Independent trust grade A- (91/100). No blocking issues found in the static + spec checks. wmcp.sh continuously watches api.docverdict.com for tool drift and rug-pulls. The grade is free and identical whether or not the operator pays.
verify_pdfCheck one PDF: digital signature status, whether content was added after signing, and metadata observations (creation dates, producing software, edit
verify_photoCheck one photo (JPG, PNG, or HEIC): camera metadata, capture time, edit traces, and timestamp consistency. Observations suggest, never prove, how the
verify_emailCheck one email saved as .eml: sender alignment, authentication results as recorded by the receiving server, and the delivery route. Classifications o
compare_pdfsCompare two PDFs: byte identity, whether one file derives from the other, and what changed (pages, metadata, signature events). Reports the relationsh
No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.
We re-grade api.docverdict.com on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Run api.docverdict.com? Claim it (free) to get drift alerts and show an independently-verified trust badge. The grade stays free — claiming just ties it to you.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.