{"protocol":"mcp","protocolVersion":"2025-06-18","transport":"http-jsonrpc","endpoint":"https://sicher.halowerk.com/mcp","server":{"name":"sicherwerk","title":"HALOWERK sicherwerk","version":"1.0.0"},"methods":["initialize","ping","tools/list","tools/call"],"tools":[{"name":"cve_check","title":"Check a package list against known vulnerabilities and get, per package, the severity breakdown and the lowest version that closes every finding.","price_usdc":0.005},{"name":"sbom_build","title":"Build a CycloneDX or SPDX software bill of materials from package manifests or lockfiles, and say whether the versions are exact enough to be evidence.","price_usdc":0.005},{"name":"license_check","title":"Resolve package licences and classify them for commercial use: which force disclosure, which only need attribution, and which are unknown.","price_usdc":0.002},{"name":"container_inspect","title":"Inspect a container image without pulling it: manifest, layers with sizes, architectures, entrypoint, user, exposed ports and image age.","price_usdc":0.005},{"name":"tls_chain","title":"Read the TLS certificate chain of a host: every certificate with its names, validity, key type and signature, plus expiry warnings and whether the hostname is actually covered.","price_usdc":0.002},{"name":"jwt_verify","title":"Verify a JWT signature and claims, and name the classic token attacks explicitly: alg none, HMAC confusion, unbounded lifetime, missing audience.","price_usdc":0.002},{"name":"webhook_signature","title":"Verify a signed webhook from GitHub, Stripe, Shopify, Slack, Svix or a plain HMAC scheme, with the timestamp window checked where the provider signs one.","price_usdc":0.002},{"name":"provenance_verify","title":"Look up an artefact hash in the Sigstore transparency log and report who signed it, from which repository and workflow, and when.","price_usdc":0.005}],"payment":{"protocol":"x402","network":"eip155:8453","asset":"USDC","note":"tools/list braucht keine Zahlung. tools/call rechnet den Werkzeugpreis über x402 ab."}}