write sealed files + SKILL.md paths. Requires tx_hash.
| Name | Type | Req | Description |
|---|---|---|---|
| agents | string | – | – |
| skill_id | string | yes | – |
| tx_hash | string | yes | – |
No output schema declared.
No examples provided.
install_skill_payload ~54
After purchase: sealed files + SKILL.md install paths. Requires tx_hash (routes through /api/pay).
| Name | Type | Req | Description |
|---|---|---|---|
| agents | string | – | – |
| skill_id | string | yes | – |
| tx_hash | string | yes | – |
No output schema declared.
No examples provided.
intent_search ~38
Natural-language goal → ranked skills/stacks (semantic TF-IDF). Free.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| q | string | yes | – |
No output schema declared.
No examples provided.
list_all_skills ~60
Paginated full catalog listing (all public skills from catalog.json — not a subset). Free.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| limit | number | – | default 50, max 200 |
| offset | number | – | default 0 |
No output schema declared.
No examples provided.
list_oracles ~66
List Oracle Rails (kind=oracle ESP skills). Free. Same discovery path as skills — free eval sacred, reputation from proof ledger only.
| Name | Type | Req | Description |
|---|---|---|---|
| live | boolean | – | If true, only live/beta |
| priority | string | – | P0 | P1 | P2 |
No output schema declared.
No examples provided.
list_recurring_plans ~52
List catalog live / update / bundle-renew / metered plans. One-time unlocks remain separate and perpetual. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| wallet | string | – | Optional — include this wallet's subs + meter |
No output schema declared.
No examples provided.
lookup_agent_identity ~36
ERC-8004 / local identity lookup for a wallet. Additive — not required to buy.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
No output schema declared.
No examples provided.
memory_discover ~49
Sealed memory rails discovery + free-eval meta. Full value requires settle. Free for discovery/eval.
| Name | Type | Req | Description |
|---|---|---|---|
| cid | string | – | – |
| phase | string | – | evaluate for free meta |
No output schema declared.
No examples provided.
meter_budget ~73
Get or set spend cap; or quote metered per-call x402 for a skill. Caps prevent runaway agent spend.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | status | set_cap | quote (default status) |
| skill_id | string | – | – |
| spend_cap_usd | number | – | – |
| wallet | string | yes | – |
No output schema declared.
No examples provided.
oracle_challenge ~36
x402 402 challenge for a sealed oracle result. Free. Pay then oracle_settle.
| Name | Type | Req | Description |
|---|---|---|---|
| oracle_id | string | yes | – |
No output schema declared.
No examples provided.
oracle_free_eval ~57
Free-evaluate an oracle (capped sample). Sacred free path — no payment. Returns sealed sample pack (not ledger-recorded).
| Name | Type | Req | Description |
|---|---|---|---|
| oracle_id | string | yes | – |
| query | object | – | Optional; defaults to sample_query |
No output schema declared.
No examples provided.
oracle_result ~47
Re-download content-addressed sealed oracle result by cid for independent re-verification.
| Name | Type | Req | Description |
|---|---|---|---|
| cid | string | yes | – |
| oracle_id | string | yes | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.
oracle_settle ~63
Without tx_hash: payment_required 402. With tx_hash: settle → sealed attested result + proof ledger (kind=oracle). No payment bypass.
| Name | Type | Req | Description |
|---|---|---|---|
| oracle_id | string | yes | – |
| query | object | – | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.
purchase_skill ~69
Without tx_hash: payment_required 402 payload. With tx_hash: POST unlock via existing /api/pay (no payment bypass).
| Name | Type | Req | Description |
|---|---|---|---|
| ap2_mandate | string | – | Optional AP2 mandate JSON for authorized spend |
| skill_id | string | yes | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.
quote_price ~40
Alias of get_payment_challenge — live x402 quote (amount, payTo, asset). Free. Full catalog.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
quote_skill ~33
Alias of quote_price / get_payment_challenge — live x402 quote. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | yes | – |
No output schema declared.
No examples provided.
search_skills ~66
Search lvlltd.com x402 skill catalog. Free. Returns price + free_eval URLs.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| limit | number | – | – |
| max_price_usd | number | – | – |
| q | string | – | – |
| tag | string | – | – |
No output schema declared.
No examples provided.
subscribe_plan ~82
Without tx_hash: 402 challenge for a plan. With tx_hash: start/renew. Cancel: action=cancel (one step). Never revokes one-time unlocks.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | start | renew | cancel (default start) |
| plan_id | string | yes | – |
| tx_hash | string | – | – |
| wallet | string | yes | – |
No output schema declared.
No examples provided.
verify_skill ~46
Alias of verify_unlock — check public /api/proof ledger for confirmed unlocks (never invents volume).
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | – | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.
verify_unlock ~41
Check public /api/proof ledger for confirmed unlocks (never invents volume).
| Name | Type | Req | Description |
|---|---|---|---|
| skill_id | string | – | – |
| tx_hash | string | – | – |
No output schema declared.
No examples provided.