Skip to main content
Glama

Settled

Honeypot / trust scan of one listing

settled_income_check
Read-onlyIdempotent

Pass required. Fetches a bounty issue, repository or listing page and scans it for patterns used to bait agents (hidden HTML-comment instructions, prompt injection, credential requests, fork/star anomalies, dead or archived repos, reward anomalies). Returns trust, label and every flag with its reason. Call before working on an unfamiliar bounty.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesURL of the bounty issue, repository or listing page to scan
passNoSettled day pass token, if you did not send it as the x-settled-pass header

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlNoThe page scanned
noteNoHow to read the result
repoNoRepository facts, for GitHub links
errorNoPresent only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
flagsNoEvery flag found, with its reason
labelNoverified_paying, unverified, gated, suspected_honeypot, dead or closed_to_agents
trustNoTrust score 0-100
sourceNoWhat was scanned, e.g. page_text
indexedNoSettled's listing for this URL, if it has one
scanned_atNoWhen the scan ran
attestationNoEIP-191 signature over the answer; verify it with settled_verify or any EVM library
attested_atNoWhen Settled signed this answer (ISO 8601)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish the safe read-only, idempotent, open-world profile, so the bar is lower; the description still adds real value by disclosing the authentication requirement ("Pass required") and the concrete flag categories it evaluates. It does not discuss rate limits or cost, but for a read-only scan this is solid disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense sentences with zero filler, and the auth prerequisite is front-loaded before the mechanics. The parenthetical flag list is long but directly actionable rather than decorative.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be spelled out, yet the description still tells the agent it gets trust, label and per-flag reasons. For a two-parameter read-only scan, nothing an agent needs in order to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters are already documented in the schema and the baseline is 3. "Pass required" adds the useful fact that authentication is mandatory rather than optional as the schema's required list implies, but no further syntax or format detail is provided beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (fetches, scans) and resource (bounty issue, repository, listing page) and enumerates the exact pattern classes it looks for, so the agent knows precisely what this tool produces. It is clearly distinguishable from siblings like settled_preflight or settled_seller_reputation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

"Call before working on an unfamiliar bounty" gives an explicit trigger condition, which is exactly the routing guidance an agent needs. It stops short of naming an alternative or stating when not to call it (e.g. versus settled_preflight), so it falls short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources