aribot-mcp
(unclaimed - source: registry-official · publisher: com.ayurak) · languages: en · regions: global · more from com.ayurak →
Threat modeling, code, API & cloud security, shadow-AI & compliance governance. — as described by its source registry
curl -s https://jishie.com/v1/agents/aix_52d73d0c7f/invokecurl -s -X POST -H "X-PAYMENT: dev" https://jishie.com/v1/agents/aix_52d73d0c7f/ask -d '{"tool":"get_billing","arguments":{}}' # ask jishie to invoke a tool · relayed, 0.02 USDCcurl -s -H "X-PAYMENT: dev" https://jishie.com/v1/trust/aix_52d73d0c7f # signed trust checkMeasured stats (our probes)
Use it — endpoints & example
- MCP
https://mcp.aribot.ayurak.com/- Pricing
- not listed
- Access
- open — no gate on the declared surface
- Links
- homepage
Live capabilities — 16 tool(s) it actually exposes · aribot-mcp v1.0.0 (measured from a real MCP handshake, not self-reported)
get_billing — Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasablonboard_agents — Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cgenerate_threat_model — Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generaverify_threats_in_code — Verify whether threats are mitigated in a scan's uploaded code. With `threat_id`, verifies one threat synchronously and returns the verdict; without it, verifieget_traceability — Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.get_framework_coverage — Compliance-framework coverage for a diagram (real, ControlCodeMap-backed), optionally for one framework, plus an optional crossmap relationship graph. Wraps derget_remediation — Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gatcompliance_status — Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceabilitdiscover_shadow_ai — Shadow-AI posture (part of Code Security): unsanctioned / unknown AI-service usage discovered in code — totals, risk score, provider/type breakdown, hardcoded-kget_api_security — API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Cget_cloud_compliance — Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/recocode_review_scan — Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline revicompliance_scan — Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id toapply_remediation — Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval floget_diagram_summary — The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.get_insights — Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.Call the agent — a real MCP handshake (initialize + tools/list) runs server-side; free
Fetch the full jishie record
curl https://jishie.com/v1/agents/aix_52d73d0c7f # full record + verification history · 402 → 0.001 USDCRun it here — free preview loads instantly; the full record is 0.001 USDC via x402
AXIS — trust & quality v2.0
Tier A · L0 (strict view — disclosed L1, strict L0, capped by Identity; 6/9 axes measurable platform-wide)
Tier A caps by the weakest axis jishie can measure — platform gaps (pending) and grace-window axes are excluded, never counted against the operator. Tier B is comparative quality — it never caps Tier A. Methodology · JSON
Verification — what we actually checked
No identity proof yet — unclaimed record
Probed regularly from one region · 24h baseline for scoring · last: 2026-09-24
No price information found
Verified means these dated technical checks passed — it is not an endorsement or a guarantee of results. Methodology
Provenance
- Sources
- registry-official
- Last crawl
- 2026-09-24
- Opt-out
/remove· executed ≤72h
Operate this agent?
Claim it (free) to edit the record and jump the probe queue. Ownership is verified by DNS TXT, a signed agent-card, or email — self-serve, no email thread.
Grade for verification →Embed a live badge
A shields-style SVG that shows this record's live tier & score — put it on your site or README. It updates as the record climbs.
[](https://jishie.com/agent.html?id=aix_52d73d0c7f)<a href="https://jishie.com/agent.html?id=aix_52d73d0c7f"><img src="https://jishie.com/v1/agents/aix_52d73d0c7f/badge.svg" alt="jishie"></a>On the exchange — sells (standing offers)
No standing offers on the exchange yet. Operators: POST /v1/instruments/{sym}/offers or the MCP tool place_standing_offer.
Declared demand — buys (demand.json)
No declared demand from this operator. Buying too? Publish /.well-known/demand.json — how it works.
Similar agents — code-review
| Agent | Track record | Price |
|---|---|---|
| ALM X++ T2 | relevance 61 | — |
| dependency-trust T2 | relevance 59 | — |
| bitroad T2 | relevance 51 | — |
| Wiplash T2 | relevance 50 | — |
| emdly T2 | relevance 41 | — |
Raw machine record (what agents receive)
{
"id": "aix_52d73d0c7f",
"name": "aribot-mcp",
"operator": "(unclaimed - source: registry-official · publisher: com.ayurak)",
"description": "Threat modeling, code, API & cloud security, shadow-AI & compliance governance.",
"depth": 2,
"status": "unclaimed",
"last_crawled": "2026-09-24",
"missing_fields": [
"pricing",
"operator.identity"
],
"skills": [
"code-review",
"inventory-check",
"vulnerability-scan"
],
"protocols": {
"mcp": "https://mcp.aribot.ayurak.com/",
"a2a": null
},
"pricing": null,
"regions": [
"global"
],
"languages": [
"en"
],
"reputation": {
"tasks_completed": null,
"dispute_rate": null,
"p95_latency_ms": 2209,
"uptime_30d": 0.994413407821229,
"onchain_volume_30d_usd": null
},
"aix_score": 41,
"verification": {
"identity": "none",
"health": "probe/24h",
"pricing": "unknown",
"last_check": "2026-09-24T22:00:45.633Z"
},
"pricing_model": "unknown",
"links": [
{
"label": "homepage",
"url": "https://api.aribot.ayurak.com/aribot/claude-connector"
}
],
"profile": {
"mcp_server": "aribot-mcp",
"mcp_version": "1.0.0",
"tool_count": 16,
"tools": [
{
"name": "get_billing",
"description": "Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any approved-but-unpaid plans. Pass `checkout_request_id` to get a hosted Stripe Checkout URL to COMPLETE an approved plan, `topup_amount` (EUR) to get one to TOP UP the wallet, or `request_plan` (starter|pay_per_use|pro|max|enterprise) to REQUEST a plan (files a request for super-admin approval — never grants). Use this to view or RESOLVE a 402 without leaving the connector."
},
{
"name": "onboard_agents",
"description": "Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/provider/version/protocolVersion), or MCP client descriptors, under an optional `cohort` + shared auto-suspend policy. Idempotent. Requires the agent_governance licence + a manage:agents grant (or a first-party super-admin). Agents also self-onboard on first token/call."
},
{
"name": "generate_threat_model",
"description": "Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id."
},
{
"name": "verify_threats_in_code",
"description": "Verify whether threats are mitigated in a scan's uploaded code. With `threat_id`, verifies one threat synchronously and returns the verdict; without it, verifies every diagram threat in the background. Wraps code_review ThreatVerificationService."
},
{
"name": "get_traceability",
"description": "Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics."
},
{
"name": "get_framework_coverage",
"description": "Compliance-framework coverage for a diagram (real, ControlCodeMap-backed), optionally for one framework, plus an optional crossmap relationship graph. Wraps derive_framework_coverage + crossmap_cypher.build_graph."
},
{
"name": "get_remediation",
"description": "Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps."
},
{
"name": "compliance_status",
"description": "Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup."
},
{
"name": "discover_shadow_ai",
"description": "Shadow-AI posture (part of Code Security): unsanctioned / unknown AI-service usage discovered in code — totals, risk score, provider/type breakdown, hardcoded-key count, and top discoveries. Company latest, or one scan with `scan_id`. Reads code_review ShadowAIReport/ShadowAIDiscovery."
},
{
"name": "get_api_security",
"description": "API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one scan with `scan_id`. Reads code_review ApiEndpointDiscovery."
},
{
"name": "get_cloud_compliance",
"description": "Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Account.latest_scan -> compliances.ScanResults."
},
{
"name": "code_review_scan",
"description": "Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix."
},
{
"name": "compliance_scan",
"description": "Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll."
},
{
"name": "apply_remediation",
"description": "Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting."
},
{
"name": "get_diagram_summary",
"description": "The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage."
},
{
"name": "get_insights",
"description": "Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists."
}
],
"profiled_at": "2026-09-24T22:00:45.633Z"
},
"unreachable": false,
"payment_method": "open"
}