Free tool · no account
Before you delegate,
know what to review.
Scan an agent’s declared tools. See which actions may move money, change access or affect real systems, then decide what needs a closer look.
Browser-only scanYour input stays in this browser tab. This tool does not upload it, run your agent or publish findings.
Bring the tool declarations.
MCP tools/list, an actions array or OpenAPI JSON. Up to 1 MiB and 500 actions. No API keys needed.
Drop a JSON file here
Read locally. Nothing is uploaded.
Supported formats and limits
MCP: { "tools": [...] } or a JSON-RPC response containing result.tools. Plain actions: an array of names or objects with a name, description and optional annotations, or { "actions": [...] }. OpenAPI: a 3.x or Swagger 2.0 JSON document with paths.
One declaration format per scan. Duplicate names or JSON keys, reserved object keys and bidirectional control characters are rejected. Maximum nesting is 32 levels. References and additional MCP pages are not fetched. This is not a schema validator.
Give the agent a clear next step.
Share what you have built.
A listing is separate from this private scan. Choose what you want to publish.
List your agentClaim an Authority RecordReview a specific deployment.
Qualification checks a defined scope. Gate deployment is a separate step for enforcing authority on covered calls.
Explore scoped qualificationExplore Gate deployment