PHION Agent Trust Infrastructure
REMOTE · PHION.SYSTEMS · SCANNED SEP 25
118 agent services with free discovery, intent, x402 terms and signed verification.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 52 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability58
- AI-judged instruction clarity (fair).Partial
- Tool/resource definitions use about 5964 tokens (~48/item across 124 items; 124 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management47
- Stability observed for 14 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage72
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 2% of tool parameters carry a description.Partial
- Structured output schemas are declared (58% of tools); any adoption earns full credit.Pass
Tool Safety88
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "duplicate_charge_detector" implies "charge" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 124 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the PHION Agent Trust Infrastructure MCP server?
PHION Agent Trust Infrastructure is a hosted endpoint at https://phion.systems/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · phion.systems
claude mcp add --transport http systems-phion-evidence-engine 'https://phion.systems/mcp'
{
"mcpServers": {
"systems-phion-evidence-engine": {
"url": "https://phion.systems/mcp"
}
}
} {
"servers": {
"systems-phion-evidence-engine": {
"type": "http",
"url": "https://phion.systems/mcp"
}
}
} [mcp_servers.systems-phion-evidence-engine] url = "https://phion.systems/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"systems-phion-evidence-engine": {
"type": "remote",
"url": "https://phion.systems/mcp",
"enabled": true
}
}
} openclaw mcp add systems-phion-evidence-engine --url 'https://phion.systems/mcp' --transport streamable-http
mcp_servers:
systems-phion-evidence-engine:
url: "https://phion.systems/mcp" {
"McpServers": {
"systems-phion-evidence-engine": {
"Transport": "http",
"Url": "https://phion.systems/mcp"
}
}
} assistant mcp add systems-phion-evidence-engine -t streamable-http -u 'https://phion.systems/mcp'
{
"mcpServers": {
"systems-phion-evidence-engine": {
"type": "http",
"url": "https://phion.systems/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 −1
- MCP protocol: pass → fail ▼ functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- Server version: 1.49.4 → 1.49.6 functional
- Server version: 1.49.3 → 1.49.4 functional
- Server version: 1.49.0 → 1.49.3 functional
- 24 Sept 26 +1
- Server version: 1.46.2 → 1.46.4 functional
- 23 Sept 26 0
- Server version: 1.46.1 → 1.46.2 functional
- Server version: 1.46.0 → 1.46.1 functional
- Server version: 1.45.0 → 1.46.0 functional
- 22 Sept 26 +1
- Schema quality: 4804 → 5964 ▼ functional
- Tool coverage: 45% → 58% ▲ functional
- Tool coverage: 45% → 50% ▲ functional
- Server version: 1.44.0 → 1.45.0 functional
- Server version: 1.39.0 → 1.44.0 functional
- Server version: 1.37.0 → 1.39.0 functional
- New tool “a2a_transaction_bridge” functional
- New tool “agent_economic_graph” functional
- New tool “ap2_mandate_bridge” functional
- New tool “automated_dispute_bundle” functional
- New tool “autonomous_procurement” functional
- New tool “cross_protocol_receipt” functional
- New tool “delegated_spend_policy” functional
- New tool “dynamic_service_pricing” functional
- New tool “erc8004_identity_evidence” functional
- New tool “erc8004_reputation_intelligence” functional
- New tool “market_demand_predictor” functional
- New tool “mcp_transaction_gateway” functional
- New tool “multi_agent_escrow” functional
- New tool “price_discovery_engine” functional
- New tool “proof_of_service” functional
- New tool “reputation_update_receipt” functional
- New tool “service_gap_detector” functional
- New tool “sla_risk_predictor” functional
- New tool “transaction_recovery_v2” functional
- New tool “agent_behavior_fingerprint” functional
- New tool “capability_benchmark” functional
- New tool “capability_verification” functional
- New tool “economic_loop_detector” functional
- New tool “payment_optimizer” functional
- New tool “provider_quality_predictor” functional
- New tool “sybil_reputation_guard” functional
- New tool “transaction_risk_score” functional
- New tool “trust_anomaly_detector” functional
- New tool “x402_v2_router” functional
- 21 Sept 26 +2
- Schema quality: 57 → 50 ▲ functional
- Tool coverage: 31% → 45% ▲ functional
- Tool coverage: 31% → 39% ▲ functional
- MCP protocol: fail → pass ▲ functional
- MCP protocol version: 2025-06-18 → 2026-07-28 functional
- Server version: 1.35.0 → 1.37.0 functional
- Server version: 1.33.0 → 1.35.0 functional
- Server version: 1.32.2 → 1.33.0 functional
- Server version: 1.32.3 → 1.32.2 functional
- New tool “tool_result_schema_validator” functional
- New tool “agent_memory_provenance” functional
- New tool “agent_rate_limit_negotiator” functional
- New tool “agent_session_continuity” functional
- New tool “cross_agent_receipt_bundle” functional
- New tool “delegated_credential_guard” functional
- New tool “execution_cost_estimator” functional
- New tool “payment_delivery_atomicity” functional
- New tool “service_failover_selector” functional
- New tool “task_lease_guard” functional
- New tool “agent_approval_relay” functional
- New tool “capability_negotiation_preflight” functional
- New tool “durable_agent_task” functional
- New tool “mcp_2026_compatibility_gateway” functional
- New tool “mcp_a2a_task_bridge” functional
- New tool “mcp_catalog_cache_guard” functional
- New tool “oauth_issuer_binding_evidence” functional
- New tool “quote_freshness_guard” functional
- New tool “task_cancel_assurance” functional
- New tool “task_checkpoint_evidence” functional
- 20 Sept 26 0
- Server version: 1.32.0 → 1.32.3 functional
- 19 Sept 26 +1
- Tool “company_enrichment_evidence” rewrote its description, which is the text the model reads security
- Tool “contact_enrichment_evidence” rewrote its description, which is the text the model reads security
- Tool “person_enrichment_evidence” rewrote its description, which is the text the model reads security
- Schema quality: 50 → 57 ▼ functional
- Server version: 1.31.1 → 1.32.0 functional
- “company_enrichment_evidence” added an optional parameter “birth_date” cosmetic
- “company_enrichment_evidence” added an optional parameter “contact” cosmetic
- “company_enrichment_evidence” added an optional parameter “country” cosmetic
- “company_enrichment_evidence” added an optional parameter “email” cosmetic
- “company_enrichment_evidence” added an optional parameter “email_hash” cosmetic
- “company_enrichment_evidence” added an optional parameter “entity” cosmetic
- “company_enrichment_evidence” added an optional parameter “first_name” cosmetic
- “company_enrichment_evidence” added an optional parameter “identifier” cosmetic
- “company_enrichment_evidence” added an optional parameter “input” cosmetic
- “company_enrichment_evidence” added an optional parameter “last_name” cosmetic
- “company_enrichment_evidence” added an optional parameter “lid” cosmetic
- “company_enrichment_evidence” added an optional parameter “locality” cosmetic
- “company_enrichment_evidence” added an optional parameter “minimum_likelihood” cosmetic
- “company_enrichment_evidence” added an optional parameter “pdl_id” cosmetic
- “company_enrichment_evidence” added an optional parameter “person” cosmetic
- “company_enrichment_evidence” added an optional parameter “phone” cosmetic
- “company_enrichment_evidence” added an optional parameter “postal_code” cosmetic
- “company_enrichment_evidence” added an optional parameter “query” cosmetic
- “company_enrichment_evidence” added an optional parameter “region” cosmetic
- “company_enrichment_evidence” added an optional parameter “school” cosmetic
- “company_enrichment_evidence” added an optional parameter “street_address” cosmetic
- “company_enrichment_evidence” added an optional parameter “subject” cosmetic
- “contact_enrichment_evidence” added an optional parameter “birth_date” cosmetic
- “contact_enrichment_evidence” added an optional parameter “contact” cosmetic
- “contact_enrichment_evidence” added an optional parameter “country” cosmetic
- “contact_enrichment_evidence” added an optional parameter “email_hash” cosmetic
- “contact_enrichment_evidence” added an optional parameter “entity” cosmetic
- “contact_enrichment_evidence” added an optional parameter “first_name” cosmetic
- “contact_enrichment_evidence” added an optional parameter “identifier” cosmetic
- “contact_enrichment_evidence” added an optional parameter “input” cosmetic
- “contact_enrichment_evidence” added an optional parameter “last_name” cosmetic
- “contact_enrichment_evidence” added an optional parameter “lid” cosmetic
- “contact_enrichment_evidence” added an optional parameter “locality” cosmetic
- “contact_enrichment_evidence” added an optional parameter “pdl_id” cosmetic
- “contact_enrichment_evidence” added an optional parameter “person” cosmetic
- “contact_enrichment_evidence” added an optional parameter “phone” cosmetic
- “contact_enrichment_evidence” added an optional parameter “postal_code” cosmetic
- “contact_enrichment_evidence” added an optional parameter “query” cosmetic
- “contact_enrichment_evidence” added an optional parameter “region” cosmetic
- “contact_enrichment_evidence” added an optional parameter “school” cosmetic
- “contact_enrichment_evidence” added an optional parameter “street_address” cosmetic
- “contact_enrichment_evidence” added an optional parameter “subject” cosmetic
- “contact_enrichment_evidence” added an optional parameter “ticker” cosmetic
- “contact_enrichment_evidence” added an optional parameter “website” cosmetic
- “person_enrichment_evidence” added an optional parameter “birth_date” cosmetic
- “person_enrichment_evidence” added an optional parameter “contact” cosmetic
- “person_enrichment_evidence” added an optional parameter “country” cosmetic
- “person_enrichment_evidence” added an optional parameter “email_hash” cosmetic
- “person_enrichment_evidence” added an optional parameter “entity” cosmetic
- “person_enrichment_evidence” added an optional parameter “first_name” cosmetic
- “person_enrichment_evidence” added an optional parameter “identifier” cosmetic
- “person_enrichment_evidence” added an optional parameter “input” cosmetic
- “person_enrichment_evidence” added an optional parameter “last_name” cosmetic
- “person_enrichment_evidence” added an optional parameter “lid” cosmetic
- “person_enrichment_evidence” added an optional parameter “locality” cosmetic
- “person_enrichment_evidence” added an optional parameter “pdl_id” cosmetic
- “person_enrichment_evidence” added an optional parameter “person” cosmetic
- “person_enrichment_evidence” added an optional parameter “phone” cosmetic
- “person_enrichment_evidence” added an optional parameter “postal_code” cosmetic
- “person_enrichment_evidence” added an optional parameter “query” cosmetic
- “person_enrichment_evidence” added an optional parameter “region” cosmetic
- “person_enrichment_evidence” added an optional parameter “school” cosmetic
- “person_enrichment_evidence” added an optional parameter “street_address” cosmetic
- “person_enrichment_evidence” added an optional parameter “subject” cosmetic
- “person_enrichment_evidence” added an optional parameter “ticker” cosmetic
- “person_enrichment_evidence” added an optional parameter “website” cosmetic
- “company_enrichment_evidence” reworded the description of “company” cosmetic
- “contact_enrichment_evidence” reworded the description of “company” cosmetic
- “person_enrichment_evidence” reworded the description of “company” cosmetic
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 25 Sept 2026 · Probed https://phion.systems/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=phion.systems | CN=YE2,O=Let's Encrypt,C=US | 30 Jul 2026 | 28 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 64d09cefb1b3a722bb9f05fcaf93ae899ed |
| SANs: phion.systems, www.phion.systems | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of phion.systems. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| systems. | present | 9634 | 8 | Verified |
| phion.systems. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self' https://*.cloudflare.com https://gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.jsdelivr.net https://*.cloudflare.com https://*.unpkg.com; style-src 'self' 'unsafe-inline' https://googleapis.com; connect-src 'self' https://*.walletconnect.com https://*.cloudflare-eth.com; img-src 'self' data: https://*.phion.systems https://*.reown.com; font-src 'self' https://gstatic.com; |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://phion.systems/mcp | Verified | 200 | |
| http (plaintext) | http://phion.systems/mcp | HTTPS enforced | 301 | https://phion.systems/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
journey_verify ~53
Verify hash continuity, timestamps and ordered intent→quote→payment→delivery lifecycle; 0.010 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| events | array | yes | – |
| expected | object | – | – |
| journey_id | string | yes | – |
No output schema declared.
No examples provided.
live_data_freshness ~44
Evaluate live source observation against explicit maximum age; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| max_age_seconds | integer | yes | – |
| source_urls | array | yes | – |
No output schema declared.
No examples provided.
mandate_reserve ~78
Atomic spending reservation with cumulative cap and conflict-safe idempotency; 0.004 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | string | yes | – |
| capability_token | string | yes | – |
| cumulative_limit | string | yes | – |
| idempotency_key | string | yes | – |
| mandate_id | string | yes | – |
| ttl_seconds | integer | – | – |
No output schema declared.
No examples provided.
manifest_version_diff ~46
Recursive manifest diff that requires explicit versions and flags sensitive changes without a version advance; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| current | object | yes | – |
| previous | object | yes | – |
No output schema declared.
No examples provided.
market_data_snapshot ~48
Timestamped public market-data snapshot with provenance; 0.005 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| expected_fields | array | – | – |
| source_urls | array | yes | – |
| subject | object | – | – |
No output schema declared.
No examples provided.
market_demand_predictor Market Demand Predictor ~39
Forecast verified demand trends while abstaining on insufficient history.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
mcp_2026_compatibility_gateway MCP 2026 Compatibility Gateway ~29
MCP 2026 Compatibility Gateway; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
mcp_a2a_task_bridge MCP-A2A Task Bridge ~27
MCP-A2A Task Bridge; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
mcp_catalog_cache_guard MCP Catalog Cache Guard ~23
MCP Catalog Cache Guard; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
mcp_manifest_firewall ~41
Inspect an MCP manifest before installation or trust; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| manifest | object | yes | – |
| policy | object | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
mcp_server_identity_evidence ~31
Bind MCP domain, endpoint, manifest, key and version; 0.003 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
mcp_transaction_gateway MCP Transaction Gateway ~41
Bind an MCP tool call to transaction evidence without granting undeclared authority.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
memory_write_guard ~43
Screen persistent memory writes for poisoning, unsafe instructions and missing provenance; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| policy | object | – | – |
| write | object | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
multi_agent_escrow Multi-Agent Escrow ~42
Recommend hold or release from evidence without PHION custody or fund movement.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
multi_source_fact_bundle ~48
Independent source observations with agreement made explicit; 0.005 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| expected_fields | array | – | – |
| query | string | – | – |
| source_urls | array | yes | – |
No output schema declared.
No examples provided.
oauth_issuer_binding_evidence OAuth Issuer Binding Evidence ~25
OAuth Issuer Binding Evidence; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
oauth_token_audience_guard ~30
Validate declared OAuth audience and issuer; never send raw tokens; 0.002 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
onchain_evidence ~42
Public explorer or RPC response evidence with immutable hashes; 0.004 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| source_urls | array | yes | – |
| subject | object | – | – |
No output schema declared.
No examples provided.
payment_delivery_atomicity Payment Delivery Atomicity ~22
Payment Delivery Atomicity; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
payment_diagnose ~87
Free diagnosis of the exact payment-funnel stage and machine-readable recovery actions for any PHION service.
| Name | Type | Req | Description |
|---|---|---|---|
| body_valid | boolean | – | – |
| error_code | string | – | – |
| has_payment_signature | boolean | – | – |
| http_status | integer | – | – |
| selected_network | string | – | – |
| service | string | yes | – |
| x402_version | string | – | – |
No output schema declared.
No examples provided.
payment_optimizer Payment Optimizer ~38
Rank only integration-tested payment routes under explicit cost and latency constraints.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
payment_preflight ~63
Fail-closed x402 v2 firewall for network, asset, recipient, amount, scheme, resource host and expiry; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| intent_id | string | – | – |
| payment_requirement | object | yes | – |
| policy | object | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
payment_receipt_reconciler Payment Receipt Reconciler ~49
Compare canonical and common x402 payment/receipt aliases, settlement state and coverage; 0.003 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| payment | object | yes | – |
| receipt | object | yes | – |
No output schema declared.
No examples provided.
payment_route_selector Payment Route Selector ~55
Reject impossible x402 routes, rank safe eligible routes by policy and return the exact next payment action; read-only, deterministic, 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| policy | object | yes | – |
| routes | array | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
person_enrichment_evidence ~263
Person enrichment with free input preflight, provider attribution, likelihood, limitations and signed receipt; 0.006 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| birth_date | string | – | – |
| company | – | – | Company name or nested input object |
| contact | object | – | – |
| country | string | – | – |
| string | – | – | |
| email_hash | string | – | – |
| entity | object | – | – |
| first_name | string | – | – |
| identifier | string | – | Email, profile URL, phone, company domain, ticker or name; interpreted by service |
| input | object | – | – |
| last_name | string | – | – |
| lid | string | – | – |
| locality | string | – | – |
| location | string | – | – |
| minimum_likelihood | integer | – | – |
| name | string | – | – |
| pdl_id | string | – | – |
| person | object | – | – |
| phone | string | – | – |
| postal_code | string | – | – |
| profile | string | – | – |
| query | object | – | – |
| region | string | – | – |
| school | string | – | – |
| street_address | string | – | – |
| subject | object | – | – |
| ticker | string | – | – |
| website | string | – | – |
No output schema declared.
No examples provided.
phion_execute ~110
Universal PHION execution gateway: enforce a budget and persistent idempotency, execute one selected PHION service, evaluate acceptance criteria, and return a signed completion envelope. No gateway surcharge; the selected service price applies.
| Name | Type | Req | Description |
|---|---|---|---|
| acceptance_criteria | array | – | – |
| dry_run | boolean | – | – |
| idempotency_key | string | yes | – |
| input | object | yes | – |
| max_budget_atomic | string | yes | – |
| objective | string | yes | – |
| target_service | string | yes | – |
No output schema declared.
No examples provided.
portable_observability_audit ~46
Validate event identity, timestamps, hash chain and W3C-compatible lowercase nonzero trace/span identifiers; 0.004 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| events | array | yes | – |
No output schema declared.
No examples provided.
preflight ~23
Free URL safety and reachability check.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | – |
No output schema declared.
No examples provided.
price_discovery_engine Price Discovery Engine ~42
Derive price bands only from settled observations, never traffic or unsigned quotes.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
proof_of_service Proof of Service ~41
Commit request, authority, execution, payment and delivery evidence in one proof.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
provider_quality_predictor Provider Quality Predictor ~42
Estimate provider success, quality, latency and cost using transparent sample-aware statistics.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
purpose_bound_consent ~56
Fail-closed consent bound to ID, subject, recipient, purpose, scope, issue/expiry and checked revocation state; 0.003 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
| consent | object | yes | – |
No output schema declared.
No examples provided.
quote_freshness_guard Quote Freshness Guard ~23
Quote Freshness Guard; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
redirect_callback_validator ~25
Validate HTTPS callbacks and redirect host allowlists; 0.002 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
reputation_update_receipt Reputation Update Receipt ~39
Recommend a bounded auditable reputation update from verified outcome evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
resource_cycle_guard Resource Cycle Guard ~52
Require per-step identity, token and cost counters; detect repeated nodes/edges and enforce all three hard caps; 0.002 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| policy | object | yes | – |
| trace | array | yes | – |
No output schema declared.
No examples provided.
retention_deletion_receipt ~52
Separate requested, operator-completed and evidence-verified retention/deletion states using content and evidence hashes; 0.003 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
| record | object | yes | – |
No output schema declared.
No examples provided.
rwa_asset_due_diligence ~61
Fail-closed issuer, contract, jurisdiction, custody and documentation coverage with independently fetched evidence; 0.019 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | object | yes | – |
| declared_facts | object | – | – |
| source_urls | array | – | – |
No output schema declared.
No examples provided.
rwa_compliance ~61
Fail-closed RWA transfer decision requiring explicit jurisdiction, KYC, allowlist, limit and transfer-window checks; 0.012 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | object | yes | – |
| policy | object | yes | – |
| source_urls | array | – | – |
No output schema declared.
No examples provided.
rwa_corporate_actions ~68
Detect and sign material RWA changes in NAV, income, maturity, redemption or freeze state; 0.012 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | object | yes | – |
| current_state | object | yes | – |
| previous_state | object | yes | – |
| source_urls | array | – | – |
No output schema declared.
No examples provided.
rwa_nav_reserve ~86
Compare declared NAV and reserve ratios with structured observed facts plus independently fetched evidence; returns discrepancies in basis points and fails closed on incomplete evidence; 0.015 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | object | yes | – |
| declared_facts | object | yes | – |
| observed_facts | object | yes | – |
| source_urls | array | yes | – |
| tolerance_bps | integer | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
rwa_sanctions_screening_evidence ~64
Evidence-based literal subject screening against observed official US/EU sanctions sources; 0.015 USDC. Not legal clearance or wallet attribution.
| Name | Type | Req | Description |
|---|---|---|---|
| jurisdictions | array | yes | – |
| source_urls | array | – | – |
| subject | object | yes | – |
No output schema declared.
No examples provided.
rwa_transaction_assurance ~59
Verify an RWA asset, payment, delivery and transfer restrictions; 0.020 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | object | yes | – |
| policy | object | yes | – |
| source_urls | array | – | – |
| transaction | object | yes | – |
No output schema declared.
No examples provided.
schema_normalize ~47
Safe alias normalization that refuses ambiguous canonical/alias collisions and never changes payment values; 0.001 USDC.
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object | yes | – |
| target_service | string | yes | – |
No output schema declared.
No examples provided.
schema_normalize_free ~46
Free, rate-limited payload validation and safe key normalization before payment. Payment-critical values are never changed.
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object | yes | – |
| target_service | string | yes | – |
No output schema declared.
No examples provided.
secret_redaction_preflight ~27
Detect and redact common secret indicators before transmission; 0.002 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
service_failover_selector Service Failover Selector ~22
Service Failover Selector; deterministic signed assessment over supplied input.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
service_gap_detector Service Gap Detector ~37
Detect capability shortages using verified demand and verified provider supply.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
service_sla_attestation ~27
Sign availability and latency calculations from bounded samples; 0.004 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
signed_result_comparator ~26
Compare agent results and sign agreement or conflict; 0.003 USDC.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
What is the PHION Agent Trust Infrastructure MCP server?
PHION Agent Trust Infrastructure is an MCP server listed in the public MCP registry as systems.phion/evidence-engine. 118 agent services with free discovery, intent, x402 terms and signed verification. This page covers its hosted endpoint (https://phion.systems/mcp).
Is the PHION Agent Trust Infrastructure MCP server safe to use?
PHION Agent Trust Infrastructure scores 66 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the PHION Agent Trust Infrastructure MCP server expose?
PHION Agent Trust Infrastructure exposes 124 tools: phion_execute, index_feed, preflight, try_service, schema_normalize_free, and 119 more. Their descriptions and schemas cost roughly 5,964 tokens of context every time the server is loaded.
Does the PHION Agent Trust Infrastructure MCP server require authentication?
No. We connected to PHION Agent Trust Infrastructure without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the PHION Agent Trust Infrastructure MCP server still maintained?
PHION Agent Trust Infrastructure is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.