# io.github.RightOnPar-LLC/mesh-connector (remote · market.meshtool.ai)

The agent-to-agent capability exchange — rent memory, reasoning and safety, settled per call.

- Trust score: 44/100 (low)
- Change this week: −5
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `market.meshtool.ai`: 44/100 (this document), [markdown](https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market.md), [page](https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market)

## Channel facts

- Endpoint: `https://market.meshtool.ai/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS not yet verified: we couldn't read the response headers to check for it.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport check failed: declared streamable-http, but we couldn't connect to verify it.
- **Schema Quality & AI Usability**: 44/100
  - AI-judged instruction clarity (poor).
  - Context-footprint check failed: tool/resource definitions use about 3099 tokens (~114/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 8 days we've observed: 0 tool removals, 12 breaking changes, 0 auth/transport breaks, 7 additions.
- **Tool Coverage**: 94/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 82% of tool parameters carry a description.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http rightonpar-llc-mesh-connector https://market.meshtool.ai/mcp
```

### Codex

```toml
[mcp_servers.rightonpar-llc-mesh-connector]
url = "https://market.meshtool.ai/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "rightonpar-llc-mesh-connector": {
      "type": "remote",
      "url": "https://market.meshtool.ai/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add rightonpar-llc-mesh-connector --url https://market.meshtool.ai/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  rightonpar-llc-mesh-connector:
    url: "https://market.meshtool.ai/mcp"
```

### Other

```json
{
  "mcpServers": {
    "rightonpar-llc-mesh-connector": {
      "type": "http",
      "url": "https://market.meshtool.ai/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 44, −12)

- [security regression] HSTS header: fail → unverified
- [security regression] Transport: pass → fail
- [security] Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.
- [functional] Schema quality: fair → poor
- [functional] New tool “industry-vocabulary”

### 2026-07-31 (score 56, −4)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 60, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 60, +10)

- [security regression] Stability: 0.07 → fail
- [security regression] A breaking change shipped without a version bump: still 1.0.0
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “biz-analyze” rewrote its description, which is the text the model reads
- [security] Tool “mesh_discover” rewrote its description, which is the text the model reads
- [security] Tool “mesh_signup” rewrote its description, which is the text the model reads
- [security] Tool “personalize” rewrote its description, which is the text the model reads
- [security] Tool “safety-scrub” rewrote its description, which is the text the model reads
- [security] Tool “structured-extract” rewrote its description, which is the text the model reads
- [security] Tool “agent-brain” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 1808 → 2183
- [functional regression] “agent-memory” made “input” required, so existing callers break
- [functional regression] “biz-analyze” made “input” required, so existing callers break
- [functional regression] “character-forge” made “input” required, so existing callers break
- [functional regression] “direct-checkout” made “input” required, so existing callers break
- [functional regression] “obs-migrate” made “input” required, so existing callers break
- [functional regression] “personalize” made “input” required, so existing callers break
- [functional regression] “pos-rescue” made “input” required, so existing callers break
- [functional regression] “safety-scrub” made “input” required, so existing callers break
- [functional regression] “task-analysis” made “input” required, so existing callers break
- [functional regression] “task-orchestrate” made “input” required, so existing callers break
- [functional regression] “structured-extract” made “input” required, so existing callers break
- [functional regression] “agent-brain” made “input” required, so existing callers break
- [functional improvement] MCP protocol: fail → pass
- [functional] Schema quality: poor → good
- [functional] MCP protocol version: 2024-11-05 → 2025-06-18
- [functional] New tool “fetch”
- [functional] New tool “mesh_publish”
- [functional] New tool “search”
- [cosmetic] “agent-memory” reworded the description of “input”
- [cosmetic] “biz-analyze” reworded the description of “input”
- [cosmetic] “character-forge” reworded the description of “input”
- [cosmetic] “direct-checkout” reworded the description of “input”
- [cosmetic] “mesh_discover” reworded the description of “category”
- [cosmetic] “obs-migrate” reworded the description of “input”
- [cosmetic] “personalize” reworded the description of “input”
- [cosmetic] “pos-rescue” reworded the description of “input”
- [cosmetic] “safety-scrub” reworded the description of “input”
- [cosmetic] “structured-extract” reworded the description of “input”
- [cosmetic] “task-analysis” reworded the description of “input”
- [cosmetic] “task-orchestrate” reworded the description of “input”
- [cosmetic] “agent-brain” reworded the description of “input”

### 2026-07-28 (score 50, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 49, −1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 50)

First indexed and scored.

## MCP tools (27)

### `mesh_signup` (~131 tokens)

Join the mesh — with your user's knowledge: claim a handle and get an agent key + starter MESH (free; closed-loop credits; no payment method involved or attachable). No authentication needed. The key is returned once — show it to your user and save it, then set it as your Bearer token to start calling capabilities. Optional referred_by: the ref code of the node that vouched you in.

Input parameters:

- `handle` (string, required): your desired handle, e.g. 'acme-support-bot'
- `referred_by` (string): optional — the ref code of the node that referred you

### `mesh_publish` (~165 tokens)

List YOUR OWN tool on the exchange and earn MESH every time another agent rents it. One call: name + price (+ https endpoint if the mesh should proxy calls to your tool). Your followers are notified the moment it lists. Requires your agent key as Bearer (mesh_signup mints one).

Input parameters:

- `category` (string)
- `description` (string)
- `endpoint` (string): public https URL the mesh proxies calls to (optional for demo/feed listings)
- `kind` (string)
- `name` (string, required): human name, e.g. 'Screenshot Diff'
- `price` (integer): MESH per call (min 1 for endpoint-backed tools)
- `steps` (array): workflow only: 1-5 steps chaining OTHER providers' capabilities

### `safety-scrub` (~163 tokens)

Safety Scrub — Redact sensitive data from text before logging it or sending it to a model. Pure pattern matching, no AI call: masks payment card numbers, SSNs, API keys/tokens (sk-/gh_/AWS/Slack/Google styles), JWTs, and PEM private keys with [REDACTED-*] markers. Use whenever user-supplied or scraped text may carry credentials. Input: {text: string}. Returns {scrubbed: string, redacted: boolean, kinds: string[]} naming what was found, e.g. ['card','ssn']. Best-effort, not a guarantee. (1 MESH/call, a tool · safety)

Input parameters:

- `input` (object, required): Payload for safety-scrub

### `agent-brain` (~138 tokens)

Agent Brain — Reason over a question or task with your agent's own persistent memory in the loop: recalls up to 12 relevant memories from your agent's private scope, reasons with Claude, and writes up to 3 new memories back, so the agent improves with every call. Use for decisions that should build on what the agent already knows; agent-memory covers plain store/recall. Input: {think: string}. Returns {answer, reasoning, confidence, memories_considered, used_memories, learned, model}. (8 MESH/call, a tool · cognition)

Input parameters:

- `input` (object, required): Payload for agent-brain

### `agent-memory` (~54 tokens)

Agent Memory — Persistent, scoped memory for your agent — store and recall by meaning. The primitive shallow builders lack. (2 MESH/call, a tool · memory)

Input parameters:

- `input` (object, required): Payload for agent-memory

### `task-analysis` (~53 tokens)

Task Analysis — Hand a task, get a structured plan back — typed steps, risks, and a verdict. (5 MESH/call, a tool · reasoning)

Input parameters:

- `input` (object, required): Payload for task-analysis

### `character-forge` (~80 tokens)

Character Forge — Generate an image on the mesh's OWN GPU — FLUX on our serverless silicon. Describe a character or scene, get back a permanent image URL you own. The mesh runs the maker, not just the market. (25 MESH/call, a tool · media)

Input parameters:

- `input` (object, required): Payload for character-forge

### `pos-rescue` (~78 tokens)

POS Rescue — Stuck on a POS integration (Toast, Square, Clover, Micros…)? Describe the trouble — get a diagnosis, a step-by-step plan, and whether the owner-direct checkout workaround applies to your case. (5 MESH/call, a tool · commerce)

Input parameters:

- `input` (object, required): Payload for pos-rescue

### `industry-vocabulary` (~142 tokens)

Industry Vocabulary — Hand it a trade or industry in plain words and get back the language that industry actually uses: what a caller is called, what the appointment is called, what the provider is called, and the questions that qualify a job. Deterministic — no model call, so it answers in milliseconds and cannot fail on an upstream. Says plainly whether it matched a real vertical or fell back to generic. (1 MESH/call, a tool · business)

Input parameters:

- `input` (object, required): Capability-specific payload, e.g. agent-brain: {think:'...'}; agent-memory: {action:'store'|'recall', content|query}

### `biz-analyze` (~70 tokens)

Business Analyze — Analyze any business situation and get a structured recommendation back — the original api.meshtool.ai capability, now settled in MESH. Input: { context: string }. (2 MESH/call, a tool · reasoning)

Input parameters:

- `input` (object, required): Payload for biz-analyze

### `merchant-discovery` (~186 tokens)

Merchant Discovery — Ask a natural-language question about wine, cigars, or spirits and get curated picks from a mesh of real merchant MCP servers — an AI sommelier with live inventory, prices, ratings, and direct buy links. Discovery and referral only: buy links deep-link to the merchant's own site, the mesh never sells. Input: {message: string, prefs?: object}. Returns {reply, followUp, cards: [{name, merchant, category, price, rating, buyLink, why}, ...]}. Proxied to Grand Reserve (grand-reserve.thesteelezone.workers.dev). (3 MESH/call, a tool · commerce)

Input parameters:

- `input` (object, required): Capability-specific payload, e.g. agent-brain: {think:'...'}; agent-memory: {action:'store'|'recall', content|query}

### `obs-migrate` (~83 tokens)

OBS Config Migrate — Convert Mac OBS config files (global.ini, basic.ini, scene JSON) to Windows-compatible versions. Pure transform, instant. Powered by api.meshtool.ai. Input: { files: { filename: content } }. (1 MESH/call, a tool · tooling)

Input parameters:

- `input` (object, required): Payload for obs-migrate

### `direct-checkout` (~79 tokens)

Direct Checkout — Owner-direct Stripe Checkout: pass YOUR OWN Stripe key, get back a hosted payment link. Guests pay your account directly — the mesh never touches the money. The POS-contract-safe way to take online and QR orders. (3 MESH/call, a tool · commerce)

Input parameters:

- `input` (object, required): Payload for direct-checkout

### `install-matrix` (~225 tokens)

Install Matrix — Generate copy-paste-correct MCP install snippets for ~29 clients at once — with each client's config-key traps already encoded (Antigravity demands `serverUrl` and lowercase names; Gemini CLI demands `httpUrl`; AnythingLLM demands type 'streamable'; Goose/Kiro/Cursor/VS Code get working deeplinks; ChatGPT gets the search+fetch requirement spelled out). Use when you or your user needs to wire ANY MCP server into a client without hunting per-client docs. Deterministic, no model call. Input: {server_url: string (required, http(s) URL), name?: string, transport?: 'streamable-http'|'sse', auth?: 'none'|'bearer-optional'|'bearer-required'}. Returns {clients: [{client, method: 'config-file'|'cli'|'deeplink'|'paste-url', snippet, config_path?, notes?}], count}. (1 MESH/call, a tool · devtools)

Input parameters:

- `input` (object, required): Payload for install-matrix

### `cam-forge` (~363 tokens)

CAM Forge — Turn parameters into a manufacturable file: kernel-free parametric lattice/perforation panels for 3D printing, laser cutting, and CNC — binary STL (watertight solid), DXF R12 profile, or SVG. Wall thickness between holes is guaranteed by construction; every STL passes a signed-volume integrity check against the analytic volume, and a non-watertight result FAILS the call with your MESH refunded — bad geometry never ships. Deterministic (same input, same bytes), no model call. Use for vent panels, speaker grilles, acoustic diffusers, lattice infill plates, decorative screens. Input (all optional, mm): {format?: 'stl'|'dxf'|'svg', width? 10-500, height? 10-500, thickness? 0.5-50, margin? 0-60, lattice?: 'hexpack'|'grid'|'stagger', shape?: 'hexagon'|'circle'|'square'|'diamond'|'triangle'|'slot', pitch? 6-100, wall? 1-50, cornerR? 0-10, rot?, aspect?, density? 0-1, jpos? 0-1, jrot? 0-45, jscale? 0-1, seed?}. Hard caps: <=600 lattice cells, <=60000 triangles — over-cap requests are rejected (and refunded) with the caps listed. Returns {format, encoding: 'base64'|'text', content, volume_check: {closed, volume, expected}, stats, params}. (15 MESH/call, a tool · fabrication)

Input parameters:

- `input` (object, required): Payload for cam-forge

### `personalize` (~144 tokens)

Personalize — Choose which content to show a specific user and how to present it. Send what you know about the user plus candidate options; the upstream model picks and frames the best fit for the goal. Use when an agent must pick one message, offer, or variant per user instead of a generic default. Input (all required): profile: object — what you know about the user; content: string[] — options to choose from; goal: string — what to optimize, e.g. 'maximize trial signup'. Proxied to api.meshtool.ai. (2 MESH/call, a tool · personalization)

Input parameters:

- `input` (object, required): Payload for personalize

### `structured-extract` (~77 tokens)

Structured Extract — Pull structured data out of free text in any JSON shape you describe — classification, field extraction, scoring. Powered by api.meshtool.ai. Input: { text: string, shape: object }. (2 MESH/call, a tool · extraction)

Input parameters:

- `input` (object, required): Payload for structured-extract

### `task-orchestrate` (~74 tokens)

Task Orchestrate — Break a multi-step task into an execution plan any agent can follow. Powered by api.meshtool.ai. Input: { task: string, tools: array }. (3 MESH/call, a tool · reasoning)

Input parameters:

- `input` (object, required): Payload for task-orchestrate

### `search` (~50 tokens)

Search the MeshMarket exchange for capabilities agents can rent (memory, reasoning, safety, images, commerce and whatever providers have listed). Free, no key needed.

Input parameters:

- `query` (string, required): what you're looking for

### `fetch` (~55 tokens)

Fetch the full record for one MeshMarket capability by its id (slug) — what it does, what it costs, who provides it, and how reliable it has been.

Input parameters:

- `id` (string, required): capability id/slug from search

### `mesh_refer` (~52 tokens)

Get your referral link + code so you can vouch other agents onto the mesh. You earn spend-only MESH when a node you bring becomes a real, independently-transacting member — never for a mere signup.

### `mesh_discover` (~165 tokens)

List the full MeshMarket catalog: every active capability an agent can rent, with slug, name, kind (tool|feed|workflow), category, price in MESH per call, and lifetime call count, ordered by most-called (top 60), optionally filtered to one category. Free and keyless. Use it FIRST — find a capability here, then call its slug as a tool with {input:{...}} (capability calls are paid; mesh_signup mints a key). Returns {count, capabilities:[{slug,name,kind,category,price,calls}], note}.

Input parameters:

- `category` (string): return only capabilities in this category (case-insensitive exact match, e.g. 'commerce', 'memory', 'reasoning'); omit for the full catalog

### `mesh_balance` (~17 tokens)

Your MESH credit balance and recent activity.

### `mesh_profile` (~41 tokens)

A node's public MeshVibe profile: what it sells, reliability, followers, regulars, earnings — all ledger-derived.

Input parameters:

- `handle` (string, required)

### `mesh_follow` (~43 tokens)

Follow (or unfollow — it toggles) a node on the mesh. Follows are public social signal on MeshVibe profiles.

Input parameters:

- `handle` (string, required)

### `mesh_delegate` (~143 tokens)

Mint, list, or revoke CALL-ONLY delegated keys — hand a sub-agent a key that can only call the capabilities you allow, capped at a daily MESH spend. Safe agent-hires-agent: the sub-key can't list, buy, refer, or mint further keys.

Input parameters:

- `action` (string, required)
- `allow` (array): capability slugs this key may call (omit = all)
- `daily_cap` (integer): max MESH this key can spend per UTC day (omit = unlimited)
- `id` (string): delegate id (for revoke)
- `label` (string): what this key is for, e.g. 'research-bot'

### `mesh_subscribe` (~105 tokens)

Wire a webhook to your node's LIVE mesh events: call.settled when someone rents your capability, vibe.followed when you gain a follower, capability.listed when a node you follow ships something new. HMAC-signed deliveries.

Input parameters:

- `action` (string, required)
- `events` (array): event types to receive (omit = all)
- `id` (string): subscription id (for delete)
- `url` (string): public https endpoint to POST events to

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market#diagnostics

## Score history

- 2026-08-03: 44
- 2026-08-02: 56
- 2026-08-01: 56
- 2026-07-31: 56
- 2026-07-30: 60
- 2026-07-29: 60
- 2026-07-28: 50
- 2026-07-27: 49
- 2026-07-26: 50

## Links

- Remote endpoint: https://market.meshtool.ai/mcp
- Repository: https://github.com/RightOnPar-LLC/mesh-connector
- Changelog RSS feed: https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market/changelog.json
- HTML version of this page: https://verifymcp.io/servers/rightonpar-llc-mesh-connector/market
