GroundTruth — subsurface scan QA & trade estimating
Two independent AI models read a GPR, locate or pipe scan and flag the do-not-core call.
Block For Production
trustsnap_c0cd82a0f451b6b8.- Utility Coverage
- Transport Compliance
- Step Up Auth
- Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tool…
- Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
- Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.
- No segmented attention signals observed in the current window.
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risks
Security posture
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes | Evidence |
|---|---|---|---|---|---|
read_scan |
read write network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {},
"capabilities": [
"read",
"write",
"network"
],
"input_schema": {
"properties": {
"discipline": {
"description": "One of: gpr (concrete scanning), locate (utility locating), pipe (CCTV sewer), xray (concrete radiograph), milestone (FL SB 4-D condo concrete). Defaults to gpr.",
"type": "string"
},
"field_note": {
"description": "Optional: what the technician said on site. Used as context for names and depths only \u2014 it can never clear a hazard the image shows.",
"type": "string"
},
"image_url": {
"description": "Public https URL to a JPEG or PNG of the scan or the marked-up surface. Max 8 MB.",
"type": "string"
}
},
"required": [
"image_url"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
draft_estimate |
write exec | Medium | command execution | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {},
"capabilities": [
"write",
"exec"
],
"input_schema": {
"properties": {
"job_description": {
"description": "What the contractor did or will do, in plain words. e.g. \"Replaced the panel, 85 feet of conduit, 8 can lights, 16 hours.\"",
"type": "string"
},
"trade": {
"description": "electrical, plumbing, hvac, or general. Defaults to general.",
"type": "string"
}
},
"required": [
"job_description"
],
"type": "object"
},
"risk_flags": [
"command_execution"
]
}
Dispute this classification
|
get_pricing |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {},
"capabilities": [
"read"
],
"input_schema": {
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
Write-action governance
Status detail: 1 exec-capable tool(s) are exposed without a clear auth boundary; no safeguards or confirmation signals detected.
Exec-capable tools are medium risk here because they are scoped/authenticated and not destructive, but they still require confirmation safeguards before write-safe publishing.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Recommended runtime policy
No policy blockers under the default policy stance.
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
| No newly added actions. | ||
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Critical alerts
Compatibility
Client readiness verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Errorstep_up_auth_probe• Missingconnector_replay_probe• OK — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Error
Evidence provenance
action_safety_probe• Error
Evidence provenance
tool_snapshot_probe• OKconnector_replay_probe• OK
Client readiness gate details
Remediation checklist
- Add OAuth-based authentication for remote connector auth.
- Support dynamic client registration (DCR) to simplify connector setup.
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Document step-up auth requirements in a connector-friendly way.
- Improve OAuth interoperability -- see the OAuth Interop score breakdown.
- Limit the exposed surface to search/fetch-style read tools.
Remediation checklist
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Limit the exposed surface to search/fetch-style read tools.
- Remove or isolate write, delete, and exec-capable tools before using this read/search-only client profile.
- Configure OAuth for authenticated remote MCP access.
- Remove export, bulk, mutating, and high-blast-radius exposure before certifying company-knowledge use.
- Satisfy OAuth, compatibility, and connector-refresh requirements before using the Messages API remote MCP path.
Remediation checklist
- Add a clearer auth boundary around risky write actions.
- Add confirmation or dry-run semantics for the risky tools named in the action-safety evidence.
- Constrain or sandbox exec-capable tools before publishing broadly.
- Resolve the blocking production-readiness verdict before treating this as write-safe.
Verdict traces
instruction_tool_reference_mismatch• low • Server instructions name unavailable tools
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Not Assessed
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Degraded
Recommended for
Evidence
Current trust snapshot
trustsnap_c0cd82a0f451b6b8Canonical machine links
Evidence confidence
Latest validation evidence
Failures
oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://gtfi.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization serverserver_cardClient error '404 Not Found' for url 'https://gtfi.ai/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404transport_compliance_probeIssues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=200).
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Error | n/a | 1 exec-capable, 1 egress-capable, non-read capabilities: write, exec tool(s); no clear auth boundary; safeguards=0; confirmation=none. |
advanced_capabilities_probe |
Missing | n/a | No advanced MCP capability signals detected. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: protocol version, session resume, step up auth, transport compliance, +3 more. |
connector_replay_probe |
OK | n/a | Backward compatible with no breaking tool-surface changes. |
determinism_probe |
OK | 110.3 ms | Check completed |
initialize |
OK | 817.9 ms | Protocol 2025-03-26 |
instruction_tool_reference_probe |
Warning | n/a | Check completed |
interactive_flow_probe |
Missing | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 282.9 ms | Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
OK | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 377.2 ms | Fetched https://gtfi.ai/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Missing | 118.5 ms | not supported |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Missing | 99.9 ms | not supported |
schema_divergence_probe |
Missing | n/a | no server card tools |
server_card |
Error | 244.9 ms | Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
session_resume_probe |
Warning | n/a | no session id |
step_up_auth_probe |
Missing | n/a | No OAuth or incremental-scope signals detected. |
tool_snapshot_probe |
OK | n/a | Check completed |
tools_list |
OK | 248.3 ms | 3 tool(s) exposed |
transport_compliance_probe |
Error | 95.3 ms | Issues: missing session id, missing protocol header, bad protocol not rejected (bad protocol=200). |
utility_coverage_probe |
Missing | 121.1 ms | No completions evidence; no pagination evidence; tasks missing. |
Known versions
1.0.1
Public server reputation
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Degraded |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Tool snapshot diff & changelog
Required-argument changes
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument changes detected. | ||
Output-schema drift
| Tool | Previous properties | Latest properties |
|---|---|---|
| No output-schema drift detected. | ||
Validation diff
Regressed checks: none
Improved checks: none
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
| No component deltas between the latest two runs. | |||
Registry & provenance divergence
Active alerts
- Server instructions name unavailable tools (low)
Initialize instructions reference tools not present in tools/list: before
Aliases & registry graph
| Identifier | Source | Canonical | Identity evidence | Score |
|---|---|---|---|---|
ai.gtfi/groundtruth |
official_registry | yes | canonical | 57.3 |
Alias consolidation
Strong alias identity requires matching remote URL, server-card URL, repository slug, or explicit registry cross-reference; shared provider namespace alone is not identity.
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
1 component(s) not assessed for this run: Provenance Divergence
Experimental candidate components
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| High | Add confirmation and dry-run semantics for risky actions | High-risk write, delete, exec, or egress tools should communicate safeguards clearly. | Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tools before they can make destructive changes.Playbook
|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| High | Publish a complete server card | Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. | Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | Resolve every blocker named by connector_publishability_probe, then rerun it before submitting or refreshing a connector listing.Playbook
|
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Persist session state keyed by Mcp-Session-Id and honor Last-Event-ID on GET reconnects so clients can resume a dropped Streamable HTTP session.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
| Low | Remove stale tool names from server instructions | Initialize instructions explicitly reference tools that tools/list does not expose. | Update initialize instructions so every explicitly named tool exists in tools/list.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 0/4 | -4.0 |
| Transport Compliance | 0/4 | -4.0 |
| Step-Up Auth | 0/4 | -4.0 |
| Resource Contract | 0/4 | -4.0 |
| Request Association | 0/4 | -4.0 |
| Recovery Semantics | 0/4 | -4.0 |
| Prompt Contract | 0/4 | -4.0 |
| OAuth Interop | 0/4 | -4.0 |
| Interactive Flow Safety | 0/4 | -4.0 |
| Advanced Capability Coverage | 0/4 | -4.0 |
| Error Contract Quality | 1/4 | -3.0 |
| Supply Chain Signal | 1/4 | -3.0 |
Technical compatibility profiles
These scores measure technical client compatibility only. Client publishability and production readiness are evaluated separately against policy, transport, and write-surface blockers.
Connector URL: https://gtfi.ai/mcp # No OAuth metadata detected. # Server: ai.gtfi/groundtruth
{
"mcpServers": {
"groundtruth": {
"command": "npx",
"args": ["mcp-remote", "https://gtfi.ai/mcp"]
}
}
}
smithery mcp add "https://gtfi.ai/mcp"
curl -sS https://gtfi.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: validation targets and SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://gtfi.ai/mcp # No OAuth metadata detected. # Server: ai.gtfi/groundtruth
{
"mcpServers": {
"groundtruth": {
"command": "npx",
"args": ["mcp-remote", "https://gtfi.ai/mcp"]
}
}
}
smithery mcp add "https://gtfi.ai/mcp"
curl -sS https://gtfi.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.ai.gtfi/groundtruth.History
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 14, 2026 03:53:35 PM UTC | Healthy | 57.3 | 2644.6 ms | 3 |
| Aug 14, 2026 03:22:00 AM UTC | Healthy | 57.3 | 1684.1 ms | 3 |
| Aug 13, 2026 08:38:43 PM UTC | Healthy | 57.3 | 1649.8 ms | 3 |
| Aug 13, 2026 08:32:22 AM UTC | Healthy | 57.3 | 1582.0 ms | 3 |
| Aug 12, 2026 08:12:03 PM UTC | Healthy | 57.8 | 1762.0 ms | 3 |
| Aug 12, 2026 07:59:00 AM UTC | Healthy | 57.8 | 1536.4 ms | 3 |
| Aug 11, 2026 07:29:59 PM UTC | Healthy | 57.8 | 1770.7 ms | 3 |
| Aug 11, 2026 07:08:41 AM UTC | Healthy | 58.3 | 1456.1 ms | 3 |
| Aug 10, 2026 07:04:15 PM UTC | Healthy | 58.3 | 1416.7 ms | 3 |
| Aug 10, 2026 07:00:46 AM UTC | Healthy | 58.3 | 1443.3 ms | 3 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 14, 2026 03:53:35 PM UTC | Healthy | 57.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 14, 2026 03:22:00 AM UTC | Healthy | 57.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 13, 2026 08:38:43 PM UTC | Healthy | 57.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 13, 2026 08:32:22 AM UTC | Healthy | 57.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 12, 2026 08:12:03 PM UTC | Healthy | 57.8 | 2025-03-26 | public | 3 | 0 | none |
| Aug 12, 2026 07:59:00 AM UTC | Healthy | 57.8 | 2025-03-26 | public | 3 | 0 | none |
| Aug 11, 2026 07:29:59 PM UTC | Healthy | 57.8 | 2025-03-26 | public | 3 | 0 | none |
| Aug 11, 2026 07:08:41 AM UTC | Healthy | 58.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 10, 2026 07:04:15 PM UTC | Healthy | 58.3 | 2025-03-26 | public | 3 | 0 | none |
| Aug 10, 2026 07:00:46 AM UTC | Healthy | 58.3 | 2025-03-26 | public | 3 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 14, 2026 03:53:33 PM UTC | Completed | Healthy | 2644.6 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 14, 2026 03:21:58 AM UTC | Completed | Healthy | 1684.1 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 13, 2026 08:38:41 PM UTC | Completed | Healthy | 1649.8 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 13, 2026 08:32:20 AM UTC | Completed | Healthy | 1582.0 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 12, 2026 08:12:01 PM UTC | Completed | Healthy | 1762.0 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 12, 2026 07:58:59 AM UTC | Completed | Healthy | 1536.4 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 11, 2026 07:29:57 PM UTC | Completed | Healthy | 1770.7 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 11, 2026 07:08:39 AM UTC | Completed | Healthy | 1456.1 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 10, 2026 07:04:13 PM UTC | Completed | Healthy | 1416.7 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 10, 2026 07:00:45 AM UTC | Completed | Healthy | 1443.3 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 14, 2026 03:53:35 PM UTC | Latest validation: healthy | Score 57.3 with status healthy. |
| Aug 05, 2026 10:58:13 AM UTC | Score corrected (post-1.0.503 remediation, R1 zero-anchoring) | Prior: 69.17. Corrected: 66.96. |
Technical details
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": false,
"confirmation_signals": [],
"reason": null,
"safeguard_count": 0,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {
"exec": 1,
"network": 1,
"read": 2,
"write": 2
},
"declared_non_read_only_tools": 0,
"destructive_tools": 0,
"egress_tools": 1,
"exec_tools": 1,
"has_mutating_capability": true,
"has_non_read_capability": true,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 1,
"medium": 2
},
"secret_tools": 0,
"tool_count": 3
}
},
"latency_ms": null,
"status": "error"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [],
"enabled_count": 0,
"initialize_capability_keys": [
"tools"
]
},
"latency_ms": null,
"status": "missing"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"protocol_version",
"session_resume",
"step_up_auth",
"transport_compliance",
"request_association",
"action_safety",
"server_card"
],
"criteria": {
"action_safety": false,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": false,
"remote_transport": true,
"request_association": false,
"server_card": false,
"session_resume": false,
"step_up_auth": false,
"tool_surface": true,
"tools_list": true,
"transport_compliance": false
},
"high_risk_tools": 0,
"tool_count": 3,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"connector_replay_probe": {
"details": {
"added_tools": [],
"additive_output_changes": [],
"backward_compatible": true,
"output_breaks": [],
"removed_tools": [],
"required_arg_breaks": [],
"would_break_after_refresh": false
},
"latency_ms": null,
"status": "ok"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "a22e2175dae87da423fbf182f61aeb39e128aeb74d83b2dcb3f1e149ae9721e2",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 110.28,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "application/json; charset=utf-8"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"tools": {
"listChanged": false
}
},
"instructions": "Two products from one company. GroundTruth is an AI second set of eyes for subsurface crews: read_scan gives an independent, two-model read of a GPR / utility-locate / pipe / radiograph image and flags the dangerous call before anyone cores or digs \u2014 always advisory, a certified tech signs off. GruntPay is the $29/mo voice-first bid-and-invoice app for one-truck trades: draft_estimate turns a plain-English job description into a real itemized bid. Call get_pricing before answering cost questions.",
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "groundtruth",
"version": "1.0.0"
}
}
},
"url": "https://gtfi.ai/mcp"
},
"latency_ms": 817.87,
"status": "ok"
},
"instruction_tool_reference_probe": {
"details": {
"missing_tools": [
"before"
],
"observed_tool_count": 3,
"referenced_tools": [
"before",
"get_pricing"
]
},
"latency_ms": null,
"status": "warning"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": []
},
"latency_ms": null,
"status": "missing"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gtfi.ai/.well-known/oauth-protected-resource"
},
"latency_ms": 282.95,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": true,
"official_peer_count": 1,
"registry_identifier": "ai.gtfi/groundtruth",
"registry_source": "official_registry"
},
"latency_ms": null,
"status": "ok"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"consent_error": null,
"headers": {
"content-type": "text/plain; charset=utf-8"
},
"http_status": 200,
"url": "https://gtfi.ai/robots.txt",
"validation_disallowed": false
},
"latency_ms": 377.22,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "application/json; charset=utf-8"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found: prompts/list"
},
"id": 3,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://gtfi.ai/mcp"
},
"latency_ms": 118.47,
"status": "missing"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": true,
"drift_fields": [],
"metadata_document_count": 2,
"readable_sources": [
"registry"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": null,
"server_card_version": null
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"headers": {
"content-type": "application/json; charset=utf-8"
},
"http_status": 200,
"payload": {
"error": {
"code": -32601,
"message": "Method not found: resources/list"
},
"id": 5,
"jsonrpc": "2.0"
},
"reason": "not_supported",
"url": "https://gtfi.ai/mcp"
},
"latency_ms": 99.91,
"status": "missing"
},
"schema_divergence_probe": {
"details": {
"auth_scheme_mismatch": false,
"card_server_name": null,
"card_server_version": null,
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_server_name": "groundtruth",
"live_server_version": "1.0.0",
"reason": "no_server_card_tools",
"server_name_mismatch": false,
"server_version_mismatch": false
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"error": "Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gtfi.ai/.well-known/mcp/server-card.json"
},
"latency_ms": 244.87,
"status": "error"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "missing"
},
"tool_snapshot_probe": {
"details": {
"added": [],
"changed_outputs": [],
"current_tool_count": 3,
"previous_tool_count": 3,
"removed": [],
"similarity": 1.0
},
"latency_ms": null,
"status": "ok"
},
"tools_list": {
"details": {
"headers": {
"content-type": "application/json; charset=utf-8"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"description": "Get an independent AI second opinion on a subsurface scan before anyone cores or digs. Send a public image URL of a GPR scan, a marked-up concrete slab photo, a utility-locate markup, a concrete radiograph, or a CCTV pipe frame. TWO different AI models read it independently \u2014 the second is prompted to refute the first \u2014 and you get back every located target with its hazard class (do-not-core / rebar / verify / clear), plus a QA flag when the two reads disagree. Advisory only: a certified technician must review and sign off before any cutting.",
"inputSchema": {
"properties": {
"discipline": {
"description": "One of: gpr (concrete scanning), locate (utility locating), pipe (CCTV sewer), xray (concrete radiograph), milestone (FL SB 4-D condo concrete). Defaults to gpr.",
"type": "string"
},
"field_note": {
"description": "Optional: what the technician said on site. Used as context for names and depths only \u2014 it can never clear a hazard the image shows.",
"type": "string"
},
"image_url": {
"description": "Public https URL to a JPEG or PNG of the scan or the marked-up surface. Max 8 MB.",
"type": "string"
}
},
"required": [
"image_url"
],
"type": "object"
},
"name": "read_scan"
},
{
"description": "Turn a plain-English description of a trade job into a professional itemized bid \u2014 real materials by size, fittings, consumables and labor on its own line, at realistic US market prices. Built for one-truck electrical, plumbing, HVAC and general-contracting shops. This is GruntPay: the contractor normally speaks this into their phone. Returns the line items plus a link to brand it and send it to the customer.",
"inputSchema": {
"properties": {
"job_description": {
"description": "What the contractor did or will do, in plain words. e.g. \"Replaced the panel, 85 feet of conduit, 8 can lights, 16 hours.\"",
"type": "string"
},
"trade": {
"description": "electrical, plumbing, hvac, or general. Defaults to general.",
"type": "string"
}
},
"required": [
"job_description"
],
"type": "object"
},
"name": "draft_estimate"
},
{
"description": "Current GroundTruth and GruntPay plans and prices. Free to call \u2014 use it before answering any cost question rather than guessing.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_pricing"
}
]
}
},
"url": "https://gtfi.ai/mcp"
},
"latency_ms": 248.34,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json; charset=utf-8"
},
"bad_protocol_payload": {
"id": 410,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"description": "Get an independent AI second opinion on a subsurface scan before anyone cores or digs. Send a public image URL of a GPR scan, a marked-up concrete slab photo, a utility-locate markup, a concrete radiograph, or a CCTV pipe frame. TWO different AI models read it independently \u2014 the second is prompted to refute the first \u2014 and you get back every located target with its hazard class (do-not-core / rebar / verify / clear), plus a QA flag when the two reads disagree. Advisory only: a certified technician must review and sign off before any cutting.",
"inputSchema": {
"properties": {
"discipline": {
"description": "One of: gpr (concrete scanning), locate (utility locating), pipe (CCTV sewer), xray (concrete radiograph), milestone (FL SB 4-D condo concrete). Defaults to gpr.",
"type": "string"
},
"field_note": {
"description": "Optional: what the technician said on site. Used as context for names and depths only \u2014 it can never clear a hazard the image shows.",
"type": "string"
},
"image_url": {
"description": "Public https URL to a JPEG or PNG of the scan or the marked-up surface. Max 8 MB.",
"type": "string"
}
},
"required": [
"image_url"
],
"type": "object"
},
"name": "read_scan"
},
{
"description": "Turn a plain-English description of a trade job into a professional itemized bid \u2014 real materials by size, fittings, consumables and labor on its own line, at realistic US market prices. Built for one-truck electrical, plumbing, HVAC and general-contracting shops. This is GruntPay: the contractor normally speaks this into their phone. Returns the line items plus a link to brand it and send it to the customer.",
"inputSchema": {
"properties": {
"job_description": {
"description": "What the contractor did or will do, in plain words. e.g. \"Replaced the panel, 85 feet of conduit, 8 can lights, 16 hours.\"",
"type": "string"
},
"trade": {
"description": "electrical, plumbing, hvac, or general. Defaults to general.",
"type": "string"
}
},
"required": [
"job_description"
],
"type": "object"
},
"name": "draft_estimate"
},
{
"description": "Current GroundTruth and GruntPay plans and prices. Free to call \u2014 use it before answering any cost question rather than guessing.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_pricing"
}
]
}
},
"bad_protocol_status_code": 200,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 95.33,
"status": "error"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 200,
"probe_status": "missing"
}
},
"latency_ms": 121.11,
"status": "missing"
}
},
"failures": {
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gtfi.ai/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
},
"server_card": {
"error": "Client error '404 Not Found' for url 'https://gtfi.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://gtfi.ai/.well-known/mcp/server-card.json"
},
"transport_compliance_probe": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json; charset=utf-8"
},
"bad_protocol_payload": {
"id": 410,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"description": "Get an independent AI second opinion on a subsurface scan before anyone cores or digs. Send a public image URL of a GPR scan, a marked-up concrete slab photo, a utility-locate markup, a concrete radiograph, or a CCTV pipe frame. TWO different AI models read it independently \u2014 the second is prompted to refute the first \u2014 and you get back every located target with its hazard class (do-not-core / rebar / verify / clear), plus a QA flag when the two reads disagree. Advisory only: a certified technician must review and sign off before any cutting.",
"inputSchema": {
"properties": {
"discipline": {
"description": "One of: gpr (concrete scanning), locate (utility locating), pipe (CCTV sewer), xray (concrete radiograph), milestone (FL SB 4-D condo concrete). Defaults to gpr.",
"type": "string"
},
"field_note": {
"description": "Optional: what the technician said on site. Used as context for names and depths only \u2014 it can never clear a hazard the image shows.",
"type": "string"
},
"image_url": {
"description": "Public https URL to a JPEG or PNG of the scan or the marked-up surface. Max 8 MB.",
"type": "string"
}
},
"required": [
"image_url"
],
"type": "object"
},
"name": "read_scan"
},
{
"description": "Turn a plain-English description of a trade job into a professional itemized bid \u2014 real materials by size, fittings, consumables and labor on its own line, at realistic US market prices. Built for one-truck electrical, plumbing, HVAC and general-contracting shops. This is GruntPay: the contractor normally speaks this into their phone. Returns the line items plus a link to brand it and send it to the customer.",
"inputSchema": {
"properties": {
"job_description": {
"description": "What the contractor did or will do, in plain words. e.g. \"Replaced the panel, 85 feet of conduit, 8 can lights, 16 hours.\"",
"type": "string"
},
"trade": {
"description": "electrical, plumbing, hvac, or general. Defaults to general.",
"type": "string"
}
},
"required": [
"job_description"
],
"type": "object"
},
"name": "draft_estimate"
},
{
"description": "Current GroundTruth and GruntPay plans and prices. Free to call \u2014 use it before answering any cost question rather than guessing.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "get_pricing"
}
]
}
},
"bad_protocol_status_code": 200,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
}
},
"remote_url": "https://gtfi.ai/mcp",
"server_card_payload": null,
"server_identifier": "ai.gtfi/groundtruth"
}
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://gtfi.ai/for-agents
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://gtfi.ai/mcp
- Directory listing: none
- Server card: none
Transport compliance drilldown
Issues: missing_session_id, missing_protocol_header, bad_protocol_not_rejected
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||