{"schema_version":"verify.report.v1","generated_at":"2026-07-31T14:42:45.541599+00:00","snapshot_id":"trustsnap_84f3f2975755a03c","server":{"namespace":"ankitkapur1992-hlido","name":"hlido-mcp","title":"hlido-mcp","description":"Independent trust scores, claim audits, and side-by-side comparisons for AI agents, queryable over MCP. Every verdict is backed by hands-on testing and signed evidence from Hlido (hlido.eu). Hosted endpoint available at https://hlido.eu/mcp — no auth required.","homepage_url":"https://glama.ai/mcp/servers/f3lbnk9mwd","docs_url":null,"icon_url":null,"support_url":"https://github.com/ankitkapur1992-hlido/hlido-mcp","remote_url":"https://hlido.eu/mcp","server_card_url":null,"latest_version":null,"current_status":"healthy","current_score":68.47,"transport_type":"streamable-http","has_oauth":false,"has_dcr":false,"has_prompts":false,"tool_count":17,"current_validation_schema_version":"16d1d270090d6c8f","last_validated_at":"2026-07-31T10:26:23.896390+00:00","registry_source":"glama_registry","registry_identifier":"glama_registry:f3lbnk9mwd","canonical_identifier":"ankitkapur1992-hlido/hlido-mcp","current_score_components":{"auth_operability_score":2.0,"error_contract_score":3.4,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":4.0,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":1.5,"resource_contract_score":1.5,"discovery_metadata_score":2.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":2.4,"maintenance_signal_score":3.95,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":4.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":2.0,"official_registry_presence_score":3.0,"provenance_divergence_score":4.0,"safety_transparency_score":3.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":2.5,"execution_sandbox_safety_score":1.0,"data_exfiltration_resilience_score":3.7,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":2.0,"dependency_supply_chain_signal_score":0.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"capability_taxonomy":["development","database","search","productivity","read","exec","network","filesystem","web","healthcare","automation","export","write","secrets","files","monitoring","security","streamable_http"],"machine_summary":{"verdict":"safe_for_evaluation","best_for":["Claude Desktop","Smithery","Generic Streamable HTTP"],"avoid_if":["You need a low-risk tool surface."],"requires_auth":false,"supports_oauth":false,"risk_level":"critical"},"taxonomy_tags":["development","database","search","productivity"],"score_decomposition":[{"key":"access_protocol","label":"Access & Protocol","score":32.0,"max_score":44.0,"hint":"Connectivity, auth, and transport expectations for common clients.","components":[{"key":"auth_operability_score","score":2.0},{"key":"installability_score","score":4.0},{"key":"session_semantics_score","score":4.0},{"key":"transport_fidelity_score","score":4.0},{"key":"spec_recency_score","score":4.0},{"key":"session_resume_score","score":3.0},{"key":"step_up_auth_score","score":3.0},{"key":"transport_compliance_score","score":0.0},{"key":"request_association_score","score":3.0},{"key":"oauth_interop_score","score":3.0},{"key":"least_privilege_scope_score","score":2.0}]},{"key":"interface_quality","label":"Interface Quality","score":35.8,"max_score":56.0,"hint":"How well the tool/resource interface communicates and behaves under automation.","components":[{"key":"error_contract_score","score":3.4},{"key":"rate_limit_semantics_score","score":2.0},{"key":"schema_completeness_score","score":2.0},{"key":"prompt_contract_score","score":1.5},{"key":"resource_contract_score","score":1.5},{"key":"tool_surface_design_score","score":3.0},{"key":"tool_capability_clarity_score","score":4.0},{"key":"tool_namespace_clarity_score","score":4.0},{"key":"result_shape_stability_score","score":2.0},{"key":"utility_coverage_score","score":2.0},{"key":"advanced_capability_coverage_score","score":2.0},{"key":"tool_snapshot_churn_score","score":3.0},{"key":"connector_replay_score","score":3.0},{"key":"recovery_semantics_score","score":2.4}]},{"key":"security_posture","label":"Security Posture","score":24.2,"max_score":36.0,"hint":"How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.","components":[{"key":"security_hygiene_score","score":4.0},{"key":"destructive_operation_safety_score","score":3.0},{"key":"egress_ssrf_resilience_score","score":2.5},{"key":"execution_sandbox_safety_score","score":1.0},{"key":"data_exfiltration_resilience_score","score":3.7},{"key":"secret_handling_hygiene_score","score":2.0},{"key":"input_sanitization_safety_score","score":3.0},{"key":"interactive_flow_safety_score","score":3.0},{"key":"action_safety_score","score":2.0}]},{"key":"reliability_trust","label":"Reliability & Trust","score":18.75,"max_score":24.0,"hint":"Operational stability, consistency, and trustworthiness over time.","components":[{"key":"backward_compatibility_score","score":2.0},{"key":"slo_health_score","score":4.0},{"key":"task_success_score","score":4.0},{"key":"trust_confidence_score","score":1.75},{"key":"abuse_noise_ratio_score","score":4.0},{"key":"freshness_confidence_score","score":3.0}]},{"key":"discovery_governance","label":"Discovery & Governance","score":18.45,"max_score":28.0,"hint":"How well the server is documented, listed, and governed in public registries.","components":[{"key":"discovery_metadata_score","score":2.0},{"key":"registry_consistency_score","score":2.0},{"key":"maintenance_signal_score","score":3.95},{"key":"safety_transparency_score","score":3.0},{"key":"dependency_supply_chain_signal_score","score":0.5},{"key":"official_registry_presence_score","score":3.0},{"key":"provenance_divergence_score","score":4.0}]},{"key":"adoption_market","label":"Adoption & Market","score":5.0,"max_score":8.0,"hint":"Adoption clues and public evidence that the server is intended for external use.","components":[{"key":"adoption_signal_score","score":2.0},{"key":"connector_publishability_score","score":3.0}]}],"validation_diff":null,"tool_snapshot_diff":null,"connector_replay":{"status":"missing","backward_compatible":false,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]},"request_association":{"status":"missing","advertised_capabilities":[],"session_id_present":false,"protocol_version":null,"observed_methods":[],"violating_methods":[],"http_status":null,"issues":[]},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"history_summary":{"points":[{"timestamp":"2026-07-31T10:26:23.896390+00:00","score":68.47,"status":"healthy","latency_ms":448.42,"tool_count":17,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":448.42,"healthy_ratio_recent":1.0,"freshness_hours":4.27,"latest_status":"healthy"},"validation_timeline":[{"timestamp":"2026-07-31T10:26:23.896390+00:00","summary_status":"healthy","score":68.47,"protocol_version":"2024-11-05","auth_mode":"public","tool_count":17,"prompt_count":0,"resource_count":0,"high_risk_tools":3,"safe_to_publish":false,"change_flags":[]}],"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 4.3 hours.","live_check_count":26,"validation_age_hours":4.27},"incident_feed":[{"type":"validation_snapshot","timestamp":"2026-07-31T10:26:23.896390+00:00","title":"Latest validation: healthy","message":"Score 68.5 with status healthy."}],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_to_official_registry","severity":"low","title":"Publish or reconcile the server in the official MCP registry","why":"Official registry presence improves discovery confidence and cross-source consistency.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"client_remediation_modes":[{"key":"openai_connectors","label":"ChatGPT custom connector","status":"partial","why_not_ready":[{"label":"OpenAI connectors expect OAuth for remote server auth.","state":"blocked"},{"label":"Dynamic client registration materially improves connector setup.","state":"blocked"},{"label":"Transport compliance should be in good shape.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"claude_desktop","label":"Claude remote MCP","status":"ready","why_not_ready":[{"label":"Transport behavior should match Claude-compatible HTTP expectations.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"},{"label":"safe for company knowledge is not yet satisfied","state":"blocked"},{"label":"safe for messages api remote mcp is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"write_safe","label":"Write-safe publishing","status":"blocked","why_not_ready":[{"label":"Add a clearer auth boundary around risky write actions.","state":"blocked"},{"label":"Constrain or sandbox exec-capable tools before publishing broadly.","state":"blocked"}],"maintainer_context":null}],"client_profiles":[{"key":"openai_connectors","label":"OpenAI Connectors","score":66.7,"compatibility":"partial","missing_requirements":["OpenAI connectors expect OAuth for remote server auth.","Dynamic client registration materially improves connector setup.","Transport compliance should be in good shape."],"snippet":"Connector URL: https://hlido.eu/mcp\n# No OAuth metadata detected.\n# Server: ankitkapur1992-hlido/hlido-mcp"},{"key":"claude_desktop","label":"Claude Desktop","score":83.3,"compatibility":"compatible","missing_requirements":["Transport behavior should match Claude-compatible HTTP expectations."],"snippet":"{\n  \"mcpServers\": {\n    \"hlido-mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://hlido.eu/mcp\"]\n    }\n  }\n}"},{"key":"smithery","label":"Smithery","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"smithery mcp add \"https://hlido.eu/mcp\""},{"key":"generic_streamable_http","label":"Generic Streamable HTTP","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"curl -sS https://hlido.eu/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"}],"client_readiness_verdicts":[{"key":"openai_connectors","label":"Client compatibility: ChatGPT","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":"Frozen tool snapshots must survive refresh.","http_status":null},{"check":"request_association_probe","status":"missing","source":"live_validation","note":"Roots, sampling, and elicitation should stay request-scoped.","http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"claude_desktop","label":"Client compatibility: Claude","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"unsafe_for_write_actions","label":"Write-action publishing","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history"],"disagreements":[]}},{"key":"snapshot_churn_risk","label":"Snapshot churn risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","evidence":[{"check":"tool_snapshot_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"history","supporting_sources":["history","live_validation"],"disagreements":[]}}],"publishability_policy_profiles":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"claude_remote_mcp","label":"Claude remote MCP compatibility","status":"ready","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"compatibility_fixtures":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector fixture","status":"degraded","assumptions":[{"name":"remote_http_endpoint","status":"passes"},{"name":"oauth_discovery","status":"degraded"},{"name":"frozen_tool_snapshot_refresh","status":"passes"},{"name":"request_association","status":"passes"}],"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"anthropic_remote_mcp","label":"Anthropic remote MCP fixture","status":"degraded","assumptions":[{"name":"remote_transport","status":"passes"},{"name":"tool_discovery","status":"passes"},{"name":"auth_connect","status":"passes"},{"name":"safe_write_review","status":"degraded"}],"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"install_snippets":{"openai_connectors":"Connector URL: https://hlido.eu/mcp\n# No OAuth metadata detected.\n# Server: ankitkapur1992-hlido/hlido-mcp","claude_desktop":"{\n  \"mcpServers\": {\n    \"hlido-mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://hlido.eu/mcp\"]\n    }\n  }\n}","smithery":"smithery mcp add \"https://hlido.eu/mcp\"","generic_http":"curl -sS https://hlido.eu/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"},"aliases":[{"identifier":"ankitkapur1992-hlido/hlido-mcp","registry_source":"glama_registry","remote_url":"https://hlido.eu/mcp","canonical":true,"score":68.47},{"identifier":"awesome-ankitkapur1992-hlido/hlido-mcp","registry_source":"awesome_mcp_servers","remote_url":"https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp/badges/score.svg)](https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp","canonical":false,"score":46.71}],"raw_evidence":{"server_identifier":"ankitkapur1992-hlido/hlido-mcp","remote_url":"https://hlido.eu/mcp","server_card_payload":null,"checks":{"server_card":{"status":"ok","latency_ms":168.65,"details":{"url":"https://hlido.eu/.well-known/mcp/server-card.json","payload":{"serverInfo":{"name":"hlido-agent-reviews","version":"3.2.0"},"description":"The independent trust layer for AI agents — each agent hands-on tested for one evidence-backed Laddoo Score (0-100). Query trust checks, scorecards, incidents, and recommendations over MCP.","url":"https://hlido.eu/mcp","endpoint":"https://hlido.eu/mcp","transport":{"type":"streamable-http"},"transports":["streamable-http","http"],"capabilities":{"tools":true,"resources":false,"prompts":false},"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard."},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend."},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it."},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison."},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead."},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review."},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation."},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability."},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent."},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually)."},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted."},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes."},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis."},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls."},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims."},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent."},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/"}],"documentation":"https://hlido.eu/llms.txt","publisher":"hlido.eu","contact":"ankit@hlido.eu"},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"oauth_protected_resource":{"status":"error","latency_ms":43.71,"details":{"url":"https://hlido.eu/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://hlido.eu/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":76.11,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2024-11-05","capabilities":{"tools":{}},"serverInfo":{"name":"hlido-agent-reviews","version":"3.3.0-workers"}}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2024-11-05","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":3,"lag_days":385}},"tools_list":{"status":"ok","latency_ms":8.92,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"prompts_list":{"status":"error","latency_ms":7.43,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"no_prompt_name"}},"resources_list":{"status":"error","latency_ms":7.3,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"no_resource_uri"}},"probe_noise_resilience":{"status":"ok","latency_ms":84.11,"details":{"url":"https://hlido.eu/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":9.81,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"36f7b162f3d5586171852d1535b45533eb79f84e9fefba50052aaea73319a6a5","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2024-11-05"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":9.48,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2024-11-05","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"bad_protocol_headers":{"content-type":"application/json; charset=utf-8"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":8.72,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":17}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":17,"high_risk_tools":3,"destructive_tools":0,"exec_tools":4,"egress_tools":6,"secret_tools":2,"bulk_access_tools":2,"risk_distribution":{"low":3,"medium":11,"high":2,"critical":1},"capability_distribution":{"read":16,"exec":4,"network":12,"filesystem":4,"export":2,"write":4,"secrets":2}},"auth_present":false,"safeguard_count":2,"confirmation_signals":["submit_agent","subscribe"]}},"official_registry_probe":{"status":"warning","latency_ms":null,"details":{"registry_source":"glama_registry","direct_match":false,"official_peer_count":10,"official_identifiers":["ai.agentutility/mcp-bestiary","ai.ai-akari/one-minute-akari","ai.artidrop/artidrop","ai.agentutility/mcp-browser-workflow","ai.adramp/google-ads","ai.adweave/meta-ads-mcp","ai.agentutility/mcp-edge-finance","ai.aetherwealth/mcp","ai.afmr/discovery","ai.agentberg/agentberg"]}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":false,"registry_title":null,"server_card_title":"hlido-agent-reviews","registry_version":null,"server_card_version":"3.2.0","registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":2}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":17,"high_risk_tools":3,"blockers":["transport_compliance","action_safety"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":true,"tool_surface":true,"auth_flow":true}}}},"failures":{"oauth_protected_resource":{"url":"https://hlido.eu/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://hlido.eu/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"prompts_list":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}},"resources_list":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2024-11-05","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"bad_protocol_headers":{"content-type":"application/json; charset=utf-8"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}}},"active_alerts":[],"maintainer_analytics":{"validation_run_count":1,"average_latency_ms":448.42,"healthy_run_ratio_recent":1.0,"registry_presence_count":2,"active_alert_count":0,"watcher_count":0,"verified_claim":false,"taxonomy_tags":["development","database","search","productivity"],"score_trend":[68.47],"remediation_count":18,"high_risk_tool_count":3,"destructive_tool_count":0,"exec_tool_count":4},"public_server_reputation":{"validation_success_ratio_7d":1.0,"validation_success_ratio_30d":1.0,"mean_time_to_recover_hours":null,"breaking_diffs_30d":0,"registry_drift_frequency_30d":0,"snapshot_change_frequency_30d":0},"maintainer_response_quality":{"score":33.33,"signals":{"verified_maintainer_claim":false,"support_contact_present":true,"changelog_present":false,"incident_notes_present":false,"tool_change_documented":true,"annotation_history_present":false},"annotation_count":0,"latest_annotation_at":null},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{"tool_count":17,"high_risk_tools":3,"destructive_tools":0,"exec_tools":4,"egress_tools":6,"secret_tools":2,"bulk_access_tools":2,"risk_distribution":{"low":3,"medium":11,"high":2,"critical":1},"capability_distribution":{"read":16,"exec":4,"network":12,"filesystem":4,"export":2,"write":4,"secrets":2}},"tool_security_inventory":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","capabilities":["read","exec","network","filesystem"],"risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","network","filesystem","development","database","web","healthcare","automation"]},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","capabilities":["read","network","filesystem","export"],"risk_flags":["bulk_data_access"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","filesystem","export","search","productivity","automation"]},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","capabilities":["network"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["network","development","healthcare","automation"]},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","productivity","healthcare","automation"]},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","capabilities":["read","write","network"],"risk_flags":["arbitrary_network_egress","freeform_input_surface"],"risk_level":"medium","has_safeguards":true,"capability_taxonomy":["read","write","network","automation"]},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","capabilities":["read","write","network"],"risk_flags":["arbitrary_network_egress","freeform_input_surface"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","write","network","search","automation"]},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","development","healthcare","automation"]},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","capabilities":["read","export"],"risk_flags":["bulk_data_access"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","export","development","automation"]},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","capabilities":["read","write","network"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","write","network","healthcare","automation"]},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","capabilities":["read","network","secrets"],"risk_flags":["arbitrary_network_egress","secret_material_access","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","network","secrets","healthcare","automation"]},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","capabilities":["read","network","filesystem"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","filesystem","search","productivity","files","automation"]},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","capabilities":["read","network"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","web","automation","monitoring"]},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","capabilities":["read","exec","network"],"risk_flags":["command_execution"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","exec","network","security","healthcare","automation"]},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","files","automation"]},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","capabilities":["read","exec"],"risk_flags":["command_execution"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","exec","productivity","healthcare","automation"]},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","capabilities":["read","network"],"risk_flags":["arbitrary_network_egress","freeform_input_surface"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","development","productivity","automation"]},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","capabilities":["read","write","exec","network","filesystem","secrets"],"risk_flags":["command_execution","arbitrary_network_egress","secret_material_access","filesystem_mutation"],"risk_level":"critical","has_safeguards":true,"capability_taxonomy":["read","write","exec","network","filesystem","secrets","development","web","security"]}],"transport_compliance":{"status":"error","transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"bad_protocol_status_code":200,"delete_status_code":null,"expired_session_status_code":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]},"utility_coverage":{"status":"missing","completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]},"write_action_governance":{"status":"error","safe_to_publish":false,"auth_boundary":"public_or_unclear","blast_radius":"high","summary":{"tool_count":17,"high_risk_tools":3,"destructive_tools":0,"exec_tools":4,"egress_tools":6,"secret_tools":2,"bulk_access_tools":2,"risk_distribution":{"low":3,"medium":11,"high":2,"critical":1},"capability_distribution":{"read":16,"exec":4,"network":12,"filesystem":4,"export":2,"write":4,"secrets":2}},"high_risk_tools":[{"name":"trust_check","risk_level":"high","risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"has_safeguards":false},{"name":"request_quick_audit","risk_level":"high","risk_flags":["arbitrary_network_egress","secret_material_access","freeform_input_surface"],"has_safeguards":false},{"name":"scan_mcp","risk_level":"critical","risk_flags":["command_execution","arbitrary_network_egress","secret_material_access","filesystem_mutation"],"has_safeguards":true}],"confirmation_signals":["submit_agent","subscribe"],"safeguard_count":2},"provenance_divergence":{"status":"ok","direct_official_match":false,"drift_fields":[],"registry_title":null,"server_card_title":"hlido-agent-reviews","registry_version":null,"server_card_version":"3.2.0","registry_homepage":null,"server_card_homepage":null},"alias_consolidation":{"canonical_identifier":"ankitkapur1992-hlido/hlido-mcp","duplicate_count":1,"registry_sources":["awesome_mcp_servers","glama_registry"],"registry_identifiers":["awesome_mcp_servers:ankitkapur1992-hlido/hlido-mcp","glama_registry:f3lbnk9mwd"],"remote_urls":["https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp/badges/score.svg)](https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp","https://hlido.eu/mcp"],"homepages":["https://github.com/ankitkapur1992-hlido/hlido-mcp","https://glama.ai/mcp/servers/f3lbnk9mwd"],"source_disagreements":["registry_source","remote_url","homepage","registry_identifier"],"source_disagreement_details":{"registry_source":{"label":"Registry source","explanation":"Multiple registries or registry sync paths claim this same canonical server.","values":["awesome_mcp_servers","glama_registry"]},"remote_url":{"label":"Remote URL","explanation":"Aliases currently point at different MCP endpoints, which can indicate mirrors, stale registry data, or a real endpoint split.","values":["https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp/badges/score.svg)](https://glama.ai/mcp/servers/ankitkapur1992-hlido/hlido-mcp","https://hlido.eu/mcp"]},"homepage":{"label":"Homepage","explanation":"Registry entries disagree on the primary homepage for this server.","values":["https://github.com/ankitkapur1992-hlido/hlido-mcp","https://glama.ai/mcp/servers/f3lbnk9mwd"]},"registry_identifier":{"label":"Registry identifier","explanation":"Different registry-specific identifiers resolve to the same canonical server record here.","values":["awesome_mcp_servers:ankitkapur1992-hlido/hlido-mcp","glama_registry:f3lbnk9mwd"]}}},"alert_routing":{"active_watch_count":0,"route_counts":{"generic_webhook":0,"slack":0,"teams":0,"email":0},"destinations":[]},"authenticated_validation":{"latest_profile":"remote_mcp","authenticated_session_used":false,"public_score_remains_anonymous":true,"preview_endpoint":"/v1/verify","ci_preview_endpoint":"/v1/ci/preview"},"hosted_runtime":{"schema_version":"verify.hosted_runtime.v1","server":"ankitkapur1992-hlido/hlido-mcp","tier":"community","readiness":{"allowed_to_activate":false,"blockers":["score_below_hosting_threshold"],"score":68.47,"min_score":70.0,"freshness_hours":4.2722100925,"max_freshness_hours":168.0,"latest_validation_run_id":"0114e6f7-2562-4873-a748-79eeb6c25d8c"},"active_deployment_id":null,"active_endpoint_url":null,"deployments":[]},"action_controls_diff":{"snapshot_changed":false,"new_actions":[],"changed_actions":[],"disabled_by_default_candidates":[],"manual_review_candidates":[]},"benchmark_tasks":[{"key":"discover_tools","label":"Discover tools","status":"passes","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200}]},{"key":"read_only_fetch_flow","label":"Read-only fetch flow","status":"degraded","evidence":[{"check":"resource_read","status":"missing","source":"live_validation","note":"resources/read is a strong read-path signal","http_status":null},{"check":"read_only_tool_surface","status":"ok","source":"derived_tool_inventory","note":"Low-risk read tools were inferred from the current tool surface.","http_status":null}]},{"key":"oauth_required_connect","label":"OAuth-required connect","status":"degraded","evidence":[{"check":"oauth_protected_resource","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null}]},{"key":"safe_write_flow_with_confirmation","label":"Safe write flow with confirmation","status":"likely_to_fail","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}]}],"latest_capability_counts":{"tool_count":17,"prompt_count":0,"resource_count":0},"point_loss_breakdown":[{"key":"transport_compliance_score","label":"Transport Compliance","score":0.0,"max_score":4.0,"gap":4.0},{"key":"dependency_supply_chain_signal_score","label":"Dependency Supply Chain Signal","score":0.5,"max_score":4.0,"gap":3.5},{"key":"execution_sandbox_safety_score","label":"Execution Sandbox Safety","score":1.0,"max_score":4.0,"gap":3.0},{"key":"resource_contract_score","label":"Resource Contract","score":1.5,"max_score":4.0,"gap":2.5},{"key":"prompt_contract_score","label":"Prompt Contract","score":1.5,"max_score":4.0,"gap":2.5},{"key":"trust_confidence_score","label":"Trust Confidence","score":1.75,"max_score":4.0,"gap":2.25},{"key":"utility_coverage_score","label":"Utility Coverage","score":2.0,"max_score":4.0,"gap":2.0},{"key":"secret_handling_hygiene_score","label":"Secret Handling Hygiene","score":2.0,"max_score":4.0,"gap":2.0},{"key":"schema_completeness_score","label":"Schema Completeness","score":2.0,"max_score":4.0,"gap":2.0},{"key":"result_shape_stability_score","label":"Result Shape Stability","score":2.0,"max_score":4.0,"gap":2.0},{"key":"registry_consistency_score","label":"Registry Consistency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"rate_limit_semantics_score","label":"Rate Limit Semantics","score":2.0,"max_score":4.0,"gap":2.0}],"verdict_traces":{"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","confidence":{"score":76.25,"label":"high"},"triggering_alerts":[],"winning_source":"live_validation"},"client_readiness":[{"key":"openai_connectors","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","triggering_checks":["initialize","tools_list","transport_compliance_probe","step_up_auth_probe","connector_replay_probe","request_association_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"claude_desktop","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","triggering_checks":["initialize","tools_list","transport_compliance_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"unsafe_for_write_actions","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","triggering_checks":["action_safety_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"snapshot_churn_risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","triggering_checks":["tool_snapshot_probe","connector_replay_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"history","conflicting_sources":[]}]},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_84f3f2975755a03c","generated_at":"2026-07-31T14:42:44.365554+00:00","source":"current_snapshot","server":"ankitkapur1992-hlido/hlido-mcp","last_validated_at":"2026-07-31T10:26:23.896390+00:00","validation_age_hours":4.27,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T10:26:23.896390+00:00","age_hours":4.27,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":68.47,"raw_score":68.47,"confidence_score":76.2,"confidence_weighted_score":52.2,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":68.47,"display_score":68.47,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.27,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_84f3f2975755a03c","generated_at":"2026-07-31T14:42:44.365554+00:00","source":"current_snapshot","server":"ankitkapur1992-hlido/hlido-mcp","last_validated_at":"2026-07-31T10:26:23.896390+00:00","validation_age_hours":4.27,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T10:26:23.896390+00:00","age_hours":4.27,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":68.47,"raw_score":68.47,"confidence_score":76.2,"confidence_weighted_score":52.2,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":68.47,"display_score":68.47,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.27,"live_check_count":26},"active_alerts":[]},"agent_commerce":{"status":"beta","commerce_signal":"moderate","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"yes","numeric_price_context":"yes","commercial_quote_context":"yes","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"inferred","payment_rails":["ACP","AP2"],"purchase_stage_supported":[],"human_confirmation_required":"yes","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"write_capable","tool_risk_score":35,"pricing_transparency":"clear","schema_change_detected":"unknown","delegation_level":"research_only","evidence_level":"inferred","confidence":"medium","highest_risk_tools":[{"name":"submit_agent","risk_level":"write_capable"},{"name":"scan_mcp","risk_level":"write_capable"}],"skipped_unsafe_tools":["compare_agents","subscribe","scan_mcp"],"last_checked_at":"2026-07-31T14:42:44.307890+00:00","evidence":[{"field":"commerce_signal","value":"moderate","evidence_level":"observed","source":"tool_schema","matched_terms":["subscribe","limit","quote","interest","rate"],"sample":"find_trusted","confidence":"medium","last_checked_at":"2026-07-31T14:42:44.307890+00:00"},{"field":"payment_rails","value":"ACP, AP2","evidence_level":"inferred","source":"tool_schema","matched_terms":["acp","ap2"],"sample":"ACP, AP2","confidence":"medium","last_checked_at":"2026-07-31T14:42:44.307890+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":10,"tool_risk_score":35,"payment_readiness_score":60,"agent_delegation_safety_score":30,"overall_agent_commerce_score":36},"warnings":["Verify observed commerce-adjacent billing, usage, or pricing context, but did not observe a tool that can execute payment."],"recommended_fixes":["Clarify whether observed billing, usage, or pricing context can execute payment or is informational only."]},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{"count":0,"teams":[],"emails":[]}},"latest_validation":{"id":"0114e6f7-2562-4873-a748-79eeb6c25d8c","validation_profile":"remote_mcp","status":"completed","summary_status":"healthy","transport_type":"streamable-http","latency_ms":448.42,"failures":{"oauth_protected_resource":{"url":"https://hlido.eu/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://hlido.eu/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"prompts_list":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}},"resources_list":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2024-11-05","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"bad_protocol_headers":{"content-type":"application/json; charset=utf-8"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"checks":{"server_card":{"status":"ok","latency_ms":168.65,"details":{"url":"https://hlido.eu/.well-known/mcp/server-card.json","payload":{"serverInfo":{"name":"hlido-agent-reviews","version":"3.2.0"},"description":"The independent trust layer for AI agents — each agent hands-on tested for one evidence-backed Laddoo Score (0-100). Query trust checks, scorecards, incidents, and recommendations over MCP.","url":"https://hlido.eu/mcp","endpoint":"https://hlido.eu/mcp","transport":{"type":"streamable-http"},"transports":["streamable-http","http"],"capabilities":{"tools":true,"resources":false,"prompts":false},"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard."},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend."},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it."},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison."},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead."},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review."},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation."},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability."},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent."},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually)."},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted."},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes."},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis."},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls."},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims."},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent."},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/"}],"documentation":"https://hlido.eu/llms.txt","publisher":"hlido.eu","contact":"ankit@hlido.eu"},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"oauth_protected_resource":{"status":"error","latency_ms":43.71,"details":{"url":"https://hlido.eu/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://hlido.eu/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":76.11,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2024-11-05","capabilities":{"tools":{}},"serverInfo":{"name":"hlido-agent-reviews","version":"3.3.0-workers"}}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2024-11-05","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":3,"lag_days":385}},"tools_list":{"status":"ok","latency_ms":8.92,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"prompts_list":{"status":"error","latency_ms":7.43,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"no_prompt_name"}},"resources_list":{"status":"error","latency_ms":7.3,"details":{"url":"https://hlido.eu/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json; charset=utf-8"}}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"no_resource_uri"}},"probe_noise_resilience":{"status":"ok","latency_ms":84.11,"details":{"url":"https://hlido.eu/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":9.81,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"36f7b162f3d5586171852d1535b45533eb79f84e9fefba50052aaea73319a6a5","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2024-11-05"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":9.48,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2024-11-05","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"trust_check","description":"The core Hlido trust query: is a specific AI agent trustworthy? Given one agent (by Hlido slug or product/homepage URL) it returns the independent Laddoo trust score (0-100), tier (VITAL/STEADY/FADING/FLATLINE), a one-line verdict, a claim-verification summary, and any known incidents. Call this FIRST — before delegating to, installing, or relying on another agent — to get a fast trust read. Returns no_review_found if the agent isn't in Hlido's corpus (then call request_quick_audit). For the full claim-by-claim evidence, follow up with get_scorecard.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'aider', 'cursor') or its product/homepage URL (e.g. 'https://cursor.com'). A URL is matched to the closest reviewed agent."},"use_case":{"type":"string","description":"Optional. The task you're considering this agent for (e.g. 'multi-file TypeScript refactor'); tailors the verdict to that use case when provided."}},"required":["agent_or_url"]}},{"name":"find_trusted","description":"Discover Hlido-reviewed agents that match a free-text need, ranked by trust. Returns reviewed agents at or above a minimum tier, each with its Laddoo score, tier, and review URL. Use this for keyword/need-based discovery; for semantic task-matching prefer find_similar_agents, and for structured constraint filters (category/score/tier) prefer recommend.","inputSchema":{"type":"object","properties":{"need":{"type":"string","description":"Free-text description of the capability you need (e.g. 'CLI coding agent that edits multiple files at once')."},"min_tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"default":"STEADY","description":"Minimum trust tier to include (VITAL is strictest, FLATLINE allows all). Defaults to STEADY."},"limit":{"type":"integer","default":10,"description":"Maximum number of agents to return (default 10)."}},"required":["need"]}},{"name":"verify_claim","description":"Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.","inputSchema":{"type":"object","properties":{"agent":{"type":"string","description":"The agent's Hlido slug or product URL (e.g. 'cursor')."},"claim":{"type":"string","description":"The specific claim to verify, in plain language (e.g. 'works offline' or 'SOC 2 compliant')."}},"required":["agent","claim"]}},{"name":"compare_agents","description":"Head-to-head trust comparison of 2-5 Hlido-reviewed agents. Returns each agent's Laddoo score, tier, dimension scores, and key claim verdicts side by side so you can pick the most trustworthy option for a task. Use this once you've shortlisted candidates (via find_trusted, find_similar_agents, or recommend) and need a direct comparison.","inputSchema":{"type":"object","properties":{"slugs":{"type":"array","items":{"type":"string","description":"A Hlido agent slug (e.g. 'aider')."},"minItems":2,"maxItems":5,"description":"List of 2 to 5 Hlido agent slugs to compare side by side (e.g. ['aider','cursor','opencode'])."}},"required":["slugs"]}},{"name":"submit_agent","description":"Nominate a new AI agent for Hlido to review. Use this when an agent isn't in Hlido's corpus yet (trust_check returned no_review_found) and you want it added. Returns a confirmation with a tracking reference; the review is queued and produces a public scorecard. If you need a verdict right now rather than a queued review, use request_quick_audit (faster, rate-limited) instead.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com')."},"name":{"type":"string","description":"Human-readable agent name (e.g. 'Example Coder')."},"note":{"type":"string","description":"Optional context: what the agent does, or why it's worth reviewing."},"email":{"type":"string","description":"Optional contact email for the submitter — if you want a reply or a heads-up when the review publishes. Providing it always flags the submission to the Hlido team."}},"required":["url","name"]}},{"name":"verify_transparency","description":"Check any AI agent's EU AI Act Article-50 transparency posture — including agents Hlido has NOT reviewed yet. Returns two clearly separated layers: (1) Hlido's independent register verdict when the agent is in our reviewed corpus, and (2) a live public-surface probe of the Article-50 signals (AI-interaction disclosure, machine-readable marking/provenance, deepfake/synthetic labelling, detection tool). Use before adopting or delegating to a tool ahead of the 2026-08-02 transparency obligations. The live probe is a first-pass surface read, NOT a compliance determination and NOT legal advice; an undetected signal means 'not discoverable on the public surface', not 'non-compliant'. Unreviewed agents are automatically queued for a full independent review.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"The agent's product or homepage URL (e.g. 'https://example.com'), or its Hlido slug."}},"required":["url"]}},{"name":"get_scorecard","description":"Fetch the full sanitized claim-vs-evidence scorecard for one Hlido-reviewed agent. Returns every claim, verdict, evidence quote, source surface, and (for CLI/API tests) the captured command + exit_code + duration. Schema v1.0. Use this for agent-to-agent pre-flight evaluation.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug (e.g. 'aider', 'gumloop')"}},"required":["slug"]}},{"name":"get_incidents","description":"Fetch published incidents from Hlido's NTSB-style failure registry — real observed agent failures (availability outages, regressions, hallucinations, safety issues) plus Hlido self-reported process incidents, each with severity, evidence, and vendor-response status. Filter by agent slug, severity, or category. Use this before delegating to an agent to check for known recent failures; an empty list means no published incidents, not a guarantee of reliability.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Optional: only incidents for this agent slug"},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Optional minimum-interest filter (exact match)"},"category":{"type":"string","enum":["hallucination","regression","safety","availability","cost","other"],"description":"Optional category filter"},"limit":{"type":"integer","description":"Max results (default 20, max 100)","default":20}}}},{"name":"report_review_issue","description":"Report an issue with a Hlido review (stale info, wrong verdict, missing claim, broken link). Use when calling get_scorecard or trust_check returns data you can prove is incorrect. Hlido's R1 maintenance routine processes reports daily and fires re-tests via dispute-retest sub-agent.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The slug whose review has the issue"},"issue_type":{"type":"string","enum":["stale","wrong_verdict","missing_claim","broken_link","other"],"description":"Category of the report"},"detail":{"type":"string","description":"What's wrong, with a concrete reference (URL, claim id, etc) if possible"},"reporter":{"type":"string","description":"Optional self-identifier — agent name or email — purely informational"}},"required":["slug","issue_type","detail"]}},{"name":"request_quick_audit","description":"Request that Hlido audit a NEW AI agent that has no review yet. Use this when trust_check or get_scorecard returns no_review_found and you need a verdict before delegating to the unknown agent. Returns a future scorecard URL + ETA. Free-tier rate-limited (5/day per anonymous, 50/day per identified). The audit produces signed evidence + claim verification within ~24h (sooner if founder triggers manually).","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Homepage or product URL of the agent to audit"},"name":{"type":"string","description":"Optional human-readable name (we'll derive from URL if missing)"},"why":{"type":"string","description":"Optional one-liner: why are you considering this agent? helps us prioritize"},"requester":{"type":"string","description":"Optional self-identifier — agent name, email, or session id — for rate-limiting + follow-up"}},"required":["url"]}},{"name":"find_similar_agents","description":"Semantic search over Hlido's review corpus. Given a task description (e.g. 'I need an agent that can refactor TypeScript and edit multiple files at once'), returns the top-N reviewed agents ranked by embedding similarity, each with their Laddoo score, evidence_tier, and review URL. Use this when you have a task in mind and want Hlido's recommendation — much better than substring matching via find_trusted.","inputSchema":{"type":"object","properties":{"description":{"type":"string","description":"Free-text description of the task or capability you need"},"top_k":{"type":"integer","description":"Number of matches to return (default 5, max 20)","default":5},"min_score":{"type":"integer","description":"Minimum Laddoo score filter (default 0)","default":0}},"required":["description"]}},{"name":"subscribe","description":"Preview — Wave 3 will add persistent webhook + RSS subscriptions. For now this returns the agent's current state plus advisory polling instructions (RSS at /changelog/feed.xml or polling /data/attestations/{slug}.json). Use this to register interest in being notified when a slug's verdict changes.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to subscribe to (e.g. 'cursor', 'aider')"},"channel":{"type":"string","enum":["rss","json","webhook"],"description":"Preferred notification channel. webhook is advisory only until Wave 3 ships."}},"required":["slug"]}},{"name":"explain","description":"Structured natural-language explanation of why a Hlido-reviewed agent has its current score. Pulls claim-by-claim evidence from the published scorecard. Pass an optional dimension (one of: reliability, transparency, integration, security, evidence) to filter; omit for the full picture. Returns each claim with verdict (PASS|FAIL|PARTIAL|UNKNOWN), a quoted evidence snippet, plus a top-line synthesis.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The agent's Hlido slug"},"dimension":{"type":"string","description":"Optional dimension filter. Run without and check supported_dimensions in response if unsure."}},"required":["slug"]}},{"name":"recommend","description":"Constraint-driven recommendation across Hlido's reviewed agents. Pass any combination of: category, min_score, tier, use_case, max_results. Returns ranked candidates each with a why_match line. Use this when you have buyer constraints (budget, category, capability) and want Hlido's filtered shortlist instead of one-by-one trust_check calls.","inputSchema":{"type":"object","properties":{"constraints":{"type":"object","properties":{"category":{"type":"string","description":"Filter by category (e.g. 'Coding', 'Voice', 'Productivity')"},"min_score":{"type":"integer","description":"Minimum Laddoo score (0-100)","default":0},"tier":{"type":"string","enum":["VITAL","STEADY","FADING","FLATLINE"],"description":"Minimum tier filter (VITAL strictest, FLATLINE allows all)"},"use_case":{"type":"string","description":"Free-text capability description for ranking (e.g. 'multi-file refactor in TypeScript')"},"max_results":{"type":"integer","description":"Cap on results (default 5, max 25)","default":5}},"additionalProperties":false}},"required":["constraints"]}},{"name":"get_behavioral_trace","description":"Fetch the behavioral evaluation trace for a Hlido-reviewed agent — per-task pass/fail, adapter used, behavioral tier, and signed trace link. Returns status 'not_yet_bench_tested' if the slug hasn't been evaluated yet, or 'not_testable' if the agent's interface doesn't support automated bench runs. Use this when you need evidence that an agent's coding/task behaviour has been independently verified beyond marketing claims.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The Hlido slug to fetch behavioral trace for (e.g. 'aider', 'opencode')"},"spec_version":{"type":"string","description":"Behavioral spec version (default 'v0.1'). Omit to get the latest available.","default":"v0.1"}},"required":["slug"]}},{"name":"commerce_check","description":"Check whether a Hlido-reviewed agent is ready to be delegated to / transacted with in the agentic-commerce world (MCP/ACP/AP2). Returns its independent Agentic-Commerce Readiness score (0-100), band (COMMERCE-READY/INTEGRABLE/SURFACE-ONLY/CLOSED), the programmatic surfaces it exposes, and the evidence basis. Call this before an orchestrator delegates a paid/identity-bearing task to another agent.","inputSchema":{"type":"object","properties":{"agent_or_url":{"type":"string","description":"The agent to check: either its Hlido slug (e.g. 'voltagent', 'aider') or its product/homepage URL. A URL is matched to the closest reviewed agent."}},"required":["agent_or_url"]}},{"name":"scan_mcp","description":"On-demand independent SAFETY scan of an MCP server — call this BEFORE installing or connecting to one. Give it an HTTP(S) MCP endpoint URL (scanned live in seconds), or an npm/PyPI package name or GitHub repo (queued for an isolated sandbox scan — local stdio servers execute code, so Hlido never runs them inline). Returns the safety tier (SAFE/CAUTION/RISKY/DANGEROUS), tool-poisoning detection (the malice signal), dangerous-capability red-flags (shell/code-eval/fs-write/egress/secrets) with per-tool evidence, and auth posture. Tier = blast radius if hijacked, not maintainer trustworthiness. A server Hlido hasn't scanned returns not_scanned — never assumed safe. Register of already-scanned servers: https://hlido.eu/mcp/","inputSchema":{"type":"object","properties":{"server":{"type":"string","description":"The MCP server to scan: an HTTP(S) MCP endpoint URL (e.g. 'https://mcp.example.com/mcp' — scanned live), OR an npm package (e.g. '@modelcontextprotocol/server-filesystem'), PyPI package, or GitHub repo URL (queued for sandbox scan)."},"requester":{"type":"string","description":"Optional self-identifier — agent name or email — for follow-up when a queued scan completes."}},"required":["server"]}}]}},"bad_protocol_headers":{"content-type":"application/json; charset=utf-8"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":8.72,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":17}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":17,"high_risk_tools":3,"destructive_tools":0,"exec_tools":4,"egress_tools":6,"secret_tools":2,"bulk_access_tools":2,"risk_distribution":{"low":3,"medium":11,"high":2,"critical":1},"capability_distribution":{"read":16,"exec":4,"network":12,"filesystem":4,"export":2,"write":4,"secrets":2}},"auth_present":false,"safeguard_count":2,"confirmation_signals":["submit_agent","subscribe"]}},"official_registry_probe":{"status":"warning","latency_ms":null,"details":{"registry_source":"glama_registry","direct_match":false,"official_peer_count":10,"official_identifiers":["ai.agentutility/mcp-bestiary","ai.ai-akari/one-minute-akari","ai.artidrop/artidrop","ai.agentutility/mcp-browser-workflow","ai.adramp/google-ads","ai.adweave/meta-ads-mcp","ai.agentutility/mcp-edge-finance","ai.aetherwealth/mcp","ai.afmr/discovery","ai.agentberg/agentberg"]}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":false,"registry_title":null,"server_card_title":"hlido-agent-reviews","registry_version":null,"server_card_version":"3.2.0","registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":2}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":17,"high_risk_tools":3,"blockers":["transport_compliance","action_safety"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":true,"tool_surface":true,"auth_flow":true}}}},"score_components":{"auth_operability_score":2.0,"error_contract_score":3.4,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":4.0,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":1.5,"resource_contract_score":1.5,"discovery_metadata_score":2.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":2.4,"maintenance_signal_score":3.95,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":4.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":2.0,"official_registry_presence_score":3.0,"provenance_divergence_score":4.0,"safety_transparency_score":3.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":2.5,"execution_sandbox_safety_score":1.0,"data_exfiltration_resilience_score":3.7,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":2.0,"dependency_supply_chain_signal_score":0.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"validation_schema_version":"16d1d270090d6c8f","started_at":"2026-07-31T10:26:23.446977+00:00","completed_at":"2026-07-31T10:26:23.896390+00:00"},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_84f3f2975755a03c","generated_at":"2026-07-31T14:42:44.365554+00:00","source":"current_snapshot","server":"ankitkapur1992-hlido/hlido-mcp","last_validated_at":"2026-07-31T10:26:23.896390+00:00","validation_age_hours":4.27,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T10:26:23.896390+00:00","age_hours":4.27,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":68.47,"raw_score":68.47,"confidence_score":76.2,"confidence_weighted_score":52.2,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":68.47,"display_score":68.47,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.27,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_84f3f2975755a03c","generated_at":"2026-07-31T14:42:44.365554+00:00","source":"current_snapshot","server":"ankitkapur1992-hlido/hlido-mcp","last_validated_at":"2026-07-31T10:26:23.896390+00:00","validation_age_hours":4.27,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T10:26:23.896390+00:00","age_hours":4.27,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":68.47,"raw_score":68.47,"confidence_score":76.2,"confidence_weighted_score":52.2,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":68.47,"display_score":68.47,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.27,"live_check_count":26},"active_alerts":[]},"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"ankitkapur1992-hlido/hlido-mcp","ok":true,"surface_snapshot_ids":{"page":"trustsnap_84f3f2975755a03c","badge":null,"report":"trustsnap_84f3f2975755a03c","policy":null},"checked_at":"2026-07-31T14:42:45.543054+00:00"},"history":{"points":[{"timestamp":"2026-07-31T10:26:23.896390+00:00","score":68.47,"status":"healthy","latency_ms":448.42,"tool_count":17,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":448.42,"healthy_ratio_recent":1.0,"freshness_hours":4.27,"latest_status":"healthy"},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"agent_commerce_readiness":{"status":"beta","commerce_signal":"moderate","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"yes","numeric_price_context":"yes","commercial_quote_context":"yes","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"inferred","payment_rails":["ACP","AP2"],"purchase_stage_supported":[],"human_confirmation_required":"yes","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"write_capable","tool_risk_score":35,"pricing_transparency":"clear","schema_change_detected":"unknown","delegation_level":"research_only","evidence_level":"inferred","confidence":"medium","highest_risk_tools":[{"name":"submit_agent","risk_level":"write_capable"},{"name":"scan_mcp","risk_level":"write_capable"}],"skipped_unsafe_tools":["compare_agents","subscribe","scan_mcp"],"last_checked_at":"2026-07-31T14:42:44.307890+00:00","evidence":[{"field":"commerce_signal","value":"moderate","evidence_level":"observed","source":"tool_schema","matched_terms":["subscribe","limit","quote","interest","rate"],"sample":"find_trusted","confidence":"medium","last_checked_at":"2026-07-31T14:42:44.307890+00:00"},{"field":"payment_rails","value":"ACP, AP2","evidence_level":"inferred","source":"tool_schema","matched_terms":["acp","ap2"],"sample":"ACP, AP2","confidence":"medium","last_checked_at":"2026-07-31T14:42:44.307890+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":10,"tool_risk_score":35,"payment_readiness_score":60,"agent_delegation_safety_score":30,"overall_agent_commerce_score":36},"warnings":["Verify observed commerce-adjacent billing, usage, or pricing context, but did not observe a tool that can execute payment."],"recommended_fixes":["Clarify whether observed billing, usage, or pricing context can execute payment or is informational only."]},"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 4.3 hours.","live_check_count":26,"validation_age_hours":4.27},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"active_alerts":[],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_to_official_registry","severity":"low","title":"Publish or reconcile the server in the official MCP registry","why":"Official registry presence improves discovery confidence and cross-source consistency.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=ankitkapur1992-hlido%2Fhlido-mcp&source=report_json","reason_code":"machine_attention_detected","reason":"Agents and crawlers are already evaluating this server. Claim to publish authoritative owner, security, trust, and integration metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"moderate","label":"Moderate observed attention","summary":"Recent machine-readable trust and discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"none","observed":false,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"none","observed":false,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"moderate","observed":true,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":true,"compare":false,"compare_json":false,"compare_api":false,"report_json":false,"policy":true,"ledger":false,"badge_metadata":true,"badge_svg":false,"trust_summary":false,"mcp_tool":false},"claim_prompt":{"recommended":true,"reason":"This server has recent machine attention. A verified publisher claim can improve owner, policy, security, and trust metadata available to agents."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":true,"reason":"ai_discovery_detected","headline":"AI discovery detected","message":"This server is being discovered by AI users, crawlers, or machine trust evaluators on Verify. Claim this profile to add publisher metadata, official links, a security contact, and machine-readable trust details agents can use.","claim_url":"https://verify.sentinelsignal.io/claim?server=ankitkapur1992-hlido%2Fhlido-mcp&source=report_json","trust_summary_url":"https://verify.sentinelsignal.io/v1/servers/ankitkapur1992-hlido/hlido-mcp/trust-summary"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=ankitkapur1992-hlido%2Fhlido-mcp","trust_summary":"/v1/servers/ankitkapur1992-hlido/hlido-mcp/trust-summary","ledger":"/v1/servers/ankitkapur1992-hlido/hlido-mcp/ledger","policy":"/v1/servers/ankitkapur1992-hlido/hlido-mcp/policy","report":"/v1/servers/ankitkapur1992-hlido/hlido-mcp/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."}}