Security & Testing
tunnelmind.ai
Provides surveillance intelligence data on domains and corporate entities.
ENDPOINT 1
https://mcp-data.tunnelmind.ai/mcp
MCP server metadata
- Name
- tunnelmind-data-api
- Version
- 1.0.0
TunnelMind Data API — surveillance intelligence. Use search() to find domains/entities, get_domain() for full records, intel_* for live probes. Pass Authorization: Bearer <key> for authenticated access. The tunnelmind_analyst prompt (prompts/get) returns the full BYOM config bundle to configure any LLM as a TunnelMind analyst.
Known tools 93
get_domainReturns the complete surveillance intelligence record for a domain name.
Inferred read-onlyget_entityReturns an entity record for a surveillance company or data broker, including its industry, estimated annual data value per user (in USD), categories of personal data collected, and the full list of domains it controls.
Inferred read-onlylist_entitiesReturns a paginated list of corporate entities in the TunnelMind surveillance database.
Inferred read-onlyintel_httpMakes a live HEAD request to the target domain from the Cloudflare edge, follows up to 5 redirects, and returns the full redirect chain, final HTTP status, key response headers, a security header score, and any third-party surveillance actors referenced in the Content-Security-Policy header.
Inferred read-onlyintel_stackFetches up to 32KB of the domain's HTML and response headers from the edge, then fingerprints the content for known CMS platforms, JavaScript frameworks, CDN providers, and analytics tools.
Inferred read-onlyintel_injectFetches a domain's homepage and checks for content patterns that could constitute prompt injection attacks against AI agents that visit and ingest the page.
Inferred read-onlyintel_optoutChecks a domain for all known AI training data opt-out mechanisms beyond robots.
Inferred read-onlyget_receiptReturns metadata for a TunnelMind surveillance receipt — a signed document proving that a specific user's surveillance exposure was observed, measured, and recorded at a specific time.
Inferred read-onlycreate_free_keySelf-serve free tier — the rung between anonymous access and paid blocks.
Inferred read-onlyget_api_keyReturns the tier, label, masked owner email, creation date, last-used timestamp, today's request count, and daily request limit for the API key used in this request.
Potential side effectsstream_taskOpens a persistent SSE connection that emits events as the task progresses.
Inferred read-onlygenerate_receiptLooks up each submitted domain in the TunnelMind tracker database, aggregates risk metrics (avg score, max score, fingerprinters, high-risk domains, entity ownership), and issues a signed surveillance receipt.
Inferred read-onlysigil_verify_ads_txtConfirms whether an SSP/exchange is authorized to sell a publisher's inventory according to that publisher's ads.
Inferred read-onlytractionLive traction numbers computed from sources the Worker owns: the hash-chained D1 audit log (7-day call volume, distinct identified callers, top operations), the stored-receipt table, and Stripe (succeeded charges → paying customers, gross USD).
Inferred read-onlysnapshot_diffJSONL diff vs the previous snapshot — apply +/~/- lines instead of re-pulling the corpus.
Inferred read-onlyagent_registries_lookupP75 registry aggregation: the cross-lens join applied to agent identity.
Inferred read-onlyverify_agentReconciles a claimed bot User-Agent against the operator's OWN published IP-range feed (Googlebot, GPTBot, OAI-SearchBot, ChatGPT-User, PerplexityBot, Perplexity-User, Bingbot).
Inferred read-onlylist_subscriptionsReturns the caller's active and inactive subscriptions (signing_key redacted).
Inferred read-onlyreceipt_log_sthP72 RFC 6962 transparency log over the unified receipt ledger (ADR-010).
Inferred read-onlyreceipt_log_inclusion_proofProves a specific receipt (by unified `receipt_id`, lens alias, or raw `leaf_index`) is included in the tree at `tree_size` (default: the latest STH's).
Inferred read-onlyreceipt_log_consistency_proofProves the log at size `second` is an append-only extension of the log at size `first` — history was never rewritten.
Inferred read-onlyreceipt_lookupP72 unified receipt ledger (ADR-010): every receipt-issuing surface (cross-lens verify, tracker verify, verdict, profile, explain, GhostRoute, Sigil/ATAP, compliance export) records the exact signed document it returned, keyed by one ID space.
Inferred read-onlyattributes_lookupP73 fast attributes endpoint (PIP-PLAN P3): a full `POST /v1/verify` resolve fans out across four lenses (~2s) — fine for preflight, fatal inside a per-request authorization loop.
Potential side effectstracker_verifyThe Tracker lens-owned verify surface: a per-node verdict over the normalized DDG Tracker Radar / IAB TCF / Disconnect.
Inferred read-onlysigil_verify_domainConfirms a publisher controls a domain by checking for a DNS TXT record the owner publishes under `_tunnelmind.
Inferred read-onlysigil_verify_ip_typeClassifies an IPv4 or IPv6 address by network type — the high-value ad-fraud signal being datacenter traffic posing as residential or living-room (CTV) devices.
Inferred read-onlysigil_verify_app_bundleVerifies that a mobile or CTV app bundle ID actually exists in the relevant app store — used to detect bundle spoofing in bid requests.
Inferred read-onlycross_lens_lookupReturns all three lens views for a single node key without computing a fused verdict.
Inferred read-onlypreflight_should_i_actThe single call an agent makes before transacting with a destination on the open web.
Inferred read-onlyprofile_entityCall this before routing traffic, bidding on inventory, or trusting a counterparty.
Inferred read-onlysignal_tracker_densityObserved component counts first, a labelled derived roll-up second.
Inferred read-onlysignal_dark_pool_riskReconciles every sell path a publisher declares (`sells_through`) against each SSP's own sellers.
Inferred read-onlysignal_halo_scoreScores an entity by the trust character of its neighbours — the SSPs its publishers sell through and the DSPs it buys through.
Inferred read-onlysignal_team_signalSurfaces other entities that operate as a coordinated team with this one: they share a NARROWLY-held direct seller account (2–8 entities — network house accounts shared by hundreds are separated into `house_accounts_excluded`, not counted) or co-own an exchange seat.
Inferred read-onlysigil_verify_tokenVerifies the authenticity and expiry of a `sigil_token` returned by `sigil_verify_supply_path`.
Inferred read-onlysigil_traverseReconstructs the supply paths for a publisher domain from Sigil's own crawl and returns them ITEMIZED — distinct from `sigil_verify_supply_chain` (which verifies a schain the caller brings) and from `signal_dark_pool_risk` (which returns only aggregate counts).
Inferred read-onlyget_statsOne public "state of the corpus" readout — the whole graph in a single call.
Inferred read-onlyget_website_historyThe over-time layer behind the site's website map (the radar's evolution).
Inferred read-onlyghostroute_checkGhostRoute is TunnelMind's fourth lens: routing-integrity / sovereignty verification.
Inferred read-onlyghostroute_verifyRetrieves a previously-issued, signed GhostRoute receipt by its GR-YYYY-NNNNNNN id, for independent audit of a past sovereignty verdict.
Inferred read-onlyghostroute_asn_lookupReturns GhostRoute's ownership-graph record for an autonomous system: the registrant/parent organisation, its HQ country and sovereign zone, RIR, and cloud/AI-infrastructure flags.
Inferred read-onlyghostroute_ai_lookupChecks whether a domain or ASN belongs to a known AI company's infrastructure and what sovereignty it CLAIMS (program, zone, HQ), the baseline GhostRoute scores routing reality against.
Inferred read-onlyghostroute_ct_witnessReturns GhostRoute's first-party Certificate-Transparency witness state: the latest signature-verified Signed Tree Head (STH) for every trusted, non-Google CT log TunnelMind independently witnesses, plus a regression scan over our own append-only history.
Inferred read-onlyghostroute_ct_proofsReturns GhostRoute's per-cert inclusion proofs: each is a cryptographic demonstration that the exact certificate a host serves is included in an append-only CT log whose root TunnelMind signature-verified — upgrading "a monitor said this cert exists" to "proven in a log we witness".
Inferred read-onlyghostroute_ct_alertsReturns the durable, deduplicated ledger of CT equivocation events the GhostRoute witness worker detects and pushes — a tree_size_rewind (an append-only log shrank), a root_fork (one tree_size witnessed with two different Merkle roots = a split-view log), or an sth_signature_invalid (a log's latest Signed Tree Head failed signature verification).
Inferred read-onlyget_bgp_eventsReturns the routing anomalies the bgp-monitor has observed against TunnelMind's BGP watchlist — the witnessability layer's routing dimension.
Inferred read-onlysigil_score_weightsReturns the active, versioned default weights used to combine an entity's trust-score components, plus the list of spec components that are not yet evaluated.
Inferred read-onlysigil_score_batchScores up to 200 entities in one round-trip — built for agents evaluating many supply sources during campaign setup.
Inferred read-onlysigil_atap_witnessIngests one agent-reported event (`bid:submitted`, `bid:won`, `bid:lost`, `budget:decremented`) into an AIT's hash-chained attestation log.
Inferred read-onlysigil_atap_roll_blockRolls every not-yet-blocked Witness Event for an AIT into one signed ATAP Attestation Block with a profile `period_summary`, chained onto the prior block.
Inferred read-onlysigil_atap_ait_statusReturns an AIT's status, chain head hash, event count, pending-event count, per-tier event counts, and the anchored-bid coverage ratio.
Inferred read-onlycompliance_profileReturns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.
Inferred read-onlycompliance_configureSet the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer.
Inferred read-onlycompliance_ledgerReturns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled.
Inferred read-onlycompliance_exportGenerates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint.
Inferred read-onlycompliance_verifyRecomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 checkpoint signed with the TunnelMind receipt key.
Inferred read-onlyscan_injectionRuns a curated signature corpus over a piece of untrusted text — content an agent is about to consume, a retrieved document, a tool result, an email body — and returns the matched injection patterns plus a bounded 0.
Potential side effectsscan_mcpConnect to a caller-supplied MCP server (Streamable-HTTP transport), read its advertised tools, and run the injection corpus over every tool name / description / input schema — plus a capability heuristic that flags broad, dangerous powers (shell execution, filesystem write, credential access, arbitrary network, destructive DB ops).
Potential side effectssubmit_feedbackClose the loop: after you acted on a TunnelMind verdict, tell us how it went.
Inferred read-onlyget_feedbackPublic read of the crowd-sourced outcome aggregate for a node — how callers reported their real-world results after acting on its verdict.
Inferred read-onlyx402_echoValidates an agent's x402 v1 client implementation against a TunnelMind surface end-to-end.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.tunnelmind-data-api]
url = "https://mcp-data.tunnelmind.ai/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"tunnelmind-data-api": {
"type": "http",
"url": "https://mcp-data.tunnelmind.ai/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: tunnelmind-data-api
Remote MCP URL: https://mcp-data.tunnelmind.ai/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"tunnelmind-data-api": {
"url": "https://mcp-data.tunnelmind.ai/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"tunnelmind-data-api": {
"type": "http",
"url": "https://mcp-data.tunnelmind.ai/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "tunnelmind-data-api",
"transport": "streamable-http",
"url": "https://mcp-data.tunnelmind.ai/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
ENDPOINT 2
https://mcp.tunnelmind.ai/mcp
MCP server metadata
- Name
- scry
- Version
- 0.5.0
Known tools 12
scry_statsReturns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns.
Inferred read-onlyscry_checkReturns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and confidence_bucket (low/medium/high).
Inferred read-onlyscry_asnRoll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.
Inferred read-onlyscry_toolsList detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs.
Inferred read-onlyscry_campaignsActive threat campaigns — coordinated attacker activity that exceeds the noise floor.
Inferred read-onlyscry_recentRecent observations feed — aggregated by source IP within a time window.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.scry]
url = "https://mcp.tunnelmind.ai/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"scry": {
"type": "http",
"url": "https://mcp.tunnelmind.ai/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: scry
Remote MCP URL: https://mcp.tunnelmind.ai/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"scry": {
"url": "https://mcp.tunnelmind.ai/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"scry": {
"type": "http",
"url": "https://mcp.tunnelmind.ai/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "scry",
"transport": "streamable-http",
"url": "https://mcp.tunnelmind.ai/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
ENDPOINT 3
https://mcp.sigil.tunnelmind.ai/mcp
Known tools 0
No tool metadata was available in the registry cache.
CONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.tunnelmind-ai]
url = "https://mcp.sigil.tunnelmind.ai/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"tunnelmind-ai": {
"type": "http",
"url": "https://mcp.sigil.tunnelmind.ai/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: tunnelmind-ai
Remote MCP URL: https://mcp.sigil.tunnelmind.ai/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"tunnelmind-ai": {
"url": "https://mcp.sigil.tunnelmind.ai/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"tunnelmind-ai": {
"type": "http",
"url": "https://mcp.sigil.tunnelmind.ai/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "tunnelmind-ai",
"transport": "streamable-http",
"url": "https://mcp.sigil.tunnelmind.ai/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Loading Trust v2 evidence…
Checking the associated registrable domain. The BuiltWith key remains server-side.
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.