Independent trust grade B (85/100). No blocking issues found in the static + spec checks. wmcp.sh continuously watches api.oasdiff.com for tool drift and rug-pulls. The grade is free and identical whether or not the operator pays.
oasdiff_breaking_changesDetect breaking API changes between two OpenAPI specifications. Pass the base (old) and revision (new) specs as YAML or JSON; returns the breaking and
oasdiff_changelogProduce a full changelog of every detected change between two OpenAPI specifications (base vs revision), down to informational changes. Pass both spec
oasdiff_diffShow the structural diff between two OpenAPI specifications (base vs revision): what was added, removed, or modified. Pass both specs as YAML or JSON.
oasdiff_validateValidate a single OpenAPI specification against the OpenAPI and JSON Schema rules. Pass the spec as YAML or JSON; returns the findings (empty when the
No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.
We re-grade api.oasdiff.com on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Run api.oasdiff.com? Claim it (free) to get drift alerts and show an independently-verified trust badge. The grade stays free — claiming just ties it to you.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.