A zero-dependency MCP server over stdio that serves scvd.store's five free x402 verifier tools — preflight, receipt verification, readiness lookup, defect definitions, artifact verification — to any MCP client.
Single tool 'buy_spot_check' with well-structured definition. Tool name is action-verb-based and clear. Input schema present with all three parameters typed as strings and described. Description explains purpose (purchasing certificate with specific data) but could be more LLM-optimized regarding when/why to call it. No output schema documented, critical gap. Error handling not visible in definition. Risk classification (READ_ONLY) present and appropriate, suggesting some security awareness.
Purchase a spot check certificate for a specified host, containing recorded rounds, verdicts, observation dates, coverage, and explicit gaps from the observatory's books.
Output schema not documented. LLMs cannot plan downstream operations or extract returned certificate data without knowing the response structure.
Tool description (84 chars) lacks guidance on when to use vs. alternatives. Does not explain prerequisites, expected inputs, or what data the certificate contains. No dependency hints for multi-step flows.
No error handling guidance visible. What errors can occur? (invalid host, invalid agent_name length, payment failure?). Descriptions should include 'this may fail if...' and recovery hints.
Parameter 'agent_name' constraint (up to 80 characters) buried in description text, not formalized in schema as maxLength. Machine-parseable constraints are better than prose.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 77 | 2025-06-18+ | v2 |
Parameter 'purpose' constraint (up to 280 characters) also prose-only. Should be in schema as maxLength property.
No validation guidance. What makes a 'bare hostname' valid? (no protocol, no path? TLD required?). Without explicit format constraints, LLMs may pass malformed hosts.