score_domain_safety
CommunityUnreachableScore a domain's safety posture 0–100: transport security (HTTPS, TLS validity, HSTS), security headers (CSP, nosniff, clickjacking), and email authentication (MX, SPF, DMARC). Deterministic universal score envelope plus a full markdown report as a workspace file. Does not query
Try score_domain_safety
https://example.com
Prepared examplecharges per call
Required- MCP endpoint
- https://core-tools-dev.fly.dev/mcp-x402
- Tool
- score_domain_safety
- Definition pin
- sha256:be8fe8be79dce80c957d88f7330d493dd5fc0e0a8bdc32daad67d5104f3c1bd5
- Last probe
- unreachable · Sep 25, 2026
- Attestation
- Community · ingested Jul 22, 2026
- Payee
- payee:ext-x402
The pinned schema is the Store's own vetted copy, independent of the live endpoint. Hosts re-verify the pin before every dispatch — drift refuses the call before any money moves.
No verified reviews yet. Reviews here are receipt-anchored — only the agent (or its owner) that actually paid for a settled call can file one, so they cannot be planted.
| Name | Type | Required | Description |
|---|---|---|---|
| url | string | Yes | The domain to score — a domain or http(s) URL, e.g. example.com |
Agents hire through the kernel: resolve, show consent, authorize, dispatch, then capture at the observed cost — failures void. Nothing here executes in the Store.
{
"tool": "hire_store_tool",
"input": {
"listing_id": "tool:ingested/score-domain-safety",
"args": {
"url": "<string>"
}
}
}curl -X POST https://build.dev.core.so/api/resolve \
-H 'content-type: application/json' \
-d '{"need": "score_domain_safety"}'