Security & Testing
tunnelmind.ai
Provides surveillance intelligence data on domains and corporate entities.
ENDPOINT 1
https://mcp-data.tunnelmind.ai/mcp
Known tools 78
health_checkReturns a minimal status object confirming the API is alive.
get_domainReturns the complete surveillance intelligence record for a domain name.
list_domainsReturns a paginated list of domains from the tracker database.
get_entityReturns an entity record for a surveillance company or data broker, including its industry, estimated annual data value per user (in USD), categories of personal data collected, and the full list of domains it controls.
list_entitiesReturns a paginated list of corporate entities in the TunnelMind surveillance database.
searchSearches both the domains table and the entities table simultaneously.
intel_httpMakes a live HEAD request to the target domain from the Cloudflare edge, follows up to 5 redirects, and returns the full redirect chain, final HTTP status, key response headers, a security header score, and any third-party surveillance actors referenced in the Content-Security-Policy header.
intel_stackFetches up to 32KB of the domain's HTML and response headers from the edge, then fingerprints the content for known CMS platforms, JavaScript frameworks, CDN providers, and analytics tools.
intel_robotsRetrieves the target domain's `robots.txt` file and parses it for AI crawler disallow rules.
intel_agentProbes a domain for known AI agent integration signals: `llms.txt`, `ai.txt`, `/.well-known/ai-plugin.json`, `openapi.json`, `swagger.json`, MCP manifest, MCP SSE endpoint.
intel_injectFetches a domain's homepage and checks for content patterns that could constitute prompt injection attacks against AI agents that visit and ingest the page.
intel_optoutChecks a domain for all known AI training data opt-out mechanisms beyond robots.txt: TDM (Text and Data Mining) reservation headers, `<meta name="ai">` tags, Creative Commons NonCommercial licenses, and other machine-readable opt-out signals.
get_receiptReturns metadata for a TunnelMind surveillance receipt — a signed document proving that a specific user's surveillance exposure was observed, measured, and recorded at a specific time.
verify_receiptTamper-detection verification for TunnelMind surveillance receipts.
get_api_keyReturns the tier, label, masked owner email, creation date, last-used timestamp, today's request count, and daily request limit for the API key used in this request.
revoke_api_keyPermanently deactivates the API key used to make this request.
get_taskReturns the current status of a task created by an `?async=true` intel request.
cancel_taskMarks the task as `cancelled`.
stream_taskOpens a persistent SSE connection that emits events as the task progresses.
audit_exportReturns NDJSON (one JSON object per line) of audit log entries.
generate_receiptLooks up each submitted domain in the TunnelMind tracker database, aggregates risk metrics (avg score, max score, fingerprinters, high-risk domains, entity ownership), and issues a signed surveillance receipt.
sigil_verify_ads_txtConfirms whether an SSP/exchange is authorized to sell a publisher's inventory according to that publisher's ads.txt.
sigil_verify_ads_txt_batchRuns up to 100 ads.txt verifications in a single call — the endpoint an ad-buying agent uses for pre-bid checks across a whole campaign's supply.
tractionLive traction numbers computed from sources the Worker owns: the hash-chained D1 audit log (7-day call volume, distinct identified callers, top operations), the stored-receipt table, and Stripe (succeeded charges → paying customers, gross USD).
verify_agentReconciles a claimed bot User-Agent against the operator's OWN published IP-range feed (Googlebot, GPTBot, OAI-SearchBot, ChatGPT-User, PerplexityBot, Perplexity-User, Bingbot).
create_subscriptionSubscribe to a node (ip, domain, asn, or entity slug).
list_subscriptionsReturns the caller's active and inactive subscriptions (signing_key redacted).
get_subscriptionRead one of your subscriptions (signing_key redacted).
delete_subscriptionCancel a subscription.
tracker_verifyThe Tracker lens-owned verify surface: a per-node verdict over the normalized DDG Tracker Radar / IAB TCF / Disconnect.me corpus, with an optional signed TunnelMind Receipt v1.0.
sigil_verify_domainConfirms a publisher controls a domain by checking for a DNS TXT record the owner publishes under `_tunnelmind.{domain}`.
sigil_verify_ip_typeClassifies an IPv4 or IPv6 address by network type — the high-value ad-fraud signal being datacenter traffic posing as residential or living-room (CTV) devices.
sigil_verify_adscertReports whether a domain publishes ads.cert (IAB Tech Lab Authenticated Connections) DNS records — a readiness signal showing the domain supports cryptographically authenticated ad-tech connections.
sigil_verify_app_bundleVerifies that a mobile or CTV app bundle ID actually exists in the relevant app store — used to detect bundle spoofing in bid requests.
cross_lens_verifyA2 — the cross-lens join.
cross_lens_lookupReturns all three lens views for a single node key without computing a fused verdict.
verdict_lookupThe reconciliation layer in one call.
preflight_should_i_actThe single call an agent makes before transacting with a destination on the open web.
explain_verdictCall this when you need to ACT ON a verdict and prove why.
profile_entityCall this before routing traffic, bidding on inventory, or trusting a counterparty.
signal_tracker_densityObserved component counts first, a labelled derived roll-up second.
signal_dark_pool_riskReconciles every sell path a publisher declares (`sells_through`) against each SSP's own sellers.json (`exchange_seat`) and keeps three classes strictly separate: `corroborated` (seat present), `contradicted` (SSP crawled but seller_id absent — real risk), and `unchecked` (SSP not yet crawled — excluded from risk, lowers confidence).
signal_halo_scoreScores an entity by the trust character of its neighbours — the SSPs its publishers sell through and the DSPs it buys through.
signal_team_signalSurfaces other entities that operate as a coordinated team with this one: they share a NARROWLY-held direct seller account (2–8 entities — network house accounts shared by hundreds are separated into `house_accounts_excluded`, not counted) or co-own an exchange seat.
sigil_verify_supply_pathThe core Sigil pre-bid call.
sigil_verify_tokenVerifies the authenticity and expiry of a `sigil_token` returned by `sigil_verify_supply_path`.
sigil_verify_supply_chainThe bid-time contract.
sigil_traverseReconstructs the supply paths for a publisher domain from Sigil's own crawl and returns them ITEMIZED — distinct from `sigil_verify_supply_chain` (which verifies a schain the caller brings) and from `signal_dark_pool_risk` (which returns only aggregate counts).
get_statsOne public "state of the corpus" readout — the whole graph in a single call.
ghostroute_checkGhostRoute is TunnelMind's fourth lens: routing-integrity / sovereignty verification.
ghostroute_verifyRetrieves a previously-issued, signed GhostRoute receipt by its GR-YYYY-NNNNNNN id, for independent audit of a past sovereignty verdict.
ghostroute_asn_lookupReturns GhostRoute's ownership-graph record for an autonomous system: the registrant/parent organisation, its HQ country and sovereign zone, RIR, and cloud/AI-infrastructure flags.
ghostroute_ai_lookupChecks whether a domain or ASN belongs to a known AI company's infrastructure and what sovereignty it CLAIMS (program, zone, HQ), the baseline GhostRoute scores routing reality against.
ghostroute_ct_witnessReturns GhostRoute's first-party Certificate-Transparency witness state: the latest signature-verified Signed Tree Head (STH) for every trusted, non-Google CT log TunnelMind independently witnesses, plus a regression scan over our own append-only history.
ghostroute_ct_proofsReturns GhostRoute's per-cert inclusion proofs: each is a cryptographic demonstration that the exact certificate a host serves is included in an append-only CT log whose root TunnelMind signature-verified — upgrading "a monitor said this cert exists" to "proven in a log we witness".
ghostroute_ct_alertsReturns the durable, deduplicated ledger of CT equivocation events the GhostRoute witness worker detects and pushes — a tree_size_rewind (an append-only log shrank), a root_fork (one tree_size witnessed with two different Merkle roots = a split-view log), or an sth_signature_invalid (a log's latest Signed Tree Head failed signature verification).
get_bgp_eventsReturns the routing anomalies the bgp-monitor has observed against TunnelMind's BGP watchlist — the witnessability layer's routing dimension.
sigil_ads_txt_historyReturns a publisher's ads.txt change log — one entry per crawl in which its authorized-seller set changed.
sigil_score_weightsReturns the active, versioned default weights used to combine an entity's trust-score components, plus the list of spec components that are not yet evaluated.
sigil_score_entityReturns the pre-computed 0.0–1.0 trust score for one entity, its component breakdown, and the 14-day trend.
sigil_score_batchScores up to 200 entities in one round-trip — built for agents evaluating many supply sources during campaign setup.
sigil_atap_register_aitRegisters an ATAP v0.1 AIT for a media-buying agent under the `sigil:media_buyer:v1` profile.
sigil_atap_witnessIngests one agent-reported event (`bid:submitted`, `bid:won`, `bid:lost`, `budget:decremented`) into an AIT's hash-chained attestation log.
sigil_atap_roll_blockRolls every not-yet-blocked Witness Event for an AIT into one signed ATAP Attestation Block with a profile `period_summary`, chained onto the prior block.
sigil_atap_ait_statusReturns an AIT's status, chain head hash, event count, pending-event count, per-tier event counts, and the anchored-bid coverage ratio.
sigil_receipt_generateAssembles the ATAP v0.1 §7.5 Receipt ZIP for an AIT — the signed Receipt (`manifest.json`), the AIT, the Attestation Block chain, the witness public key, a tier-graded `summary.json`, the bundled `verify.sh` reference verifier, and the witness events + sigil_tokens as profile artifacts.
compliance_profileReturns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.12, DORA, NYDFS 500, HIPAA, PCI DSS, SOC 2, generic) and export formats (signed_json, csv, eat, stix).
compliance_configureSet the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer.
compliance_ledgerReturns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled.
compliance_exportGenerates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint.
compliance_verifyRecomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 checkpoint signed with the TunnelMind receipt key.
get_analyst_configReturns the TunnelMind analyst config bundle.
check_receipt_revokedSingle-item revocation lookup per Receipt Format v1.0 §8.2.
scan_injectionRuns a curated signature corpus over a piece of untrusted text — content an agent is about to consume, a retrieved document, a tool result, an email body — and returns the matched injection patterns plus a bounded 0..1 risk score.
scan_mcpConnect to a caller-supplied MCP server (Streamable-HTTP transport), read its advertised tools, and run the injection corpus over every tool name / description / input schema — plus a capability heuristic that flags broad, dangerous powers (shell execution, filesystem write, credential access, arbitrary network, destructive DB ops).
submit_feedbackClose the loop: after you acted on a TunnelMind verdict, tell us how it went.
get_feedbackPublic read of the crowd-sourced outcome aggregate for a node — how callers reported their real-world results after acting on its verdict.
x402_echoValidates an agent's x402 v1 client implementation against a TunnelMind surface end-to-end.