InterAI Risk Oracle
REMOTE · API.INTERAILABS.DEV · SCANNED SEP 25
Pre-execution policy gate for consequential agent actions with durable trust receipts.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability87
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1962 tokens (~115/item across 17 items; 9 tools + 8 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
- Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 9 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the InterAI Risk Oracle MCP server?
InterAI Risk Oracle is a hosted endpoint at https://api.interailabs.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.interailabs.dev
claude mcp add --transport http interailabs-ai-risk-oracle 'https://api.interailabs.dev/mcp'
{
"mcpServers": {
"interailabs-ai-risk-oracle": {
"url": "https://api.interailabs.dev/mcp"
}
}
} {
"servers": {
"interailabs-ai-risk-oracle": {
"type": "http",
"url": "https://api.interailabs.dev/mcp"
}
}
} [mcp_servers.interailabs-ai-risk-oracle] url = "https://api.interailabs.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"interailabs-ai-risk-oracle": {
"type": "remote",
"url": "https://api.interailabs.dev/mcp",
"enabled": true
}
}
} openclaw mcp add interailabs-ai-risk-oracle --url 'https://api.interailabs.dev/mcp' --transport streamable-http
mcp_servers:
interailabs-ai-risk-oracle:
url: "https://api.interailabs.dev/mcp" {
"McpServers": {
"interailabs-ai-risk-oracle": {
"Transport": "http",
"Url": "https://api.interailabs.dev/mcp"
}
}
} assistant mcp add interailabs-ai-risk-oracle -t streamable-http -u 'https://api.interailabs.dev/mcp'
{
"mcpServers": {
"interailabs-ai-risk-oracle": {
"type": "http",
"url": "https://api.interailabs.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- Server version: 0.1.3-beta → 0.1.3-beta.1 functional
- 16 Sept 26 73
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 25 Sept 2026 · Probed https://api.interailabs.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.interailabs.dev | CN=YE2,O=Let's Encrypt,C=US | 15 Sept 2026 | 14 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5f94b0ce59f042e5ace80c8517e3dbf1253 |
| SANs: api.interailabs.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.interailabs.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| interailabs.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.interailabs.dev/mcp | Verified | 200 | |
| http (plaintext) | http://api.interailabs.dev/mcp | HTTPS enforced | 301 | https://api.interailabs.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
oracle.agent_card A2A Agent Card ~58
Read-only A2A Agent Card with agent identity, security scheme, capabilities, and skills. Use it when selecting or integrating InterAI through A2A; use oracle.service_descriptor for general service metadata or oracle.discovery_bundle for complete bootstrap context.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| capabilities | object | yes | – |
| defaultInputModes | array | – | – |
| defaultOutputModes | array | – | – |
| description | string | yes | – |
| documentationUrl | string | – | – |
| name | string | yes | – |
| provider | object | – | – |
| security | array | – | – |
| securitySchemes | object | – | – |
| skills | array | yes | – |
| url | string | yes | – |
| version | string | yes | – |
No examples provided.
oracle.discovery_bundle Discovery Bundle ~70
Read-only bootstrap or handoff bundle with service identity, interfaces, runtime mode, contracts, schemas, and sample payloads in one response. Use it for complete integration context; use oracle.service_descriptor for focused service metadata, oracle.agent_card for A2A capabilities, or oracle.get_pricing for costs.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| discovery | object | yes | – |
| interfaces | object | yes | – |
| name | string | yes | – |
| runtime | object | yes | – |
| samples | object | yes | – |
| service | object | yes | – |
No examples provided.
oracle.get_pricing Get Pricing ~49
Read-only public metadata for costs, trial availability, idempotency, and top-up or payment paths. Use it before budgeting or onboarding; it does not evaluate risk or create a trust receipt.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| auth | object | yes | – |
| chain | string | yes | – |
| currency | string | yes | – |
| demo | object | yes | – |
| idempotency | object | yes | – |
| model | string | yes | – |
| protocols | object | yes | – |
| topup | object | yes | – |
| trial | object | yes | – |
| unit | string | yes | – |
| verify | object | yes | – |
| verify_batch | object | yes | – |
No examples provided.
oracle.get_trust_receipt Get Trust Receipt ~86
Read-only lookup of the canonical public representation and signature metadata for a trust receipt that already exists. Supply receipt_id. It does not create or re-run a decision; use oracle.verify_trust_receipt_signature when the goal is signature validation.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt_id | string | yes | Identifier of the existing InterAI trust receipt whose canonical public representation and signature metadata should be returned. |
| Name | Type | Req | Description |
|---|---|---|---|
| ok | boolean | yes | – |
| receipt | object | yes | – |
| trust | object | yes | – |
| verification | object | yes | – |
No examples provided.
oracle.service_descriptor Service Descriptor ~56
Read-only general service descriptor with identity, endpoints, billing, trust, and supported agent protocols. Use it to inspect service-level integration metadata; use oracle.agent_card for A2A skills or oracle.discovery_bundle for the complete bootstrap package.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_protocols | object | yes | – |
| billing | object | yes | – |
| description | string | yes | – |
| discovery | object | yes | – |
| endpoints | object | yes | – |
| id | string | yes | – |
| name | string | yes | – |
| version | string | yes | – |
No examples provided.
oracle.verify_autonomous_action Verify Autonomous Action ~465
Primary tool for one concrete proposed autonomous action before it executes. This authenticated prepaid verification may consume account balance and records a signed trust receipt; InterAI evaluates the proposal but does not execute or modify the proposed external action. Reuse idempotency_key only when retrying the same logical request to avoid duplicate billing. Returns allow, review_required, or block with policy signals. Use oracle.verify_batch for multiple independent items and oracle.verify_response only for legacy prompt/response compatibility.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | The proposed action. For executable pilot authorization use interai-canonical-action/v1 with host-registry tool_id, type, operation, exact arguments, and explicit side-effect semantics. |
| authorization_ttl_seconds | integer | – | Lifetime of a single-use execution authorization for a canonical action. Only Bearer-authenticated pilot requests receive executable authorization material. |
| context | object | – | Optional runtime context surrounding the proposed action, such as environment, agent identity, counterparty, user confirmation, or other facts relevant to this decision. |
| domain | string | – | Optional domain label used to provide verification context. It does not replace the exact action, context, or policy inputs. |
| execution_context | object | – | Host-attested execution context bound to a canonical action. InterAI authenticates the account, not the truth of host-provided workspace, actor, run, or environment values. |
| external_evidence | array | – | Optional signed or verifiable external assertions. Current Stage 2 evidence is parsed, verified, bound, and recorded as non-authoritative evidence; it does not directly determine the InterAI executio… |
| idempotency_key | string | – | Stable caller-provided key for retrying the same billed verification without duplicating the economic operation. Reuse it only for the same logical request. |
| mode | string | – | Verification mode. Use fast_heuristic for the default low-latency path or semantic_judge when a semantic model judgment is explicitly required. |
| policy | object | – | Optional strictly validated caller-scoped restrictions. They may tighten the boundary but cannot weaken host or account policy. |
| use_case | string | yes | Stable identifier describing why the exact autonomous action is being proposed. Required together with action for the autonomous_execution contract. |
| Name | Type | Req | Description |
|---|---|---|---|
| billed | object | yes | Billing metadata for this verification call. |
| result | object | yes | Pre-execution decision, policy evaluation, signals, and trust-receipt evidence. |
No examples provided.
oracle.verify_batch Verify Batch ~151
Use for multiple independent legacy or autonomous verification items in one authenticated prepaid call (1 to 100). The batch may consume account balance and records one trust receipt per item; InterAI does not execute any proposed external action. Reuse idempotency_key only for the same logical batch retry. For one proposed action, use oracle.verify_autonomous_action instead.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Stable caller-provided key for retrying the same billed verification without duplicating the economic operation. Reuse it only for the same logical request. |
| items | array | yes | Independent verification items. Each item must contain either prompt + response or use_case + action; 1 to 100 items are accepted. |
| Name | Type | Req | Description |
|---|---|---|---|
| batch_size | integer | yes | Number of independently evaluated batch items. |
| billed | object | yes | Billing metadata for the batch operation. |
| oracle | object | yes | InterAI engine and signing metadata. |
| results | array | yes | Independent verification decisions in the same order as the submitted items. |
| summary | object | yes | Aggregate batch summary. |
No examples provided.
oracle.verify_response Verify Response (Legacy) ~511
Legacy compatibility entry point for existing clients. This authenticated prepaid verification may consume account balance and records a trust receipt, but it does not execute any proposed external action. Supply exactly one contract: prompt + response, or use_case + action; never mix them. Reuse idempotency_key only for the same logical retry. For new action preflight use oracle.verify_autonomous_action; use oracle.verify_batch for multiple items.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | – | The proposed action. For executable pilot authorization use interai-canonical-action/v1 with host-registry tool_id, type, operation, exact arguments, and explicit side-effect semantics. |
| authorization_ttl_seconds | integer | – | Lifetime of a single-use execution authorization for a canonical action. Only Bearer-authenticated pilot requests receive executable authorization material. |
| context | object | – | Optional runtime context surrounding the proposed action, such as environment, agent identity, counterparty, user confirmation, or other facts relevant to this decision. |
| domain | string | – | Optional domain label used to provide verification context. It does not replace the exact action, context, or policy inputs. |
| execution_context | object | – | Host-attested execution context bound to a canonical action. InterAI authenticates the account, not the truth of host-provided workspace, actor, run, or environment values. |
| external_evidence | array | – | Optional signed or verifiable external assertions. Current Stage 2 evidence is parsed, verified, bound, and recorded as non-authoritative evidence; it does not directly determine the InterAI executio… |
| idempotency_key | string | – | Stable caller-provided key for retrying the same billed verification without duplicating the economic operation. Reuse it only for the same logical request. |
| mode | string | – | Verification mode. Use fast_heuristic for the default low-latency path or semantic_judge when a semantic model judgment is explicitly required. |
| policy | object | – | Optional strictly validated caller-scoped restrictions. They may tighten the boundary but cannot weaken host or account policy. |
| prompt | string | – | Legacy compatibility input: the original prompt whose response is being verified. Use together with response, not with autonomous action fields. |
| response | string | – | Legacy compatibility input: the response to evaluate against prompt. Use together with prompt, not with autonomous action fields. |
| use_case | string | – | Stable identifier describing why the exact autonomous action is being proposed. Required together with action for the autonomous_execution contract. |
| Name | Type | Req | Description |
|---|---|---|---|
| billed | object | yes | Billing metadata for this verification call. |
| result | object | yes | Pre-execution decision, policy evaluation, signals, and trust-receipt evidence. |
No examples provided.
oracle.verify_trust_receipt_signature Verify Trust Receipt Signature ~251
Read-only service-side validation of a trust receipt that already exists. Supply signature plus either receipt_id for the canonical server-stored receipt or a caller-supplied receipt object. Returns valid true or false when signing is enabled. Current signatures use HMAC-SHA256 and are service-verifiable by InterAI, not independent offline public-key proofs. It does not evaluate risk or create a receipt; use oracle.get_trust_receipt to retrieve receipt metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt | object | – | Optional caller-supplied receipt object, typically evidence received from another agent or system. Either receipt or receipt_id is required. |
| receipt_id | string | – | Optional ID of an existing InterAI trust receipt. InterAI resolves the canonical server-stored record before validating the supplied signature. Either receipt_id or receipt is required. |
| signature | string | yes | HMAC-SHA256 signature to validate against the referenced InterAI receipt. Required. |
| signature_alg | string | – | Optional signature algorithm declaration. The current supported value is hmac-sha256. |
| signed_payload | string | – | Optional exact serialized payload that was signed. Supply it when validating externally transported receipt evidence that includes the original signed payload. |
| Name | Type | Req | Description |
|---|---|---|---|
| signature_alg | string | yes | Signature algorithm used by the current InterAI receipt verifier. |
| valid | boolean | yes | Whether the supplied signature matches the referenced stored receipt. |
No examples provided.
What is the InterAI Risk Oracle MCP server?
InterAI Risk Oracle is an MCP server listed in the public MCP registry as io.github.InterAILabs/ai-risk-oracle. Pre-execution policy gate for consequential agent actions with durable trust receipts. This page covers its hosted endpoint (https://api.interailabs.dev/mcp).
Is the InterAI Risk Oracle MCP server safe to use?
InterAI Risk Oracle scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the InterAI Risk Oracle MCP server expose?
InterAI Risk Oracle exposes 9 tools: oracle.verify_autonomous_action, oracle.verify_response, oracle.verify_batch, oracle.get_pricing, oracle.discovery_bundle, and 4 more. Their descriptions and schemas cost roughly 1,697 tokens of context every time the server is loaded.
Does the InterAI Risk Oracle MCP server require authentication?
No. We connected to InterAI Risk Oracle without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the InterAI Risk Oracle MCP server still maintained?
InterAI Risk Oracle is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.