{"schema_version":"verify.report.v1","generated_at":"2026-07-31T11:03:03.905805+00:00","snapshot_id":"trustsnap_1b7775513114b3e2","server":{"namespace":"ai.boolsai","name":"scan","title":"Boolsai Scan","description":"Live tech-stack scan of any public site — vendors, account IDs, scripts, JSON-LD. 2 tools.","homepage_url":null,"docs_url":null,"icon_url":null,"support_url":null,"remote_url":"https://boolsai.ai/mcp","server_card_url":null,"latest_version":"1.0.0","current_status":"healthy","current_score":70.19,"transport_type":"streamable-http","has_oauth":false,"has_dcr":false,"has_prompts":false,"tool_count":2,"current_validation_schema_version":"16d1d270090d6c8f","last_validated_at":"2026-07-31T05:36:00.052677+00:00","registry_source":"official_registry","registry_identifier":"ai.boolsai/scan","canonical_identifier":"ai.boolsai/scan","current_score_components":{"auth_operability_score":2.0,"error_contract_score":2.83,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":2.5,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":3.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":4.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":4.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":4.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"capability_taxonomy":["web","read","network","write","filesystem","streamable_http"],"machine_summary":{"verdict":"safe_for_evaluation","best_for":["Claude Desktop","Smithery","Generic Streamable HTTP"],"avoid_if":["You need a low-risk tool surface."],"requires_auth":false,"supports_oauth":false,"risk_level":"high"},"taxonomy_tags":["web"],"score_decomposition":[{"key":"access_protocol","label":"Access & Protocol","score":30.0,"max_score":44.0,"hint":"Connectivity, auth, and transport expectations for common clients.","components":[{"key":"auth_operability_score","score":2.0},{"key":"installability_score","score":4.0},{"key":"session_semantics_score","score":4.0},{"key":"transport_fidelity_score","score":4.0},{"key":"spec_recency_score","score":2.0},{"key":"session_resume_score","score":3.0},{"key":"step_up_auth_score","score":3.0},{"key":"transport_compliance_score","score":0.0},{"key":"request_association_score","score":3.0},{"key":"oauth_interop_score","score":3.0},{"key":"least_privilege_scope_score","score":2.0}]},{"key":"interface_quality","label":"Interface Quality","score":33.83,"max_score":56.0,"hint":"How well the tool/resource interface communicates and behaves under automation.","components":[{"key":"error_contract_score","score":2.83},{"key":"rate_limit_semantics_score","score":2.0},{"key":"schema_completeness_score","score":2.0},{"key":"prompt_contract_score","score":2.0},{"key":"resource_contract_score","score":2.0},{"key":"tool_surface_design_score","score":3.0},{"key":"tool_capability_clarity_score","score":4.0},{"key":"tool_namespace_clarity_score","score":4.0},{"key":"result_shape_stability_score","score":2.0},{"key":"utility_coverage_score","score":2.0},{"key":"advanced_capability_coverage_score","score":2.0},{"key":"tool_snapshot_churn_score","score":3.0},{"key":"connector_replay_score","score":3.0},{"key":"recovery_semantics_score","score":0.0}]},{"key":"security_posture","label":"Security Posture","score":27.5,"max_score":36.0,"hint":"How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.","components":[{"key":"security_hygiene_score","score":2.5},{"key":"destructive_operation_safety_score","score":3.0},{"key":"egress_ssrf_resilience_score","score":3.0},{"key":"execution_sandbox_safety_score","score":4.0},{"key":"data_exfiltration_resilience_score","score":3.0},{"key":"secret_handling_hygiene_score","score":3.0},{"key":"input_sanitization_safety_score","score":3.0},{"key":"interactive_flow_safety_score","score":4.0},{"key":"action_safety_score","score":2.0}]},{"key":"reliability_trust","label":"Reliability & Trust","score":18.75,"max_score":24.0,"hint":"Operational stability, consistency, and trustworthiness over time.","components":[{"key":"backward_compatibility_score","score":2.0},{"key":"slo_health_score","score":4.0},{"key":"task_success_score","score":4.0},{"key":"trust_confidence_score","score":1.75},{"key":"abuse_noise_ratio_score","score":4.0},{"key":"freshness_confidence_score","score":3.0}]},{"key":"discovery_governance","label":"Discovery & Governance","score":22.5,"max_score":28.0,"hint":"How well the server is documented, listed, and governed in public registries.","components":[{"key":"discovery_metadata_score","score":3.0},{"key":"registry_consistency_score","score":2.0},{"key":"maintenance_signal_score","score":3.0},{"key":"safety_transparency_score","score":4.0},{"key":"dependency_supply_chain_signal_score","score":2.5},{"key":"official_registry_presence_score","score":4.0},{"key":"provenance_divergence_score","score":4.0}]},{"key":"adoption_market","label":"Adoption & Market","score":5.0,"max_score":8.0,"hint":"Adoption clues and public evidence that the server is intended for external use.","components":[{"key":"adoption_signal_score","score":2.0},{"key":"connector_publishability_score","score":3.0}]}],"validation_diff":null,"tool_snapshot_diff":null,"connector_replay":{"status":"missing","backward_compatible":false,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]},"request_association":{"status":"missing","advertised_capabilities":[],"session_id_present":false,"protocol_version":null,"observed_methods":[],"violating_methods":[],"http_status":null,"issues":[]},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"history_summary":{"points":[{"timestamp":"2026-07-31T05:36:00.052677+00:00","score":70.19,"status":"healthy","latency_ms":199.52,"tool_count":2,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":199.52,"healthy_ratio_recent":1.0,"freshness_hours":5.45,"latest_status":"healthy"},"validation_timeline":[{"timestamp":"2026-07-31T05:36:00.052677+00:00","summary_status":"healthy","score":70.19,"protocol_version":"2025-03-26","auth_mode":"public","tool_count":2,"prompt_count":0,"resource_count":0,"high_risk_tools":1,"safe_to_publish":false,"change_flags":[]}],"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 5.5 hours.","live_check_count":26,"validation_age_hours":5.45},"incident_feed":[{"type":"validation_snapshot","timestamp":"2026-07-31T05:36:00.052677+00:00","title":"Latest validation: healthy","message":"Score 70.2 with status healthy."}],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"client_remediation_modes":[{"key":"openai_connectors","label":"ChatGPT custom connector","status":"partial","why_not_ready":[{"label":"OpenAI connectors expect OAuth for remote server auth.","state":"blocked"},{"label":"Dynamic client registration materially improves connector setup.","state":"blocked"},{"label":"Transport compliance should be in good shape.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"claude_desktop","label":"Claude remote MCP","status":"ready","why_not_ready":[{"label":"Transport behavior should match Claude-compatible HTTP expectations.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"},{"label":"safe for company knowledge is not yet satisfied","state":"blocked"},{"label":"safe for messages api remote mcp is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"write_safe","label":"Write-safe publishing","status":"blocked","why_not_ready":[{"label":"Add a clearer auth boundary around risky write actions.","state":"blocked"},{"label":"Add confirmation or dry-run semantics for risky actions.","state":"blocked"}],"maintainer_context":null}],"client_profiles":[{"key":"openai_connectors","label":"OpenAI Connectors","score":66.7,"compatibility":"partial","missing_requirements":["OpenAI connectors expect OAuth for remote server auth.","Dynamic client registration materially improves connector setup.","Transport compliance should be in good shape."],"snippet":"Connector URL: https://boolsai.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.boolsai/scan"},{"key":"claude_desktop","label":"Claude Desktop","score":83.3,"compatibility":"compatible","missing_requirements":["Transport behavior should match Claude-compatible HTTP expectations."],"snippet":"{\n  \"mcpServers\": {\n    \"scan\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://boolsai.ai/mcp\"]\n    }\n  }\n}"},{"key":"smithery","label":"Smithery","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"smithery mcp add \"https://boolsai.ai/mcp\""},{"key":"generic_streamable_http","label":"Generic Streamable HTTP","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"curl -sS https://boolsai.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"}],"client_readiness_verdicts":[{"key":"openai_connectors","label":"Client compatibility: ChatGPT","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":"Frozen tool snapshots must survive refresh.","http_status":null},{"check":"request_association_probe","status":"missing","source":"live_validation","note":"Roots, sampling, and elicitation should stay request-scoped.","http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"claude_desktop","label":"Client compatibility: Claude","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"unsafe_for_write_actions","label":"Write-action publishing","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history"],"disagreements":[]}},{"key":"snapshot_churn_risk","label":"Snapshot churn risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","evidence":[{"check":"tool_snapshot_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"history","supporting_sources":["history","live_validation"],"disagreements":[]}}],"publishability_policy_profiles":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"claude_remote_mcp","label":"Claude remote MCP compatibility","status":"ready","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"compatibility_fixtures":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector fixture","status":"degraded","assumptions":[{"name":"remote_http_endpoint","status":"passes"},{"name":"oauth_discovery","status":"degraded"},{"name":"frozen_tool_snapshot_refresh","status":"passes"},{"name":"request_association","status":"passes"}],"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"anthropic_remote_mcp","label":"Anthropic remote MCP fixture","status":"degraded","assumptions":[{"name":"remote_transport","status":"passes"},{"name":"tool_discovery","status":"passes"},{"name":"auth_connect","status":"passes"},{"name":"safe_write_review","status":"degraded"}],"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"install_snippets":{"openai_connectors":"Connector URL: https://boolsai.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.boolsai/scan","claude_desktop":"{\n  \"mcpServers\": {\n    \"scan\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://boolsai.ai/mcp\"]\n    }\n  }\n}","smithery":"smithery mcp add \"https://boolsai.ai/mcp\"","generic_http":"curl -sS https://boolsai.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"},"aliases":[{"identifier":"ai.boolsai/scan","registry_source":"official_registry","remote_url":"https://boolsai.ai/mcp","canonical":true,"score":70.19}],"raw_evidence":{"server_identifier":"ai.boolsai/scan","remote_url":"https://boolsai.ai/mcp","server_card_payload":null,"checks":{"server_card":{"status":"error","latency_ms":40.47,"details":{"url":"https://boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":37.02,"details":{"url":"https://boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":26.87,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{"listChanged":false}},"serverInfo":{"name":"boolsai-scan","title":"Boolsai Scan","version":"1.0.0"},"instructions":"You are connected to **Boolsai Scan** — one of four MCP servers in the Boolsai suite. ALWAYS refer to this server by its full name \"Boolsai Scan\" when discussing it with the user. Do not shorten to \"Boolsai\", \"scan\", \"the MCP\", \"Scan MCP\", etc. Sister servers in the suite (cross-discovery only — not connected here): \"Boolsai Directory\" (https://directory.boolsai.ai/mcp), \"Boolsai Grep\" (https://grep.boolsai.ai/mcp), \"Boolsai Signals\" (https://signals.boolsai.ai/mcp). Refer to those by their full names too if they come up.\n\nBoolsai Scan · stack intelligence guide for e-commerce agencies.\n\nROLE: you are the analyst sitting next to an agency operator (account director, growth strategist, head of new business). Your job is to translate a live site scan into agency-grade intel for three use cases:\n\n1. Pre-pitch prospect work — \"what is this brand running?\" Pixel coverage, CDP, consent posture, server-side tagging, personalisation, reviews, support, payments, BNPL, CDN, framework / CMS. Be specific about what you SEE on the page vs. what's LIKELY happening server-side. Flag gaps a competing agency could pitch on (missing GA4, no consent, no SST, no personalisation, broken pixel firing order, etc.).\n2. Existing-client audits — \"what's actually in production?\" Be matter-of-fact, list everything detected, flag anything obviously broken or misconfigured.\n3. Competitor watch — \"what did they just roll out?\" New vendor, swapped CDP, new BNPL, fresh consent vendor, framework migration.\n\nVOICE: tight, specific, agency-strategist. Tell the operator WHAT you see, then WHY it matters for the pitch / audit / watch. Never invent — if a pixel isn't in the scan, say \"not visible on this page\" and propose a follow-up scan. Distinguish \"definitely client-side\" (hostname is present) from \"likely server-side\" (CDP present + no client-side equivalent). Use concrete account IDs / container IDs / data plan names when the scan surfaces them — those are agency gold.\n\nTOOLS:\n- boolsai_scan({url}) — raw scanner JSON for one URL. Use first. Response includes a top-level _summary block with the structural facts pre-extracted (external hosts, internal routes, inline scripts with signals, canonical, structured data presence).\n- boolsai_scan_paths({url, paths[]}) — scan multiple paths on the same site in parallel; returns per-path host lists + a homepage_missed diff (hosts visible on PDP/cart/checkout but NOT on /). Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths.\n\nCONVERSATIONAL HANDOFF: every tool response ends with a \"Next moves\" block. After you present the result, ALWAYS finish your reply by asking the user if they want to dig deeper — frame options as natural questions (\"Want me to also scan their /products and /cart to catch lazy-loaded pixels?\" / \"Should I pull a competitor for comparison?\" / \"Want the inline-script signals on their Trekkie config?\"). Do NOT list tool names to the user — offer the action. Keep the question short (one sentence, max two options).\n\nREADING boolsai_scan OUTPUT: the _summary block at the top is the fastest way in — read it first. Then for the full picture, domTree.head.external and domTree.body.external are URL-path tries — root keys are HOSTNAMES, subkeys are URL path segments split on '/', empty {} is a URL terminator (path ends here, NOT \"no data\"). domTree.head.internal / body.internal are the same trie minus the hostname level (paths on the scanned host). domTree.head.inlineScripts.<name> has per-script analysis: structural (hosts referenced), important.urls (detected URLs), important.configHits (behaviour patterns), raw_preview (truncated source). Bulky build-artifact clusters (_next/static/chunks, etc.) are compressed to {_count, _sample} for token efficiency — treat as \"N files here, here's a sample\" not missing data. Segments may be normalised to {hash}/{ver}/{date}/{env}/{bundle}.\n\nVENDOR RECOGNITION: the MCP does NOT pre-label hostnames. You recognise them yourself using your own knowledge — and that's the point, because the agency value is in YOUR interpretation. Examples: cdn.shopify.com → Shopify CDN; us.checkout.gymshark.com + perf-kit → Shopify Plus checkout; connect.facebook.net → Meta Pixel; monorail-edge.shopifysvc.com → Shopify Trekkie analytics (server-side); cdn.cookielaw.org → OneTrust consent; mparticle.com → mParticle CDP (usually server-side forwarding); cdn.dynamicyield.com → Dynamic Yield personalisation; elevarcdn.com → Elevar server-side tagging; klaviyo.com → Klaviyo email; klarna.com → Klarna BNPL; etc. When you don't recognise a hostname, say so and flag it for the operator to check."}},"http_status":200,"headers":{"content-type":"application/json"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":10.02,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"http_status":200,"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":10.74,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":8.55,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":12.11,"details":{"url":"https://boolsai.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":11.38,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"2af3f25a6a3f6c7db7baa31194ef9f00b7f963454b172e5c769748fd08efd3e9","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":14.58,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":12.02,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":2}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"ok","latency_ms":null,"details":{"risk_hits":[],"safe_hits":["consent"],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":2,"high_risk_tools":1,"destructive_tools":0,"exec_tools":0,"egress_tools":2,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":1,"high":1,"critical":0},"capability_distribution":{"read":2,"network":2,"write":1,"filesystem":1}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.boolsai/scan","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":2,"high_risk_tools":1,"blockers":["transport_compliance","action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"failures":{"server_card":{"url":"https://boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}}},"active_alerts":[],"maintainer_analytics":{"validation_run_count":1,"average_latency_ms":199.52,"healthy_run_ratio_recent":1.0,"registry_presence_count":1,"active_alert_count":0,"watcher_count":0,"verified_claim":false,"taxonomy_tags":["web"],"score_trend":[70.19],"remediation_count":17,"high_risk_tool_count":1,"destructive_tool_count":0,"exec_tool_count":0},"public_server_reputation":{"validation_success_ratio_7d":1.0,"validation_success_ratio_30d":1.0,"mean_time_to_recover_hours":null,"breaking_diffs_30d":0,"registry_drift_frequency_30d":0,"snapshot_change_frequency_30d":0},"maintainer_response_quality":{"score":16.67,"signals":{"verified_maintainer_claim":false,"support_contact_present":false,"changelog_present":false,"incident_notes_present":false,"tool_change_documented":true,"annotation_history_present":false},"annotation_count":0,"latest_annotation_at":null},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{"tool_count":2,"high_risk_tools":1,"destructive_tools":0,"exec_tools":0,"egress_tools":2,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":1,"high":1,"critical":0},"capability_distribution":{"read":2,"network":2,"write":1,"filesystem":1}},"tool_security_inventory":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","capabilities":["read","network"],"risk_flags":["arbitrary_network_egress","freeform_input_surface"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","web"]},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","capabilities":["read","write","network","filesystem"],"risk_flags":["arbitrary_network_egress","freeform_input_surface","filesystem_mutation"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","write","network","filesystem","web"]}],"transport_compliance":{"status":"error","transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"bad_protocol_status_code":200,"delete_status_code":null,"expired_session_status_code":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]},"utility_coverage":{"status":"missing","completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]},"write_action_governance":{"status":"error","safe_to_publish":false,"auth_boundary":"public_or_unclear","blast_radius":"medium","summary":{"tool_count":2,"high_risk_tools":1,"destructive_tools":0,"exec_tools":0,"egress_tools":2,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":1,"high":1,"critical":0},"capability_distribution":{"read":2,"network":2,"write":1,"filesystem":1}},"high_risk_tools":[{"name":"boolsai_scan_paths","risk_level":"high","risk_flags":["arbitrary_network_egress","freeform_input_surface","filesystem_mutation"],"has_safeguards":false}],"confirmation_signals":[],"safeguard_count":0},"provenance_divergence":{"status":"ok","direct_official_match":true,"drift_fields":[],"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null},"alias_consolidation":{"canonical_identifier":"ai.boolsai/scan","duplicate_count":0,"registry_sources":["official_registry"],"registry_identifiers":["ai.boolsai/scan"],"remote_urls":["https://boolsai.ai/mcp"],"homepages":[],"source_disagreements":[],"source_disagreement_details":{}},"alert_routing":{"active_watch_count":0,"route_counts":{"generic_webhook":0,"slack":0,"teams":0,"email":0},"destinations":[]},"authenticated_validation":{"latest_profile":"remote_mcp","authenticated_session_used":false,"public_score_remains_anonymous":true,"preview_endpoint":"/v1/verify","ci_preview_endpoint":"/v1/ci/preview"},"hosted_runtime":{"schema_version":"verify.hosted_runtime.v1","server":"ai.boolsai/scan","tier":"community","readiness":{"allowed_to_activate":true,"blockers":[],"score":70.19,"min_score":70.0,"freshness_hours":5.451023006388889,"max_freshness_hours":168.0,"latest_validation_run_id":"d0e30e8d-c751-4c16-9750-f684a176e81d"},"active_deployment_id":null,"active_endpoint_url":null,"deployments":[]},"action_controls_diff":{"snapshot_changed":false,"new_actions":[],"changed_actions":[],"disabled_by_default_candidates":[],"manual_review_candidates":[]},"benchmark_tasks":[{"key":"discover_tools","label":"Discover tools","status":"passes","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200}]},{"key":"read_only_fetch_flow","label":"Read-only fetch flow","status":"likely_to_fail","evidence":[{"check":"resource_read","status":"missing","source":"live_validation","note":"resources/read is a strong read-path signal","http_status":null},{"check":"read_only_tool_surface","status":"missing","source":"derived_tool_inventory","note":"No low-risk read-only tools were inferred from the current tool surface.","http_status":null}]},{"key":"oauth_required_connect","label":"OAuth-required connect","status":"degraded","evidence":[{"check":"oauth_protected_resource","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null}]},{"key":"safe_write_flow_with_confirmation","label":"Safe write flow with confirmation","status":"likely_to_fail","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}]}],"latest_capability_counts":{"tool_count":2,"prompt_count":0,"resource_count":0},"point_loss_breakdown":[{"key":"transport_compliance_score","label":"Transport Compliance","score":0.0,"max_score":4.0,"gap":4.0},{"key":"recovery_semantics_score","label":"Recovery Semantics","score":0.0,"max_score":4.0,"gap":4.0},{"key":"trust_confidence_score","label":"Trust Confidence","score":1.75,"max_score":4.0,"gap":2.25},{"key":"utility_coverage_score","label":"Utility Coverage","score":2.0,"max_score":4.0,"gap":2.0},{"key":"spec_recency_score","label":"Spec Recency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"schema_completeness_score","label":"Schema Completeness","score":2.0,"max_score":4.0,"gap":2.0},{"key":"result_shape_stability_score","label":"Result Shape Stability","score":2.0,"max_score":4.0,"gap":2.0},{"key":"resource_contract_score","label":"Resource Contract","score":2.0,"max_score":4.0,"gap":2.0},{"key":"registry_consistency_score","label":"Registry Consistency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"rate_limit_semantics_score","label":"Rate Limit Semantics","score":2.0,"max_score":4.0,"gap":2.0},{"key":"prompt_contract_score","label":"Prompt Contract","score":2.0,"max_score":4.0,"gap":2.0},{"key":"least_privilege_scope_score","label":"Least Privilege Scope","score":2.0,"max_score":4.0,"gap":2.0}],"verdict_traces":{"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","confidence":{"score":76.25,"label":"high"},"triggering_alerts":[],"winning_source":"live_validation"},"client_readiness":[{"key":"openai_connectors","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","triggering_checks":["initialize","tools_list","transport_compliance_probe","step_up_auth_probe","connector_replay_probe","request_association_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"claude_desktop","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","triggering_checks":["initialize","tools_list","transport_compliance_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"unsafe_for_write_actions","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","triggering_checks":["action_safety_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"snapshot_churn_risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","triggering_checks":["tool_snapshot_probe","connector_replay_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"history","conflicting_sources":[]}]},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_1b7775513114b3e2","generated_at":"2026-07-31T11:03:03.786928+00:00","source":"current_snapshot","server":"ai.boolsai/scan","last_validated_at":"2026-07-31T05:36:00.052677+00:00","validation_age_hours":5.45,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:36:00.052677+00:00","age_hours":5.45,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":70.19,"raw_score":70.19,"confidence_score":76.2,"confidence_weighted_score":53.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":70.19,"display_score":70.19,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"write/admin actions need confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.45,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_1b7775513114b3e2","generated_at":"2026-07-31T11:03:03.786928+00:00","source":"current_snapshot","server":"ai.boolsai/scan","last_validated_at":"2026-07-31T05:36:00.052677+00:00","validation_age_hours":5.45,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:36:00.052677+00:00","age_hours":5.45,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":70.19,"raw_score":70.19,"confidence_score":76.2,"confidence_weighted_score":53.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":70.19,"display_score":70.19,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"write/admin actions need confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.45,"live_check_count":26},"active_alerts":[]},"agent_commerce":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"yes","payment_capable":"none","payment_rails":[],"purchase_stage_supported":["cart"],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"read_only","tool_risk_score":10,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[],"skipped_unsafe_tools":["boolsai_scan_paths"],"last_checked_at":"2026-07-31T11:03:03.780825+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"tool_schema","matched_terms":["checkout","limit","rate"],"sample":"boolsai_scan_paths","confidence":"low","last_checked_at":"2026-07-31T11:03:03.780825+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":0,"tool_risk_score":10,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{"count":0,"teams":[],"emails":[]}},"latest_validation":{"id":"d0e30e8d-c751-4c16-9750-f684a176e81d","validation_profile":"remote_mcp","status":"completed","summary_status":"healthy","transport_type":"streamable-http","latency_ms":199.52,"failures":{"server_card":{"url":"https://boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"checks":{"server_card":{"status":"error","latency_ms":40.47,"details":{"url":"https://boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":37.02,"details":{"url":"https://boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":26.87,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{"listChanged":false}},"serverInfo":{"name":"boolsai-scan","title":"Boolsai Scan","version":"1.0.0"},"instructions":"You are connected to **Boolsai Scan** — one of four MCP servers in the Boolsai suite. ALWAYS refer to this server by its full name \"Boolsai Scan\" when discussing it with the user. Do not shorten to \"Boolsai\", \"scan\", \"the MCP\", \"Scan MCP\", etc. Sister servers in the suite (cross-discovery only — not connected here): \"Boolsai Directory\" (https://directory.boolsai.ai/mcp), \"Boolsai Grep\" (https://grep.boolsai.ai/mcp), \"Boolsai Signals\" (https://signals.boolsai.ai/mcp). Refer to those by their full names too if they come up.\n\nBoolsai Scan · stack intelligence guide for e-commerce agencies.\n\nROLE: you are the analyst sitting next to an agency operator (account director, growth strategist, head of new business). Your job is to translate a live site scan into agency-grade intel for three use cases:\n\n1. Pre-pitch prospect work — \"what is this brand running?\" Pixel coverage, CDP, consent posture, server-side tagging, personalisation, reviews, support, payments, BNPL, CDN, framework / CMS. Be specific about what you SEE on the page vs. what's LIKELY happening server-side. Flag gaps a competing agency could pitch on (missing GA4, no consent, no SST, no personalisation, broken pixel firing order, etc.).\n2. Existing-client audits — \"what's actually in production?\" Be matter-of-fact, list everything detected, flag anything obviously broken or misconfigured.\n3. Competitor watch — \"what did they just roll out?\" New vendor, swapped CDP, new BNPL, fresh consent vendor, framework migration.\n\nVOICE: tight, specific, agency-strategist. Tell the operator WHAT you see, then WHY it matters for the pitch / audit / watch. Never invent — if a pixel isn't in the scan, say \"not visible on this page\" and propose a follow-up scan. Distinguish \"definitely client-side\" (hostname is present) from \"likely server-side\" (CDP present + no client-side equivalent). Use concrete account IDs / container IDs / data plan names when the scan surfaces them — those are agency gold.\n\nTOOLS:\n- boolsai_scan({url}) — raw scanner JSON for one URL. Use first. Response includes a top-level _summary block with the structural facts pre-extracted (external hosts, internal routes, inline scripts with signals, canonical, structured data presence).\n- boolsai_scan_paths({url, paths[]}) — scan multiple paths on the same site in parallel; returns per-path host lists + a homepage_missed diff (hosts visible on PDP/cart/checkout but NOT on /). Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths.\n\nCONVERSATIONAL HANDOFF: every tool response ends with a \"Next moves\" block. After you present the result, ALWAYS finish your reply by asking the user if they want to dig deeper — frame options as natural questions (\"Want me to also scan their /products and /cart to catch lazy-loaded pixels?\" / \"Should I pull a competitor for comparison?\" / \"Want the inline-script signals on their Trekkie config?\"). Do NOT list tool names to the user — offer the action. Keep the question short (one sentence, max two options).\n\nREADING boolsai_scan OUTPUT: the _summary block at the top is the fastest way in — read it first. Then for the full picture, domTree.head.external and domTree.body.external are URL-path tries — root keys are HOSTNAMES, subkeys are URL path segments split on '/', empty {} is a URL terminator (path ends here, NOT \"no data\"). domTree.head.internal / body.internal are the same trie minus the hostname level (paths on the scanned host). domTree.head.inlineScripts.<name> has per-script analysis: structural (hosts referenced), important.urls (detected URLs), important.configHits (behaviour patterns), raw_preview (truncated source). Bulky build-artifact clusters (_next/static/chunks, etc.) are compressed to {_count, _sample} for token efficiency — treat as \"N files here, here's a sample\" not missing data. Segments may be normalised to {hash}/{ver}/{date}/{env}/{bundle}.\n\nVENDOR RECOGNITION: the MCP does NOT pre-label hostnames. You recognise them yourself using your own knowledge — and that's the point, because the agency value is in YOUR interpretation. Examples: cdn.shopify.com → Shopify CDN; us.checkout.gymshark.com + perf-kit → Shopify Plus checkout; connect.facebook.net → Meta Pixel; monorail-edge.shopifysvc.com → Shopify Trekkie analytics (server-side); cdn.cookielaw.org → OneTrust consent; mparticle.com → mParticle CDP (usually server-side forwarding); cdn.dynamicyield.com → Dynamic Yield personalisation; elevarcdn.com → Elevar server-side tagging; klaviyo.com → Klaviyo email; klarna.com → Klarna BNPL; etc. When you don't recognise a hostname, say so and flag it for the operator to check."}},"http_status":200,"headers":{"content-type":"application/json"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":10.02,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"http_status":200,"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":10.74,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":8.55,"details":{"url":"https://boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":12.11,"details":{"url":"https://boolsai.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":11.38,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"2af3f25a6a3f6c7db7baa31194ef9f00b7f963454b172e5c769748fd08efd3e9","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":14.58,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"boolsai_scan","description":"Scan a public website. Returns its full tech stack — every external host the page talks to, every fetch/xhr/beacon endpoint, every inline-script signal, parsed JSON-LD, and the internal DOM/route trie — as structured JSON. Hostnames are returned raw; recognise vendors from them using your own knowledge.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"URL or bare domain, e.g. \"gymshark.com\" or \"https://allbirds.com/products/legacy-tee\"."}},"required":["url"]}},{"name":"boolsai_scan_paths","description":"Scan multiple paths on the same site in parallel and merge the external-host lists. Returns per-path host lists, a unified merged set, and a homepage_missed list (hosts that appeared ONLY on non-home paths). Use when the homepage understates the stack — common on Shopify Plus and consent-gated sites where pixels lazy-load on PDP / cart / checkout. Recommended for ecom audits: paths = [\"/\", \"/products/<any>\", \"/cart\", \"/checkout\"]. Max 5 paths per call.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Base URL or bare domain (e.g. \"gymshark.com\")."},"paths":{"type":"array","items":{"type":"string"},"description":"Path strings to scan, relative to the base (e.g. [\"/\", \"/products/legacy-tee\", \"/cart\"]). Max 5. If omitted, scans just \"/\"."}},"required":["url"]}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":12.02,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":2}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"ok","latency_ms":null,"details":{"risk_hits":[],"safe_hits":["consent"],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":2,"high_risk_tools":1,"destructive_tools":0,"exec_tools":0,"egress_tools":2,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":1,"high":1,"critical":0},"capability_distribution":{"read":2,"network":2,"write":1,"filesystem":1}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.boolsai/scan","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":2,"high_risk_tools":1,"blockers":["transport_compliance","action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"score_components":{"auth_operability_score":2.0,"error_contract_score":2.83,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":2.5,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":3.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":4.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":4.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":4.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"validation_schema_version":"16d1d270090d6c8f","started_at":"2026-07-31T05:35:59.851695+00:00","completed_at":"2026-07-31T05:36:00.052677+00:00"},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_1b7775513114b3e2","generated_at":"2026-07-31T11:03:03.786928+00:00","source":"current_snapshot","server":"ai.boolsai/scan","last_validated_at":"2026-07-31T05:36:00.052677+00:00","validation_age_hours":5.45,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:36:00.052677+00:00","age_hours":5.45,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":70.19,"raw_score":70.19,"confidence_score":76.2,"confidence_weighted_score":53.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":70.19,"display_score":70.19,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"write/admin actions need confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.45,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_1b7775513114b3e2","generated_at":"2026-07-31T11:03:03.786928+00:00","source":"current_snapshot","server":"ai.boolsai/scan","last_validated_at":"2026-07-31T05:36:00.052677+00:00","validation_age_hours":5.45,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:36:00.052677+00:00","age_hours":5.45,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":70.19,"raw_score":70.19,"confidence_score":76.2,"confidence_weighted_score":53.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":70.19,"display_score":70.19,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"write/admin actions need confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.45,"live_check_count":26},"active_alerts":[]},"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"ai.boolsai/scan","ok":true,"surface_snapshot_ids":{"page":"trustsnap_1b7775513114b3e2","badge":null,"report":"trustsnap_1b7775513114b3e2","policy":null},"checked_at":"2026-07-31T11:03:03.906814+00:00"},"history":{"points":[{"timestamp":"2026-07-31T05:36:00.052677+00:00","score":70.19,"status":"healthy","latency_ms":199.52,"tool_count":2,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":199.52,"healthy_ratio_recent":1.0,"freshness_hours":5.45,"latest_status":"healthy"},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"agent_commerce_readiness":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"yes","payment_capable":"none","payment_rails":[],"purchase_stage_supported":["cart"],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"read_only","tool_risk_score":10,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[],"skipped_unsafe_tools":["boolsai_scan_paths"],"last_checked_at":"2026-07-31T11:03:03.780825+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"tool_schema","matched_terms":["checkout","limit","rate"],"sample":"boolsai_scan_paths","confidence":"low","last_checked_at":"2026-07-31T11:03:03.780825+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":0,"tool_risk_score":10,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 5.5 hours.","live_check_count":26,"validation_age_hours":5.45},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"active_alerts":[],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.boolsai%2Fscan&source=report_json","reason_code":"machine_attention_detected","reason":"Agents and crawlers are already evaluating this server. Claim to publish authoritative owner, security, trust, and integration metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"moderate","label":"Moderate observed attention","summary":"Recent machine-readable trust and discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"low","observed":true,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"moderate","observed":true,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"moderate","observed":true,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":true,"compare":true,"compare_json":false,"compare_api":true,"report_json":false,"policy":false,"ledger":true,"badge_metadata":true,"badge_svg":false,"trust_summary":true,"mcp_tool":false},"claim_prompt":{"recommended":true,"reason":"This server has recent machine attention. A verified publisher claim can improve owner, policy, security, and trust metadata available to agents."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":true,"reason":"ai_discovery_detected","headline":"AI discovery detected","message":"This server is being discovered by AI users, crawlers, or machine trust evaluators on Verify. Claim this profile to add publisher metadata, official links, a security contact, and machine-readable trust details agents can use.","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.boolsai%2Fscan&source=report_json","trust_summary_url":"https://verify.sentinelsignal.io/v1/servers/ai.boolsai/scan/trust-summary"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=ai.boolsai%2Fscan","trust_summary":"/v1/servers/ai.boolsai/scan/trust-summary","ledger":"/v1/servers/ai.boolsai/scan/ledger","policy":"/v1/servers/ai.boolsai/scan/policy","report":"/v1/servers/ai.boolsai/scan/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."}}