Atlas / MCP servers / impanyu / agentic_services

agentic_servicesSAFE

mcp/impanyu/agentic-services

Paid claim verification with cited web evidence, source provenance, snapshots, and hashes.

Verdict
SAFE
Grade
B
Trust score
85 /100
Exposed tools
3 3r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Agentic Services is a multi-service platform for human users, autonomous agents, or both. Each service owns a focused capability and can be sold independently through the appropriate user-facing and/or machine-facing channel.

Services belong to one of three product categories:

  • Human-only: designed for people to use through a UI; no agent-callable interface is required.
  • Agent-only: designed for autonomous agents to discover, purchase, and invoke through a machine interface; an informational product page is not a human-use UI.
  • Human-and-agent: provides both a usable human UI and a machine service interface for the same underlying capability.

The category describes intended users, not whether a website or API happens to exist. APIs, MCP tools, and A2A services are possible machine transports; a human UI is a separate product surface.

Product contract

Every published service has a stable identity, its own offer and delivery contract, a payment path, and service-level and policy information. Requirements depend on its category:

  • Human-only services need a usable UI and human checkout or entitlement flow.
  • Agent-only services need a machine-readable description, input/output schemas, a callable transport, and machine-compatible pricing and payment.
  • Human-and-agent services need both complete surfaces, backed by the same service identity and consistent results and commercial terms where applicable.
  • Paid delivery must be metered and recorded. Machine calls require idempotency and verifiable receipts; human transactions require an order record and appropriate receipt.
  • Data services publish provenance and freshness appropriate to their claims.

For services with an agent interface, the canonical public manifest lives at:

https:///.well-known/agent-service.json

The same manifest can be indexed by the platform registry and exported to compatible discovery networks. Human-only services do not need

Read from source at commit 32418e87109fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentic-services-payment-gateway --env ADMIN_API_KEY=${ADMIN_API_KEY} --env BRAVE_SEARCH_API_KEY=${BRAVE_SEARCH_API_KEY} --env CONTACT_IP_HASH_SECRET=${CONTACT_IP_HASH_SECRET} --env CONTACT_SMTP_APP_PASSWORD=${CONTACT_SMTP_APP_PASSWORD} -- npx -y agentic-services-payment-gateway
claude-desktop
{
  "mcpServers": {
    "agentic-services-payment-gateway": {
      "command": "npx",
      "args": [
        "-y",
        "agentic-services-payment-gateway"
      ],
      "env": {
        "ADMIN_API_KEY": "${ADMIN_API_KEY}",
        "BRAVE_SEARCH_API_KEY": "${BRAVE_SEARCH_API_KEY}",
        "CONTACT_IP_HASH_SECRET": "${CONTACT_IP_HASH_SECRET}",
        "CONTACT_SMTP_APP_PASSWORD": "${CONTACT_SMTP_APP_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
check_c10_licenseread
list_contractor_check_pricesread
list_verification_tiersread
04

Trust audit

SAFEgrade B · trust 85/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/google-cloud-vm.md:57
curl http://127.0.0.1:8010/healthz
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_niche_manager.py:212
web_tools.validate_scope('https://127.0.0.1/',web_tools.configured_domains())
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_niche_search.py:38
{'url':'http://127.0.0.1/secret'}, {'url':'javascript:alert(1)'}]}})
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_niche_search.py:61
for url in ['http://localhost/a','http://192.168.0.1/a','https://user:[email protected]/a','https://example.org:9000/a','https://abc.local/a']:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_photo_scout.py:22
assert not image_host('http://127.0.0.1/a.jpg')
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/agentic_services/photo_scout/routes.py:240
return Response(base64.b64decode(data.split(',',1)[1]),media_type='image/jpeg',
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/niche-discovery-architecture.md:23
access credentials, permissions and deployment policy.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/niche-discovery-architecture.md:78
| Access | API/feed/permitted page access, credential reference, source policy reference and review date |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/niche-manager-agent.md:24
under configured access/credentials. The agent sees the entire available tool
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/niche-manager-agent.md:127
handles, not access to deployment credentials. These execution boundaries protect
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
niche-discovery-site/index.html:43
<label>Already have an access token<input id="access-token" type="password" autocomplete="off" placeholder="nd_..."></label>
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
contractor-check-site/privacy/index.html:3
<body><header class="top"><a class="brand" href="/contractor-check/">◉ <span>Dream Workshop</span></a><nav><a href="/contractor-check/">Contractor Check ↗</a></nav></header><main class="report-page"><
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
contractor-check-site/terms/index.html:3
<body><header class="top"><a class="brand" href="/contractor-check/">◉ <span>Dream Workshop</span></a><nav><a href="/contractor-check/">Contractor Check ↗</a></nav></header><main class="report-page"><
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/agent-service-release.md:5
For an agent service, expose a public HTTP 402 challenge and a Streamable HTTP MCP endpoint. The MCP tool list should state the per-call price and include one free pricing tool. A paid call must produ
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
niche-discovery-site/privacy/index.html:16
<p>We retain search keywords, optional categories, result counts, channel and timestamps for up to 30 days. Free search limits use a server-generated hash of the client network address; we do not stor
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
photo-scout-site/terms.html:1
<!doctype html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1"><title>Photo Scout terms</title><link rel="stylesheet" href="./style.css">
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 32418e87109ffull audit observations/trust-audit/mcp-server/impanyu__agentic_services.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0832418e87109fSAFEB85first audit
06

Questions

What is the agentic_services MCP server?

Paid claim verification with cited web evidence, source provenance, snapshots, and hashes.

What tools does agentic_services expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is agentic_services safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (85/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does agentic_services need?

It reads ADMIN_API_KEY, BRAVE_SEARCH_API_KEY, CONTACT_IP_HASH_SECRET, CONTACT_SMTP_APP_PASSWORD, CONTRACTOR_STRIPE_SECRET_KEY, HUMAN_STRIPE_WEBHOOK_SECRET, INDEXNOW_KEY, NICHE_STRIPE_SECRET_KEY, NICHE_STRIPE_WEBHOOK_SECRET, NICHE_TOKEN_SECRET, OPENAI_API_KEY and OPENAI_MAX_OUTPUT_TOKENS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does agentic_services run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as agentic-services-payment-gateway.

How current is this page?

The grade is for one exact copy of the source (32418e87109f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement