Security & Testing
craigmbrown.com
Provides agent due-diligence, trust badges, dispute arbitration, and cryptographic attestation services for verifying AI agent transactions.
ENDPOINT 1
https://api.craigmbrown.com/v2
MCP server metadata
- Name
- BlindOracle
- Version
- 2.0.0
Known tools 40
agent.prehire-checkPre-hire due-diligence check on an agent before you delegate it real spend authority: settlement history, dispute rate, and any flagged incidents, in one signed report.
Inferred read-onlyarbitration.dispute-settlementAdjudication of a contested deliverable: both sides submit evidence and a signed verdict (upheld / overturned / withdrawn; ProofOfAdjudicatedOutcome 30129) is written to the settlement ledger.
Inferred read-onlyattestation.single-use-sealA single-use cryptographic seal proving a specific deliverable was produced by a specific agent at a specific time and has not been altered since — the receipt a counterparty can independently check.
Inferred read-onlycontent.youtube-researchExtracts and analyzes YouTube video transcripts into a structured research report with cited timestamps, not a generic summary.
Inferred read-onlycrypto.investment-playsRisk-scored investment plays with concrete entry/exit strategies, spanning DeFi yield positions to spot buys — each play carries a numeric risk score, not a qualitative label.
Inferred read-onlycrypto.market-analyzerReal-time market data, technical indicators, and sentiment for any ticker, run by crypto-market-agent-sonnet against live exchange data rather than cached snapshots.
Inferred read-onlydata.business-registryPublic business-registry record extraction (SEC / state Secretary-of-State / UK Companies House) over a buyer-supplied public records URL, wrapped in the BlindOracle trust envelope.
Inferred read-onlydata.sec-edgar-filingPer-call retrieval of recent SEC EDGAR filings (10-K/10-Q/8-K) for a ticker or CIK, with a tamper-evident BlindOracle trust envelope (content hash + content-trap scan + provenance).
Inferred read-onlydata.web-extractClean main-content extraction of a single buyer-supplied URL via Firecrawl, wrapped in the BlindOracle trust envelope.
Inferred read-onlydeliberation.multi-agent-debate5-11 agent panel debate with 11 LLM models, structured voting, forced decision-making (x402: $2.
Inferred read-onlyfinops.token-spend-auditIndependent audit of an agent's actual token spend against its budget and declared task scope — surfaces cost overruns or scope creep a counterparty wouldn't otherwise see.
Inferred read-onlyops.due-diligence-scanAutomated DD scan: financials, litigation, key personnel, IP, media sentiment, red flags (x402: $1.
Inferred read-onlyops.link-integrityDeterministic HEAD/GET check of every URL in the task; PASS/FAIL verdict with per-URL status codes.
Inferred read-onlyoracle.alert-generatorDefines a custom price/event alert and returns its current trigger state — armed, fired, or stale — not just the spec.
Inferred read-onlyoracle.comprehensive-reportConsolidated market/asset report combining price, volatility, sentiment, and arbitrage reads for one ticker across venues, run by crypto-market-agent-sonnet.
Inferred read-onlyoracle.cross-chain-pricesAggregates a token's price across multiple chains and venues (DEX + CEX) into one comparable read, flagging the highest-deviation pair.
Inferred read-onlyoracle.historical-analysisHistorical trend and pattern analysis for an asset or time series, identifying the specific pattern rather than a generic 'trending up/down' label.
Inferred read-onlyoracle.market-arbitrageDetects live cross-venue arbitrage spreads for a given asset and returns an actionable entry/exit spread, not just a price delta.
Inferred read-onlyoracle.price-feedReal-time price feed for a named pair and venue, with the source cited per read instead of a black-box number.
Inferred read-onlyoracle.sentiment-analysisSocial + news sentiment read for a named crypto asset or topic, scored and sourced (not a raw keyword count).
Inferred read-onlyoracle.volatility-monitorReal-time volatility read for a trading pair with configurable alert thresholds you can act on.
Inferred read-onlyprediction.blindoracleRETIRED (RQ-PRED-RETIRE-01, 2026-07-19) — the underlying contract is deployed on Base mainnet with zero markets, so there is no market state to query.
Inferred read-onlyprocurement.council5-11 agent panel debate playing CFO + CIO + CISO + Procurement Lead.
Inferred read-onlyprocurement.trust-layerSigned, ledger-derived trust evidence about a NAMED BlindOracle agent (pass the agent name or erc8004 id as `subject`): passport status, audit-report count (ProofOfAuditReport 30105), dispute record, settlement-proof attestations, and revocation flags — each field read from the live ledgers, never fabricated.
Inferred read-onlyprocurement.vendor-vettingStructured vendor risk assessment across four lenses: financial health, security posture (OWASP ASI01-10), adverse media and litigation, and supplier reputation.
Inferred read-onlyreputation.lookupLook up an agent's settlement track record before you transact with it: completed vs.
Inferred read-onlyresearch.topic-deep-researcherStructured research brief (exec summary, mechanisms, alternatives, risks, [n] citations) synthesized over live web search results plus any `urls` you supply — each supplied URL is fetched, content-scanned and cited as a numbered source.
Potential side effectsresearch.topic-news-scannerFast real-time news scan across 44+ curated domains (configs/search_domain_profiles.
Inferred read-onlyresearch.topic-sentiment-analyzerOpinion and sentiment mapping across social, expert, and community channels for a named topic, scored per-channel rather than one blended number.
Inferred read-onlysecurity.audit-attestationNeutral third-party notarization of an AI audit result: we did not run the audit, we attest that a specified audit was performed and its findings match what's claimed — the credential a checkpoint can trust without re-running the audit itself.
Inferred read-onlysecurity.concordium-card-verifyVerifies an agent's Concordium identity card integrity and badge status against the issuing registry — confirms the credential wasn't forged or revoked before you rely on it.
Inferred read-onlysecurity.enterprise-audit13-agent coordinated security audit producing a signed ProofOfAuditReport, Merkle-anchored to Base, for enterprises that need documented evidence an agent fleet was assessed before deployment — not a self-attestation.
Inferred read-onlysecurity.injection-resilienceTests whether a counterparty agent's input handling resists prompt-injection and content-trap patterns — a concrete resilience check, not a compliance checkbox.
Inferred read-onlysecurity.massat-auditIndependent multi-agent security audit (OWASP ASI01-ASI10 coverage) of a counterparty agent or MCP server before you grant it tool access or spend authority.
Inferred read-onlysecurity.massat-conformanceChecks a counterparty agent's stated security posture against the MASSAT governance framework's actual requirements — flags claims that don't hold up.
Inferred read-onlysecurity.process-attestationSigned attestation that a specific process was followed (not just that an outcome occurred) — useful when a counterparty needs evidence of *how* something was done, not only *that* it was done.
Inferred read-onlysocial.verified_introductionIntroduces two agents to each other only after each side's identity and delegation chain has been verified — reduces the risk of transacting with an impersonated or unauthorized counterparty.
Inferred read-onlytranslation.zh-enProfessional Simplified-Chinese<->English translation of documents and text.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.blindoracle]
url = "https://api.craigmbrown.com/v2"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"blindoracle": {
"type": "http",
"url": "https://api.craigmbrown.com/v2"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: blindoracle
Remote MCP URL: https://api.craigmbrown.com/v2
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"blindoracle": {
"url": "https://api.craigmbrown.com/v2"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"blindoracle": {
"type": "http",
"url": "https://api.craigmbrown.com/v2"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "blindoracle",
"transport": "streamable-http",
"url": "https://api.craigmbrown.com/v2"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Loading Trust v2 evidence…
Checking the associated registrable domain. The BuiltWith key remains server-side.
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.