PHION Agent Trust Infrastructure
systems.phion/evidence-engine · v1.32.2 · MCP 2025-06-18
69 agent services: verified data, enrichment, Index Feed and PHION Execute via x402.
Reachability
reachable
checked 2026-09-20 05:33 UTC
Registry status active
Tools pinned 75
eb135617ea3e
Tools last changed
2026-09-20
Provenance
Registry namespace systems.phion
(domain verified by the official registry)
Website
https://phion.systems
Remote endpoints
https://phion.systems/mcp (streamable-http)
Observed changes
| When (UTC) | Event | Detail |
|---|---|---|
| 2026-09-20 05:33 | tools changed | 0 added, 0 removed, 3 changed |
| 2026-09-16 05:32 | tools changed | 13 added, 0 removed, 0 changed |
| 2026-09-15 05:31 | tools changed | 1 added, 0 removed, 1 changed |
| 2026-09-14 05:31 | tools changed | 42 added, 0 removed, 12 changed |
| 2026-09-13 05:30 | tools changed | 8 added, 0 removed, 1 changed |
| 2026-09-12 05:30 | first capture | 11 tools pinned |
Pinned tool definitions (75)
| Tool | Description |
|---|---|
| phion_execute | Universal PHION execution gateway: enforce a budget and persistent idempotency, execute one selected PHION service, evaluate acceptance criteria, and return a signed completion envelope. No gateway surcharge; the selected service price applies. |
| index_feed | Canonical catalog snapshot or digest-based delta with exact HTTP/MCP records, PHION Execute templates and signed evidence; 0.005 USDC. |
| preflight | Free URL safety and reachability check. |
| try_service | Free representative preview, exact price and upgrade instructions for any PHION paid service; no wallet required. |
| schema_normalize_free | Free, rate-limited payload validation and safe key normalization before payment. Payment-critical values are never changed. |
| payment_diagnose | Free diagnosis of the exact payment-funnel stage and machine-readable recovery actions for any PHION service. |
| verify | Free verification of a PHION signed receipt. |
| attest | x402 paid signed JSON attestation; 0.001 USDC on Base. |
| payment_preflight | Fail-closed x402 v2 firewall for network, asset, recipient, amount, scheme, resource host and expiry; 0.002 USDC. |
| fetch_evidence | Independently fetch bounded public evidence with redirect/DNS/connected-address SSRF checks, hashes and injection screening; 0.004 USDC. |
| mandate_reserve | Atomic spending reservation with cumulative cap and conflict-safe idempotency; 0.004 USDC. |
| inspect_agent | Pre-payment agent inspection across x402, A2A, ERC-8004, OpenAPI and MCP; failed inspections are not charged; 0.009 USDC. |
| journey_verify | Verify hash continuity, timestamps and ordered intent→quote→payment→delivery lifecycle; 0.010 USDC. |
| transaction_assurance | End-to-end settlement, timestamp, delivery-hash and deterministic acceptance assurance; 0.015 USDC. |
| transaction_recovery | Failure classification and non-repeating recovery plan with validated attempt history; 0.010 USDC. |
| schema_normalize | Safe alias normalization that refuses ambiguous canonical/alias collisions and never changes payment values; 0.001 USDC. |
| agent_reputation_evidence | Evidence-bounded agent reputation assessment with confidence, coverage, provenance limitations and a signed receipt; 0.005 USDC. |
| counterparty_risk_preflight | Deterministic counterparty policy preflight using supplied reputation evidence and transaction limits; 0.003 USDC. |
| tool_output_firewall | Inspect untrusted MCP/tool output before it enters agent context or triggers an action; 0.002 USDC. |
| delegation_scope_guard | Least-privilege guard for agent-to-agent delegation scope, destinations, budget and expiry; 0.003 USDC. |
| memory_write_guard | Screen persistent memory writes for poisoning, unsafe instructions and missing provenance; 0.002 USDC. |
| mcp_manifest_firewall | Inspect an MCP manifest before installation or trust; 0.002 USDC. |
| tool_call_policy_guard | Bind a proposed tool call to declared intent and execution policy; 0.002 USDC. |
| data_egress_preflight | Inspect outbound agent data and destination before transmission; 0.002 USDC. |
| agent_budget_guard | Enforce per-call, task, session and period budgets; 0.002 USDC. |
| idempotency_replay_guard | Detect safe replays and conflicting idempotency-key reuse; 0.002 USDC. |
| human_approval_policy | Classify an action as automatic, approval-required or denied; 0.002 USDC. |
| secret_redaction_preflight | Detect and redact common secret indicators before transmission; 0.002 USDC. |
| oauth_token_audience_guard | Validate declared OAuth audience and issuer; never send raw tokens; 0.002 USDC. |
| redirect_callback_validator | Validate HTTPS callbacks and redirect host allowlists; 0.002 USDC. |
| tool_capability_drift_monitor | Detect tool capability or manifest drift; 0.002 USDC. |
| mcp_server_identity_evidence | Bind MCP domain, endpoint, manifest, key and version; 0.003 USDC. |
| agent_task_handoff_receipt | Sign a bounded agent-task handoff; 0.003 USDC. |
| context_provenance_labeler | Hash and label context integrity, confidentiality and source; 0.002 USDC. |
| signed_result_comparator | Compare agent results and sign agreement or conflict; 0.003 USDC. |
| service_sla_attestation | Sign availability and latency calculations from bounded samples; 0.004 USDC. |
| payment_route_selector | Reject impossible x402 routes, rank safe eligible routes by policy and return the exact next payment action; read-only, deterministic, 0.002 USDC. |
| x402_quote_comparator | Validate x402 v2 fields and compare only quotes sharing asset and decimals; 0.002 USDC. |
| payment_receipt_reconciler | Compare canonical and common x402 payment/receipt aliases, settlement state and coverage; 0.003 USDC. |
| duplicate_charge_detector | Detect repeated transaction hashes, payment identifiers and idempotent intents; 0.003 USDC. |
| subscription_spend_guard | Bind one recurring charge to approval, merchant, due time and per-charge/period budgets; 0.003 USDC. |
| webhook_verifier | Fail-closed RFC 9421-style webhook preflight requiring trusted key, algorithm, nonce, freshness, replay status and signature coverage of method, target and content; 0.003 USDC. |
| delivery_evidence | Bind successful delivery to transaction, request and matching 64-hex expected/observed content hashes without echoing content; 0.003 USDC. |
| inter_agent_policy_evaluator | Require policy identity, subject, action, lifetime and valid decisions; compute the restrictive cap and shared actions; 0.003 USDC. |
| concurrency_guard | Fail closed unless capacity counter is fresh and the request carries a lease plus idempotency binding; 0.002 USDC. |
| resource_cycle_guard | Require per-step identity, token and cost counters; detect repeated nodes/edges and enforce all three hard caps; 0.002 USDC. |
| abandoned_tool_detector | Require stale success plus multiple independent failed probes before classifying likely abandonment; 0.003 USDC. |
| manifest_version_diff | Recursive manifest diff that requires explicit versions and flags sensitive changes without a version advance; 0.002 USDC. |
| dependency_provenance_assessment | Fail closed on empty dependency sets or absent registry policy; distinguish digest declarations from verified provenance; 0.003 USDC. |
| conflict_resolution | Resolve or abstain; every candidate must bind source, value hash, observation time and bounded confidence; 0.003 USDC. |
| data_freshness_certificate | Certify freshness only when timestamp is bound to source URI and a 64-hex content hash; 0.002 USDC. |
| domain_ownership_evidence | Require a fresh domain-bound DNS-01/HTTP-01 challenge and separate control from legal ownership; 0.003 USDC. |
| purpose_bound_consent | Fail-closed consent bound to ID, subject, recipient, purpose, scope, issue/expiry and checked revocation state; 0.003 USDC. |
| retention_deletion_receipt | Separate requested, operator-completed and evidence-verified retention/deletion states using content and evidence hashes; 0.003 USDC. |
| interrupted_task_recovery | Resume only when task/checkpoint identity, sequence, deadline, attempt budget, idempotency and side effects are explicit; 0.003 USDC. |
| portable_observability_audit | Validate event identity, timestamps, hash chain and W3C-compatible lowercase nonzero trace/span identifiers; 0.004 USDC. |
| rwa_asset_due_diligence | Fail-closed issuer, contract, jurisdiction, custody and documentation coverage with independently fetched evidence; 0.019 USDC. |
| rwa_compliance | Fail-closed RWA transfer decision requiring explicit jurisdiction, KYC, allowlist, limit and transfer-window checks; 0.012 USDC. |
| rwa_nav_reserve | Compare declared NAV and reserve ratios with structured observed facts plus independently fetched evidence; returns discrepancies in basis points and fails closed on incomplete evidence; 0.015 USDC. |
| rwa_transaction_assurance | Verify an RWA asset, payment, delivery and transfer restrictions; 0.020 USDC. |
| rwa_corporate_actions | Detect and sign material RWA changes in NAV, income, maturity, redemption or freeze state; 0.012 USDC. |
| rwa_sanctions_screening_evidence | Evidence-based literal subject screening against observed official US/EU sanctions sources; 0.015 USDC. Not legal clearance or wallet attribution. |
| verified_web_extract | Bounded public web extraction with source, timestamp and hashes; 0.003 USDC. |
| entity_enrichment_evidence | Source-bounded entity field coverage with explicit missing facts; 0.008 USDC. |
| social_source_evidence | Attributable public social-source observations with identity limitations; 0.006 USDC. |
| market_data_snapshot | Timestamped public market-data snapshot with provenance; 0.005 USDC. |
| onchain_evidence | Public explorer or RPC response evidence with immutable hashes; 0.004 USDC. |
| verified_news_monitor | Literal query evidence across bounded public news sources; 0.006 USDC. |
| multi_source_fact_bundle | Independent source observations with agreement made explicit; 0.005 USDC. |
| document_to_verified_json | Public text, HTML, JSON or XML normalized to source-backed JSON; no OCR; 0.010 USDC. |
| source_backed_search | Literal search over supplied public sources with citations and hashes; 0.004 USDC. |
| live_data_freshness | Evaluate live source observation against explicit maximum age; 0.002 USDC. |
| person_enrichment_evidence | Person enrichment with free input preflight, provider attribution, likelihood, limitations and signed receipt; 0.006 USDC. |
| company_enrichment_evidence | Company enrichment with free input preflight, provider attribution and signed evidence; 0.005 USDC. |
| contact_enrichment_evidence | Business-contact enrichment with free input preflight, identity limitations and signed receipt; 0.007 USDC. |
Get alerted when this changes.
Email the moment systems.phion/evidence-engine drifts, dies, or revives.
Status badge
[](https://toolpin.dev/servers/systems.phion/evidence-engine)
Maintain this server? Add the badge to your README. It links your users to this live status page.