{"uid":"cap_FtWJwsTZVd-J6B7aX8MNy","slug":"blockchain-money-map-mcp-paid-tool-permission-scope-auditor-ff573803","name":"Blockchain Money Map MCP Paid Tool Permission Scope Auditor","description":"Choose Blockchain Money Map for human-readable public blockchain reports or x402-paid agent API services.","url":"https://api.blockchainmoneymap.com/api/x402/x402-mcp-paid-tool-permission-scope-auditor","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"mode":{"enum":["audit"]},"facts":{"type":"object","required":["tool_name","tool_description","input_schema","declared_permission_scope","paid_operation_description"],"properties":{"tool_name":{"type":"string","maxLength":500},"input_schema":{"type":"object","maxProperties":50,"additionalProperties":true},"tool_description":{"type":"string","maxLength":500},"declared_permission_scope":{"type":"string","maxLength":500},"paid_operation_description":{"type":"string","maxLength":500},"destructive_action_declared":{"type":"boolean"}},"additionalProperties":false},"policy":{"type":"object","additionalProperties":true},"reference_facts":{"type":"object","required":["tool_name","tool_description","input_schema","declared_permission_scope","paid_operation_description"],"properties":{"tool_name":{"type":"string","maxLength":500},"input_schema":{"type":"object","maxProperties":50,"additionalProperties":true},"tool_description":{"type":"string","maxLength":500},"declared_permission_scope":{"type":"string","maxLength":500},"paid_operation_description":{"type":"string","maxLength":500},"destructive_action_declared":{"type":"boolean"}},"additionalProperties":false}}},"responseSchema":{"type":"json"},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_02Aqdl3XoRXvobCrkez3D","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits an MCP tool's declared permission scope and paid operation description against reference facts to detect drift, misrepresentation, or unauthorized scope expansion.","exampleAgentPrompt":"Audit this MCP tool for permission scope drift — the tool is called 'TransferFunds', its description says 'moves funds between wallets', its declared permission scope is 'read:wallet write:transfer', the paid operation description is 'executes on-chain token transfer', and compare it against the reference snapshot I registered last week where the scope was 'read:wallet' only. Flag any expansion or undeclared destructive actions.","exampleUseCases":[{"title":"Catch silent permission scope expansion","prompt":"I need to audit our 'SendEmail' MCP tool — its current declared scope is 'read:contacts write:email delete:email' but the reference version only had 'read:contacts write:email'. The tool description says 'sends and manages emails', the paid operation is 'delivers email via SMTP', and no destructive action was declared. Check if this scope expansion is a problem."},{"title":"Validate new tool before deployment","prompt":"Before we deploy this new MCP tool called 'QueryLedger', can you audit it? Its description is 'queries blockchain transaction history', input schema accepts wallet_address and date_range, declared permission scope is 'read:ledger', paid operation description is 'returns paginated tx history', and destructive_action_declared is false. Compare it against the approved reference spec and tell me if everything checks out."},{"title":"Policy compliance check for agent marketplace","prompt":"We're listing a tool called 'RevokeAccess' on our agent marketplace — its declared scope is 'write:permissions', paid operation is 'removes user access tokens', and destructive_action_declared is false. Audit this against our policy that any tool with write:permissions must declare destructive actions, and flag any violations."}],"resultDescription":"Returns a JSON audit result indicating whether the submitted tool facts match the reference facts, highlighting any permission scope drift, undeclared destructive actions, schema mismatches, or policy violations. Typically includes a compliance verdict, a list of specific discrepancies found, and severity indicators for each flag.","failureModes":["Missing required fields in facts or reference_facts objects returns a validation error","Mismatched schema structure between facts and reference_facts may cause incomplete diff results","Payment failure via x402 returns 402 with payment details before audit is performed","Overly large input schemas (beyond 50 properties) are rejected by schema constraints","Ambiguous or truncated tool descriptions may reduce audit accuracy"],"whenToPreferThis":"Choose this endpoint when you need to programmatically verify that an MCP tool's declared permission scope has not drifted from a known-good reference state, especially in agentic pipelines where tool definitions could be tampered with or silently updated. It is particularly valuable for marketplace operators, agent orchestrators, or security-conscious deployments that need continuous compliance validation of paid MCP tools before execution.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:43:21.223Z","isFirstParty":false}