PHION Agent Trust Infrastructure
69 agent services: verified data, enrichment, Index Feed and PHION Execute via x402.
Little public usage data yet
Reviews
Write oneNobody has reviewed PHION Agent Trust Infrastructure yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Tools (75, 8 write)
write = sends, deletes, buys or postsabandoned_tool_detectorFreeRequire stale success plus multiple independent failed probes before classifying likely abandonment; 0.003 USDC.
agent_budget_guardFreeEnforce per-call, task, session and period budgets; 0.002 USDC.
agent_reputation_evidenceFreeEvidence-bounded agent reputation assessment with confidence, coverage, provenance limitations and a signed receipt; 0.005 USDC.
agent_task_handoff_receiptFreeSign a bounded agent-task handoff; 0.003 USDC.
attestFreex402 paid signed JSON attestation; 0.001 USDC on Base.
company_enrichment_evidenceFreeCompany enrichment from domain, profile, ticker or name with provider attribution and signed evidence; 0.005 USDC.
concurrency_guardFreeFail closed unless capacity counter is fresh and the request carries a lease plus idempotency binding; 0.002 USDC.
conflict_resolutionFreeResolve or abstain; every candidate must bind source, value hash, observation time and bounded confidence; 0.003 USDC.
contact_enrichment_evidenceFreeBusiness-contact enrichment from strong identifiers with explicit identity limitations and a signed receipt; 0.007 USDC.
context_provenance_labelerFreeHash and label context integrity, confidentiality and source; 0.002 USDC.
counterparty_risk_preflightFreeDeterministic counterparty policy preflight using supplied reputation evidence and transaction limits; 0.003 USDC.
data_egress_preflightFreeInspect outbound agent data and destination before transmission; 0.002 USDC.
data_freshness_certificateFreeCertify freshness only when timestamp is bound to source URI and a 64-hex content hash; 0.002 USDC.
delegation_scope_guardFreeLeast-privilege guard for agent-to-agent delegation scope, destinations, budget and expiry; 0.003 USDC.
delivery_evidenceFreeBind successful delivery to transaction, request and matching 64-hex expected/observed content hashes without echoing content; 0.003 USDC.
dependency_provenance_assessmentFreeFail closed on empty dependency sets or absent registry policy; distinguish digest declarations from verified provenance; 0.003 USDC.
document_to_verified_jsonFreePublic text, HTML, JSON or XML normalized to source-backed JSON; no OCR; 0.010 USDC.
domain_ownership_evidenceFreeRequire a fresh domain-bound DNS-01/HTTP-01 challenge and separate control from legal ownership; 0.003 USDC.
duplicate_charge_detectorwrite actionFreeDetect repeated transaction hashes, payment identifiers and idempotent intents; 0.003 USDC.
entity_enrichment_evidenceFreeSource-bounded entity field coverage with explicit missing facts; 0.008 USDC.
fetch_evidenceFreeIndependently fetch bounded public evidence with redirect/DNS/connected-address SSRF checks, hashes and injection screening; 0.004 USDC.
human_approval_policyFreeClassify an action as automatic, approval-required or denied; 0.002 USDC.
idempotency_replay_guardFreeDetect safe replays and conflicting idempotency-key reuse; 0.002 USDC.
index_feedwrite actionFreeCanonical catalog snapshot or digest-based delta with exact HTTP/MCP records, PHION Execute templates and signed evidence; 0.005 USDC.
inspect_agentFreePre-payment agent inspection across x402, A2A, ERC-8004, OpenAPI and MCP; failed inspections are not charged; 0.009 USDC.
inter_agent_policy_evaluatorFreeRequire policy identity, subject, action, lifetime and valid decisions; compute the restrictive cap and shared actions; 0.003 USDC.
interrupted_task_recoveryFreeResume only when task/checkpoint identity, sequence, deadline, attempt budget, idempotency and side effects are explicit; 0.003 USDC.
journey_verifyFreeVerify hash continuity, timestamps and ordered intent→quote→payment→delivery lifecycle; 0.010 USDC.
live_data_freshnessFreeEvaluate live source observation against explicit maximum age; 0.002 USDC.
mandate_reserveFreeAtomic spending reservation with cumulative cap and conflict-safe idempotency; 0.004 USDC.
manifest_version_diffFreeRecursive manifest diff that requires explicit versions and flags sensitive changes without a version advance; 0.002 USDC.
market_data_snapshotFreeTimestamped public market-data snapshot with provenance; 0.005 USDC.
mcp_manifest_firewallFreeInspect an MCP manifest before installation or trust; 0.002 USDC.
mcp_server_identity_evidenceFreeBind MCP domain, endpoint, manifest, key and version; 0.003 USDC.
memory_write_guardwrite actionFreeScreen persistent memory writes for poisoning, unsafe instructions and missing provenance; 0.002 USDC.
multi_source_fact_bundleFreeIndependent source observations with agreement made explicit; 0.005 USDC.
oauth_token_audience_guardwrite actionFreeValidate declared OAuth audience and issuer; never send raw tokens; 0.002 USDC.
onchain_evidenceFreePublic explorer or RPC response evidence with immutable hashes; 0.004 USDC.
payment_diagnoseFreeFree diagnosis of the exact payment-funnel stage and machine-readable recovery actions for any PHION service.
payment_preflightFreeFail-closed x402 v2 firewall for network, asset, recipient, amount, scheme, resource host and expiry; 0.002 USDC.
payment_receipt_reconcilerFreeCompare canonical and common x402 payment/receipt aliases, settlement state and coverage; 0.003 USDC.
payment_route_selectorFreeReject impossible x402 routes, rank safe eligible routes by policy and return the exact next payment action; read-only, deterministic, 0.002 USDC.
person_enrichment_evidenceFreePerson enrichment from strong identifiers with provider attribution, likelihood, limitations and a signed receipt; 0.006 USDC.
phion_executewrite actionFreeUniversal PHION execution gateway: enforce a budget and persistent idempotency, execute one selected PHION service, evaluate acceptance criteria, and return a signed completion envelope. No gateway surcharge; the selected service price applies.
portable_observability_auditFreeValidate event identity, timestamps, hash chain and W3C-compatible lowercase nonzero trace/span identifiers; 0.004 USDC.
preflightFreeFree URL safety and reachability check.
purpose_bound_consentFreeFail-closed consent bound to ID, subject, recipient, purpose, scope, issue/expiry and checked revocation state; 0.003 USDC.
redirect_callback_validatorFreeValidate HTTPS callbacks and redirect host allowlists; 0.002 USDC.
resource_cycle_guardFreeRequire per-step identity, token and cost counters; detect repeated nodes/edges and enforce all three hard caps; 0.002 USDC.
retention_deletion_receiptFreeSeparate requested, operator-completed and evidence-verified retention/deletion states using content and evidence hashes; 0.003 USDC.
rwa_asset_due_diligenceFreeFail-closed issuer, contract, jurisdiction, custody and documentation coverage with independently fetched evidence; 0.019 USDC.
rwa_compliancewrite actionFreeFail-closed RWA transfer decision requiring explicit jurisdiction, KYC, allowlist, limit and transfer-window checks; 0.012 USDC.
rwa_corporate_actionsFreeDetect and sign material RWA changes in NAV, income, maturity, redemption or freeze state; 0.012 USDC.
rwa_nav_reserveFreeCompare declared NAV and reserve ratios with structured observed facts plus independently fetched evidence; returns discrepancies in basis points and fails closed on incomplete evidence; 0.015 USDC.
rwa_sanctions_screening_evidenceFreeEvidence-based literal subject screening against observed official US/EU sanctions sources; 0.015 USDC. Not legal clearance or wallet attribution.
rwa_transaction_assurancewrite actionFreeVerify an RWA asset, payment, delivery and transfer restrictions; 0.020 USDC.
schema_normalizeFreeSafe alias normalization that refuses ambiguous canonical/alias collisions and never changes payment values; 0.001 USDC.
schema_normalize_freeFreeFree, rate-limited payload validation and safe key normalization before payment. Payment-critical values are never changed.
secret_redaction_preflightFreeDetect and redact common secret indicators before transmission; 0.002 USDC.
service_sla_attestationFreeSign availability and latency calculations from bounded samples; 0.004 USDC.
signed_result_comparatorFreeCompare agent results and sign agreement or conflict; 0.003 USDC.
social_source_evidenceFreeAttributable public social-source observations with identity limitations; 0.006 USDC.
source_backed_searchFreeLiteral search over supplied public sources with citations and hashes; 0.004 USDC.
subscription_spend_guardwrite actionFreeBind one recurring charge to approval, merchant, due time and per-charge/period budgets; 0.003 USDC.
tool_call_policy_guardFreeBind a proposed tool call to declared intent and execution policy; 0.002 USDC.
tool_capability_drift_monitorFreeDetect tool capability or manifest drift; 0.002 USDC.
tool_output_firewallFreeInspect untrusted MCP/tool output before it enters agent context or triggers an action; 0.002 USDC.
transaction_assuranceFreeEnd-to-end settlement, timestamp, delivery-hash and deterministic acceptance assurance; 0.015 USDC.
transaction_recoveryFreeFailure classification and non-repeating recovery plan with validated attempt history; 0.010 USDC.
try_serviceFreeFree representative preview, exact price and upgrade instructions for any PHION paid service; no wallet required.
verified_news_monitorFreeLiteral query evidence across bounded public news sources; 0.006 USDC.
verified_web_extractFreeBounded public web extraction with source, timestamp and hashes; 0.003 USDC.
verifyFreeFree verification of a PHION signed receipt.
webhook_verifierFreeFail-closed RFC 9421-style webhook preflight requiring trusted key, algorithm, nonce, freshness, replay status and signature coverage of method, target and content; 0.003 USDC.
x402_quote_comparatorFreeValidate x402 v2 fields and compare only quotes sharing asset and decimals; 0.002 USDC.
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 655ms20/20
- Tool poisoning75 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 8 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http evidence-engine https://phion.systems/mcp
Alternatives to PHION Agent Trust Infrastructure
Same job from other publishers, ranked by rating then adoption.
- ha-mcpComprehensive Model Context Protocol server for managing Home Assistant through AI assistants.not reviewedWidely usedC
- IWEMarkdown knowledge base as agent memory. Runs against the notes directory it is started in.not reviewedEstablishedA
- fiori-mcp-serverSAP Fiori - Model Context Protocol (MCP) servernot reviewedEstablishedA
- mcp-local-ragEasy-to-setup local RAG server with minimal configurationnot reviewedEstablishedA
- mcp-ts-coreAgent-native TypeScript framework for MCP servers.not reviewedEstablishedC