@toolstop/check-digits
Advanced tools
+1
-1
@@ -71,3 +71,3 @@ // The single source of truth for this server. Both transports (Worker HTTP and | ||
| name: "check-digits", | ||
| version: "0.2.1", | ||
| version: "0.2.2", | ||
| instructions: | ||
@@ -74,0 +74,0 @@ "Catches mistyped barcodes, VINs, ISBNs and other public structured " + |
+1
-1
| { | ||
| "name": "@toolstop/check-digits", | ||
| "version": "0.2.1", | ||
| "version": "0.2.2", | ||
| "mcpName": "dev.toolstop/check-digits", | ||
@@ -5,0 +5,0 @@ "description": "MCP server that catches mistyped barcodes, ISBNs, VINs and other public structured identifiers before a bad one causes a rejected listing, a bounced claim or a corrupted record.", |
+27
-1
@@ -71,4 +71,30 @@ # mcp-check-digits | ||
| Running over stdio, nothing leaves your machine at all. | ||
| **What is recorded.** Saying only what is *not* stored would be a half-answer, so | ||
| here is the whole row. One record per request, retained 90 days: | ||
| | | | | ||
| |---|---| | ||
| | The call | Server name and version, MCP method, tool name, outcome, error *class* (never the message), duration, result size | | ||
| | The client | Client name and version and protocol version as your software reports them, plus a truncated user agent | | ||
| | Coarse location | Country and Cloudflare data centre. Never a precise location | | ||
| | Argument *shape* | Field names with types and lengths, for example `str:22`. Never a value | | ||
| | A session id | See below | | ||
| **The session id is derived from your network, not from you.** It is a hash of | ||
| your user agent, the date, this server's name, and the **network block** your | ||
| request came from, truncated to a /24 (IPv4) or /48 (IPv6) before anything | ||
| hashes it. It exists to count distinct sessions in a day and it deliberately | ||
| cannot do more: it does not link across days, and two people behind the same | ||
| network running the same client are indistinguishable in it. | ||
| That truncation was added on 2026-08-10 and it fixed a real weakness rather than | ||
| adding a nicety. The id previously covered the full client address, and an | ||
| 8-byte hash does not conceal a 32-bit value when the other inputs are public, so | ||
| it could be walked back to a single address. It no longer can. Being specific | ||
| about this matters more than looking clean: an unknown vendor asking you to | ||
| route data through their server owes you the actual answer. | ||
| **Running over stdio, none of this happens.** The server runs on your machine and | ||
| deliberately does not phone home, so there is no row and no network request. | ||
| ## What it does not do | ||
@@ -75,0 +101,0 @@ |
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
45447
3.71%108
31.71%