IntentFence Agent Action Firewall is answering right now. Last checked 3 min ago. It exposes 10 tools. Last commit 30 Jul 2026.
Fail-closed action authorization, MCP risk scanning, x402 checks, and signed receipts.
We read the source, 7 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
"eyJ4NDAyVmVyc2lvbiI6MiwicmVzb3VyY2UiOnsidXJsIjoiaHR0cHM6Ly9tZXJjaGFudC5leGFtcGxlL2FwaS9wYWlkLXJlc291cmNlIiwiZGVzY3JpcHRpb24iOiJQYWlkIHJlc291cmNlIiwibWltZVR5cGUiOiJhcHBsaWNhdGlvbi9qc29uIn0sImFjY2VwdHMiOlt7InNjaGVtZSI6ImV4YWN0IiwibmV0d29yayI6ImVpcDE1NTo4NDUzIiwiYW1vdW50IjoiMTAwM…
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
- name: Create or update IntentFence marketplace offers
env:
PAYANAGENT_API_KEY: ${{ secrets.PAYANAGENT_API_KEY }}
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 3 min ago.
claude mcp add intentfence --transport http https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp
{
"mcpServers": {
"intentfence": {
"url": "https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp"
}
}
}
[mcp_servers.intentfence]
url = "https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp"
{
"mcpServers": {
"intentfence": {
"url": "https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp"
}
}
}
{
"mcpServers": {
"intentfence": {
"url": "https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
intentfence_agent_risk_scan
intentfence_authorize_action
intentfence_checkout
intentfence_policy_pack
intentfence_preflight
intentfence_us_cpi
intentfence_verified_preflight
intentfence_wallet_risk
intentfence_x402_assessment
intentfence_x402_readiness
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://agentpass-protocol.rmalka06.chatgpt.site/api/mcp | streamable-http | answering | 1618 ms | 3 min ago |
Runtime verification MCP server: fail-closed checks for agent tool calls, signed evidence receipts.
Runtime verification for agent tool calls: Ed25519 signed receipts, fail-closed RCE/SSRF checks.
AI document intelligence: extract, summarize, claim-check, notarize, and signed action receipts.
Fail-closed deterministic checks and hash-chained receipts for AI agent outputs via MCP.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.
Fail-closed verify-before-you-act gate for AI agents. Signed receipts. Pay-per-call via x402.
Answers built from our own checks of this server.