{"schema_version":"verify.report.v1","generated_at":"2026-08-19T14:11:06.366117+00:00","snapshot_id":"trustsnap_601badd5792320b4","server":{"namespace":"honeylabshq","name":"honeylabs-mcp","title":"honeylabs-mcp","description":"Honeypot threat intelligence for AI agents. Query 90 days of probe data from our sensor network: IP reputation, scanner classification, CVE probing trends, TLS/SSH/JA4 fingerprints. Free tier 500 credits/day, OAuth + bearer auth, streamable HTTP at https://mcp.honeylabs.net/mcp.","homepage_url":"https://glama.ai/mcp/servers/jnlq7n0oeh","docs_url":null,"icon_url":null,"support_url":"https://github.com/honeylabshq/honeylabs-mcp","remote_url":"https://mcp.honeylabs.net/mcp","server_card_url":null,"latest_version":null,"current_status":"healthy","current_score":66.67,"transport_type":"streamable-http","has_oauth":true,"has_dcr":true,"has_prompts":false,"tool_count":9,"current_validation_schema_version":"8058defc70ca932c","last_validated_at":"2026-08-19T04:30:31.095014+00:00","registry_source":"glama_registry","registry_identifier":"glama_registry:jnlq7n0oeh","canonical_identifier":null,"current_score_components":{"auth_operability_score":4.0,"error_contract_score":0.0,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":4.0,"slo_health_score":3.0,"security_hygiene_score":4.0,"task_success_score":4.0,"trust_confidence_score":4.0,"abuse_noise_ratio_score":4.0,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":2.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":3.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":2.0,"freshness_confidence_score":4.0,"transport_fidelity_score":4.0,"spec_recency_score":3.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":1.0,"advanced_capability_coverage_score":1.0,"connector_publishability_score":2.0,"tool_snapshot_churn_score":4.0,"connector_replay_score":4.0,"request_association_score":0.0,"interactive_flow_safety_score":3.0,"action_safety_score":3.0,"official_registry_presence_score":2.0,"safety_transparency_score":2.0,"tool_capability_clarity_score":3.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":4.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":0.0,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"capability_taxonomy":[],"machine_summary":{},"taxonomy_tags":[],"score_decomposition":[],"validation_diff":null,"tool_snapshot_diff":null,"connector_replay":{},"request_association":{},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0,"high_or_critical_alerts":0,"degraded_by_active_alerts":false},"recommended_for":[],"history_summary":{},"validation_timeline":[],"evidence_confidence":{"score":100.0,"label":"high","reason":"Based on 20 recent validations, 17 captured checks, and validation age of 9.7 hours.","live_check_count":17,"validation_age_hours":9.68,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"incident_feed":[],"disputes":[],"remediations":[],"client_remediation_modes":[],"client_profiles":[],"client_readiness_verdicts":[],"publishability_policy_profiles":[],"compatibility_fixtures":[],"install_snippets":{},"aliases":[],"raw_evidence":{"checks":{"probe_noise_resilience":{"status":"ok","latency_ms":416.34,"details":{"url":"https://mcp.honeylabs.net/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8","strict-transport-security":"max-age=31536000; includeSubDomains"},"validation_disallowed":false,"consent_error":null}},"server_card":{"status":"error","latency_ms":128.17,"details":{"url":"https://mcp.honeylabs.net/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://mcp.honeylabs.net/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"ok","latency_ms":388.2,"details":{"url":"https://mcp.honeylabs.net/.well-known/oauth-protected-resource","payload":{"resource":"https://mcp.honeylabs.net/mcp","authorization_servers":["https://mcp.honeylabs.net"],"bearer_methods_supported":["header"],"resource_documentation":"https://mcp.honeylabs.net"},"http_status":200,"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains"}}},"oauth_authorization_server":{"status":"ok","latency_ms":121.97,"details":{"url":"https://mcp.honeylabs.net/.well-known/oauth-authorization-server","payload":{"issuer":"https://mcp.honeylabs.net","authorization_endpoint":"https://mcp.honeylabs.net/oauth/authorize","token_endpoint":"https://mcp.honeylabs.net/oauth/token","registration_endpoint":"https://mcp.honeylabs.net/oauth/register","response_types_supported":["code"],"grant_types_supported":["authorization_code"],"code_challenge_methods_supported":["S256"],"token_endpoint_auth_methods_supported":["none"]},"http_status":200,"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains"}}},"openid_configuration":{"status":"error","latency_ms":122.19,"details":{"url":"https://mcp.honeylabs.net/.well-known/openid-configuration","error":"Client error '404 Not Found' for url 'https://mcp.honeylabs.net/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"initialize":{"status":"ok","latency_ms":363.01,"details":{"url":"https://mcp.honeylabs.net/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-06-18","capabilities":{"tools":{"listChanged":false}},"serverInfo":{"name":"HoneyLabs Threat Intelligence","version":"1.0.0"}}},"http_status":200,"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-06-18","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":1,"lag_days":160}},"tools_list":{"status":"ok","latency_ms":123.7,"details":{"url":"https://mcp.honeylabs.net/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last week', 'events from\nRussia yesterday'. Filters: source_ip, country (2-letter code), asn (e.g. 'AS12345'),\ndest_port, protocol ('tls' or '' = the coarse TLS/raw-TCP signal),\napp_protocol (nDPI L7 protocol label: 'bittorrent', 'ssh', 'rdp', 'mssql-tds', 'mining',\n'rtsp', 'smbv1', ... — find everything speaking a protocol regardless of port),\nhttp_method, request_header (substring of the masked\nHTTP request headers), ja4/ja3 (exact TLS client fingerprint),\nhas_client_cert (true = only events where the client presented an mTLS cert),\nip_version (4 or 6 = only IPv4 or IPv6 sources).\nsince/until are ISO-8601 UTC strings. Each record includes: source_ip, country, asn,\ndest_port, user_agent, url_path, http_request_headers, tls_client_ja4, tls_client_ja3,\nhttp_request_ja4h, ssh_client_hassh, tls_client_cert_subject/issuer,\nevent_sequence, event_duration, source_bytes/dest_bytes/network_bytes, network_protocol,\napplication_protocol, timestamp.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"source_ip":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"asn":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"app_protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"http_method":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"request_header":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"ja4":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"ja3":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"has_client_cert":{"anyOf":[{"type":"boolean"},{"type":"null"}],"default":null},"ip_version":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"limit":{"default":100,"type":"integer"}},"required":["since","until"],"type":"object"}},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top ASNs by\nattack volume', 'top IPs from China', 'top attackers hitting port 22'.\n'by' controls grouping: ip, asn, country, port, user_agent, ja4, url_path, domain, cve.\nby='cve' answers 'what CVEs are being mass-scanned right now' and returns\nvalue (the CVE id), title, severity, actively_exploited and counts; drill into any of\nthem with cve_lookup. by='cve' does not accept the country/dest_port/asn filters.\nOptional filters: country (2-letter ISO, e.g. 'CN'), dest_port, asn (e.g. 'AS12345').\nAdding a filter is required for large time ranges to stay within memory limits.\nsince/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"by":{"default":"ip","type":"string"},"limit":{"default":20,"type":"integer"},"country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"asn":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null}},"required":["since","until"],"type":"object"}},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?', 'is this a known scanner?', 'have you seen this IP?',\n    'what does this IP do?', 'when was it last seen?', 'is this IP in your data?'. Returns:\n    total_events (0 = never observed), first_seen, last_seen, country, ASN, the 50 most-hit\nports plus ports_targeted_count for the true total,\n    top user agents, top URL paths, TLS/HTTP/SSH fingerprints. Covers both IPv4 and domains.\n    Also returns our own judgement: `verdict` (human sentence) with `verdict_key` (stable\n    machine value to alert on) and `verdict_why`; `scanner` (benign-scanner identity from our\n    classification table, or null) so research traffic can be told apart from real attacks;\n    and `cve_probes`, the CVE signatures this address was seen probing.\n\n    WINDOW: `days` bounds the query to the last N days; leave it unset for every\n    retained event, which is the right default for \"have we ever seen this\". The\n    website's /lookup defaults to 7 days for anonymous visitors, so the same\n    address can read very differently on the two surfaces. Every response states\n    which window it used in `window`; quote it alongside any count you report.\n\n    RANGES: pass a CIDR ('103.66.28.0/22') for a whole-network aggregate, or several at once\n    separated by commas, spaces or newlines ('103.66.28.0/22, 8.34.210.32/27') to answer\n    'have any of this vendor's ranges touched us' in ONE call. Never expand a network into\n    individual addresses and loop -- that is hundreds of calls for an answer this returns in\n    one, and it will exhaust your quota. A range answer sets query_type to 'cidr' or\n    'cidr_set', lists every range back in `ranges`, and gives `per_range` counts plus\n    `top_source_ips`; total_events 0 with those fields present is a real observed absence.","inputSchema":{"additionalProperties":false,"properties":{"ioc":{"type":"string"},"days":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null}},"required":["ioc"],"type":"object"}},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me actors probing\nCVE-2023-1389'. Returns severity, KEV (actively_exploited), event and unique-IP counts,\nthe top probing IPs with country/ASN/scanner tag, top ASNs, exploiter fingerprints,\nsample request paths and a daily timeline. window: 24h, 7d, 30d or 90d.\n`observed: false` with a note means we hold no detection pattern for that CVE, which is\nNOT the same as nobody scanning it. Do not use payload_search for a CVE id: the id is\nour tag for a pattern and never appears in the payload text.","inputSchema":{"additionalProperties":false,"properties":{"cve_id":{"type":"string"},"window":{"default":"7d","type":"string"},"limit":{"default":25,"type":"integer"}},"required":["cve_id"],"type":"object"}},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'find requests with this user agent string', 'what payloads hit port 80 last week'.\n\nIt matches text that literally appeared in the request, and nothing else. These do\nNOT work and will return an empty list:\n  - a CVE id ('CVE-2024-4577'), which is our tag for a pattern, never payload text.\n    Use cve_lookup instead. This tool rejects them rather than answering emptily.\n  - a product or vendor name ('Cisco FMC', '7-Zip'), which appears in an advisory,\n    not in the request. Search the endpoint it exposes instead, e.g. '/ccmadmin' or\n    the vulnerable path.\n  - a description of behaviour ('SQL injection attempts'). Search a marker that\n    occurs in the traffic, e.g. 'UNION SELECT' or '../'.\n\nAn empty list is a real answer: it means no captured request in that window\ncontained the string. Widen since/until before concluding the activity does not\nexist. Free to call; volume is metered like every other tool.\nsince/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"query":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"},"limit":{"default":50,"type":"integer"}},"required":["query","since","until"],"type":"object"}},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'attack volume\nfrom China over 30 days'. bucket: 'hour' or 'day'. Optional filters: filter_protocol\n('tls'/'''), filter_country (2-letter code), filter_dest_port. since/until ISO-8601 UTC.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"bucket":{"default":"day","type":"string"},"filter_protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"filter_country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"filter_dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null}},"required":["since","until"],"type":"object"}},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks from this\nhosting provider', 'attribute this IP to its network'. asn format: 'AS12345'.\nReturns: total events, unique IPs, top targeted ports, top source countries, top user\nagents, org name. since/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"asn":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"}},"required":["asn","since","until"],"type":"object"}},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how\ncommon is this HASSH?', 'find all scanners with this SSH client fingerprint'. fp_type:\n'ja4' (TLS client), 'ja3' (legacy TLS client, MD5 — still keyed by many TI feeds),\n'ja4h' (HTTP client), 'hassh' (SSH client). since/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"fingerprint":{"type":"string"},"fp_type":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"},"limit":{"default":50,"type":"integer"}},"required":["fingerprint","fp_type","since","until"],"type":"object"}},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top networks\nand a sample of the IPs, plus a read on whether it is concentrated (a likely\ncoordinated operation, many IPs on few networks) or spread thin (a common client).\nUse when a user asks: 'is this JA4 one botnet or a common tool?', 'how many networks\nuse this HASSH?', 'how specific / concentrated is this fingerprint?'. fp_type: 'ja4'\n(TLS), 'ja4h' (HTTP), 'hassh' (SSH). Covers the full retained window (no date range).","inputSchema":{"additionalProperties":false,"properties":{"fingerprint":{"type":"string"},"fp_type":{"type":"string"}},"required":["fingerprint","fp_type"],"type":"object"}}]}},"http_status":200,"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains"}}},"prompts_list":{"status":"auth_required","latency_ms":125.7,"details":{"url":"https://mcp.honeylabs.net/mcp","error":"Client error '401 Unauthorized' for url 'https://mcp.honeylabs.net/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401","http_status":401,"payload":{},"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains","www-authenticate":"Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\""},"reason":"auth_required"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"auth_required","latency_ms":385.28,"details":{"url":"https://mcp.honeylabs.net/mcp","error":"Client error '401 Unauthorized' for url 'https://mcp.honeylabs.net/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401","http_status":401,"payload":{},"headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains","www-authenticate":"Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\""},"reason":"auth_required"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"determinism_probe":{"status":"ok","latency_ms":246.16,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"1884d7c76640d7bd9a896bd9e94eb61fd1e157dc7ea8c34ab45cf91fee2f24b7","errors":[]}},"instruction_tool_reference_probe":{"status":"ok","latency_ms":null,"details":{"referenced_tools":[],"missing_tools":[],"observed_tool_count":9}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-06-18"}},"step_up_auth_probe":{"status":"warning","latency_ms":null,"details":{"oauth_present":true,"auth_required_checks":["prompts_list","resources_list"],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":["Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\"","Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\""],"step_up_signals":["Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\"","Bearer realm=\"HoneyLabs MCP\", resource_metadata=\"https://mcp.honeylabs.net/.well-known/oauth-protected-resource\""],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":124.32,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-06-18","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last week', 'events from\nRussia yesterday'. Filters: source_ip, country (2-letter code), asn (e.g. 'AS12345'),\ndest_port, protocol ('tls' or '' = the coarse TLS/raw-TCP signal),\napp_protocol (nDPI L7 protocol label: 'bittorrent', 'ssh', 'rdp', 'mssql-tds', 'mining',\n'rtsp', 'smbv1', ... — find everything speaking a protocol regardless of port),\nhttp_method, request_header (substring of the masked\nHTTP request headers), ja4/ja3 (exact TLS client fingerprint),\nhas_client_cert (true = only events where the client presented an mTLS cert),\nip_version (4 or 6 = only IPv4 or IPv6 sources).\nsince/until are ISO-8601 UTC strings. Each record includes: source_ip, country, asn,\ndest_port, user_agent, url_path, http_request_headers, tls_client_ja4, tls_client_ja3,\nhttp_request_ja4h, ssh_client_hassh, tls_client_cert_subject/issuer,\nevent_sequence, event_duration, source_bytes/dest_bytes/network_bytes, network_protocol,\napplication_protocol, timestamp.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"source_ip":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"asn":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"app_protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"http_method":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"request_header":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"ja4":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"ja3":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"has_client_cert":{"anyOf":[{"type":"boolean"},{"type":"null"}],"default":null},"ip_version":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"limit":{"default":100,"type":"integer"}},"required":["since","until"],"type":"object"}},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top ASNs by\nattack volume', 'top IPs from China', 'top attackers hitting port 22'.\n'by' controls grouping: ip, asn, country, port, user_agent, ja4, url_path, domain, cve.\nby='cve' answers 'what CVEs are being mass-scanned right now' and returns\nvalue (the CVE id), title, severity, actively_exploited and counts; drill into any of\nthem with cve_lookup. by='cve' does not accept the country/dest_port/asn filters.\nOptional filters: country (2-letter ISO, e.g. 'CN'), dest_port, asn (e.g. 'AS12345').\nAdding a filter is required for large time ranges to stay within memory limits.\nsince/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"by":{"default":"ip","type":"string"},"limit":{"default":20,"type":"integer"},"country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null},"asn":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null}},"required":["since","until"],"type":"object"}},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?', 'is this a known scanner?', 'have you seen this IP?',\n    'what does this IP do?', 'when was it last seen?', 'is this IP in your data?'. Returns:\n    total_events (0 = never observed), first_seen, last_seen, country, ASN, the 50 most-hit\nports plus ports_targeted_count for the true total,\n    top user agents, top URL paths, TLS/HTTP/SSH fingerprints. Covers both IPv4 and domains.\n    Also returns our own judgement: `verdict` (human sentence) with `verdict_key` (stable\n    machine value to alert on) and `verdict_why`; `scanner` (benign-scanner identity from our\n    classification table, or null) so research traffic can be told apart from real attacks;\n    and `cve_probes`, the CVE signatures this address was seen probing.\n\n    WINDOW: `days` bounds the query to the last N days; leave it unset for every\n    retained event, which is the right default for \"have we ever seen this\". The\n    website's /lookup defaults to 7 days for anonymous visitors, so the same\n    address can read very differently on the two surfaces. Every response states\n    which window it used in `window`; quote it alongside any count you report.\n\n    RANGES: pass a CIDR ('103.66.28.0/22') for a whole-network aggregate, or several at once\n    separated by commas, spaces or newlines ('103.66.28.0/22, 8.34.210.32/27') to answer\n    'have any of this vendor's ranges touched us' in ONE call. Never expand a network into\n    individual addresses and loop -- that is hundreds of calls for an answer this returns in\n    one, and it will exhaust your quota. A range answer sets query_type to 'cidr' or\n    'cidr_set', lists every range back in `ranges`, and gives `per_range` counts plus\n    `top_source_ips`; total_events 0 with those fields present is a real observed absence.","inputSchema":{"additionalProperties":false,"properties":{"ioc":{"type":"string"},"days":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null}},"required":["ioc"],"type":"object"}},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me actors probing\nCVE-2023-1389'. Returns severity, KEV (actively_exploited), event and unique-IP counts,\nthe top probing IPs with country/ASN/scanner tag, top ASNs, exploiter fingerprints,\nsample request paths and a daily timeline. window: 24h, 7d, 30d or 90d.\n`observed: false` with a note means we hold no detection pattern for that CVE, which is\nNOT the same as nobody scanning it. Do not use payload_search for a CVE id: the id is\nour tag for a pattern and never appears in the payload text.","inputSchema":{"additionalProperties":false,"properties":{"cve_id":{"type":"string"},"window":{"default":"7d","type":"string"},"limit":{"default":25,"type":"integer"}},"required":["cve_id"],"type":"object"}},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'find requests with this user agent string', 'what payloads hit port 80 last week'.\n\nIt matches text that literally appeared in the request, and nothing else. These do\nNOT work and will return an empty list:\n  - a CVE id ('CVE-2024-4577'), which is our tag for a pattern, never payload text.\n    Use cve_lookup instead. This tool rejects them rather than answering emptily.\n  - a product or vendor name ('Cisco FMC', '7-Zip'), which appears in an advisory,\n    not in the request. Search the endpoint it exposes instead, e.g. '/ccmadmin' or\n    the vulnerable path.\n  - a description of behaviour ('SQL injection attempts'). Search a marker that\n    occurs in the traffic, e.g. 'UNION SELECT' or '../'.\n\nAn empty list is a real answer: it means no captured request in that window\ncontained the string. Widen since/until before concluding the activity does not\nexist. Free to call; volume is metered like every other tool.\nsince/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"query":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"},"limit":{"default":50,"type":"integer"}},"required":["query","since","until"],"type":"object"}},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'attack volume\nfrom China over 30 days'. bucket: 'hour' or 'day'. Optional filters: filter_protocol\n('tls'/'''), filter_country (2-letter code), filter_dest_port. since/until ISO-8601 UTC.","inputSchema":{"additionalProperties":false,"properties":{"since":{"type":"string"},"until":{"type":"string"},"bucket":{"default":"day","type":"string"},"filter_protocol":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"filter_country":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"filter_dest_port":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null}},"required":["since","until"],"type":"object"}},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks from this\nhosting provider', 'attribute this IP to its network'. asn format: 'AS12345'.\nReturns: total events, unique IPs, top targeted ports, top source countries, top user\nagents, org name. since/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"asn":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"}},"required":["asn","since","until"],"type":"object"}},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how\ncommon is this HASSH?', 'find all scanners with this SSH client fingerprint'. fp_type:\n'ja4' (TLS client), 'ja3' (legacy TLS client, MD5 — still keyed by many TI feeds),\n'ja4h' (HTTP client), 'hassh' (SSH client). since/until are ISO-8601 UTC strings.","inputSchema":{"additionalProperties":false,"properties":{"fingerprint":{"type":"string"},"fp_type":{"type":"string"},"since":{"type":"string"},"until":{"type":"string"},"limit":{"default":50,"type":"integer"}},"required":["fingerprint","fp_type","since","until"],"type":"object"}},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top networks\nand a sample of the IPs, plus a read on whether it is concentrated (a likely\ncoordinated operation, many IPs on few networks) or spread thin (a common client).\nUse when a user asks: 'is this JA4 one botnet or a common tool?', 'how many networks\nuse this HASSH?', 'how specific / concentrated is this fingerprint?'. fp_type: 'ja4'\n(TLS), 'ja4h' (HTTP), 'hassh' (SSH). Covers the full retained window (no date range).","inputSchema":{"additionalProperties":false,"properties":{"fingerprint":{"type":"string"},"fp_type":{"type":"string"}},"required":["fingerprint","fp_type"],"type":"object"}}]}},"bad_protocol_headers":{"content-type":"application/json","strict-transport-security":"max-age=31536000; includeSubDomains"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"ok","latency_ms":121.76,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"auth_required","http_status":401},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"warning","latency_ms":null,"details":{"capabilities":{"prompts":true,"resources":true,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":2,"enabled":["prompts","resources"],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"ok","latency_ms":null,"details":{"current_tool_count":9,"previous_tool_count":9,"similarity":1.0,"added":[],"removed":[],"changed_outputs":[]}},"connector_replay_probe":{"status":"ok","latency_ms":null,"details":{"backward_compatible":true,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"ok","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":true,"prompt_available":false}},"action_safety_probe":{"status":"ok","latency_ms":null,"details":{"summary":{"tool_count":9,"high_risk_tools":0,"destructive_tools":0,"exec_tools":0,"egress_tools":0,"secret_tools":0,"bulk_access_tools":0,"declared_non_read_only_tools":0,"annotation_conflict_tools":0,"risk_distribution":{"low":9,"medium":0,"high":0,"critical":0},"capability_distribution":{"read":6,"undetermined":2,"filesystem":1},"has_mutating_capability":false,"has_non_read_capability":false},"auth_present":true,"safeguard_count":1,"confirmation_signals":[],"reason":null}},"official_registry_probe":{"status":"missing","latency_ms":null,"details":{"registry_source":"glama_registry","direct_match":false,"official_peer_count":0}},"provenance_divergence_probe":{"status":"not_assessed","latency_ms":null,"details":{"direct_official_match":false,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1,"compared_fields":["title","version","homepage","repository"],"readable_sources":[],"comparable_field_count":0}},"schema_divergence_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_server_card_tools","compared_tool_count":0,"compared_dimensions":["server_name","server_version","declared_vs_observed_auth","tool_membership","parameter_names","required_parameters","parameter_types","output_schema_presence"],"server_name_mismatch":false,"card_server_name":null,"live_server_name":"HoneyLabs Threat Intelligence","server_version_mismatch":false,"card_server_version":null,"live_server_version":"1.0.0","auth_scheme_mismatch":false}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":9,"high_risk_tools":0,"blockers":["protocol_version","session_resume","step_up_auth","transport_compliance","request_association","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":false,"session_resume":false,"step_up_auth":false,"transport_compliance":false,"connector_replay":true,"request_association":false,"action_safety":true,"server_card":false,"tool_surface":true,"auth_flow":true}}}}},"active_alerts":[],"maintainer_analytics":{},"public_server_reputation":{},"maintainer_response_quality":{},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{},"tool_security_inventory":[],"transport_compliance":{},"utility_coverage":{},"write_action_governance":{},"provenance_divergence":{},"alias_consolidation":{},"alert_routing":{},"authenticated_validation":{},"hosted_runtime":{},"action_controls_diff":null,"benchmark_tasks":[],"latest_capability_counts":{},"point_loss_breakdown":[],"verdict_traces":{},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_601badd5792320b4","generated_at":"2026-08-19T14:11:06.382014+00:00","trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","source":"current_snapshot","server":"honeylabshq/honeylabs-mcp","last_validated_at":"2026-08-19T04:30:31.095014+00:00","validation_age_hours":9.68,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-19T04:30:31.095014+00:00","age_hours":9.68,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":720.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":66.67,"raw_score":66.67,"confidence_score":100.0,"confidence_weighted_score":66.7,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":66.67,"display_score":66.67,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"unauthenticated behavior not proven","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":1},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":100.0,"label":"high","validation_age_hours":9.68,"live_check_count":17,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"active_alerts":[],"active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"}},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_601badd5792320b4","generated_at":"2026-08-19T14:11:06.382014+00:00","trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","source":"current_snapshot","server":"honeylabshq/honeylabs-mcp","last_validated_at":"2026-08-19T04:30:31.095014+00:00","validation_age_hours":9.68,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-19T04:30:31.095014+00:00","age_hours":9.68,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":720.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":66.67,"raw_score":66.67,"confidence_score":100.0,"confidence_weighted_score":66.7,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":66.67,"display_score":66.67,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"unauthenticated behavior not proven","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":1},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":100.0,"label":"high","validation_age_hours":9.68,"live_check_count":17,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"active_alerts":[],"active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"}},"agent_commerce":{},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{},"partial":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"},"owner_opted_out":false},"latest_validation":null,"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_601badd5792320b4","generated_at":"2026-08-19T14:11:06.382014+00:00","trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","source":"current_snapshot","server":"honeylabshq/honeylabs-mcp","last_validated_at":"2026-08-19T04:30:31.095014+00:00","validation_age_hours":9.68,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-19T04:30:31.095014+00:00","age_hours":9.68,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":720.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":66.67,"raw_score":66.67,"confidence_score":100.0,"confidence_weighted_score":66.7,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":66.67,"display_score":66.67,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"unauthenticated behavior not proven","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":1},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":100.0,"label":"high","validation_age_hours":9.68,"live_check_count":17,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"active_alerts":[],"active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"}},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_601badd5792320b4","generated_at":"2026-08-19T14:11:06.382014+00:00","trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","source":"current_snapshot","server":"honeylabshq/honeylabs-mcp","last_validated_at":"2026-08-19T04:30:31.095014+00:00","validation_age_hours":9.68,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-19T04:30:31.095014+00:00","age_hours":9.68,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":720.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":66.67,"raw_score":66.67,"confidence_score":100.0,"confidence_weighted_score":66.7,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":66.67,"display_score":66.67,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"unauthenticated behavior not proven","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":1},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":100.0,"label":"high","validation_age_hours":9.68,"live_check_count":17,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"active_alerts":[],"active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"}},"partial":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"honeylabshq/honeylabs-mcp","ok":true,"surface_snapshot_ids":{"page":"trustsnap_601badd5792320b4","badge":null,"report":"trustsnap_601badd5792320b4","policy":null},"checked_surfaces":["page","report"],"unchecked_surfaces":["badge","policy"],"checked_count_surfaces":[],"count_mismatches":{},"checked_at":"2026-08-19T14:11:06.366728+00:00"},"history":{},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0,"high_or_critical_alerts":0,"degraded_by_active_alerts":false},"agent_commerce_readiness":{},"evidence_confidence":{"score":100.0,"label":"high","reason":"Based on 20 recent validations, 17 captured checks, and validation age of 9.7 hours.","live_check_count":17,"validation_age_hours":9.68,"basis":{"evidence_bearing_validations":20,"affirmative_live_check_count":17,"validation_age_hours":9.68,"freshness_threshold_hours":24}},"recommended_for":[],"active_alerts":[],"remediations":[],"cache_note":"Fast fallback response; full report evidence is deferred to protect web capacity. Fields listed in fields_unavailable (including tool_security_inventory, and write_action_governance) are not yet computed on this response -- an empty value means unchecked, not confirmed clean. Treat partial responses as indeterminate.","publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=honeylabshq%2Fhoneylabs-mcp&source=report_json","reason_code":"claim_to_publish_metadata","reason":"Claim this profile to verify publisher identity, add evidence, and manage trust metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"none","label":"No observed attention","summary":"No recent machine-readable trust or discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"none","observed":false,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"none","observed":false,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"none","observed":false,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":false,"compare":false,"compare_json":false,"compare_api":false,"report_json":false,"policy":false,"ledger":false,"badge_metadata":false,"badge_svg":false,"trust_summary":false,"mcp_tool":false},"claim_prompt":{"recommended":false,"reason":"No claim prompt is recommended from observed attention in the current window."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":false,"reason":"no_observed_attention"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=honeylabshq%2Fhoneylabs-mcp","trust_summary":"/v1/servers/honeylabshq/honeylabs-mcp/trust-summary","ledger":"/v1/servers/honeylabshq/honeylabs-mcp/ledger","policy":"/v1/servers/honeylabshq/honeylabs-mcp/policy","report":"/v1/servers/honeylabshq/honeylabs-mcp/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."},"trust_evaluated_at":"2026-08-19T14:11:06.382014+00:00","evidence_revision":"c21d059c649bd15e17cc8d36","active_alert_summary":{"critical":0,"high":0,"medium":0,"low":0,"high_or_critical":0,"total":0},"materialization":{"state":"partial","trust_core_complete":true,"fields_unavailable":["tool_security_inventory","security_posture_summary","write_action_governance","capability_taxonomy","remediations"],"materialized_at":"2026-08-19T14:11:06.382014+00:00"}}