Robin Saige we check the tools AI agents call

Wever Labs Agentic Rails

com.weverlabs/agentic-rails

Agentic rails for complex workflows with receipts, fees, and MCP tool access.

— the operator's own registry description reported

Publisher com.weverlabs · first seen 2026-08-12 · endpoint https://weverlabs.com/api/mcp

allow
verdict
rich-slow-solo
cluster
ok_tools
answers
89
tools served

Dependency rating derived

allow
allow — alive & usable · retrieval-public ● · V3 has answer key ◐
allow — because answers ●, 89 tools legible (band B) ●, no confirmed drift in 2 probes ●; not yet checked: truth (0 runs)

Cluster rich-slow-solo · distinctiveness 0.587 (moderate). Every figure is a percentile or class within the 11,094-server censussee the whole spectrum.

Does it answer? Q1 · observed
answersalive_tools
latency615 ms
vs populationslow
protocolleading
authopen
Can it be used? Q4 · observed
tools89
vs populationhigh
capabilities1
harnessB
Did it hold when checked? Q3–Q4 · derived
identitysolo
servers on its host1
verifiabilityunassessed
duplicate inventoryno
drift events0
answers trueno primary

🔏 Signed receipt rr_f7bdf536d2c64b99b22e4220 · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.

Q1Does it answer?alive & usable — 2 probes ●evidence ↓
Q2What is it?retrieval-public ● evidence ↓
Q3Can it be checked?V3 has answer key ◐evidence ↓
Q4Did it hold?harness B · truth not yet run · no drift ●evidence ↓
Q5What company does it keep?rich-slow-solo · 1 on its host (context, not verdict) ◐evidence ↓

● observed · ◐ derived · ○ reported — the verdict synthesizes Q1–Q4; Q5 is context. Methodology →

History observed

Every probe we made, oldest → newest (2 shown, 2026-08-12 → 2026-08-14). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.

changelog (1 events)
datetypewhat changed
2026-08-12outcomefirst probe: ok_tools

What kind of tools these are derived

Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):

naturetoolsmeaning what checking applies
retrieval-public37serves public factstruth-checkable against a public source — the V-ladder applies in full
action35changes the worldno true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions
unclassified13not classifiable from its textTier-1 only until its tools describe themselves
computational3deterministic transformsself-checkable by re-computation and known-answer tests
generative1creates contentno answer key exists; disclosure + stability checks, never truth verdicts

Tools last seen observed

activate_external_directory_credentials adapt_directory_submission bind_x402_facilitator_settlement build_a2a_callback_envelope build_agent_discovery_distribution_plan build_external_agent_client_package build_external_agent_client_runner build_external_discovery_submission_pack build_mcp_package_metadata build_public_agent_client_repo complete_agent_self_serve_paid_rail_run complete_paid_rail_run_with_callback create_a2a_task_lifecycle create_payment_challenge create_stripe_movement_fee_checkout create_x402_payment_challenge credential_aware_mcp_write draft_authority_mandate enforce_agent_credential evaluate_agent_commerce_proof evaluate_authority_action execute_delegated_action execute_directory_submission execute_external_registry_submission_run execute_first_paid_production_run fetch_return_package find_services get_active_rail_catalog get_free_agent_tools_index get_movement_fee_schedule get_run_status get_tool_costs inspect_authority_mandate inspect_service issue_agent_credential list_rails promote_benchmark_report publish_public_repo_ci_badge publish_verified_commerce_proof quote_movement_fee quote_run read_agent_self_serve_paid_rail_loop read_callback_receipt_records read_delegated_authority read_directory_status_console read_live_supabase_verification read_payment_settlement_records read_receipt_ledger read_recent_regressions read_verified_commerce_activity record_receipt register_issued_credential request_service_use rotate_signing_secret run_agent_to_agent_test run_autonomous_atlas_research_cycle run_claude_evidence_analysis run_claude_proof_relay run_credential_enforcement_dry_run run_directory_submission_adapter run_durable_usage_ledger_event run_external_agent_client_runner run_external_agent_invocation_test run_investor_demo_v2 run_live_supabase_verification run_multi_agent_rail_benchmark run_release_gate_automation run_service run_stripe_receipt_completion run_synthetic_agent_regression sign_directory_submission_receipt sign_receipt start_agent_self_serve_paid_rail_loop start_rail_run store_callback_receipt_record store_receipt_ledger_entry store_regression_report update_directory_status_record validate_a2a_agent_card validate_directory_submission_credentials validate_persistent_store validate_production_write validate_supabase_rls_policy_pack verify_live_registry_listing verify_managed_receipt_signature verify_receipt verify_signature_by_version verify_stripe_movement_fee_payment write_persistence_test_record

Harness readiness observed

Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band B — usable, with rough edges.

legibility checktools passingok
name is clear & specific89/89
has a description89/89
description is substantive77/8977/89
parameters are typed89/89
parameters are described16/8916/89

89 of 89 tools graded · 89 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.

Truth checks observed

Not in the Tier-2 trade lane, or not yet checked. Tier-2 re-derives a server's answers against published primary sources — see truth checks.

Protocol conformance observed

2025-11-25
protocol version
session model
3.0.0
server version wever-labs-service-resolver

Capabilities: tools

Drift observed

No confirmed drift on record. Baseline set 2026-08-14; changes appear here after human review.

raw probe records
probed (UTC) outcomehttpmsprotocol
2026-08-14T19:58:38Zok_tools2006152025-11-25
2026-08-12T05:33:52Zok_tools2002952025-11-25

Watch or embed this verdict

verdict badge

Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:

[![Robin Saige verdict](https://robinsaige.com/badge/com.weverlabs/agentic-rails.svg)](https://robinsaige.com/s/com.weverlabs/agentic-rails)

Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.

← overview