Skip to main content
Glama
README.md
# FabTally Guard — MCP server

De-risk-a-dollar verification checks an AI agent runs **before** a costly action.
Fronts the Guard HTTP API at **https://guard.fabtally.com**. Holds no private key.

## Tools (all paid; a call with no payment returns the decoded x402 402 challenge)

| Tool | Price | What it does |
|------|-------|--------------|
| `deps_check` | $0.003 | Vet a package before installing — OSV.dev CVEs, typosquat similarity, deprecation/yank, SPDX license, age/download signals + a plain-English risk verdict. Args: `ecosystem` (npm\|pypi\|crates), `name`, `version?`. |
| `x402_preflight` | $0.002 | Verify another x402 endpoint before paying it — valid x402 v2 402 challenge? price/asset/network/payTo consistent with its `/.well-known/x402`? TLS/reachability/openapi? + the parsed price. Args: `url`. |
| `json_repair` | $0.002 | Coerce near-miss LLM JSON to a JSON-Schema-conformant object (fences/commas/quotes/keys/literals/brackets, then type-coerce, defaults, drop extras) — or precise per-field errors. Args: `json` (string), `schema`. |
| `url_read` | $0.004 | Fetch a public url → clean Markdown + token estimate for RAG. Respects robots.txt, public pages only, nothing stored. Args: `url`. |

Every tool also accepts an optional `x_payment` (base64 x402 payload) that is
forwarded as the `X-PAYMENT` header to settle the call and return the real result.
Humans can instead prepay by card and use an `X-FabTally-Key` credit key against
the HTTP API.

## Transports

- **stdio** (portable): `npx fabtally-guard-mcp` (bin: `fabtally-guard-mcp`)
- **streamable-http** (hosted): `https://guard.fabtally.com/mcp`

Config: `FABTALLY_GUARD_BASE` (default `https://guard.fabtally.com`).

Read-only, keyless, stateless, descriptive. Operated by Sunstone Soft
(fabtally.com). Not a security guarantee.

TDQS

A4.5/5.0

Scored across 4 tools

Disambiguation5/5

Each tool targets a completely different function: dependency vetting, x402 endpoint verification, JSON repair, and URL reading. There is no overlap or potential for confusion between them.

Naming Consistency5/5

All tool names follow the same lower_snake_case pattern with an object followed by a verb: deps_check, x402_preflight, json_repair, url_read. The convention is uniform and predictable.

Tool Count5/5

With four tools, the server is well-scoped for its purpose. Each tool provides a distinct utility without redundancy, making the set feel intentional and complete.

Completeness5/5

The tool surface covers a coherent set of guardrail functions: vetting packages, validating payment endpoints, repairing LLM JSON output, and sanitizing URLs for ingestion. There are no obvious missing operations for this domain.

Maintenance

ActivitySlowing
ResponsivenessNo issues