SQLGuard — Execution Certificate Firewall
io.github.cabbageandtea/sqlguard
Permission before writes. Gravity→DENYs→Session $0.25. Pilot $100; Gateway $299. Probe free.
— the operator's own registry description reported
Publisher io.github.cabbageandtea · first seen 2026-08-12 · endpoint https://sqlguard.io/mcp
Dependency rating derived
Cluster mid-shared · distinctiveness 0.46 (moderate). Every figure is a percentile or class within the 11,094-server census — see the whole spectrum.
🔏 Signed receipt rr_443d2faf2f3fb8c472ca230c · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.
What kind of tools these are derived
Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. This server's 24 tools, classified, with what checking applies to each kind (the full methodology →):
| nature | tools | meaning | what checking applies |
|---|---|---|---|
| orchestration | 13 | routes other tools | identity + fronted-service disclosure checks (gateway vs costume) |
| retrieval-public | 9 | serves public facts | truth-checkable against a public source — the V-ladder applies in full |
| action | 1 | changes the world | no true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions |
| computational | 1 | deterministic transforms | self-checkable by re-computation and known-answer tests |
Tools last seen
Harness readiness observed
Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band A — an agent can pick and call these reliably.
| legibility check | tools passing | ok |
|---|---|---|
| name is clear & specific | 24/24 | ✓ |
| has a description | 24/24 | ✓ |
| description is substantive | 24/24 | ✓ |
| parameters are typed | 24/24 | ✓ |
| parameters are described | 24/24 | ✓ |
24 of 24 tools graded · 24 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.
Truth checks observed
Not in the Tier-2 trade lane, or not yet checked. Tier-2 re-derives a server's answers against published primary sources — see truth checks.
Protocol conformance observed
Capabilities: prompts resources tools
Drift
No confirmed drift on record. Baseline set 2026-08-14; changes appear here after human review.
History observed
Every probe we made, oldest → newest (2 shown, 2026-08-12 → 2026-08-14). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.
changelog (1 events)
| date | type | what changed |
|---|---|---|
| 2026-08-12 | outcome | first probe: ok_tools |
raw probe records
| probed (UTC) | outcome | http | ms | protocol |
|---|---|---|---|---|
| 2026-08-14T19:59:26Z | ok_tools | 200 | 108 | 2025-06-18 |
| 2026-08-12T05:34:38Z | ok_tools | 200 | 68 | 2025-06-18 |
Watch or embed this verdict
Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:
[](https://robinsaige.com/s/io.github.cabbageandtea/sqlguard)
Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.