{"name":"io.github.CSOAI-ORG/gspc","slug":"csoai-org-gspc","title":"Council of AI GSPC","description":"12 HTTP tools (8 free, 4 x402). GSPC board + Ed25519 + trust counts. Measure, never certify.","url":"https://mcp.market/server/csoai-org-gspc","rating":null,"grade":"B","score":75,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":8,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":"Apache-2.0"},"uptime":{"percent":100,"checks":3,"ok":3,"last_checked_at":"2026-09-20T04:15:55.768Z","last_ok_at":"2026-09-20T04:15:55.768Z","latency_ms":90},"claimed":false,"transport":"mixed","callable_via_gateway":true,"default_price_micros":0,"repository":"https://github.com/CSOAI-ORG/councilof-ai","website":"https://councilof.ai","version":"1.4.2","remotes":[{"type":"streamable-http","url":"https://councilof.ai/mcp"}],"packages":[{"registryType":"npm","identifier":"csoai-gspc-mcp","version":"0.2.2","transport":{"type":"stdio"}}],"tools":[{"name":"art50_marking_evidence","description":"PAID (x402 or CSOAI LTD invoice). Article 50 marking-evidence pack via https://councilof.ai/api/art50/marking-evidence: is a machine-readable mark DETECTABLE in these bytes right now (C2PA manifest store, assertion hashes, hard binding, claim signature; IPTC digitalSourceType), beside the verbatim Art 50(2) excerpt hash and the Art 99(4) ceiling. Watermarks are UNCHECKABLE where no public detector exists and the pack says so. Point-in-time detection — never a conformity opinion, never a compliance word of any kind. preview=true is free and returns the same measurement unsigned. Without x_payment the tool returns the 402 challenge. If the route is not deployed on this origin the tool says NOT_DEPLOYED rather than inventing a result.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"url":{"type":"string","description":"Public http(s) URL of the generative output to measure (≤20 MiB)."},"bytes_b64":{"type":"string","description":"Alternatively the output bytes, base64 (≤20 MiB decoded)."},"manifest_b64":{"type":"string","description":"Alternatively a detached C2PA manifest store, base64 (manifest-only mode)."},"preview":{"type":"boolean","description":"true = free unsigned measurement (no card sha, no signature)."},"x_payment":{"type":"string","description":"The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge."}},"additionalProperties":false}},{"name":"board_totals","description":"Live GSPC board totals from https://councilof.ai/api/gspc. Returns the slot count and the measured count as two labelled numbers WITH their kind — a slot is a declared position on the board, a measurement is a real run behind it; the two are never summed and never swapped — plus as_of dates for the board and for this fetch. We measure, never certify. If the board cannot be fetched the answer is a distinct UNREACHABLE state: no cached number is ever presented as live.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"commission_card","description":"PAID (x402). Commission one signed card-v0 receipt (surface ras.commission) for a named subject on the frozen bank via https://councilof.ai/api/request-attestation. Re-serves every signed measurement card already on file for the subject; a payment never mints a MEASURED cell (fresh_run stays UNMEASURED until a published run exists). Without x_payment the tool returns the 402 challenge (accepts[] with asset, amount, payTo) plus a free preview of the cards already on file. Measurement, not certification — never a rank, a grade or a certificate. Verification stays free.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"subject":{"type":"string","description":"Subject to commission: a model id, instrument id or card sha (1-120 chars of [A-Za-z0-9._:/@+-])."},"axis":{"type":"string","description":"Optional axis slug; omit for the subject-level commission."},"x_payment":{"type":"string","description":"The X-PAYMENT header value (base64 x402 payload) signed by your wallet against accepts[] from the previous 402. Omit to receive the challenge."}},"required":["subject"],"additionalProperties":false}},{"name":"get_axis","description":"One axis row from the live GSPC board at https://councilof.ai/api/gspc: n, accuracy, interval, MEASURED or UNMEASURED status, family, and dates. An unmeasured axis is a first-class answer — a declared slot with no run behind it, published so the gap is visible — never an error and never a zero. Never a certification.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"axis":{"type":"string","description":"The axis name as it appears on the board, e.g. governance, safety, jail, provenance-controls. Case-insensitive. An unknown name returns the list of names the board actually carries."}},"required":["axis"],"additionalProperties":false}},{"name":"get_card","description":"GET one public-root card-v0 leaf by sha256 (64 hex) from https://councilof.ai/cards/{sha16}.json. UNMEASURED cells stay visible. Three states: VALID (fetched), INVALID (not a leaf of the live root), UNCHECKABLE (fetch failed). Not a GSPC measurement-card.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"sha256":{"type":"string","description":"64-char hex payload SHA-256 of the card-v0 leaf."}},"required":["sha256"],"additionalProperties":false}},{"name":"get_root","description":"GET the permissionless public-root at https://councilof.ai/root.json. Returns merkle_root, card_count, as_of, and UNMEASURED notes. Separate from GSPC. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable). Never a certificate.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"list_cards","description":"The published signed-card index (https://councilof.ai/signed/card_index.json): what the index declares (n_cards) and how many rows it actually carries, reported next to — never reconciled with — the count the card store endpoint (https://councilof.ai/api/cards) reports for itself. Two labelled numbers from two surfaces; if they disagree, this tool shows the disagreement rather than picking one. Optional filters return recent rows: axis, limit.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"axis":{"type":"string","description":"Only list rows whose axis matches this name (case-insensitive)."},"limit":{"type":"integer","minimum":0,"maximum":150,"description":"How many rows to include in the listing (newest first). Default 10. The two counts are always reported in full regardless of this limit."}},"additionalProperties":false}},{"name":"mcp_trust","description":"GET the latest MCP handshake trust snapshot (https://councilof.ai/interop/mcp-trust/latest.json): counts of how many internet-facing MCP servers answer a correct initialize handshake, how many respond with an auth challenge, and how many are unreachable. Counts only by doctrine — host details withheld by design. A partial round or a cap change is disclosed in the snapshot. Measurement, never certification. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable).","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"receipts_batch","description":"PAID (x402 or CSOAI LTD invoice). A historical batch of the estate's measurement receipts via https://councilof.ai/api/receipts/batch: every signed card-v0 leaf whose as_of falls in [from,to] (≤200), each with its Merkle inclusion path and the public root(s) that carried it, plus the root index for the window and one signed manifest card citing the batch sha256. preview=true is free and returns count, span, root count and the sha256 of the exact bytes the paid call returns. Recent leaves are free at /root.json, /cards/ and /api/proof?sha= — the batch sells assembly across history, never a conclusion. No settlement-receipt stream exists (/api/receipts/latest is UNPUBLISHED) and this tool never claims one. Without x_payment the tool returns the 402 challenge.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"from":{"type":"string","description":"Window start, ISO-8601. Required."},"to":{"type":"string","description":"Window end, ISO-8601. Defaults to now."},"preview":{"type":"boolean","description":"true = free: count, span, roots and batch sha256 without the leaves."},"x_payment":{"type":"string","description":"The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge."}},"required":["from"],"additionalProperties":false}},{"name":"rwa_evidence","description":"PAID (x402). Per-request signed evidence card of ONE XRPL issued asset's deterministic on-ledger state via https://councilof.ai/api/rwa/evidence: AccountRoot lsf* flags, Domain, the two-way xrp-ledger.toml check (PASS / FAIL / UNCHECKABLE — unreachable is never FAIL), gateway_balances obligation, holders as the free reader has them, every raw fetch sha256'd. preview=true is free (unsigned state). Historical state at fetched_at — not a rating, not a guarantee, not a conformity mark; /api/xrpl and /root.json stay free. Without x_payment the tool returns the 402 challenge. If the route is not deployed on this origin the tool says NOT_DEPLOYED.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"asset":{"type":"string","description":"Symbol (as listed by https://councilof.ai/api/xrpl) or issuer r-address."},"preview":{"type":"boolean","description":"true = free unsigned state."},"x_payment":{"type":"string","description":"The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge."}},"required":["asset"],"additionalProperties":false}},{"name":"verify_card","description":"Verify a signed gspc.measurement-card under the published rule (https://councilof.ai/signed/HOW-TO-VERIFY.md): recompute the id from the canonical body bytes, then check the Ed25519 signature under the PINNED key published at did:web:csoai.org#card-attestation-1. A card that carries its own key proves only that the file is self-consistent — anyone can alter a body and sign it with a key they just generated — so a signer other than the published key is reported INVALID. Three verdicts, never two: VALID, INVALID (with the reason), or UNCHECKABLE when the check could not be completed — 'could not check' is a different claim from 'forged'. Accepts the card as a JSON object, a JSON string, or a councilof.ai / csoai.org URL. Never a certification.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"card":{"description":"The signed card: an object, a JSON string, or a councilof.ai / csoai.org URL to one.","anyOf":[{"type":"object"},{"type":"string"}]}},"required":["card"],"additionalProperties":false}},{"name":"verify_inclusion","description":"Check a sha256 against the live public-root merkle via GET /api/proof?sha=. Three states only: VALID (included), INVALID (not a leaf), UNCHECKABLE (proof endpoint unreachable). Does not claim Ed25519 unless sig_ed25519 is present and checked separately. Never a grade.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"sha256":{"type":"string","description":"64-char hex digest to test for inclusion."}},"required":["sha256"],"additionalProperties":false}},{"name":"x402_trust","description":"GET the latest x402 catalog trust snapshot: counts of how many catalogued x402 resources open a correct 402 challenge vs how many are phantom on the wire. Counts only by doctrine — host details withheld; a 402 is NOT delivery; measurement, never certification.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}}],"scan":{"score":75,"grade":"B","scanned_at":"2026-09-19T20:04:03.166Z","report":{"scannerVersion":"0.1.5","scannedAt":"2026-09-19T20:04:03.175Z","components":{"code":{"score":25,"max":25,"notes":["5 source files scanned"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 974ms"]},"poisoning":{"score":15,"max":15,"notes":["13 tool descriptions checked"]},"auth":{"score":10,"max":15,"notes":["open endpoint, read-only tools"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"probes":[{"url":"https://councilof.ai/mcp","reachable":true,"authRequired":false,"latencyMs":974,"serverInfo":{"name":"csoai-gspc-mcp","version":"1.4.2"}}],"packages":[{"registryType":"npm","identifier":"csoai-gspc-mcp","version":"0.2.2","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":0,"publishedAt":"2026-09-13T14:42:17.493Z","repositoryUrl":"git+https://github.com/CSOAI-ORG/councilof-ai.git"}],"repo":{"found":false,"owner":"CSOAI-ORG","repo":"councilof-ai","error":"repo not found"},"icon":{"url":"https://councilof.ai/apple-touch-icon.png","source":"registry","width":180,"height":180},"presence":{"stars":null,"forks":null,"downloadsWeek":null,"license":"Apache-2.0","lastPushAt":null,"score":8}}}},"grade_history":[],"reviews":[]}