# BountyVerdict Agent Decision Tools (remote · bountyverdict-agent-production.mimirslab.workers.dev)

Free selector plus read-only GitHub bounty, agent harness, Actions, flake, and MCP drift decisions.

- Trust score: 18/100 (low)
- Change this week: −38
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `bountyverdict-agent-production.mimirslab.workers.dev`: 18/100 (this document), [markdown](https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production.md), [page](https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production)

## Channel facts

- Endpoint: `https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.1.26`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
  - HTTPS not yet verified: we couldn't determine whether a plaintext access path exists.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport check failed: declared streamable-http, but the endpoint returned HTTP 404.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 4 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add --transport http mimirs402-bountyverdict https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry
```

### Codex

```toml
[mcp_servers.mimirs402-bountyverdict]
url = "https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "mimirs402-bountyverdict": {
      "type": "remote",
      "url": "https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add mimirs402-bountyverdict --url https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  mimirs402-bountyverdict:
    url: "https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry"
```

### Other

```json
{
  "mcpServers": {
    "mimirs402-bountyverdict": {
      "type": "http",
      "url": "https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 18, −41)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Stability: 0.20 → unverified
- [security regression] Authorization: partial → unverified
- [security regression] Transport: pass → fail
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Capabilities: pass → unverified
- [functional] First check of Schema quality: unverified

### 2026-08-01 (score 59, 0)

- [functional] Server version: 1.1.24 → 1.1.25
- [functional] Server version: 1.1.23 → 1.1.24
- [functional] Server version: 1.1.22 → 1.1.23

### 2026-07-31 (score 59, +3)

- [functional] MCP protocol: Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
- [functional] MCP protocol version: 2025-11-25 → 2026-07-28
- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server
- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server
- [functional] Server version: 1.1.21 → 1.1.22
- [functional] Server version: 1.1.18 → 1.1.21
- [functional] Server version: 1.1.17 → 1.1.18

### 2026-07-30 (score 56, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-29 (score 55, 0)

- [security] Tool “rank_github_bounties” rewrote its description, which is the text the model reads
- [security] Tool “diagnose_github_actions_run” rewrote its description, which is the text the model reads
- [security] Tool “classify_github_actions_flake” rewrote its description, which is the text the model reads
- [security] Tool “check_mcp_tool_drift” rewrote its description, which is the text the model reads
- [security] Tool “check_github_bounty” rewrote its description, which is the text the model reads
- [security] Tool “audit_agent_harness” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 173 → 206
- [functional] Server version: 1.1.15 → 1.1.16
- [functional] Server version: 1.1.14 → 1.1.15
- [functional] Server version: 1.1.13 → 1.1.14

### 2026-07-28 (score 55, −1)

- [functional regression] Schema quality: 150 → 173
- [functional regression] Schema quality: 150 → 171
- [functional] Schema quality: fair → poor

### 2026-07-27 (score 56, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 56)

First indexed and scored.

## MCP tools (7)

### `choose_github_agent_decision` (~221 tokens)

Choose the right GitHub agent decision tool for free

Call with no arguments for a free six-tool catalog, or choose the economical next call for a GitHub bounty, coding-agent instructions, failed Actions run, retry decision, or MCP tools change. Returns exact prices, samples, required fields, and unsigned-quote semantics without inspecting the target.

Input parameters:

- `candidate_count` (integer): Required only for bounty_portfolio: exact number of distinct issue URLs.
- `needs_ranked_response` (boolean): For bounty_portfolio only. True when one ranked, partial-failure-aware response is worth the premium; otherwise 2-7 route to cheaper repeated single checks.
- `task` (string): Optional exact task. Omit all arguments for the six-tool catalog. one_bounty = claimability of one issue; bounty_portfolio = economical handling of 2-10 issues; repository_agent_instructions = pre-co…

Output parameters:

- `decision_returned` (array)
- `free_sample` (string)
- `next_action` (string)
- `next_call` (object)
- `not_for` (string)
- `product` (string)
- `selector_call_payment_required` (boolean)
- `task` (string)
- `tools` (array)
- `total_price_usdc` (string)
- `unsigned_quote_cannot_charge` (boolean)
- `use_when` (string)

### `check_github_bounty` (~171 tokens)

Check GitHub bounty claimability risk

Is this public GitHub issue bounty still claimable, or is someone already working on it? Checks current status, reward evidence, competing work, and maintainer signals; returns AVOID, CAUTION, or VIABLE. For 2-7 issues, repeated single checks cost less unless one ranked response is worth the premium; use rank_github_bounties for 8-10. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/sample. Exact authorization cap: 0.05 USDC.

Input parameters:

- `issue_url` (string, required): Canonical public GitHub issue URL, for example https://github.com/owner/repository/issues/123. No query string, fragment, pull request, or non-GitHub host.

Output parameters:

- `checked_at` (string)
- `issue` (object)
- `linked_source` (object)
- `product` (string)
- `score` (integer)
- `service_reuse` (object)
- `signals` (array)
- `summary` (string)
- `verdict` (string)
- `version` (string)

### `rank_github_bounties` (~162 tokens)

Choose the best GitHub bounty

Which public GitHub bounty should I work on next? Compares 2-10 issue URLs, chooses the strongest non-AVOID candidate or recommends none, and returns cited evidence plus partial failures. Its $0.40 price equals eight $0.05 single checks and is cheaper per candidate at 9-10; repeated check_github_bounty calls cost less for 2-7 when ranked orchestration is unnecessary. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/portfolio/sample. Exact authorization cap: 0.40 USDC.

Input parameters:

- `issue_urls` (array, required): Two to ten distinct canonical public GitHub issue URLs. Duplicate issue URLs are rejected before payment.

Output parameters:

- `best_candidate`
- `checked_at` (string)
- `counts` (object)
- `failures` (array)
- `product` (string)
- `ranked` (array)
- `recommendation` (string)
- `service_reuse` (object)
- `version` (string)

### `audit_agent_harness` (~129 tokens)

Audit coding-agent repository instructions

Can a coding agent safely work in this public repository without missing project instructions? Audits AGENTS.md, CLAUDE.md, and related instructions at an immutable commit; does not diagnose CI. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/harness/sample. Exact authorization cap: 0.03 USDC.

Input parameters:

- `repo_url` (string, required): Canonical public GitHub repository URL, for example https://github.com/owner/repository. No subpath, query string, fragment, or non-GitHub host.

Output parameters:

- `checked_at` (string)
- `findings` (array)
- `product` (string)
- `recommendations` (array)
- `repository` (object)
- `score` (integer)
- `service_reuse` (object)
- `summary` (string)
- `verdict` (string)
- `version` (string)

### `diagnose_github_actions_run` (~138 tokens)

Find why a GitHub Actions run failed

Why did this public GitHub Actions run fail, and what should I fix? Uses bounded failed-job logs and redacted evidence. Use classify_github_actions_flake only for retry-once versus fix. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/run/sample. Exact authorization cap: 0.04 USDC.

Input parameters:

- `run_url` (string, required): Canonical public GitHub Actions run URL, for example https://github.com/owner/repository/actions/runs/123456. No job URL, query string, fragment, or non-GitHub host.

Output parameters:

- `checked_at` (string)
- `diagnosis` (object)
- `next_actions` (array)
- `product` (string)
- `retryability` (string)
- `run` (object)
- `service_reuse` (object)
- `summary` (string)
- `verdict` (string)
- `version` (string)

### `classify_github_actions_flake` (~167 tokens)

Decide whether to retry failed GitHub Actions

Is this failed GitHub Actions run flaky—should I retry it once or fix the code? Uses the current attempt and bounded history. Use diagnose_github_actions_run for root cause. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/flake/sample. Exact authorization cap: 0.07 USDC.

Input parameters:

- `attempt` (integer): Optional exact workflow run attempt number, starting at 1. Omit to use the run URL's latest available completed attempt.
- `run_url` (string, required): Canonical public GitHub Actions run URL, for example https://github.com/owner/repository/actions/runs/123456. No job URL, query string, fragment, or non-GitHub host.

Output parameters:

- `checked_at` (string)
- `decision` (object)
- `failure_signatures` (array)
- `product` (string)
- `service_reuse` (object)
- `summary` (string)
- `target` (object)
- `verdict` (string)
- `version` (string)

### `check_mcp_tool_drift` (~169 tokens)

Check whether an MCP tools update is breaking

Will upgrading to this complete MCP tools/list break my agent or weaken declared safety hints? Compares caller-supplied baseline and current snapshots; never fetches or invokes tools. Inspect a representative result before paying: https://bountyverdict-agent-production.mimirslab.workers.dev/api/mcp-drift/sample. Exact authorization cap: 0.02 USDC.

Input parameters:

- `annotation_source_trust` (string, required): Whether the caller recognizes the annotation source. Annotations never become runtime-behavior proof.
- `baseline` (object, required): Complete previously accepted tools/list snapshot.
- `contract_version` (string, required)
- `current` (object, required): Complete candidate tools/list snapshot.
- `subject` (object, required): Caller-chosen identity for the MCP server being compared; ownership is not verified.

Output parameters:

- `action` (string)
- `contract_version` (string)
- `findings` (array)
- `hashes` (object)
- `ruleset_version` (string)
- `service` (string)
- `service_reuse` (string)
- `summary` (object)
- `trust` (object)
- `verdict` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production#diagnostics

## Score history

- 2026-08-03: 18
- 2026-08-02: 18
- 2026-08-01: 59
- 2026-07-31: 59
- 2026-07-30: 56
- 2026-07-29: 55
- 2026-07-28: 55
- 2026-07-27: 56
- 2026-07-26: 56

## Links

- Remote endpoint: https://bountyverdict-agent-production.mimirslab.workers.dev/mcp?source=mcp-registry
- Repository: https://github.com/Mimirs402/bountyverdict
- Website: https://mimirs402.github.io/bountyverdict/
- Changelog RSS feed: https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production/changelog.json
- HTML version of this page: https://verifymcp.io/servers/mimirs402-bountyverdict/bountyverdict-agent-production
