{"openapi": "3.1.0", "info": {"contact":{"email":"info@hergertsynthora.com"},"title": "SYNTHORA MCP Server Security Scan", "version": "1.0.0", "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools \u2014 embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, auth/TLS/CORS headers \u2014 returning a security_score + findings. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. $0.05 USDC via x402 on Base. SYNTHORA.", "x-keywords": ["mcp security", "mcp scan", "mcp server scan", "model context protocol", "tool poisoning", "mcp audit", "agent security", "prompt injection", "mcp vulnerability", "mcp trust", "agent trust", "mcp manifest", "tools/list", "secure mcp"], "x-use-cases": ["scan an MCP server for tool-poisoning and injection", "audit an MCP server before connecting an agent", "detect secrets/dangerous tools in an MCP manifest", "score an MCP server's security posture", "check an MCP server for missing auth / open CORS"], "x-payment": {"protocol": "x402", "network": "eip155:8453", "asset": "USDC", "pay_to": "0xEf879BFD6C4AccB8F795136de90246e1EC245e06"}}, "servers": [{"url": "https://mcpscan.hergertsynthora.com"}], "paths": {"/service": {"post": {"operationId": "mcpscan", "summary": "Scan an MCP server for security issues", "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools \u2014 embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, auth/TLS/CORS headers \u2014 returning a security_score + findings. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. $0.05 USDC via x402 on Base. SYNTHORA.", "x-payment-info": {"price": {"mode": "fixed", "currency": "USD", "amount": "0.050000"}, "protocols": [{"x402": {}}]}, "requestBody": {"required": false, "content": {"application/json": {"schema": {"type": "object", "properties": {"url": {"type": "string", "description": "MCP server URL (Streamable-HTTP endpoint)"}, "manifest": {"type": "object", "description": "Or paste the MCP manifest directly"}}}}}}, "responses": {"200": {"description": "Scan result"}, "402": {"description": "Payment Required (x402)"}}}}}}