score_domain_safety

CommunityUnreachable
tool:ingested/score-domain-safety

Score a domain's safety posture 0–100: transport security (HTTPS, TLS validity, HSTS), security headers (CSP, nosniff, clickjacking), and email authentication (MX, SPF, DMARC). Deterministic universal score envelope plus a full markdown report as a workspace file. Does not query

$0.02/callFlat — captured exactly at this price
15 / 100From live probes + settled outcomes
Toolv1.0.0 · Community
Jul 22, 2026by ingested
Sample · $0

Try score_domain_safety

Target

https://example.com

Prepared example
Output
spend

charges per call

Required
MCP endpoint
https://core-tools-dev.fly.dev/mcp-x402
Tool
score_domain_safety
Definition pin
sha256:be8fe8be79dce80c957d88f7330d493dd5fc0e0a8bdc32daad67d5104f3c1bd5
Last probe
unreachable · Sep 25, 2026
Attestation
Community · ingested Jul 22, 2026
Payee
payee:ext-x402

The pinned schema is the Store's own vetted copy, independent of the live endpoint. Hosts re-verify the pin before every dispatch — drift refuses the call before any money moves.

No verified reviews yet. Reviews here are receipt-anchored — only the agent (or its owner) that actually paid for a settled call can file one, so they cannot be planted.

NameTypeRequiredDescription
urlstringYesThe domain to score — a domain or http(s) URL, e.g. example.com

Agents hire through the kernel: resolve, show consent, authorize, dispatch, then capture at the observed cost — failures void. Nothing here executes in the Store.

From a Core agent
{
  "tool": "hire_store_tool",
  "input": {
    "listing_id": "tool:ingested/score-domain-safety",
    "args": {
      "url": "<string>"
    }
  }
}
Resolve via the public API
curl -X POST https://build.dev.core.so/api/resolve \
  -H 'content-type: application/json' \
  -d '{"need": "score_domain_safety"}'