aml
io.tooloracle/aml
AMLOracle — 12-tool AML/CFT MCP: 87k sanctions names, PEP screening, adverse media, SAR/STR.
— the operator's own registry description reported
Publisher io.tooloracle · first seen 2026-08-12 · endpoint https://tooloracle.io/aml/mcp/
Dependency rating derived
allow — gateway · kind unknown · V n/a
Cluster gateway · distinctiveness 0.154 (typical). Every figure is a percentile or class within the 11,094-server census — see the whole spectrum.
🔏 Signed receipt rr_bcbc433af9b609d9a3c69a87 · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.
● observed · ◐ derived · ○ reported — the verdict synthesizes Q1–Q4; Q5 is context. Methodology →
History observed
Every probe we made, oldest → newest (2 shown, 2026-08-12 → 2026-08-14). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.
changelog (2 events)
| date | type | what changed |
|---|---|---|
| 2026-08-14 | outcome | ok_tools (was ok) |
| 2026-08-12 | outcome | first probe: ok |
What kind of tools these are derived
Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):
| nature | tools | meaning | what checking applies |
|---|---|---|---|
| unclassified | 8 | not classifiable from its text | Tier-1 only until its tools describe themselves |
| action | 2 | changes the world | no true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions |
| retrieval-public | 2 | serves public facts | truth-checkable against a public source — the V-ladder applies in full |
Tools last seen observed
Harness readiness observed
Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band A — an agent can pick and call these reliably.
| legibility check | tools passing | ok |
|---|---|---|
| name is clear & specific | 12/12 | ✓ |
| has a description | 12/12 | ✓ |
| description is substantive | 12/12 | ✓ |
| parameters are typed | 12/12 | ✓ |
| parameters are described | 12/12 | ✓ |
12 of 12 tools graded · 12 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.
Truth checks observed
Not yet confirmed — 2 attempt(s) currently unverifiable (rate limits, walls, or unmappable schemas — never counted against the server) · 0 disagreements.
| claim class | key | verdict | primary source |
|---|---|---|---|
| OFAC SDN screening (vs the official list) | ISLAMIC REVOLUTIONARY GUARD CORPS | unverifiable | ofac-sdn |
| OFAC SDN screening (vs the official list) | MAERSK LINE | unverifiable | ofac-sdn |
Protocol conformance observed
Capabilities: tools
Drift observed
No confirmed drift on record. Baseline set 2026-08-14; changes appear here after human review.
raw probe records
| probed (UTC) | outcome | http | ms | protocol |
|---|---|---|---|---|
| 2026-08-14T20:00:25Z | ok_tools | 200 | 292 | 2025-03-26 |
| 2026-08-12T05:35:37Z | ok | 200 | 292 | 2025-03-26 |
Watch or embed this verdict
Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:
[](https://robinsaige.com/s/io.tooloracle/aml)
Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.