{"name":"io.github.mnemom/mnemom","slug":"mnemom","title":"Mnemom — Trust Ratings for AI Agents","description":"Trust infrastructure for AI agents: read a verifiable Trust Rating, claim an identity, earn a badge.","url":"https://mcp.market/server/mnemom","rating":null,"grade":"B","score":80,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":26,"stars":1,"forks":0,"downloads_week":null,"last_push_at":"2026-09-26T22:14:57.000Z","license":null},"uptime":{"percent":100,"checks":28,"ok":28,"last_checked_at":"2026-09-27T23:35:39.366Z","last_ok_at":"2026-09-27T23:35:39.366Z","latency_ms":108},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":"https://github.com/mnemom/mcp","website":"https://www.mnemom.ai","version":"1.0.2","remotes":[{"type":"streamable-http","url":"https://api.mnemom.ai/mcp?profile=directory"}],"packages":[],"tools":[{"name":"claim_agent","description":"Claim a verifiable identity — bind an agent to your organization so its trust and accountability record is provably yours. No human in the loop.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","description":"Agent identifier (e.g. smolt-abc123)"},"hash_proof":{"type":"string","minLength":16,"description":"Agent possession proof — either the live birth token (`mnbt_…`) whose row pins this agent's hash, or the full 64-hex SHA-256 digest of `${apiKey}|${agentName}` (or `${apiKey}` for an unnamed singleton agent)."},"org_id":{"type":"string","description":"Optional. The organization to claim the agent into (e.g. `org-...` or `pers-...`). The caller must be a member of this org (role floor: member). If omitted, the agent is claimed into the caller's personal org."}},"required":["agent_id","hash_proof"],"additionalProperties":false}},{"name":"get_agent","description":"Look up an agent's public identity and trust state by ID — the accountable record other agents and humans can rely on.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","description":"Agent identifier (e.g. smolt-abc123)"}},"required":["agent_id"],"additionalProperties":false}},{"name":"get_reputation","description":"Look up an AI agent's published Trust Rating — Mnemom's portable reliability signal for autonomous software, computed from the agent's own verified activity record. Returns the rating plus the technical factors behind it. Free, public, read-only: every registered agent's rating is published by standard (the `visibility` field is the reputation-publication axis, distinct from identity-record visibility).","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","description":"Agent identifier (e.g. smolt-abc123)"}},"required":["agent_id"],"additionalProperties":false}},{"name":"get_reputation_badge","description":"Get an embeddable Trust Rating badge for an agent — returns the badge image URL plus ready-to-paste Markdown and HTML snippets for a README or agent card.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","description":"Agent identifier (e.g. smolt-abc123)"}},"required":["agent_id"],"additionalProperties":false}},{"name":"get_started","description":"Zero-auth, no-args orientation: who Mnemom is, the surface map, how to authenticate and what it unlocks, and the value tools to try right now (headlining scan_trust + the reputation reads).","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"token":{"type":"string","description":"Optional Dojo try-me invite token. When supplied and valid, returns the token-gated dojo briefing manifest (the same content as GET /v1/dojo/try-me/resolve); omit for public orientation."}},"additionalProperties":false}},{"name":"list_agents","description":"List your agents — List all agents owned by the authenticated user. Supports pagination.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"limit":{"type":"integer","default":50,"minimum":1,"maximum":100,"description":"How many agents to return, 1-100."},"offset":{"type":"integer","default":0,"minimum":0,"maximum":100000,"description":"How many agents to skip, for pagination."}},"additionalProperties":false}},{"name":"preview_compose_alignment_by_agent","description":"Preview composed alignment (dry run) — Composes the cascade against a hypothetical body at the agent layer and returns conflicts + the composed view. No DB writes. Used by the dashboard editor for live conflict markers.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field."},"card_version":{"type":"string","minLength":3,"maxLength":40,"pattern":"^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$","description":"Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`."},"autonomy_mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks."},"integrity_mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Master switch for the values pipeline. Required. Same four states as `autonomy_mode`."},"principal":{"type":"object","additionalProperties":false,"required":["type","relationship","identifier"],"description":"Whose authority this agent acts under. Required.","properties":{"type":{"type":"string","enum":["human","organization","agent","unspecified"],"description":"The kind of principal the agent answers to."},"relationship":{"type":"string","enum":["delegated_authority","advisory","autonomous"],"description":"How the agent relates to that principal."},"identifier":{"type":"string","minLength":1,"maxLength":128,"description":"Who the principal is. Use a ROLE or ORGANIZATION name (\"support-team\", \"Acme Corp Finance\"), NOT an individual's name, email address or phone number. Pass \"unspecified\" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."},"escalation_contact":{"type":"string","minLength":1,"maxLength":128,"description":"Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX (\"oncall-sre\", \"security@example.com\"), never an individual's personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}},"values":{"type":"object","additionalProperties":false,"required":["declared"],"description":"The values this agent declares it is bound by. Required.","properties":{"declared":{"type":"array","minItems":1,"maxItems":32,"items":{"type":"string","minLength":1,"maxLength":64},"description":"Value catalog IDs — e.g. [\"honesty\", \"no_harm\", \"privacy\"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)"}}},"autonomy":{"type":"object","additionalProperties":false,"required":["bounded_actions"],"description":"What the agent may do on its own authority. Required.","properties":{"bounded_actions":{"type":"array","minItems":1,"maxItems":64,"items":{"type":"string","minLength":1,"maxLength":128},"description":"Action names the agent may take within its bounds — e.g. [\"send_email\", \"create_ticket\"]. At least one required. Action identifiers only, not descriptions."},"forbidden_actions":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":128},"description":"Action names the agent must never take. Must be disjoint from `bounded_actions`."},"escalation_triggers":{"type":"array","maxItems":32,"description":"Conditions that route to a human instead of acting.","items":{"type":"object","additionalProperties":false,"required":["condition","action","reason"],"properties":{"condition":{"type":"string","minLength":1,"maxLength":200,"description":"The condition, as a short expression or slug (e.g. \"amount > 1000\"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."},"action":{"type":"string","enum":["escalate","deny","log"],"description":"What to do when the condition holds."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}}}},"audit":{"type":"object","additionalProperties":false,"required":["retention_days","queryable"],"description":"How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)","properties":{"retention_days":{"type":"integer","minimum":0,"maximum":3650,"description":"How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum."},"queryable":{"type":"boolean","default":false,"description":"Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint."},"query_endpoint":{"type":"string","maxLength":300,"description":"HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false."},"tamper_evidence":{"type":"string","enum":["append_only","signed","merkle"],"description":"Tamper-evidence scheme applied to the retained records."}}}},"required":["agent_id","card_version","autonomy_mode","integrity_mode","principal","values","autonomy","audit"],"additionalProperties":false}},{"name":"preview_compose_protection_by_agent","description":"Preview composed protection (dry run) — Composes the cascade against a hypothetical body at the agent layer and returns conflicts + the composed view. No DB writes. Used by the dashboard editor for live conflict markers.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field."},"card_version":{"type":"string","minLength":3,"maxLength":40,"pattern":"^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$","description":"Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`."},"mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks."},"thresholds":{"type":"object","additionalProperties":false,"required":["warn","quarantine","block"],"description":"Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. All three are required if this object is sent at all — omit the whole object to accept the composed defaults.","properties":{"warn":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is flagged."},"quarantine":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is held for review."},"block":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is refused."}}},"screen_surfaces":{"type":"object","additionalProperties":false,"description":"Which traffic surfaces are screened. Omit to accept the composed defaults.","properties":{"incoming":{"type":"boolean","description":"Screen prompts arriving at the agent."},"outgoing":{"type":"boolean","description":"Screen the agent's outbound messages."},"tool_calls":{"type":"boolean","description":"Screen the tool calls the agent makes."},"tool_responses":{"type":"boolean","description":"Screen tool responses returned to the agent."}}},"trusted_sources":{"type":"object","additionalProperties":false,"description":"Sources exempt from screening. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.","properties":{"domains":{"type":"array","maxItems":64,"items":{"type":"string","minLength":3,"maxLength":253},"description":"Trusted DNS names, optionally with `:port`. No wildcards."},"agent_ids":{"type":"array","maxItems":64,"items":{"type":"string","minLength":8,"maxLength":64,"pattern":"^mnm-[A-Za-z0-9-]{4,}$"},"description":"Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form."},"ip_ranges":{"type":"array","maxItems":64,"items":{"type":"string","minLength":4,"maxLength":43},"description":"Trusted CIDR ranges (e.g. `10.0.0.0/8`)."}}},"protected_surface":{"type":"object","additionalProperties":false,"description":"The assets and operations this agent must protect. Omit to accept the composed default (empty surface).","properties":{"assets":{"type":"array","maxItems":64,"description":"The assets under protection.","items":{"type":"object","additionalProperties":false,"required":["kind","selector"],"properties":{"kind":{"type":"string","minLength":1,"maxLength":64,"description":"Asset class — e.g. \"repo\", \"database\", \"bucket\"."},"selector":{"type":"string","minLength":1,"maxLength":256,"description":"Which instance — e.g. \"mnemom/mnemom-api\". A resource identifier only: no credentials, no connection strings, no personal data."},"label":{"type":"string","minLength":1,"maxLength":120,"description":"Short human-readable name for the asset."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}},"forbidden_operations":{"type":"array","maxItems":64,"description":"Operations the agent must never perform on the protected assets.","items":{"type":"object","additionalProperties":false,"required":["pattern"],"properties":{"pattern":{"type":"string","minLength":1,"maxLength":200,"description":"Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description."},"applies_to":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":256},"description":"Asset identities this entry applies to. Omit to apply to every protected asset."},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"How serious a violation of this entry is."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}},"escalation_required":{"type":"array","maxItems":64,"description":"Operations that require human approval before the agent may proceed.","items":{"type":"object","additionalProperties":false,"required":["pattern"],"properties":{"pattern":{"type":"string","minLength":1,"maxLength":200,"description":"Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description."},"applies_to":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":256},"description":"Asset identities this entry applies to. Omit to apply to every protected asset."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}}}}},"required":["agent_id","card_version","mode"],"additionalProperties":false}},{"name":"put_alignment_by_agent","description":"Publish or replace the alignment manifest — Accepts YAML (`text/yaml`, `application/yaml`) or JSON. Body is the full `UnifiedAlignmentCard`; server-side composition merges it across the platform → org → team → agent cascade and writes the canonical composed card. Requires `Idempotency-Key`. Honor...","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field."},"card_version":{"type":"string","minLength":3,"maxLength":40,"pattern":"^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$","description":"Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`."},"autonomy_mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks."},"integrity_mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Master switch for the values pipeline. Required. Same four states as `autonomy_mode`."},"principal":{"type":"object","additionalProperties":false,"required":["type","relationship","identifier"],"description":"Whose authority this agent acts under. Required.","properties":{"type":{"type":"string","enum":["human","organization","agent","unspecified"],"description":"The kind of principal the agent answers to."},"relationship":{"type":"string","enum":["delegated_authority","advisory","autonomous"],"description":"How the agent relates to that principal."},"identifier":{"type":"string","minLength":1,"maxLength":128,"description":"Who the principal is. Use a ROLE or ORGANIZATION name (\"support-team\", \"Acme Corp Finance\"), NOT an individual's name, email address or phone number. Pass \"unspecified\" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."},"escalation_contact":{"type":"string","minLength":1,"maxLength":128,"description":"Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX (\"oncall-sre\", \"security@example.com\"), never an individual's personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}},"values":{"type":"object","additionalProperties":false,"required":["declared"],"description":"The values this agent declares it is bound by. Required.","properties":{"declared":{"type":"array","minItems":1,"maxItems":32,"items":{"type":"string","minLength":1,"maxLength":64},"description":"Value catalog IDs — e.g. [\"honesty\", \"no_harm\", \"privacy\"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)"}}},"autonomy":{"type":"object","additionalProperties":false,"required":["bounded_actions"],"description":"What the agent may do on its own authority. Required.","properties":{"bounded_actions":{"type":"array","minItems":1,"maxItems":64,"items":{"type":"string","minLength":1,"maxLength":128},"description":"Action names the agent may take within its bounds — e.g. [\"send_email\", \"create_ticket\"]. At least one required. Action identifiers only, not descriptions."},"forbidden_actions":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":128},"description":"Action names the agent must never take. Must be disjoint from `bounded_actions`."},"escalation_triggers":{"type":"array","maxItems":32,"description":"Conditions that route to a human instead of acting.","items":{"type":"object","additionalProperties":false,"required":["condition","action","reason"],"properties":{"condition":{"type":"string","minLength":1,"maxLength":200,"description":"The condition, as a short expression or slug (e.g. \"amount > 1000\"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."},"action":{"type":"string","enum":["escalate","deny","log"],"description":"What to do when the condition holds."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}}}},"audit":{"type":"object","additionalProperties":false,"required":["retention_days","queryable"],"description":"How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)","properties":{"retention_days":{"type":"integer","minimum":0,"maximum":3650,"description":"How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum."},"queryable":{"type":"boolean","default":false,"description":"Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint."},"query_endpoint":{"type":"string","maxLength":300,"description":"HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false."},"tamper_evidence":{"type":"string","enum":["append_only","signed","merkle"],"description":"Tamper-evidence scheme applied to the retained records."}}}},"required":["agent_id","card_version","autonomy_mode","integrity_mode","principal","values","autonomy","audit"],"additionalProperties":false}},{"name":"put_protection_by_agent","description":"Publish or replace the protection manifest — Accepts YAML (`text/yaml`, `application/yaml`) or JSON. Body is the full `UnifiedProtectionCard`; server-side composition merges it across the platform → org → team → agent cascade and writes the canonical composed card. Requires `Idempotency-Key`. Hon...","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field."},"card_version":{"type":"string","minLength":3,"maxLength":40,"pattern":"^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$","description":"Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`."},"mode":{"type":"string","enum":["off","observe","nudge","enforce"],"description":"Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks."},"thresholds":{"type":"object","additionalProperties":false,"required":["warn","quarantine","block"],"description":"Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. All three are required if this object is sent at all — omit the whole object to accept the composed defaults.","properties":{"warn":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is flagged."},"quarantine":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is held for review."},"block":{"type":"number","minimum":0,"maximum":1,"description":"Score at or above which the request is refused."}}},"screen_surfaces":{"type":"object","additionalProperties":false,"description":"Which traffic surfaces are screened. Omit to accept the composed defaults.","properties":{"incoming":{"type":"boolean","description":"Screen prompts arriving at the agent."},"outgoing":{"type":"boolean","description":"Screen the agent's outbound messages."},"tool_calls":{"type":"boolean","description":"Screen the tool calls the agent makes."},"tool_responses":{"type":"boolean","description":"Screen tool responses returned to the agent."}}},"trusted_sources":{"type":"object","additionalProperties":false,"description":"Sources exempt from screening. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.","properties":{"domains":{"type":"array","maxItems":64,"items":{"type":"string","minLength":3,"maxLength":253},"description":"Trusted DNS names, optionally with `:port`. No wildcards."},"agent_ids":{"type":"array","maxItems":64,"items":{"type":"string","minLength":8,"maxLength":64,"pattern":"^mnm-[A-Za-z0-9-]{4,}$"},"description":"Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form."},"ip_ranges":{"type":"array","maxItems":64,"items":{"type":"string","minLength":4,"maxLength":43},"description":"Trusted CIDR ranges (e.g. `10.0.0.0/8`)."}}},"protected_surface":{"type":"object","additionalProperties":false,"description":"The assets and operations this agent must protect. Omit to accept the composed default (empty surface).","properties":{"assets":{"type":"array","maxItems":64,"description":"The assets under protection.","items":{"type":"object","additionalProperties":false,"required":["kind","selector"],"properties":{"kind":{"type":"string","minLength":1,"maxLength":64,"description":"Asset class — e.g. \"repo\", \"database\", \"bucket\"."},"selector":{"type":"string","minLength":1,"maxLength":256,"description":"Which instance — e.g. \"mnemom/mnemom-api\". A resource identifier only: no credentials, no connection strings, no personal data."},"label":{"type":"string","minLength":1,"maxLength":120,"description":"Short human-readable name for the asset."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}},"forbidden_operations":{"type":"array","maxItems":64,"description":"Operations the agent must never perform on the protected assets.","items":{"type":"object","additionalProperties":false,"required":["pattern"],"properties":{"pattern":{"type":"string","minLength":1,"maxLength":200,"description":"Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description."},"applies_to":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":256},"description":"Asset identities this entry applies to. Omit to apply to every protected asset."},"severity":{"type":"string","enum":["low","medium","high","critical"],"description":"How serious a violation of this entry is."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}},"escalation_required":{"type":"array","maxItems":64,"description":"Operations that require human approval before the agent may proceed.","items":{"type":"object","additionalProperties":false,"required":["pattern"],"properties":{"pattern":{"type":"string","minLength":1,"maxLength":200,"description":"Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description."},"applies_to":{"type":"array","maxItems":64,"items":{"type":"string","minLength":1,"maxLength":256},"description":"Asset identities this entry applies to. Omit to apply to every protected asset."},"reason":{"type":"string","minLength":1,"maxLength":200,"description":"Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."}}}}}}},"required":["agent_id","card_version","mode"],"additionalProperties":false}},{"name":"report_recipe_fn_fp","description":"Submit a false-positive / false-negative correction for one of Mnemom's automated detection rules (a 'recipe') — technical feedback that improves detection accuracy, like filing a bug report against a spam filter.","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"recipeId":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"The detection recipe the report is filed against (the one that misfired or failed to fire). Identifier only."},"type":{"type":"string","enum":["fn","fp"],"description":"`fn` = false negative (the recipe should have fired). `fp` = false positive (it fired on legitimate behaviour)."},"summary":{"type":"string","minLength":1,"maxLength":500,"description":"A short description of what the recipe got wrong — what it flagged, or what it missed, and why that was incorrect. DESCRIBE the misfire; do NOT paste the conversation, the prompt, the raw payload or the log that triggered it. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization."},"agent_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"Optional. The agent the report concerns. Identifier only."},"checkpoint_id":{"type":"string","minLength":3,"maxLength":64,"pattern":"^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$","description":"Optional. The related integrity checkpoint, so the reviewer can correlate. Identifier only."}},"required":["recipeId","type","summary"],"additionalProperties":false}},{"name":"scan_trust","description":"Scan a website's agent-trust-readiness and return a signed scorecard (Trust, plus an Access axis on newer rubrics). Zero-auth. Results are CACHED for up to 24h — check `cached` and `scannedAt` on the result; pass `fresh: true` to force a re-scan (rate-limited). Proxies to the SSRF-locked isittrustready scanner; the Ed25519 signature + permalink are preserved verbatim. Rubric + docs: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL to scan, e.g. \"example.com\" or \"https://example.com\"."},"fresh":{"type":"boolean","description":"Force a fresh re-scan instead of the cached result (results are cached up to 24h; the engine rate-limits re-scans). Equivalent to the scanner's rescan flag."}},"required":["url"],"additionalProperties":false}},{"name":"search_reputation_directory","description":"Resolve an agent name or id-prefix to a real agent_id over the PUBLIC reputation directory (only agents whose reputation visibility is public). Zero-auth. The arriving-agent entry point: discover a concrete agent_id, then call get_reputation / verify_reputation on it.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"q":{"type":"string","description":"Name search (ilike) or agent-id prefix match."},"grade":{"type":"string","description":"Filter to one grade (e.g. `AAA`, `B`, `NR`)."},"confidence":{"type":"string","enum":["high","medium","low","insufficient"],"description":"Filter to agents at a given reputation-confidence level (driven by how much evidence backs the score)."},"sort":{"type":"string","default":"score","description":"Result ordering. Default \"score\" (highest-rated first); other supported keys order by recency or name."},"page":{"type":"integer","minimum":1,"default":1,"description":"1-based page number for pagination. Default 1."},"per_page":{"type":"integer","minimum":1,"maximum":100,"default":20,"description":"Number of results per page. 1–100, default 20."}},"additionalProperties":false}},{"name":"verify_reputation","description":"Attest an agent's Trust Rating — returns a Merkle-root + hash-chain attestation (hash_chain_valid) proving the rating derives from an unbroken, append-only checkpoint chain, plus a pointer to the signed integrity certificate. This is a chain-integrity attestation, NOT an in-band Ed25519 signature check (that parity is verify_scan, for website scorecards).","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"agent_id":{"type":"string","description":"Agent identifier (e.g. smolt-abc123)"}},"required":["agent_id"],"additionalProperties":false}},{"name":"verify_scan","description":"Verify a website scan scorecard's Ed25519 signature IN-BAND (verify, don't trust). Pass a `scan` (a scorecard from scan_trust) or a `url` to re-scan; returns {verified, key_id, canonicalization} checked against the public key at mnemom://iitr/jwks. Zero-auth. Spec + rubric: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"scan":{"type":"object","description":"A scan scorecard previously returned by scan_trust (or iitr's /r/ JSON), passed back verbatim to verify. Same shape as scan_trust's result; the signature is checked against mnemom://iitr/jwks.","properties":{"schema":{"type":"string","description":"iitr-scan schema version string (e.g. \"iitr-scan/v0.N\")."},"target":{"type":"string","description":"Normalized host that was scanned."},"scannedAt":{"type":"string","format":"date-time","description":"When this scorecard was produced. Results are cached up to 24h — pass fresh:true to scan_trust to force a re-scan."},"cached":{"type":"boolean","description":"True when served from the scanner's 24h cache rather than a fresh scan."},"rubricVersion":{"type":"string","description":"Rubric version (e.g. \"0.4.0\")."},"score":{"type":"number","description":"0–100 weighted overall TRUST score."},"grade":{"type":"string","description":"Trust letter grade (A+…F)."},"categories":{"type":"array","description":"Trust-axis categories with per-category scores + checks.","items":{"type":"object","additionalProperties":true}},"access":{"type":"object","description":"The independent Access/discoverability axis (never blended with Trust). Present from the two-axis rubric (0.3.0+).","properties":{"axis":{"type":"string","description":"Always \"access\"."},"version":{"type":"string","description":"Access-axis rubric version this sub-score was computed against."},"score":{"type":"number","description":"0–100 weighted Access/discoverability score (independent of Trust)."},"grade":{"type":"string","description":"Access letter grade (A+…F)."},"applicable":{"type":"boolean","description":"False when the site declares Access N/A."},"categories":{"type":"array","description":"Per-category Access scores + checks.","items":{"type":"object","additionalProperties":true}}},"additionalProperties":true},"signature":{"type":"object","description":"Ed25519 signature over the canonical result (transport field; stripped before verify).","properties":{"alg":{"type":"string","description":"Always \"Ed25519\"."},"publicKeyId":{"type":"string","description":"16-hex key fingerprint, e.g. 94502b2b7235c986."},"value":{"type":"string","description":"base64 signature."},"signedAt":{"type":"string","format":"date-time","description":"When the scorecard was signed."}},"additionalProperties":true},"permalink":{"type":"string","format":"uri","description":"Shareable /r/ permalink (only on /r/ responses; transport field)."},"verification":{"type":"object","description":"Self-describing in-band verification block {alg, kid, jwks, canonicalization} — how to verify this scorecard's signature. Self-describing, so signed-EXCLUDED (stripped before verify).","additionalProperties":true}},"required":["schema","target","score","grade","signature"],"additionalProperties":true},"url":{"type":"string","description":"Alternatively, a domain/URL to re-scan and then verify."}},"oneOf":[{"required":["scan"],"not":{"required":["url"]}},{"required":["url"],"not":{"required":["scan"]}}],"additionalProperties":false}}],"scan":{"score":80,"grade":"B","scanned_at":"2026-09-27T05:28:24.056Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-27T05:28:24.050Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 240ms"]},"poisoning":{"score":15,"max":15,"notes":["15 tool descriptions checked"]},"auth":{"score":3,"max":15,"notes":["open endpoint exposes 3 write-action tools with no auth"]},"maintenance":{"score":15,"max":15,"notes":["last push 0 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"auth.open-write","severity":"high","component":"auth","title":"Write-action tools reachable without authentication"}],"inputs":{"probes":[{"url":"https://api.mnemom.ai/mcp?profile=directory","reachable":true,"authRequired":false,"latencyMs":240,"serverInfo":{"name":"mnemom","version":"2.0.0"}}],"packages":[],"repo":{"found":true,"owner":"mnemom","repo":"mcp","archived":false,"pushedAt":"2026-09-26T22:14:57Z","stars":1,"forks":0,"openIssues":0,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/258560721?v=4","ownerCreatedAt":"2026-02-01T06:57:36Z"},"icon":{"url":"https://www.mnemom.ai/mnemom_favicon.png","source":"registry","width":266,"height":264},"presence":{"stars":1,"forks":0,"downloadsWeek":null,"license":null,"lastPushAt":"2026-09-26T22:14:57.000Z","score":26}}}},"grade_history":[],"reviews":[]}