{"uid":"cap_gfuBKxQjAsn6s1mIWc6fa","slug":"witness-mcp-tool-surface-drift-detector-def83a60","name":"Witness MCP Tool Surface Drift Detector","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/mcp-diff","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"fail","endpoint":"mcp-diff","findings":[{"code":"TOOL_CHANGED","detail":"\"search\" has the same name and a different definition. A rewritten description is still schema-valid, so a conformance check will not see this.","severity":"change"}]}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_3V4F_YoTxE10K7sySohVQ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Compares an MCP server's current tools/list against a signed baseline digest and returns a cryptographically signed attestation listing every tool added, removed, or silently redefined.","exampleAgentPrompt":"Check whether the MCP server at https://tools.example.com/mcp has drifted from our pinned baseline — compare its current tools/list against the baseline digest we stored last week and give me a signed attestation of anything added, removed, or quietly changed.","exampleUseCases":[{"title":"Nightly MCP integrity audit","prompt":"Every night, diff the MCP server at https://agents.myplatform.io/mcp against the baseline digest we pinned on Monday and alert me if any tools were added, removed, or had their descriptions rewritten — I need a signed attestation I can log."},{"title":"Detect silent tool redefinition","prompt":"I'm worried someone may have rewritten the 'search' tool's description on our MCP server without changing the schema — can you hit https://mcp.internal.co/stream and compare it against our stored baseline to see if anything was silently redefined?"},{"title":"Pre-deployment tool surface check","prompt":"Before we promote this MCP server build to production, run a diff between its current tools/list and the approved baseline digest from our last release and tell me the verdict with a signed proof I can attach to the deployment record."}],"resultDescription":"A JSON object containing an ed25519-signed attestation with a verdict ('pass' or 'fail'), the endpoint name, and a findings array. Each finding includes a code (e.g. TOOL_CHANGED, TOOL_ADDED, TOOL_REMOVED), a severity level, and a human-readable detail string explaining what changed. The signature includes the algorithm, base64-encoded value, and key ID for independent verification.","failureModes":["Unreachable MCP URL returns connection error with no attestation","Malformed baseline digest causes 400 validation error","MCP server returns non-standard tools/list format causing parse failure","Baseline missing required 'tools' field triggers schema rejection","Network timeout if target MCP server is slow to respond","Invalid or expired signing key returns attestation with unverifiable signature"],"whenToPreferThis":"Choose this endpoint when you need a cryptographically signed, auditable record of whether an MCP server's tool surface has changed — especially for supply-chain security, compliance logging, or catching silent prompt-injection via tool description rewrites. Prefer it over manual diffing or unattested comparisons when you need a tamper-evident artifact. It's the right choice when you already have a baseline digest from a prior /v1/mcp-digest pin call and want to detect drift with non-repudiable evidence.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T22:27:31.326Z","isFirstParty":false}