io.github.f-tiger/agiscorecard-web3-workbench
REMOTE · WEB3.AGISCORECARD.COM · SCANNED SEP 27
AGI Scorecard Web3 Workbench: ten free deterministic review tools (stablecoin, gas, zkML, agents).
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security69
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability85
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 3153 tokens (~50/item across 62 items; 12 tools + 50 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management7
- Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.f-tiger/agiscorecard-web3-workbench MCP server?
io.github.f-tiger/agiscorecard-web3-workbench is a hosted endpoint at https://web3.agiscorecard.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · web3.agiscorecard.com
claude mcp add --transport http f-tiger-agiscorecard-web3-workbench 'https://web3.agiscorecard.com/mcp'
{
"mcpServers": {
"f-tiger-agiscorecard-web3-workbench": {
"url": "https://web3.agiscorecard.com/mcp"
}
}
} {
"servers": {
"f-tiger-agiscorecard-web3-workbench": {
"type": "http",
"url": "https://web3.agiscorecard.com/mcp"
}
}
} [mcp_servers.f-tiger-agiscorecard-web3-workbench] url = "https://web3.agiscorecard.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"f-tiger-agiscorecard-web3-workbench": {
"type": "remote",
"url": "https://web3.agiscorecard.com/mcp",
"enabled": true
}
}
} openclaw mcp add f-tiger-agiscorecard-web3-workbench --url 'https://web3.agiscorecard.com/mcp' --transport streamable-http
mcp_servers:
f-tiger-agiscorecard-web3-workbench:
url: "https://web3.agiscorecard.com/mcp" {
"McpServers": {
"f-tiger-agiscorecard-web3-workbench": {
"Transport": "http",
"Url": "https://web3.agiscorecard.com/mcp"
}
}
} assistant mcp add f-tiger-agiscorecard-web3-workbench -t streamable-http -u 'https://web3.agiscorecard.com/mcp'
{
"mcpServers": {
"f-tiger-agiscorecard-web3-workbench": {
"type": "http",
"url": "https://web3.agiscorecard.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 26 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 25 Sept 26 71
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://web3.agiscorecard.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=agiscorecard.com | CN=WE1,O=Google Trust Services,C=US | 19 Sept 2026 | 18 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | d564eaece833eee00ea1fd9dc90b44ae |
| SANs: agiscorecard.com, web3.agiscorecard.com, *.web3.agiscorecard.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of web3.agiscorecard.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| agiscorecard.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self' https://*.agiscorecard.com; connect-src 'self'; base-uri 'none'; form-action 'none'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://web3.agiscorecard.com/mcp | Verified | 200 | |
| http (plaintext) | http://web3.agiscorecard.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_data_permissions Data Permit ~208
Data Permit compares an intended AI use with your recorded grant conditions: region, expiry, revocation and consent status. It calculates a proposed split of received revenue and keeps incompatible shares unallocated. Matching fields does not establish a legal license. No legal opinion, rights verification, consent collection, access enforcement, token issuance or payment. Retrieve permit with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | yes | Review date (UTC) (preserve source text; decimal amounts must stay strings) |
| currency | string | yes | Currency (preserve source text; decimal amounts must stay strings) |
| datasets | array | yes | Datasets |
| receivedRevenue | string | yes | Revenue already received (preserve source text; decimal amounts must stay strings) |
| region | string | yes | Region (preserve source text; decimal amounts must stay strings) |
| use | string | yes | Use (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
compare_compute_costs Compute Lens ~178
Compute Lens compares measured workload runs using total entered compute, setup, storage and egress costs per accepted output. It filters mismatched workload labels, currencies, quality and memory limits. All examples are fictional; no live GPU quotes are supplied. No live GPU inventory, automatic benchmarking, reservation, infrastructure management or verified savings. Retrieve compute with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | yes | Currency (preserve source text; decimal amounts must stay strings) |
| minimumPassRate | number | yes | Minimum accepted fraction (0–1) |
| model | string | yes | Model (preserve source text; decimal amounts must stay strings) |
| runs | array | yes | Runs |
| workload | string | yes | Workload (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
compare_rwa_disclosures RWA Notes ~145
RWA Notes compares two sets of supplied asset disclosure fields while retaining units, dates and source references. It flags missing values and incompatible comparisons. It does not verify reserves, issuer solvency or redemption rights. No live asset feed, reserve audit, redemption verification, credit rating or investment recommendation. Retrieve disclosures with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| after | array | yes | After |
| asOf | string | yes | Review date (UTC) (preserve source text; decimal amounts must stay strings) |
| before | array | yes | Before |
| maxAgeDays | number | yes | Maximum evidence age (days) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
decode_token_call Call Lens ~253
Call Lens decodes supported token-call shapes locally and compares the recipient, spender and atomic amount with your expectations. It distinguishes ERC-20 allowances from ERC-721 token IDs using the declared standard. It never connects a wallet or evaluates contract safety. No chain simulation, malicious-contract detection, token identity lookup, balance inspection or safety verdict. Retrieve calls with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| data | string | yes | Hex calldata (preserve source text; decimal amounts must stay strings) |
| expectedRecipient | string | yes | Expected recipient / spender (preserve source text; decimal amounts must stay strings) |
| maxAtomicAmount | string | yes | Amount limit (atomic units) (preserve source text; decimal amounts must stay strings) |
| nativeValueAtomic | string | yes | Native value (atomic units) (preserve source text; decimal amounts must stay strings) |
| network | string | yes | Network (preserve source text; decimal amounts must stay strings) |
| to | string | yes | Target contract (preserve source text; decimal amounts must stay strings) |
| tokenStandard | string | yes | Token Standard (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
fetch Read a Web3 method and sources ~49
Retrieve a public tool reference by the ID returned from search. Contains methodology, limits, official source links and fictional worked examples; no user records. Cite the returned canonical URL.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| metadata | object | yes | – |
| text | string | yes | – |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
model_contributor_rewards Incentive Lab ~267
Incentive Lab separates customer revenue from token subsidy, then allocates a declared reward budget using accepted work and quality weights. Contributor caps and exact budget conservation keep the scenario inspectable. The worksheet does not establish Sybil resistance or distribute tokens. No live subnet data, fraud detection, Bittensor emission replication, staking recommendation or token distribution. Retrieve incentives with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| budget | string | yes | Total budget (preserve source text; decimal amounts must stay strings) |
| capPercent | number | yes | Maximum contributor share (%) |
| computeCost | string | yes | Compute Cost (preserve source text; decimal amounts must stay strings) |
| contributors | array | yes | Contributors |
| currency | string | yes | Currency (preserve source text; decimal amounts must stay strings) |
| customerRevenue | string | yes | Customer Revenue (preserve source text; decimal amounts must stay strings) |
| otherCost | string | yes | Other Cost (preserve source text; decimal amounts must stay strings) |
| reviewCost | string | yes | Review Cost (preserve source text; decimal amounts must stay strings) |
| tokenSubsidy | string | yes | Token Subsidy (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
plan_fallback_routes Route Lab ~184
Route Lab compares short supplier sequences using entered cost, success and latency assumptions. It checks the worst-case total against your budget before sorting feasible options by expected cost. It is an offline planning tool; no model or payment is called. Offline planning only. No live requests, model judge, payment, dynamic bandit or production routing. Retrieve route with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| budget | string | yes | Total budget (preserve source text; decimal amounts must stay strings) |
| candidates | array | yes | Candidates |
| currency | string | yes | Currency (preserve source text; decimal amounts must stay strings) |
| maxAttempts | number | yes | Maximum attempts |
| maxLatencyMs | number | yes | Total latency bound (ms) |
| minSuccess | number | yes | Minimum success probability (0–1) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
plan_zkml_costs Proof Plan ~339
Proof Plan estimates proving compute and onchain verification costs from your own measurements. It checks a per-job latency target and preserves model, input and verification-key hashes. It plans an integration; it does not generate or verify a zero-knowledge proof. No ZK proof generation or cryptographic verification. File hashing verifies bytes only; it is not proof of model correctness. Retrieve proof with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| budgetUsd | number | yes | Budget (USD) |
| computeHourlyUsd | number | yes | Proving compute (USD/hour) |
| gasPerVerify | number | yes | Gas per verification |
| gasPriceGwei | number | yes | Gas Price Gwei |
| inputHash | string | yes | Input Hash (preserve source text; decimal amounts must stay strings) |
| jobs | number | yes | Jobs |
| latencySlaSeconds | number | yes | Latency target (seconds) |
| modelHash | string | yes | Model Hash (preserve source text; decimal amounts must stay strings) |
| nativePriceUsd | number | yes | Native token price (USD) |
| proofBytes | number | yes | Proof size (bytes) |
| proveSeconds | number | yes | Proving time (seconds) |
| statement | string | yes | Statement (preserve source text; decimal amounts must stay strings) |
| verificationKeyHash | string | yes | Verification Key Hash (preserve source text; decimal amounts must stay strings) |
| verifierVersion | string | yes | Verifier Version (preserve source text; decimal amounts must stay strings) |
| verifyMs | number | yes | Verification time (ms) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
read_protocol_profiles Protocol Ledger ~174
Protocol Ledger is a free, dated reference for five payment, agent-identity and token interfaces. Each record preserves its official specification, review date and interpretation limits. Filter the same snapshot in the browser or retrieve it through the JSON API. Five initial profiles; no market prices, exhaustive schema coverage, real-time protocol monitoring or paid endpoint. Retrieve protocol with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | yes | Review date (UTC) (preserve source text; decimal amounts must stay strings) |
| maxAgeDays | number | yes | Maximum evidence age (days) |
| purpose | string | yes | Purpose (preserve source text; decimal amounts must stay strings) |
| status | string | yes | Status (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
reconcile_stablecoin_records Stable Reconcile ~112
Stable Reconcile compares your declared invoices with recorded stablecoin transfers. It separates partial payments, pending transfers and wrong-network records, with exact decimal totals. Use it for a local exception review before updating your books. No wallet sync, automatic matching, FX, refund processing, tax accounting or independent finality checks. Retrieve reconcile with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| invoices | array | yes | Invoices |
| transfers | array | yes | Transfers |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
review_agent_evidence Agent Evidence ~177
Agent Evidence reviews imported task outcomes within one task, version and date window. It deduplicates sample labels and shows failures, exclusions and uncertainty. It helps review a supplier comparison; it does not run evaluations or verify reviewer identities. No public reputation ranking, identity verification, calibrated prediction or Sybil detection. Retrieve evidence with fetch or read its example resource to obtain exact inputs. Parameters are processed remotely without application persistence.
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | yes | Review date (UTC) (preserve source text; decimal amounts must stay strings) |
| maxAgeDays | number | yes | Maximum evidence age (days) |
| records | array | yes | Records |
| task | string | yes | Task (preserve source text; decimal amounts must stay strings) |
| version | string | yes | Version (preserve source text; decimal amounts must stay strings) |
| Name | Type | Req | Description |
|---|---|---|---|
| citation | object | yes | – |
| evidenceStatus | string | yes | – |
| limitations | string | yes | – |
| officialReferences | array | yes | – |
| processing | string | yes | – |
| report | object | yes | – |
| revision | string | yes | – |
| toolId | string | yes | – |
| version | string | yes | – |
No examples provided.
search Find a Web3 worksheet ~40
Search this server’s public AI/Web3 tools and citation pages. English and Chinese names supported. Empty query lists the available worksheets.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | – |
No examples provided.
What is the io.github.f-tiger/agiscorecard-web3-workbench MCP server?
io.github.f-tiger/agiscorecard-web3-workbench is an MCP server listed in the public MCP registry as io.github.f-tiger/agiscorecard-web3-workbench. AGI Scorecard Web3 Workbench: ten free deterministic review tools (stablecoin, gas, zkML, agents). This page covers its hosted endpoint (https://web3.agiscorecard.com/mcp).
Is the io.github.f-tiger/agiscorecard-web3-workbench MCP server safe to use?
io.github.f-tiger/agiscorecard-web3-workbench scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.f-tiger/agiscorecard-web3-workbench MCP server expose?
io.github.f-tiger/agiscorecard-web3-workbench exposes 12 tools: search, fetch, reconcile_stablecoin_records, review_agent_evidence, plan_fallback_routes, and 7 more. Their descriptions and schemas cost roughly 2,126 tokens of context every time the server is loaded.
Does the io.github.f-tiger/agiscorecard-web3-workbench MCP server require authentication?
No. We connected to io.github.f-tiger/agiscorecard-web3-workbench without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.f-tiger/agiscorecard-web3-workbench MCP server still maintained?
io.github.f-tiger/agiscorecard-web3-workbench is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.