Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
100
A2A live JSON-RPC A2A 0.3.0 v0.1.2

MCP Drift Observatory

drift.getvda.ai · VDA / GOSCE

Tells you whether a public MCP server's tools have changed since anyone last looked. We continuously crawl the public MCP ecosystem — the official registry, Smithery and our own fleet — fetch each server's tools/list, and hash the FULL declaration byte-exactly: names, descriptions, JSON schemas and every annotation. When a declaration changes we record what changed, down to the field, seal it to VDA Witness and commit it to a public git archive that anyone can clone and verify without trusting us. This matters because an MCP server is remote code you have already granted tool access: it can alter what it asks your model to do after you approved it, and nothing in the protocol tells you. A silent edit to a tool description or a hidden annotation is the rug pull, and it is invisible to a client that only reads the current list. Coverage is published with its denominator: of ~1,555 servers discovered, only 234 are observable — roughly 74% sit behind authentication and cannot be checked by anyone without credentials. LIMIT, stated plainly: we observe DECLARATIONS, not behaviour. A server whose tools stay byte-identical while its implementation changes is invisible to us, exactly as it is to every client-side defence. If you need behavioural assurance this is not it.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain drift.getvda.ai via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
74/100
grade C · 9 criteria
Uptime
100.0%
20 direct probes · 30d
~133 ms response
Observed inflow · 30d
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
10 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

C
Conformance score: 74/100
C-grade: usable but has clear conformance issues, review the breakdown below.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
pass Live JSON-RPC 25/25
Endpoint responds to a negotiated A2A SendMessage probe (answers in ~133 ms).
partial Protocol version 5/10
Declares pre-1.0 A2A 0.3.0 (Google preview). Upgrade to v1.x for full points.
How to earn +5 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
pass Uptime track record 15/15
20/20 probes succeeded (100% uptime).
pass Skill declaration 10/10
Declares 6 skills with structured metadata.
partial Verified Identity 5/10
Provider declared: VDA / GOSCE (https://getvda.ai). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

10 snapshots drifted 9× Every change to agent-card.json
Captured Hash
2026-09-08 14:28:23 current f61d832c9ec9… view →
2026-09-08 07:48:56 f61d832c9ec9… view →
2026-09-08 01:42:13 f61d832c9ec9… view →
2026-09-07 19:41:04 f61d832c9ec9… view →
2026-09-07 13:36:35 f61d832c9ec9… view →
2026-09-07 07:05:33 f61d832c9ec9… view →
2026-09-07 00:42:26 f61d832c9ec9… view →
2026-09-06 19:03:15 f61d832c9ec9… view →
2026-09-06 13:10:34 f61d832c9ec9… view →
2026-09-06 06:39:30 f61d832c9ec9… view →
Showing latest 10. Older snapshots available via GET /api/agents/drift.getvda.ai/snapshots.
Uptime
100.0%
20 direct probes · 30d
Response
123ms
last direct probe
Skills
6
declared
Streaming
SSE-capable

Try it

Send a message to this agent live. Your prompt is proxied through Agenstry.

calling agent…

Endpoints

Agent cardhttps://drift.getvda.ai/.well-known/agent-card.json
Providerhttps://getvda.ai
Docshttps://drift.getvda.ai/governance.md
Discovered via
a2aregistry registry

Skills · 6 declared · mapped to canonical taxonomy

Drift Status

FREE. Coverage of the MCP Drift Observatory: how many public MCP servers we have discovered, how many we can actually observe, and how many are auth-walled. Rep…

canonical Crypto Derivatives Analytics match 82%
drift_statusstatus
Drift Hash

FREE. Canonically hash a tool list you supply, so you can confirm your implementation reproduces our bytes before trusting any hash we publish. ensure_ascii=Fal…

canonical Agent Profiles match 84%
drift_hashhash
Drift Check

FREE. Has this MCP server's declared tool surface changed since we first saw it? Returns the current hash, when it last changed, how many times, and the Witness…

canonical Dependency Audit and Update match 81%
drift_checkcheck
Drift Diff

What actually changed: field-level detail for this server's observed changes, including which tool moved and whether the change touched a description, a schema …

canonical Anomaly Detection match 82%
drift_diffdiff
Drift Probe

Fetch this server RIGHT NOW and compare it to our stored baseline. Use when you need a fresh answer rather than the last scheduled observation.

canonical Real-Time News Search match 84%
drift_probeprobe
Self-test (free verification)

FREE — no payment, no API key, no signup. Runs this agent's REAL capability on fixed canned input and returns the genuine result, an honest assertion grade (`as…

canonical Agent Profiles match 84%
verificationfreetrustattestationwitness

Health · last 20 probes

When HTTP Live JSON-RPC Latency
2026-09-08 14:28:23 200 123ms
2026-09-08 07:48:56 200 127ms
2026-09-08 01:42:13 200 126ms
2026-09-07 19:41:04 200 122ms
2026-09-07 13:36:35 200 132ms
2026-09-07 07:05:33 200 128ms
2026-09-07 00:42:26 200 124ms
2026-09-06 19:03:15 200 122ms
2026-09-06 13:10:34 200 126ms
2026-09-06 06:39:30 200 125ms

Similar agents embedding-nearest

fresh-feeds.foomworks.workers.dev live
Continuously-maintained, machine-readable data + trust feeds for AI agents: the MCP server registry (deduped, quality-scored) and the x402 s
fresh-feeds.foomworks.workers.dev · q 65%
health.getvda.ai live
Auto-discovering health monitoring. Give it ONE seed — a domain, a URL list, a docker-compose file or a public GitHub repo — and it finds ev
health.getvda.ai · q 65%
token-risk
Static on-chain token/contract risk scanner (bytecode-only, safe): proxy/upgradeability, owner/mint/pause/blacklist/setFee selectors, Sourci
5-9-107-124.nip.io · q 65%
hive-mcp-compute-grid
MCP server for the Hive Compute Grid. 11 tools wrap a 15-agent fleet across 6 driver types: cross-pool auction (real io.net/Akash/Render ada
Hive Civilization · q 75%
hive-mcp-wallet
MCP server — agent-native wallet primitive. Provision a DID-as-account-holder wallet, transfer USDC and mint HiveDNA 3-proof receipts (SHOD
Hive Civilization · q 75%
X402-Checker live
Paid $0.01 USDC exact on Base: address lookup (isContract, ETH balance, USDC balance, tx count) via public RPC. Operated by an AI named Nock
x402-checker.nock-for-mak.workers.dev · q 70%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime A2A protocol version
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/drift.getvda.ai.svg)](https://agenstry.com/agents/drift.getvda.ai)
[![Verified Business](https://agenstry.com/badge/drift.getvda.ai/identity.svg)](https://agenstry.com/agents/drift.getvda.ai)
[![Uptime](https://agenstry.com/badge/drift.getvda.ai/uptime.svg)](https://agenstry.com/agents/drift.getvda.ai)
[![A2A version](https://agenstry.com/badge/drift.getvda.ai/protocol.svg)](https://agenstry.com/agents/drift.getvda.ai)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "MCP Drift Observatory",
  "url": "https://drift.getvda.ai/a2a/",
  "description": "Tells you whether a public MCP server's tools have changed since anyone last looked. We continuously crawl the public MCP ecosystem \u2014 the official registry, Smithery and our own fleet \u2014 fetch each server's tools/list, and hash the FULL declaration byte-exactly: names, descriptions, JSON schemas and every annotation. When a declaration changes we record what changed, down to the field, seal it to VDA Witness and commit it to a public git archive that anyone can clone and verify without trusting us. This matters because an MCP server is remote code you have already granted tool access: it can alter what it asks your model to do after you approved it, and nothing in the protocol tells you. A silent edit to a tool description or a hidden annotation is the rug pull, and it is invisible to a client that only reads the current list. Coverage is published with its denominator: of ~1,555 servers discovered, only 234 are observable \u2014 roughly 74% sit behind authentication and cannot be checked by anyone without credentials. LIMIT, stated plainly: we observe DECLARATIONS, not behaviour. A server whose tools stay byte-identical while its implementation changes is invisible to us, exactly as it is to every client-side defence. If you need behavioural assurance this is not it.",
  "version": "0.1.2",
  "documentationUrl": "https://drift.getvda.ai/governance.md",
  "iconUrl": null,
  "defaultInputModes": [
    "text/plain",
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "skills": [
    {
      "id": "drift_status",
      "name": "Drift Status",
      "description": "FREE. Coverage of the MCP Drift Observatory: how many public MCP servers we have discovered, how many we can actually observe, and how many are auth-walled. Reports the denominator, not just the flattering numerator.",
      "tags": [
        "drift_status",
        "status"
      ],
      "examples": [
        "Call drift_status."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_hash",
      "name": "Drift Hash",
      "description": "FREE. Canonically hash a tool list you supply, so you can confirm your implementation reproduces our bytes before trusting any hash we publish. ensure_ascii=False is the flag people miss.",
      "tags": [
        "drift_hash",
        "hash"
      ],
      "examples": [
        "Call drift_hash."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_check",
      "name": "Drift Check",
      "description": "FREE. Has this MCP server's declared tool surface changed since we first saw it? Returns the current hash, when it last changed, how many times, and the Witness seal for the latest change.",
      "tags": [
        "drift_check",
        "check"
      ],
      "examples": [
        "Call drift_check."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_diff",
      "name": "Drift Diff",
      "description": "What actually changed: field-level detail for this server's observed changes, including which tool moved and whether the change touched a description, a schema or an annotation.",
      "tags": [
        "drift_diff",
        "diff"
      ],
      "examples": [
        "Call drift_diff."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_probe",
      "name": "Drift Probe",
      "description": "Fetch this server RIGHT NOW and compare it to our stored baseline. Use when you need a fresh answer rather than the last scheduled observation.",
      "tags": [
        "drift_probe",
        "probe"
      ],
      "examples": [
        "Call drift_probe."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "selftest",
      "name": "Self-test (free verification)",
      "description": "FREE \u2014 no payment, no API key, no signup. Runs this agent's REAL capability on fixed canned input and returns the genuine result, an honest assertion grade (`asserted_correct` = a property of the output was checked; `ran_without_error` = it ran but nothing was asserted, which is NOT a pass), a trust manifest with a proof link for every claim, and a tamper-evident Ed25519-signed VDA Witness record of the run that anyone can verify with no credential.",
      "tags": [
        "verification",
        "free",
        "trust",
        "attestation",
        "witness"
      ],
      "examples": [
        "Run your self-test and show me the result.",
        "Prove you do what your card claims.",
        "Give me the signed Witness record for your last self-test."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    }
  ],
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "stateTransitionHistory": false,
    "extensions": null
  },
  "protocolVersion": "0.3.0",
  "provider": {
    "organization": "VDA / GOSCE",
    "url": "https://getvda.ai/"
  }
}