agentic_servicesSAFE
Paid claim verification with cited web evidence, source provenance, snapshots, and hashes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Agentic Services is a multi-service platform for human users, autonomous agents, or both. Each service owns a focused capability and can be sold independently through the appropriate user-facing and/or machine-facing channel.
Services belong to one of three product categories:
- Human-only: designed for people to use through a UI; no agent-callable interface is required.
- Agent-only: designed for autonomous agents to discover, purchase, and invoke through a machine interface; an informational product page is not a human-use UI.
- Human-and-agent: provides both a usable human UI and a machine service interface for the same underlying capability.
The category describes intended users, not whether a website or API happens to exist. APIs, MCP tools, and A2A services are possible machine transports; a human UI is a separate product surface.
Product contract
Every published service has a stable identity, its own offer and delivery contract, a payment path, and service-level and policy information. Requirements depend on its category:
- Human-only services need a usable UI and human checkout or entitlement flow.
- Agent-only services need a machine-readable description, input/output schemas, a callable transport, and machine-compatible pricing and payment.
- Human-and-agent services need both complete surfaces, backed by the same service identity and consistent results and commercial terms where applicable.
- Paid delivery must be metered and recorded. Machine calls require idempotency and verifiable receipts; human transactions require an order record and appropriate receipt.
- Data services publish provenance and freshness appropriate to their claims.
For services with an agent interface, the canonical public manifest lives at:
https:///.well-known/agent-service.json
The same manifest can be indexed by the platform registry and exported to compatible discovery networks. Human-only services do not need
32418e87109fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agentic-services-payment-gateway --env ADMIN_API_KEY=${ADMIN_API_KEY} --env BRAVE_SEARCH_API_KEY=${BRAVE_SEARCH_API_KEY} --env CONTACT_IP_HASH_SECRET=${CONTACT_IP_HASH_SECRET} --env CONTACT_SMTP_APP_PASSWORD=${CONTACT_SMTP_APP_PASSWORD} -- npx -y agentic-services-payment-gateway{
"mcpServers": {
"agentic-services-payment-gateway": {
"command": "npx",
"args": [
"-y",
"agentic-services-payment-gateway"
],
"env": {
"ADMIN_API_KEY": "${ADMIN_API_KEY}",
"BRAVE_SEARCH_API_KEY": "${BRAVE_SEARCH_API_KEY}",
"CONTACT_IP_HASH_SECRET": "${CONTACT_IP_HASH_SECRET}",
"CONTACT_SMTP_APP_PASSWORD": "${CONTACT_SMTP_APP_PASSWORD}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_c10_license | read | |
list_contractor_check_prices | read | |
list_verification_tiers | read |
Trust audit
SAFEgrade B · trust 85/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (16)
curl http://127.0.0.1:8010/healthz
web_tools.validate_scope('https://127.0.0.1/',web_tools.configured_domains()){'url':'http://127.0.0.1/secret'}, {'url':'javascript:alert(1)'}]}})for url in ['http://localhost/a','http://192.168.0.1/a','https://user:[email protected]/a','https://example.org:9000/a','https://abc.local/a']:
assert not image_host('http://127.0.0.1/a.jpg')return Response(base64.b64decode(data.split(',',1)[1]),media_type='image/jpeg',access credentials, permissions and deployment policy.
| Access | API/feed/permitted page access, credential reference, source policy reference and review date |
under configured access/credentials. The agent sees the entire available tool
handles, not access to deployment credentials. These execution boundaries protect
<label>Already have an access token<input id="access-token" type="password" autocomplete="off" placeholder="nd_..."></label>
<body><header class="top"><a class="brand" href="/contractor-check/">◉ <span>Dream Workshop</span></a><nav><a href="/contractor-check/">Contractor Check ↗</a></nav></header><main class="report-page"><
<body><header class="top"><a class="brand" href="/contractor-check/">◉ <span>Dream Workshop</span></a><nav><a href="/contractor-check/">Contractor Check ↗</a></nav></header><main class="report-page"><
For an agent service, expose a public HTTP 402 challenge and a Streamable HTTP MCP endpoint. The MCP tool list should state the per-call price and include one free pricing tool. A paid call must produ
<p>We retain search keywords, optional categories, result counts, channel and timestamps for up to 30 days. Free search limits use a server-generated hash of the client network address; we do not stor
<!doctype html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1"><title>Photo Scout terms</title><link rel="stylesheet" href="./style.css">
Gates applied: no_behavioural_pass.
32418e87109ffull audit observations/trust-audit/mcp-server/impanyu__agentic_services.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 32418e87109f | SAFE | B | 85 | first audit |
Questions
What is the agentic_services MCP server?
Paid claim verification with cited web evidence, source provenance, snapshots, and hashes.
What tools does agentic_services expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is agentic_services safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (85/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does agentic_services need?
It reads ADMIN_API_KEY, BRAVE_SEARCH_API_KEY, CONTACT_IP_HASH_SECRET, CONTACT_SMTP_APP_PASSWORD, CONTRACTOR_STRIPE_SECRET_KEY, HUMAN_STRIPE_WEBHOOK_SECRET, INDEXNOW_KEY, NICHE_STRIPE_SECRET_KEY, NICHE_STRIPE_WEBHOOK_SECRET, NICHE_TOKEN_SECRET, OPENAI_API_KEY and OPENAI_MAX_OUTPUT_TOKENS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does agentic_services run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as agentic-services-payment-gateway.
How current is this page?
The grade is for one exact copy of the source (32418e87109f), read on 2026-10-08. The repository is watched and re-audited when it changes.