{"protocol":"mcp","protocolVersion":"2025-06-18","transport":"http-jsonrpc","endpoint":"https://sicher.halowerk.com/mcp","server":{"name":"sicherwerk","title":"HALOWERK sicherwerk","version":"1.0.0"},"methods":["initialize","ping","tools/list","tools/call"],"tools":[{"name":"cve_check","title":"Check a package list against known vulnerabilities and get, per package, the severity breakdown and the lowest version that closes every finding.","price_usdc":0.005},{"name":"sbom_build","title":"Build a CycloneDX or SPDX software bill of materials from package manifests or lockfiles, and say whether the versions are exact enough to be evidence.","price_usdc":0.005},{"name":"license_check","title":"Resolve package licences and classify them for commercial use: which force disclosure, which only need attribution, and which are unknown.","price_usdc":0.002},{"name":"container_inspect","title":"Inspect a container image without pulling it: manifest, layers with sizes, architectures, entrypoint, user, exposed ports and image age.","price_usdc":0.005},{"name":"tls_chain","title":"Read the TLS certificate chain of a host: every certificate with its names, validity, key type and signature, plus expiry warnings and whether the hostname is actually covered.","price_usdc":0.002},{"name":"jwt_verify","title":"Verify a JWT signature and claims, and name the classic token attacks explicitly: alg none, HMAC confusion, unbounded lifetime, missing audience.","price_usdc":0.002},{"name":"webhook_signature","title":"Verify a signed webhook from GitHub, Stripe, Shopify, Slack, Svix or a plain HMAC scheme, with the timestamp window checked where the provider signs one.","price_usdc":0.002},{"name":"provenance_verify","title":"Look up an artefact hash in the Sigstore transparency log and report who signed it, from which repository and workflow, and when.","price_usdc":0.005},{"name":"hash_reputation","title":"Check a file hash against MalwareBazaar, ThreatFox and URLhaus and return reputation metadata and linked indicators without downloading any sample.","price_usdc":0.005},{"name":"log_chain_verify","title":"Verify an audit log hash chain, identify the first broken record, and optionally compare a Merkle root over the same entries.","price_usdc":0.005},{"name":"oss_openssl_csr_self_signature_audit","title":"Verify the proof-of-possession signature on a PKCS#10 certificate request and read back the subject, key and extensions it actually asks for.","price_usdc":0.002},{"name":"oss_openssl_public_key_math_audit","title":"Check whether a SubjectPublicKeyInfo public key is mathematically sound and report its algorithm, size and parameters as the pinned OpenSSL build reads them.","price_usdc":0.002},{"name":"oss_openssl_certificate_bundle_normalize","title":"Turn a pile of PEM certificates into one deduplicated bundle, comparing canonical DER encodings so cosmetic differences do not count as distinct certificates.","price_usdc":0.002},{"name":"oss_openssl_rfc3161_request_build","title":"Build a binary RFC 3161 timestamp request around a supplied SHA-256 digest, with a fresh nonce and the certificate-request flag set.","price_usdc":0.001},{"name":"oss_openssl_cms_envelope_encrypt","title":"Encrypt supplied bytes into a CMS EnvelopedData structure for up to sixteen recipient certificates, so only the matching private keys can open it.","price_usdc":0.002},{"name":"oss_openssl_pkcs12_certificate_store_build","title":"Package up to sixteen certificates into an interoperable certificate-only PKCS#12 store with an explicitly empty password and no private key inside.","price_usdc":0.002},{"name":"oss_openssl_dh_group_check","title":"Validate supplied finite-field Diffie-Hellman parameters against the pinned OpenSSL build's own checks, under a strict CPU deadline.","price_usdc":0.003},{"name":"oss_openssl_tls12_cipher_policy_expand","title":"Compile an OpenSSL cipher policy string into the effective TLS 1.2 suite list, in preference order, under the pinned build's security level.","price_usdc":0.001},{"name":"oss_openssl_x509_purpose_evaluate","title":"Evaluate which roles a certificate's own constraints permit — TLS client, TLS server, S/MIME and timestamp signing — under the pinned OpenSSL rules.","price_usdc":0.001},{"name":"oss_openssl_asn1_structure_diagnose","title":"Map the ASN.1 objects inside a binary artifact by offset, depth and encoded length, so a malformed structure can be located at the exact byte.","price_usdc":0.001},{"name":"oss_gnupg_detached_signature_verify","title":"Verify a detached OpenPGP signature over supplied bytes against a supplied public key, and get the verdict, signing fingerprint and signature time.","price_usdc":0.002},{"name":"oss_sqlite_database_integrity_audit","title":"Audit a SQLite file with the pinned engine itself: structural integrity, broken foreign keys, schema inventory and page geometry, without writing to it.","price_usdc":0.0025},{"name":"oss_zip_archive_inventory_audit","title":"List a ZIP archive from its central directory and get the entries that would escape the target folder, duplicate names and the expansion ratio.","price_usdc":0.002}],"payment":{"protocol":"x402","network":"eip155:8453","asset":"USDC","note":"tools/list braucht keine Zahlung. tools/call rechnet den Werkzeugpreis über x402 ab."}}