Robin Saige we check the tools AI agents call

NotePom

com.notepom/notepom

Persistent workspace and visual memory for humans and autonomous agents.

— the operator's own registry description reported

Publisher com.notepom · first seen 2026-09-07 · endpoint https://api.notepom.com/mcp

allow
verdict
rich-slow-solo
cluster
ok_tools
answers
39
tools served

Dependency rating derived

allow
allow — alive & usable · action ● · V n/a
allow — because answers ●, 39 tools legible (band B) ●, no confirmed drift in 1 probes ●; not yet checked: truth (1 attempts unverifiable, 0 disagreements)

Cluster rich-slow-solo · distinctiveness 0.611 (unusual). Every figure is a percentile or class within the 19,148-server censussee the whole spectrum.

Does it answer? Q1 · observed
answersalive_tools
latency436 ms
vs populationslow
protocolcurrent
authopen
Can it be used? Q4 · observed
tools39
vs populationhigh
capabilities1
harnessB
Did it hold when checked? Q3–Q4 · derived
identitysolo
servers on its host1
verifiabilityunassessed
duplicate inventoryno
drift events0
answers true0/0 agree

🔏 Signed receipt rr_2ecb073e7b701ecdabfd276f · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.

Q1Does it answer?alive & usable — 1 probes ●evidence ↓
Q2What is it?action ● evidence ↓
Q3Can it be checked?V n/a for this kind ◐evidence ↓
Q4Did it hold?harness B · truth not yet run · no drift ●evidence ↓
Q5What company does it keep?rich-slow-solo · 1 on its host (context, not verdict) ◐evidence ↓

● observed · ◐ derived · ○ reported — the verdict synthesizes Q1–Q4; Q5 is context. Methodology →

History observed

Every probe we made, oldest → newest (1 shown, 2026-09-13 → 2026-09-13). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.

changelog (1 events)
datetypewhat changed
2026-09-13outcomefirst probe: ok_tools

What kind of tools these are derived

Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):

naturetoolsmeaning what checking applies
action21changes the worldno true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions
retrieval-public14serves public factstruth-checkable against a public source — the V-ladder applies in full
unclassified3not classifiable from its textTier-1 only until its tools describe themselves
retrieval-private1serves the caller's own dataoutside truth-checking is impossible BY NATURE, not by failure — the operator-invited pathway applies

Tools last seen observed

accept_collaboration_invitation create_stripe_onboarding_session delete_own_agent_account disable_listing get_collaboration_note get_listing get_note get_notepom_capabilities get_seller_status invite_collaborator list_collaboration_invitations list_public_pages list_sellable_content list_seller_sales list_shared_with_me list_workspace move_file move_workspace_item prepare_checkout publish_media_listing publish_note_listing publish_page purge_trash_entry read_file register_agent_account restore_trash_entry revoke_collaboration_invitation revoke_collaborator search_workspace trash_file trash_workspace_item unpublish_page update_collaboration_note update_public_page upload_file upsert_folder upsert_note validate_listing_readiness verify_agent_account

Harness readiness observed

Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band B — usable, with rough edges.

legibility checktools passingok
name is clear & specific39/39
has a description39/39
description is substantive36/3936/39
parameters are typed39/39
parameters are described6/396/39

39 of 39 tools graded · 39 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.

Truth checks observed

Not yet confirmed — 1 attempt(s) currently unverifiable (rate limits, walls, or unmappable schemas — never counted against the server) · 0 disagreements.

claim classkeyverdictprimary source
tariff-dutyunmappedunverifiableus-hts

Protocol conformance observed

2025-06-18
protocol version
session model
2.3.1
server version notepom

Capabilities: tools

Drift observed

No confirmed drift on record. Baseline set 2026-09-13; changes appear here after human review.

raw probe records
probed (UTC) outcomehttpmsprotocol
2026-09-13T06:13:22Zok_tools2004362025-06-18

Watch or embed this verdict

verdict badge

Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:

[![Robin Saige verdict](https://robinsaige.com/badge/com.notepom/notepom.svg)](https://robinsaige.com/s/com.notepom/notepom)

Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.

← overview

Operator of this server? Everything we hold about it is on this page — free, no account, for anyone. Wrong attribution, stale probe, misclassification? Dispute this record →