Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Hermes Plant — Agent Commerce Assurance

REMOTE · MCP.HERMESPLANT.COM · SCANNED AUG 3

Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.

+6 this week 64 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security66
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
Schema Quality & AI Usability42
  • AI-judged instruction clarity (fair).Partial
  • Context-footprint check failed: tool/resource definitions use about 7012 tokens (~280/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · mcp.hermesplant.com

# add to Claude Code
claude mcp add --transport http jessegdotio-hermes-plant https://mcp.hermesplant.com/mcp
# ~/.codex/config.toml
[mcp_servers.jessegdotio-hermes-plant]
url = "https://mcp.hermesplant.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "jessegdotio-hermes-plant": {
      "type": "remote",
      "url": "https://mcp.hermesplant.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add jessegdotio-hermes-plant --url https://mcp.hermesplant.com/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  jessegdotio-hermes-plant:
    url: "https://mcp.hermesplant.com/mcp"
// mcp.json
{
  "mcpServers": {
    "jessegdotio-hermes-plant": {
      "type": "http",
      "url": "https://mcp.hermesplant.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Jul 26 0
    • Server version: 2.0.1 → 2.0.2 functional
  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 57

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://mcp.hermesplant.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=hermesplant.com CN=WE1,O=Google Trust Services,C=US 30 Jun 2026 28 Sept 2026 ECDSA 256 ECDSA-SHA256 200747b8b9ef136e13541517349220ae
SANs: hermesplant.com, mcp.hermesplant.com, *.mcp.hermesplant.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC secure

Validation of mcp.hermesplant.com. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
hermesplant.com. present 2371 13 Verified
mcp.hermesplant.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
x-content-type-options nosniff
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.hermesplant.com/mcp Verified 200
http (plaintext) http://mcp.hermesplant.com/mcp HTTPS enforced 301 https://mcp.hermesplant.com/mcp
MCP tools — 25 exposed · ~7,012 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
action_safety_quick_gate ~372

AI agent action safety quick gate ($0.01 over x402 or free-tier quota). Deterministically scores a consequential action and returns the exact next call: proceed, request full DestructGuard evidence, or run the complete Action Safety workflow.

NameTypeReqDescription
actorstringAgent or tool requesting the action
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
branchstringBranch or environment context
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
commandstringyesShell, SQL, Git, deploy, or infrastructure action to preflight
cwdstringWorking directory or execution context
diffStatstringOptional git diff --stat or change summary
intentstringWhy the action is being requested
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
repostringRepository or project context
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

action_safety_run ~377

Complete AI agent action safety workflow ($0.25 over x402 or free-tier quota): DestructGuard evidence, conditional ReviewQueue triage for high or critical risk, an honest decision, signed receipt, and 30-day status record. Triage does not imply human approval.

NameTypeReqDescription
actorstringAgent or tool requesting the action
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
branchstringBranch or environment context
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
commandstringyesShell, SQL, Git, deploy, or infrastructure action to preflight
cwdstringWorking directory or execution context
diffStatstringOptional git diff --stat or change summary
intentstringWhy the action is being requested
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
repostringRepository or project context
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

assurance_attest ~433

Assurance Attest (x402-paid, $0.05): bind one x402 payment intent or MCP tool call to a canonical HMAC-signed record (binding hash, policy verdict, findings, optional settlement outcome). Loop it after every payment or tool call to build a tamper-evident audit trail a third party can check at the free verify endpoint.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
intentobjectyesx402: resourceUrl+method (+scheme/network/asset/amountUnits/payTo/settlement fields). mcp: serverId+toolName (+toolArguments or toolArgumentsHash).
outcomeobjectOptional settlement outcome: {outcome: fulfilled|failed|rejected, settlementId, responseStatus, evidenceHashes[]}
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
policyobjectOptional buyer policy (policyId+version, caps, allow-lists); omit for binding-only attestation
protocolstringyes"x402" for a payment, "mcp" for a tool call
subjectobjectyesWho acted and why
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

assurance_verify ~109

Verify a Hermes-signed assurance record for free: recomputes the canonical hash (hermes-stable-json-v1 + SHA-256) and HMAC signature server-side and reports recordHashValid / signatureValid. Use it to audit attestations produced by assurance_attest without trusting the agent that produced them.

NameTypeReqDescription
integrityobjectyesThe integrity object returned with the record (recordHash, signature, keyId)
recordobjectyesThe attestation/decision/receipt record object
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

bond_analyze ~410

BondLens (x402-paid, $0.25): deterministic fixed-income and loan analytics. Bond mode solves price<->yield-to-maturity, duration, and convexity; loan mode (send principal+annualRate+termMonths) returns an amortization schedule.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
annualRatenumberLoan annual rate, e.g. 0.06
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
couponRatenumberAnnual coupon rate, e.g. 0.05
faceValuenumberBond face value (default 1000)
frequencynumberCoupons per year (default 2)
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
periodsnumberPeriods to maturity
pricenumberBond price; supply to solve yield
principalnumberLoan principal (selects loan mode)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
termMonthsnumberLoan term in months
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
yieldnumberAnnual yield; supply to solve price
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

cashflowlens_analyze ~399

CashflowLens (x402-paid, $0.20): deterministic NPV, IRR, XIRR, DCF valuation, MOIC/DPI/TVPI, and payback period from a cashflow series. Use for valuation and return analysis instead of letting the model estimate.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
cashflowsarrayyesCashflows: numbers for periodic, or {amount,date} objects for dated XIRR. Outflows negative.
channelstringDiscovery channel or source tag
dcfobjectOptional DCF valuation inputs (projected FCFs, discount rate, terminal value, net debt, shares)
discountRatenumberAnnual rate for NPV, e.g. 0.08
navnumberResidual value, for TVPI
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
periodsPerYearnumberPeriods per year to annualize a periodic IRR
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

dealanalyzer_analyze ~351

DealAnalyzer (x402-paid, $2.00): the flagship. Deterministic full deal underwrite in a single call — DCF valuation (EV, equity value, implied share price), fund returns (IRR/MOIC), and the LP/GP distribution waterfall, plus sensitivity. Combines what CashflowLens + WaterfallLens do, cross-checked.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
dcfobjectyesRequired. DCF valuation inputs.
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
returnsobjectOptional fund/deal return inputs (IRR, MOIC, NPV).
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
waterfallobjectOptional LP/GP distribution waterfall inputs.
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

emailguard_validate ~317

EmailGuard (x402-paid, $0.02): deterministic email/contact quality scorer — validity, deliverability score, disposable/role/free classification, typo suggestion. Pure function, no DNS.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
domainstringOptional explicit domain hint (usually derived from email)
emailstringyesEmail address to validate
mxPresentbooleanCaller-supplied MX hint
namestringOptional contact name associated with the email
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

emailguard_validate_batch ~342

Validate up to 20 emails in one tool call — one deterministic verdict per record (validity, deliverability score, disposable/role/free classification, typo suggestion, canonical normalization). Pass your free apiKey (250 records/mo, no wallet — https://hermesplant.com/pricing) and each record serves from quota. Results preserve input order; the batch stops at the first 402 (quota exhausted) and marks the rest skipped so you can upgrade and resume.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
recordsarrayyesContact records to validate — one storefront call per record (max 20 per tool call)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

evidence_verify ~366

Evidence Verification (x402-paid, $0.05): verify an agent-commerce evidence bundle before trusting a paid result — x402 challenge/receipt/policy-decision/service-response artifacts, endpoint and price binding, freshness, hashes, synthetic-proof leakage. Returns verified / needs_review / rejected / insufficient_evidence with per-rule evidence.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
artifactsarrayyesEvidence artifacts (Hermes contract): x402_challenge, x402_receipt, payment_policy_decision, service_response, ...
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
policyobjectVerification policy: expected serviceId/endpoint/network/priceCents, require* flags
subjectobjectOptional run subject: kind, serviceId, endpoint, method, runId
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

freetier_status ~79

Check a free API key's remaining monthly quota, reset date, and upgrade path. Pass your hp_free_ key as apiKey. No key yet? POST an email to https://hermesplant.com/api/keys/free (250 calls/mo, no wallet).

NameTypeReqDescription
apiKeystringyesYour free-tier key (hp_free_...)
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

get_checkout_policies ~18

Return legal policy URLs required before checkout

Input schema present but exposes no named parameters.

NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

get_product ~27

Get a single product by slug

NameTypeReqDescription
slugstringyesProduct slug from the catalog
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

get_x402_manifest ~29

Return the live x402 manifest with paid endpoint prices, Bazaar metadata, and buyer policy checks

Input schema present but exposes no named parameters.

NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

list_products ~17

List active products from the Hermes Plant catalog

Input schema present but exposes no named parameters.

NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

mcp_risk_score ~326

MCP Server Risk Analyzer (x402-paid, $0.05): score an MCP server manifest for security risk before install — destructive tools, over-broad scopes, weak auth, egress — with per-tool findings and fixes.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
authModelstringe.g. oauth, token, none
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
priorToolsarrayPrior tool names to diff capability growth
serverstringServer name/URL
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
toolsarrayyesThe MCP server's tool manifest
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

options_price ~389

OptionLens (x402-paid, $0.30): deterministic Black-Scholes price and full Greeks (delta, gamma, vega, theta, rho) for European calls/puts, with dividend yield, intrinsic/time value, and moneyness.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
dividendYieldnumberContinuous dividend yield, default 0
optionTypestringOption type, 'call' or 'put' (default call)
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
riskFreeRatenumberAnnual risk-free rate, default 0
spotnumberyesUnderlying price (> 0)
strikenumberyesStrike price (> 0)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
timeToExpirynumberyesYears to expiry, e.g. 0.5
volatilitynumberyesAnnualized volatility, e.g. 0.2
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

payment_policy_decide ~508

Payment Policy Decision (x402-paid, $0.05): deterministic allow / deny / needs_review before your agent signs an x402 payment — checks resource binding, amount vs expected price, network, payTo, facilitator, replay readiness, PII leakage, and buyer spend limits, with evidence-backed findings. Loop it over every payment; pair with assurance_attest for a signed record.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
amountUnitsstringRaw x402 amount units (USDC = 6 decimals)
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
assetstringPayment asset address
buyerPolicyobjectBuyer guardrails: maxUsdPerCall, allowedNetworks, allowedPayTo, allowedHosts, requireExactScheme, requireHttps, ...
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
facilitatorUrlstringFacilitator URL used to settle
maxTimeoutSecondsnumberChallenge timeout window
methodstringHTTP method the agent intends to call
networkstringPayment network, e.g. eip155:8453
payTostringPayment recipient from the challenge
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
resourceUrlstringyesAbsolute resource URL from the x402 challenge or Bazaar listing
schemestringx402 payment scheme (exact expected)
serviceRiskobjectOptional upstream service-risk result (e.g. from mcp_risk_score)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
tagsarrayBazaar/service tags for sensitive-category detection
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

portfolioguard_score ~323

PortfolioGuard (x402-paid, $0.15): deterministic portfolio risk scoring from holdings — volatility, Sharpe, max drawdown, concentration (HHI), diversification, plus per-rule findings.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
holdingsarrayyesPositions with symbol, weight (0-1), optional returns[], sector
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
periodReturnsarrayOptional portfolio/market return series
riskFreeRatenumberOptional risk-free rate for the Sharpe ratio (default 0)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

purchase_with_x402 ~298

Purchase a one-time product via x402 (returns 402 challenge or fulfillment JSON). Call get_x402_manifest first, verify method/path/network/amount/payTo, then sign and retry with PAYMENT-SIGNATURE.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
emailstringOptional email for the order record
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
slugstringyesOne-time product slug (e.g. destructguard-pro)
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

score_destructguard_command ~346

Score a command/action with the x402-paid DestructGuard service. Call get_x402_manifest first, verify the DestructGuard price and buyer policy, then retry the 402 challenge with an x402 payment signature.

NameTypeReqDescription
actorstringAgent/tool requesting the action
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
commandstringyesCommand or agent action to score
cwdstringWorking directory or execution context
diffStatstringOptional git diff --stat or change summary
intentstringWhy the command is being requested
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
repostringRepository or project context
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

start_checkout ~29

Start a Stripe checkout session for a product slug

NameTypeReqDescription
slugstringyesProduct slug to purchase
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

submit_reviewqueue_request ~343

Submit a command/action to the x402-paid ReviewQueue agent service. Call get_x402_manifest first, verify the ReviewQueue price and buyer policy, then retry the 402 challenge with an x402 payment signature.

NameTypeReqDescription
actorstringAgent/tool requesting the action
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
branchstringBranch or environment context
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
commandstringyesCommand or agent action being requested
diffStatstringOptional git diff --stat or change summary
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
reasonstringWhy the action is being requested
repostringRepository or project context
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

walletguard_score ~384

WalletGuard (x402-paid, $0.10): deterministic wallet AML/compliance risk scorer. From caller-provided context (sanctions, exposures, labels, fund sources) returns a 0-100 risk score, level, and evidence-backed findings.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
channelstringDiscovery channel or source tag
exposuresarraySignals e.g. mixer:tornado, sanctions:ofac
fundingSourcesarrayOptional fund-source breakdown (source, share 0-1, verified)
labelsarrayAddress labels, e.g. exchange:binance, contract:..., sanctions:...
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
sanctionsHitsarraySanctions / OFAC / blacklist hit identifiers
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
transfersarrayOptional transfer summaries (direction, value, counterparty, tags)
walletstringyesWallet address
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.

waterfall_distribute ~420

WaterfallLens (x402-paid, $0.30): deterministic LP/GP distribution waterfall (return of capital, preferred, GP catch-up, carried-interest split) with the exact split, per-tier breakdown, LP MOIC, and effective carry %.

NameTypeReqDescription
actorTypestringCaller type for analytics: agent, human, synthetic, system, or unknown
apiKeystringFree-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr…
campaignstringCampaign tag for downstream telemetry
carryPercentagenumberGP carry, e.g. 0.20 (default 0.20)
catchUpPercentagenumberGP catch-up share, 1.0 = full (default)
channelstringDiscovery channel or source tag
compoundingstringPreferred-return accrual basis: 'simple' or 'compounded' (default compounded)
contributedCapitalnumberyesTotal LP capital to return in tier 1
distributablenumberyesTotal cash to distribute
payerstringOptional wallet/account identifier; stored only as a hash
paymentIdentifierstringOptional x402 payment identifier for idempotency/retry correlation
paymentSignaturestringx402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry
preferredRatenumberAnnual preferred rate, e.g. 0.08
preferredReturnAmountnumberExplicit preferred return amount
syntheticbooleanMark this paid retry as an internal test/probe for analytics exclusion
xPaymentstringRaw X-PAYMENT proof from an x402-compatible wallet/client
yearsnumberHolding period for preferred accrual
NameTypeReqDescription
httpStatusnumberyesUpstream HTTP status code
okbooleanyesTrue when the upstream storefront call returned a 2xx response
paymentRequiredbooleanTrue when the response is an x402 HTTP 402 payment challenge

No examples provided.