← Registry

Security & Testing

tunnelmind.ai

Provides surveillance intelligence data on domains and corporate entities.

1 endpoint78 known toolsFirst detected June 15, 2026Last detected July 17, 2026

ENDPOINT 1

https://mcp-data.tunnelmind.ai/mcp

No auth detected

Known tools 78

health_check

Returns a minimal status object confirming the API is alive.

get_domain

Returns the complete surveillance intelligence record for a domain name.

list_domains

Returns a paginated list of domains from the tracker database.

get_entity

Returns an entity record for a surveillance company or data broker, including its industry, estimated annual data value per user (in USD), categories of personal data collected, and the full list of domains it controls.

list_entities

Returns a paginated list of corporate entities in the TunnelMind surveillance database.

search

Searches both the domains table and the entities table simultaneously.

intel_http

Makes a live HEAD request to the target domain from the Cloudflare edge, follows up to 5 redirects, and returns the full redirect chain, final HTTP status, key response headers, a security header score, and any third-party surveillance actors referenced in the Content-Security-Policy header.

intel_stack

Fetches up to 32KB of the domain's HTML and response headers from the edge, then fingerprints the content for known CMS platforms, JavaScript frameworks, CDN providers, and analytics tools.

intel_robots

Retrieves the target domain's `robots.txt` file and parses it for AI crawler disallow rules.

intel_agent

Probes a domain for known AI agent integration signals: `llms.txt`, `ai.txt`, `/.well-known/ai-plugin.json`, `openapi.json`, `swagger.json`, MCP manifest, MCP SSE endpoint.

intel_inject

Fetches a domain's homepage and checks for content patterns that could constitute prompt injection attacks against AI agents that visit and ingest the page.

intel_optout

Checks a domain for all known AI training data opt-out mechanisms beyond robots.txt: TDM (Text and Data Mining) reservation headers, `<meta name="ai">` tags, Creative Commons NonCommercial licenses, and other machine-readable opt-out signals.

get_receipt

Returns metadata for a TunnelMind surveillance receipt — a signed document proving that a specific user's surveillance exposure was observed, measured, and recorded at a specific time.

verify_receipt

Tamper-detection verification for TunnelMind surveillance receipts.

get_api_key

Returns the tier, label, masked owner email, creation date, last-used timestamp, today's request count, and daily request limit for the API key used in this request.

revoke_api_key

Permanently deactivates the API key used to make this request.

get_task

Returns the current status of a task created by an `?async=true` intel request.

cancel_task

Marks the task as `cancelled`.

stream_task

Opens a persistent SSE connection that emits events as the task progresses.

audit_export

Returns NDJSON (one JSON object per line) of audit log entries.

generate_receipt

Looks up each submitted domain in the TunnelMind tracker database, aggregates risk metrics (avg score, max score, fingerprinters, high-risk domains, entity ownership), and issues a signed surveillance receipt.

sigil_verify_ads_txt

Confirms whether an SSP/exchange is authorized to sell a publisher's inventory according to that publisher's ads.txt.

sigil_verify_ads_txt_batch

Runs up to 100 ads.txt verifications in a single call — the endpoint an ad-buying agent uses for pre-bid checks across a whole campaign's supply.

traction

Live traction numbers computed from sources the Worker owns: the hash-chained D1 audit log (7-day call volume, distinct identified callers, top operations), the stored-receipt table, and Stripe (succeeded charges → paying customers, gross USD).

verify_agent

Reconciles a claimed bot User-Agent against the operator's OWN published IP-range feed (Googlebot, GPTBot, OAI-SearchBot, ChatGPT-User, PerplexityBot, Perplexity-User, Bingbot).

create_subscription

Subscribe to a node (ip, domain, asn, or entity slug).

list_subscriptions

Returns the caller's active and inactive subscriptions (signing_key redacted).

get_subscription

Read one of your subscriptions (signing_key redacted).

delete_subscription

Cancel a subscription.

tracker_verify

The Tracker lens-owned verify surface: a per-node verdict over the normalized DDG Tracker Radar / IAB TCF / Disconnect.me corpus, with an optional signed TunnelMind Receipt v1.0.

sigil_verify_domain

Confirms a publisher controls a domain by checking for a DNS TXT record the owner publishes under `_tunnelmind.{domain}`.

sigil_verify_ip_type

Classifies an IPv4 or IPv6 address by network type — the high-value ad-fraud signal being datacenter traffic posing as residential or living-room (CTV) devices.

sigil_verify_adscert

Reports whether a domain publishes ads.cert (IAB Tech Lab Authenticated Connections) DNS records — a readiness signal showing the domain supports cryptographically authenticated ad-tech connections.

sigil_verify_app_bundle

Verifies that a mobile or CTV app bundle ID actually exists in the relevant app store — used to detect bundle spoofing in bid requests.

cross_lens_verify

A2 — the cross-lens join.

cross_lens_lookup

Returns all three lens views for a single node key without computing a fused verdict.

verdict_lookup

The reconciliation layer in one call.

preflight_should_i_act

The single call an agent makes before transacting with a destination on the open web.

explain_verdict

Call this when you need to ACT ON a verdict and prove why.

profile_entity

Call this before routing traffic, bidding on inventory, or trusting a counterparty.

signal_tracker_density

Observed component counts first, a labelled derived roll-up second.

signal_dark_pool_risk

Reconciles every sell path a publisher declares (`sells_through`) against each SSP's own sellers.json (`exchange_seat`) and keeps three classes strictly separate: `corroborated` (seat present), `contradicted` (SSP crawled but seller_id absent — real risk), and `unchecked` (SSP not yet crawled — excluded from risk, lowers confidence).

signal_halo_score

Scores an entity by the trust character of its neighbours — the SSPs its publishers sell through and the DSPs it buys through.

signal_team_signal

Surfaces other entities that operate as a coordinated team with this one: they share a NARROWLY-held direct seller account (2–8 entities — network house accounts shared by hundreds are separated into `house_accounts_excluded`, not counted) or co-own an exchange seat.

sigil_verify_supply_path

The core Sigil pre-bid call.

sigil_verify_token

Verifies the authenticity and expiry of a `sigil_token` returned by `sigil_verify_supply_path`.

sigil_verify_supply_chain

The bid-time contract.

sigil_traverse

Reconstructs the supply paths for a publisher domain from Sigil's own crawl and returns them ITEMIZED — distinct from `sigil_verify_supply_chain` (which verifies a schain the caller brings) and from `signal_dark_pool_risk` (which returns only aggregate counts).

get_stats

One public "state of the corpus" readout — the whole graph in a single call.

ghostroute_check

GhostRoute is TunnelMind's fourth lens: routing-integrity / sovereignty verification.

ghostroute_verify

Retrieves a previously-issued, signed GhostRoute receipt by its GR-YYYY-NNNNNNN id, for independent audit of a past sovereignty verdict.

ghostroute_asn_lookup

Returns GhostRoute's ownership-graph record for an autonomous system: the registrant/parent organisation, its HQ country and sovereign zone, RIR, and cloud/AI-infrastructure flags.

ghostroute_ai_lookup

Checks whether a domain or ASN belongs to a known AI company's infrastructure and what sovereignty it CLAIMS (program, zone, HQ), the baseline GhostRoute scores routing reality against.

ghostroute_ct_witness

Returns GhostRoute's first-party Certificate-Transparency witness state: the latest signature-verified Signed Tree Head (STH) for every trusted, non-Google CT log TunnelMind independently witnesses, plus a regression scan over our own append-only history.

ghostroute_ct_proofs

Returns GhostRoute's per-cert inclusion proofs: each is a cryptographic demonstration that the exact certificate a host serves is included in an append-only CT log whose root TunnelMind signature-verified — upgrading "a monitor said this cert exists" to "proven in a log we witness".

ghostroute_ct_alerts

Returns the durable, deduplicated ledger of CT equivocation events the GhostRoute witness worker detects and pushes — a tree_size_rewind (an append-only log shrank), a root_fork (one tree_size witnessed with two different Merkle roots = a split-view log), or an sth_signature_invalid (a log's latest Signed Tree Head failed signature verification).

get_bgp_events

Returns the routing anomalies the bgp-monitor has observed against TunnelMind's BGP watchlist — the witnessability layer's routing dimension.

sigil_ads_txt_history

Returns a publisher's ads.txt change log — one entry per crawl in which its authorized-seller set changed.

sigil_score_weights

Returns the active, versioned default weights used to combine an entity's trust-score components, plus the list of spec components that are not yet evaluated.

sigil_score_entity

Returns the pre-computed 0.0–1.0 trust score for one entity, its component breakdown, and the 14-day trend.

sigil_score_batch

Scores up to 200 entities in one round-trip — built for agents evaluating many supply sources during campaign setup.

sigil_atap_register_ait

Registers an ATAP v0.1 AIT for a media-buying agent under the `sigil:media_buyer:v1` profile.

sigil_atap_witness

Ingests one agent-reported event (`bid:submitted`, `bid:won`, `bid:lost`, `budget:decremented`) into an AIT's hash-chained attestation log.

sigil_atap_roll_block

Rolls every not-yet-blocked Witness Event for an AIT into one signed ATAP Attestation Block with a profile `period_summary`, chained onto the prior block.

sigil_atap_ait_status

Returns an AIT's status, chain head hash, event count, pending-event count, per-tier event counts, and the anchored-bid coverage ratio.

sigil_receipt_generate

Assembles the ATAP v0.1 §7.5 Receipt ZIP for an AIT — the signed Receipt (`manifest.json`), the AIT, the Attestation Block chain, the witness public key, a tier-graded `summary.json`, the bundled `verify.sh` reference verifier, and the witness events + sigil_tokens as profile artifacts.

compliance_profile

Returns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.12, DORA, NYDFS 500, HIPAA, PCI DSS, SOC 2, generic) and export formats (signed_json, csv, eat, stix).

compliance_configure

Set the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer.

compliance_ledger

Returns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled.

compliance_export

Generates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint.

compliance_verify

Recomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 checkpoint signed with the TunnelMind receipt key.

get_analyst_config

Returns the TunnelMind analyst config bundle.

check_receipt_revoked

Single-item revocation lookup per Receipt Format v1.0 §8.2.

scan_injection

Runs a curated signature corpus over a piece of untrusted text — content an agent is about to consume, a retrieved document, a tool result, an email body — and returns the matched injection patterns plus a bounded 0..1 risk score.

scan_mcp

Connect to a caller-supplied MCP server (Streamable-HTTP transport), read its advertised tools, and run the injection corpus over every tool name / description / input schema — plus a capability heuristic that flags broad, dangerous powers (shell execution, filesystem write, credential access, arbitrary network, destructive DB ops).

submit_feedback

Close the loop: after you acted on a TunnelMind verdict, tell us how it went.

get_feedback

Public read of the crowd-sourced outcome aggregate for a node — how callers reported their real-world results after acting on its verdict.

x402_echo

Validates an agent's x402 v1 client implementation against a TunnelMind surface end-to-end.