CanopiiCanopiiAll serversEnterprise →
xyz.558686.gpt55/token-gateway

xyz.558686.gpt55/token-gateway v2026.7.20

Security Trust Score
Grade D · Weak posture
Tier 1 · Public sourceLow confidence · 28%
Declared MCP capabilities
ResourcesPrompts

This server scored D. Run it behind runtime policy enforcement so one bad tool call can't become an incident.

Security controls

Deterministic, evidence-backed. Score earned from passing controls; a failed guard caps it.

Model–MCP Runtime Guardrails

  • Warn
    Tool Definition Integrityguard20 tool description(s) drifted after publish (no risk signals in diff)

    Every consecutive version pair is diffed for new injection markers or destructive scope — a risky diff anywhere in history is a rug-pull (fail, durable); benign description drift warns.

    chat_standardgpt55_summarizegpt55_translategpt55_translate_get

    Fix: Never add hidden directives or destructive scope to an already-published tool; document description changes in release notes.

  • Pass
    Indirect Prompt Injection (IPI) Defensesguardno injection markers

    Tool/prompt/resource text is free of hidden instructions that could hijack the agent.

  • Pass
    User-in-the-Loop / Approval Scopeguardno destructive tool scope

    No over-broad or destructive tools (arbitrary shell, bulk-delete) that warrant human approval.

  • Not checked
    Strict JSON Schema Enforcementno source files

    Tool inputs are constrained (additionalProperties:false), so unexpected arguments can't be smuggled in.

Application Security Checks

  • Not checked
    No command-injection sinksguardno source

    Untrusted tool input reaching a shell yields remote code execution.

  • Not checked
    No dynamic code executionguardno source

    eval()/exec()/Function() on tool-derived strings allows arbitrary code execution.

  • Not checked
    No path traversalguardno source

    Naive path checks let tools read/write outside intended directories (EscapeRoute-class).

  • Not checked
    No SSRF sinksguardno source

    Fetching tool-supplied URLs can pivot into internal networks and metadata services.

  • Not checked
    No unsafe deserializationguardno source

    pickle/yaml.load/etc. on untrusted data can execute code.

  • Not checked
    No committed secretsguardno source

    Hardcoded keys/tokens in published source are live credentials an attacker can use.

  • Not checked
    Credentials sourced from environmentno source files

    Reading secrets from env/secret stores avoids hardcoding them.

  • Not checked
    Dependencies pinned (lockfile)no source files

    A lockfile makes installs reproducible and resistant to silent dependency swaps.

  • Not checked
    Actively maintainedGitHub API unavailable

    Unmaintained servers don't receive security fixes.

  • Not checked
    Repository not archivedguardGitHub API unavailable

    Archived repositories will never be patched.

  • Not checked
    Declares a licenseGitHub API unavailable

    A clear license is required for legal enterprise use.

  • Not checked
    Has a security policyno source files

    A SECURITY.md gives a private path to report vulnerabilities.

  • Not checked
    Signed releasesnot evaluated

    Signed releases let consumers verify artifacts weren't tampered with.

  • Not checked
    Adoption & popularityno adoption signal

    A small, capped nudge from stars/downloads — widely-used servers get more eyes on bugs. It can never offset a real security failure.

  • N/A
    No known-vulnerable dependenciesno dependencies to scan

    Runtime dependencies (parsed from the lockfile) are scanned against OSV.dev for published CVEs. Advisory: flagged dependencies lower the score but don't hard-cap it, since transitive reachability is unproven.

  • N/A
    No install/post-install scriptsguardno published package

    install hooks run arbitrary code on every consumer at install time.

  • N/A
    Package name not typosquattingguardno published package

    Names mimicking popular packages are a common malware delivery vector.

  • N/A
    Published with provenanceno published package

    Build provenance attests the artifact was built from the claimed source by CI.

  • N/A
    Established maintainerno published package

    Brand-new / single anonymous maintainers raise takeover and malware risk.

Transport & Trust Model

  • Warn
    IAM / Authentication Scopingno authentication handling detected

    OAuth 2.1 / Protected Resource Metadata gates who can invoke tools.

    Fix: Implement OAuth 2.1 with a .well-known/oauth-protected-resource document.

  • Pass
    Transport Encryption (TLS)guardall remotes use HTTPS

    Plaintext HTTP exposes traffic and bearer tokens to interception.

  • Not checked
    Execution Sandboxingno source files

    A container/sandbox image limits blast radius; a server that runs natively has full host access.

  • Not checked
    Network Exposureno source files

    Binding 0.0.0.0 or exposing debug inspectors widens the attack surface.

  • N/A
    Live Endpoint Reachablenot dynamically scanned

    A dynamic scan connected to the declared remote endpoint and it responded — verified live, not a dead URL.

  • N/A
    Authentication Enforced (live)not dynamically scanned

    If the server declares auth is required, it must actually reject anonymous clients. Serving tools to unauthenticated callers is a real exposure.

Tools (216)

gpt55_uuidchat_gpt_5_4chat_gpt_5_5gpt55_answerchat_standardgpt55_rewritegpt55_slugifygpt55_url_textgpt55_uuid_getgpt55_hash_textgpt55_json_keysgpt55_summarizegpt55_timestampgpt55_translategpt55_uri_codecgpt55_url_linksgpt55_url_parsegpt55_x402_pinggpt55_diff_linesgpt55_html_stripgpt55_jwt_decodegpt55_sort_linesgpt55_text_statschat_gpt_5_6_lunachat_gpt_5_6_soulgpt55_answer_minigpt55_answer_plusgpt55_code_reviewgpt55_http_statusgpt55_json_minifygpt55_query_parsegpt55_regex_matchgpt55_slugify_getchat_gpt_5_3_codexchat_gpt_5_6_terragpt55_base64_codecgpt55_case_convertgpt55_extract_jsongpt55_rewrite_minigpt55_rewrite_plusgpt55_unique_linesgpt55_url_metadatagpt55_url_text_getgpt55_balance_topupgpt55_color_convertgpt55_hash_text_getgpt55_json_keys_getgpt55_json_validategpt55_summarize_progpt55_timestamp_getgpt55_translate_getgpt55_translate_progpt55_uri_codec_getgpt55_url_links_getgpt55_url_parse_getgpt55_diff_lines_getgpt55_domain_extractgpt55_html_strip_getgpt55_jwt_decode_getgpt55_sort_lines_getgpt55_summarize_minigpt55_summarize_plusgpt55_text_stats_getgpt55_translate_minigpt55_translate_plusgpt55_answer_standardgpt55_code_review_progpt55_email_normalizegpt55_http_status_getgpt55_json_minify_getgpt55_query_parse_getgpt55_regex_match_getgpt55_translate_batchgpt55_x402_site_auditgpt55_base64_codec_getgpt55_case_convert_getgpt55_code_review_minigpt55_code_review_plusgpt55_rewrite_standardgpt55_unique_lines_getgpt55_url_metadata_getgpt55_color_convert_getgpt55_extract_json_minigpt55_extract_json_plusgpt55_html_entity_codecgpt55_json_validate_getgpt55_domain_extract_getgpt55_summarize_standardgpt55_translate_standardgpt55_x402_bazaar_searchgpt55_answer_professionalgpt55_email_normalize_getgpt55_x402_site_audit_getgpt55_code_review_standardgpt55_rewrite_professionalgpt55_x402_buyer_shortlistgpt55_x402_quote_inspectorgpt55_extract_json_standardgpt55_html_entity_codec_getgpt55_x402_market_benchmarkgpt55_summarize_professionalgpt55_translate_professionalgpt55_x402_bazaar_search_getgpt55_x402_listing_seo_auditgpt55_x402_opportunity_findergpt55_x402_prepay_trust_checkgpt55_x402_seller_action_plangpt55_code_review_professionalgpt55_x402_buyer_shortlist_getgpt55_x402_mcp_integration_kitgpt55_x402_quote_inspector_getgpt55_extract_json_professionalgpt55_x402_market_benchmark_getgpt55_x402_receipt_dispute_packgpt55_wallet_signing_safety_packgpt55_x402_agent_spend_simulatorgpt55_x402_batch_quote_inspectorgpt55_x402_listing_seo_audit_getgpt55_x402_directory_rank_trackergpt55_x402_opportunity_finder_getgpt55_x402_payment_failure_doctorgpt55_x402_prepay_trust_check_getgpt55_x402_revenue_recovery_agentgpt55_x402_seller_action_plan_getgpt55_evm_transaction_risk_decodergpt55_x402_buyer_prepay_risk_scoregpt55_x402_discovery_price_comparegpt55_x402_mcp_integration_kit_getgpt55_eip712_signature_risk_decodergpt55_x402_crawler_monetization_kitgpt55_x402_receipt_dispute_pack_getgpt55_wallet_signing_safety_pack_getgpt55_x402_agent_task_receipt_outboxgpt55_x402_batch_quote_inspector_getgpt55_x402_buyer_client_adapter_packgpt55_balance_metered_chat_completiongpt55_x402_agent_core_integration_kitgpt55_x402_agentic_api_red_team_briefgpt55_x402_directory_rank_tracker_getgpt55_x402_payment_failure_doctor_getgpt55_x402_seller_intelligence_bundlegpt55_evm_transaction_risk_decoder_getgpt55_sub2api_balance_ledger_simulatorgpt55_sub2api_official_metered_invoicegpt55_x402_agent_payment_approval_packgpt55_x402_buyer_prepay_risk_score_getgpt55_x402_discovery_price_compare_getgpt55_x402_mcp_enterprise_rollout_packgpt55_x402_mcp_production_launch_auditgpt55_x402_payment_retry_slo_autopilotgpt55_x402_payment_slo_monitoring_packgpt55_x402_verify_settle_recovery_packgpt55_eip712_signature_risk_decoder_getgpt55_x402_agent_spend_recurrence_guardgpt55_x402_client_compatibility_adaptergpt55_x402_crawler_monetization_kit_getgpt55_x402_model_sla_breach_claims_packgpt55_x402_paid_api_contract_test_suitegpt55_x402_receipt_bound_execution_gategpt55_gpt55_plus_half_price_subscriptiongpt55_x402_agent_payment_policy_compilergpt55_x402_bazaar_listing_revenue_repairgpt55_x402_conversion_forensics_war_roomgpt55_x402_directory_trust_evidence_packgpt55_x402_mcp_tool_revenue_share_ledgergpt55_x402_model_arbitrage_router_policygpt55_x402_paid_mcp_authorization_bridgegpt55_x402_seller_price_ladder_optimizergpt55_x402_agent_core_integration_kit_getgpt55_x402_base_builder_funding_readinessgpt55_x402_flowise_payment_node_blueprintgpt55_x402_seller_intelligence_bundle_getgpt55_x402_wallet_receipt_accounting_packgpt55_x402_agent_wallet_key_rotation_drillgpt55_x402_buyer_payment_execution_runbookgpt55_x402_mcp_entitlement_receipt_gatewaygpt55_x402_private_gateway_deployment_plangpt55_x402_procurement_vendor_risk_dossiergpt55_x402_wallet_funding_readiness_doctorgpt55_x402_wallet_payment_activation_agentgpt55_x402_agent_approval_workflow_compilergpt55_x402_agent_data_leak_containment_plangpt55_x402_agent_payment_due_diligence_packgpt55_x402_client_compatibility_adapter_getgpt55_x402_data_room_receipt_redaction_packgpt55_x402_directory_compliance_repair_packgpt55_x402_model_procurement_benchmark_packgpt55_x402_wallet_drain_prevention_firewallgpt55_x402_agent_treasury_rebalancing_policygpt55_x402_mcp_asset_inventory_risk_registergpt55_github_repository_supply_chain_evidencegpt55_x402_base_builder_funding_readiness_getgpt55_x402_refund_dispute_resolution_playbookgpt55_x402_soc2_payment_control_evidence_packgpt55_x402_agent_credit_line_underwriting_packgpt55_x402_agent_procurement_rfp_response_packgpt55_x402_agent_wallet_incident_response_packgpt55_x402_ai_crawler_license_enforcement_packgpt55_x402_enterprise_buyer_onboarding_dossiergpt55_x402_settlement_dispute_evidence_lockboxgpt55_x402_wallet_funding_readiness_doctor_getgpt55_x402_wallet_payment_activation_agent_getgpt55_x402_agent_payment_authorization_ato_packgpt55_x402_agent_payment_due_diligence_pack_getgpt55_x402_autonomous_procurement_policy_enginegpt55_x402_customer_support_refund_triage_agentgpt55_x402_directory_compliance_repair_pack_getgpt55_x402_cross_chain_payment_failover_playbookgpt55_x402_mcp_tenant_entitlement_isolation_packgpt55_x402_seller_revenue_leakage_forensics_packgpt55_x402_agent_market_data_procurement_firewallgpt55_x402_payment_tax_invoice_reconciliation_kitgpt55_x402_usage_quota_billing_reconciliation_agentgpt55_x402_agent_runbook_compliance_attestation_packgpt55_x402_buyer_payment_client_implementation_sprintgpt55_x402_enterprise_security_questionnaire_autofill

AI-flagged — for review

Observations from an AI review of tool descriptions. These are advisory only and do not affect the score — they can be noisy and need human judgement.

  • info
    Tool "chat_standard" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

  • info
    Tool "gpt55_summarize" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

  • info
    Tool "gpt55_translate" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

Show 5 more