Skip to content
Official MCP RegistryListed

com.obeliskgate/trust-tools

Part oftrust-toolsMCP server

Website security ratings, token verification, and tamper-evident ledger heads from Obelisk Gate.

First seen 2 Oct 2026. Evidence as of 7 Oct 2026.

8
Tools
From an anonymous probe
1
Source listings
Each with its own history
2
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
explain_ratingExplain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is read.Not declared
gate_statusRead the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.Not declared
get_agent_proofRead an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.Not declared
get_org_ratingRead the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.Not declared
scan_trustRun Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.Not declared
transparency_headRead the current signed transparency head of Obelisk's tamper-evident receipt ledger — pin it and compare later to prove history only extends. Same data as /.well-known/obelisk-transparency.json.Not declared
verify_agent_run_proofVerify an Obelisk run proof. Pass run_proof_token, the token Obelisk signs at POST /api/agent-proof/run: the tool checks Obelisk's signature against its published keys, that the named agent is active now with the same key that answered the run challenge, and which delegation hops matched the owner's registry when the token was signed. A bare run_proof envelope is only checked for internal consistency and is never reported as verified, because anyone can build one. Reports the envelope's commitment scheme: a legacy v1 envelope, whose hashes are unsalted, carries the warning unsalted-v1. Does not reveal or infer raw task data.Not declared
verify_tokenVerify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.Not declared

Change history

  1. verify_agent_run_proof: input schema changed (+expected_audience, +run_proof_token)
  2. verify_agent_run_proof: description changed (+"an Obelisk run proof. Pass run_proof_token," +"token Obelisk signs at POST /api/agent-proof/run: the tool checks Obelisk's signature against its published keys, that the named" +"is active now with the same key that answered the run challenge, and which")
Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registrycom.obeliskgate/trust-tools2 Oct 20267 Oct 20261