HORIZON SHIELD: Construction Estimate Auditor for Japan (KIRA)
REMOTE · WEB.HORIZONSHIELD.DEV · SCANNED AUG 20
Agent intake desk for property renovation. Read only, CORS open, fail closed, receipts recompute.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability79
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1999 tokens (~199/item across 10 items; 5 tools + 5 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability check failed: schema churn in the 11 days we've observed: 2 tool removals, 0 breaking changes, 0 auth/transport breaks, 2 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · web.horizonshield.dev
claude mcp add --transport http ogasurfproject-jpg-horizon-shield-webmcp https://web.horizonshield.dev/mcp
[mcp_servers.ogasurfproject-jpg-horizon-shield-webmcp] url = "https://web.horizonshield.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ogasurfproject-jpg-horizon-shield-webmcp": {
"type": "remote",
"url": "https://web.horizonshield.dev/mcp",
"enabled": true
}
}
} openclaw mcp add ogasurfproject-jpg-horizon-shield-webmcp --url https://web.horizonshield.dev/mcp --transport streamable-http
mcp_servers:
ogasurfproject-jpg-horizon-shield-webmcp:
url: "https://web.horizonshield.dev/mcp" {
"mcpServers": {
"ogasurfproject-jpg-horizon-shield-webmcp": {
"type": "http",
"url": "https://web.horizonshield.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 14 Aug 26 −2
- Stability: 0.13 → fail ▼ security
- Tool “orchestrate” was removed ▼ security
- Tool “ask” was removed ▼ security
- Tool “draft_broadcast” rewrote its description, which is the text the model reads security
- Tool “intake_estimate” rewrote its description, which is the text the model reads security
- Tool “scan_tactics” rewrote its description, which is the text the model reads security
- Schema quality: 165 → 199 ▼ functional
- Server version: 0.5.0 → 0.6.0 functional
- New tool “run_full_audit” functional
- New tool “route_request” functional
- 12 Aug 26 +7
- Schema quality: unverified → excellent ▲ functional
- 11 Aug 26 −5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 10 Aug 26 +1
- Stability: unverified → 0.03 ▲ functional
- 9 Aug 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Aug 2026 · Probed https://web.horizonshield.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=horizonshield.dev | CN=WE1,O=Google Trust Services,C=US | 8 Aug 2026 | 7 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | f0e36c93718be43713d6a6e220cc900c |
| SANs: horizonshield.dev, *.horizonshield.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of web.horizonshield.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| horizonshield.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://web.horizonshield.dev/mcp | Verified | 200 | |
| http (plaintext) | http://web.horizonshield.dev/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
draft_broadcast 注意喚起の発信下書き ~250
ある工事の過剰請求への注意喚起を発信する下書き(note用長文・X用短文)を生成し、HORIZON SHIELDの該当解説ページ(実在URL)への被リンクを添える。価格はKIRA(検証可能SHA-256付き)の一次データのみ。推測の数字は入れない。下書きであり公開前に運営者が最終版にする(自動投稿しない)。 / Generates broadcast DRAFTS with backlinks. Verifiable first-party prices only. Draft; operator finalizes. No auto-posting. USE WHEN: the operator wants note/X draft text warning about overcharging for a given work type. DO NOT USE WHEN: the caller wants a verdict on a specific quote (call intake_estimate) or the tactic list itself (call scan_tactics). Output is a DRAFT for a human to finalise. This tool never posts.
| Name | Type | Req | Description |
|---|---|---|---|
| work | string | yes | 工事名やキーワード(日本語)。例: 外壁塗装, トイレ, 火災保険 |
| Name | Type | Req | Description |
|---|---|---|---|
| notice | string | – | This is a DRAFT. A human finalises it. Nothing is posted. |
| ok | boolean | yes | Whether a draft was produced. |
| post_targets | array | – | Per-channel draft text (note long form, X short form) with backlinks. |
| price_source | string | – | Which first-party data any figure in the draft came from. |
| source | string | – | Which server produced this. |
No examples provided.
intake_estimate 見積もり適正診断(KIRA) ~282
施主の建設・リフォーム見積もりを受け付け、HORIZON SHIELD KIRA(内部・中立)の適正価格診断へ橋渡しする集客窓口。工事名と業者提示額を渡すと、適正かどうかの判定と、無料の第三者チェック(EHN)への導線を返す。価格の断定はせず、確認すべき点を渡す。 / Intake desk: bridges a homeowner quote to the KIRA fair-price audit and returns the verdict plus a free third-party check (EHN) path. USE WHEN: a homeowner has a specific quoted price for a named construction or renovation work item in Japan and wants to know whether that price is reasonable. DO NOT USE WHEN: there is no price yet (call ask), the caller wants the known overcharge tactics rather than a verdict on their own quote (call scan_tactics), or the caller wants publishable text (call draft_broadcast). Returns a verdict and a free third-party check path. It does not draft or post.
| Name | Type | Req | Description |
|---|---|---|---|
| quoted_price | number | yes | 業者提示の金額(円) |
| work | string | yes | 工事名(日本語)。例: 外壁塗装 シリコン |
| Name | Type | Req | Description |
|---|---|---|---|
| audit | object | – | The fair-price verdict from the internal KIRA audit. |
| message | string | – | Reason when ok is false. |
| next | array | – | Suggested follow-up tools or paths, including the free third-party check. |
| ok | boolean | yes | Whether the quote was accepted for audit. |
| source | string | – | Which server produced this. |
No examples provided.
route_request 一文で聞けば、正しい窓口に繋ぐ ~541
Check whether a construction or renovation quote in JAPAN is fairly priced, against 65,520 open catalogue items and Bitcoin-anchored verification records. Single entry point: pass one sentence. USE WHEN: the user has a quote or a price for building/renovation work in Japan and wants to know if it is reasonable; or wants to check a HORIZON SHIELD receipt or a jidec: citation; or asks about overcharging tactics used by contractors; or is looking for a verified contractor. DO NOT USE WHEN: the work is outside Japan; the question is not about construction or renovation; the user has already signed or paid and needs consumer-protection help; or there is an active emergency (gas smell, collapse, water not stopping). In those cases this tool does not answer - it returns the appropriate outside destination instead, and says so. Every reply carries verify (a URL that checks the answer) and limits (what the answer does NOT prove). Routing is a deterministic keyword table, not an LLM, so the same input always routes the same way. Examples: "is 800,000 yen high for exterior wall painting?" / "is jidec:entry:9 genuine?" / "how do I refuse a door-to-door sales pitch?" 日本の建設・リフォーム見積もりが適正かを確認する単一入口。日本語の一文で渡してよい。適正診断・台帳(JIDEC)の記録検証・過剰請求の手口・検証済み加盟店の4方向へ決定的に振り分ける。日本国外/建設以外/契約後の紛争/緊急時は**答えずに適切な外部の窓口を返す。**返り値には必ず verify(検証URL)と limits(証明していないこと)が入る。
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | – | (任意)業者提示の金額(円) |
| ask | string | – | やりたいことを一文で。例:「外壁塗装80万は高いですか」「jidec:entry:9 は本物ですか」 |
| ref | string | – | (任意)検証したい引用ID。jidec:entry:N / 64桁hex / エントリ番号 |
| work | string | – | (任意)工事名。分かっているなら渡すと推測を挟まない。 |
| Name | Type | Req | Description |
|---|---|---|---|
| answered_by | string | – | Which desk answered: the router itself, an internal audit, the ledger, or a guide fallback. |
| limits | string | – | What this answer does NOT prove. Always present. |
| message | string | – | Reason when ok is false. |
| next | array | – | Tool names to call next. |
| ok | boolean | yes | Whether the request was handled. |
| result | object | – | The answering desk's payload. |
| routed_out | boolean | – | True when the question was routed to an external desk rather than answered here. |
| verify | string | – | URL where the caller can recompute and check the claim. |
No examples provided.
run_full_audit 集客→診断→発信 一括実行 ~342
1回の呼び出しで HORIZON SHIELD の集客→診断→注意喚起→発信を一気通貫で回す司令塔。work(と任意の quoted_price)を渡すと、内部で intake(KIRA適正診断)・scan_tactics(検証済み手口+一次ソース)・draft_broadcast(発信下書き+被リンク)を順に実行し、結果を1つに束ねて返す。価格は検証可能な一次データのみ。発信は下書きで自動投稿しない。 / One-call orchestrator returning audit + tactics + broadcast draft. Verifiable first-party prices only. Drafts only, no auto-posting. USE WHEN: the caller wants all three steps (audit, tactics, broadcast draft) for one named work item in a single call and will act on the combined result. DO NOT USE WHEN: only one step is needed. Call intake_estimate for a verdict on a specific quote, scan_tactics for the documented overcharge tactics, or draft_broadcast for publishable text. If the request is still a free-form question with no work item, call ask first. This tool never posts anything.
| Name | Type | Req | Description |
|---|---|---|---|
| quoted_price | number | – | (任意)業者提示の金額(円)。あればKIRA適正診断も実行する。 |
| work | string | yes | 工事名やキーワード(日本語)。例: 外壁塗装, トイレ, シロアリ |
| Name | Type | Req | Description |
|---|---|---|---|
| flow | string | – | The fixed step order that was executed. |
| message | string | – | Reason when ok is false. |
| notice | string | – | Standing caveat: first-party prices only, drafts only, no auto-posting. |
| ok | boolean | yes | Whether the flow ran. |
| source | string | – | Which server produced this. |
| steps | object | – | One entry per step: intake, scan_tactics, draft_broadcast. A step may be skipped or fail without failing the flow. |
| work | string | – | The work item the flow was run for. |
No examples provided.
scan_tactics 過剰請求の手口スキャン ~239
ある工事・キーワードに関する『過剰請求の手口』を、HORIZON SHIELD(大賀俊勝30年監修)の検証済みデータ(内部KIRA)から返し、一次ソース(国民生活センター/消費者庁/EHN実例ボード)の在処を添える。価格判定ではなく注意喚起。推測で新事例を断定しない。 / Returns verified overcharge tactics and points to primary sources. Awareness, not a price verdict. USE WHEN: the caller wants the documented overcharge tactics for a work type or keyword, together with their primary sources. DO NOT USE WHEN: the caller has their own quote and wants a verdict on it (call intake_estimate), or wants publishable text (call draft_broadcast). This returns awareness material and never a price verdict on a specific quote.
| Name | Type | Req | Description |
|---|---|---|---|
| work | string | yes | 工事名やキーワード(日本語)。例: 外壁塗装, シロアリ, 火災保険 |
| Name | Type | Req | Description |
|---|---|---|---|
| disclaimer | string | – | Awareness material. Not a price verdict on any specific quote. |
| ok | boolean | yes | Whether tactics were found. |
| primary_sources | array | – | Where each tactic is documented publicly. |
| scan_mode | string | – | How the set was assembled. |
| source | string | – | Which server produced this. |
| verified_tactics | array | – | Documented overcharge tactics for the work type. |
No examples provided.