Ainumbers Mcp Apps — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Ainumbers Mcp Apps (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Live endpoint: https://mcp.ainumbers.co/mcp (streamable HTTP, no auth)
An MCP Apps (SEP-1865) server that renders AINumbers.co fintech tools as interactive widgets inside Claude, ChatGPT, M365 Copilot, VS Code, and any other MCP Apps host. Published in the Official MCP Registry as co.ainumbers/tools.
Fifteen flagship tools render as widgets — the actual single-file AINumbers tool, served as a text/html;profile=mcp-app resource, driven by the AIN Bridge (prefill → run → Policy Mandate export):
| MCP tool | AINumbers tool |
|---|---|
baas_provider_comparator | T152 BaaS Provider Comparator |
validate_ap2_mcp_policy | T320 AP2 MCP Policy Validator & Bridge |
build_google_ap2_mandate | T285 Google AP2 Checkout/Payment Mandate Builder |
score_mcp_readiness | T288 MCP Developer Readiness Scorecard |
agentic_mandate_sandbox | RBE-06 Agentic Mandate Sandbox |
customer_risk_rating | T110 Customer Risk Rating Engine |
ap2_aml_mandate_builder | T131 AP2 AML Mandate Builder |
lint_mcp_tool_definition | T274 MCP Tool-Definition Linter |
validate_mcp_server_json | T275 MCP server.json Validator |
compare_agentic_payment_protocols | T276 Agentic Payments Protocol Comparator |
decode_x402_payment | T277 x402 Decoder & 402 Flow Simulator |
audit_mcp_oauth | T278 MCP OAuth 2.1 Authorization Auditor |
scan_tool_poisoning | T282 MCP Tool-Poisoning Scanner |
validate_a2a_agent_card | T283 A2A Agent Card Validator |
inspect_visa_tap_signature | T286 Visa TAP Signature Inspector |
Plus list_ainumbers_tools — catalog search across all 420+ tools, returning deep-links; prefill-enabled tools accept #in=<base64url(JSON of {element_id: value})>[&run=1] for one-click invocation.
All 16 tools are read-only (readOnlyHint: true), no account, no auth, zero PII — inputs are processed transiently and never stored.
https://mcp.ainumbers.co/mcpnpx @modelcontextprotocol/inspector → Streamable HTTP → same URL/healthz reports runtime: cloudflare-workers) — no cold starts.npm install
node generate.mjs # re-vendor tool HTML + manifests + catalog from ../repo into ./data
npm start # http://localhost:3300/mcp (+ /healthz) — Node/express variant (server.mjs)
npx wrangler deploy # deploy the Cloudflare Workers variant (worker.mjs)pilot.mjs is the single source of truth for the widget tool set. After changing any pilot tool in the AINumbers repo, run node generate.mjs, commit data/, and push; run npx wrangler deploy to update production.
Docs: ainumbers.co/mcp.html (privacy, terms, support).
All tool content is client-side, deterministic, zero PII — © Post Oak Labs, CC BY 4.0. See README-SPEC.md for architecture and history.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.