Back to Browse

Faro MCP Server

by Vedux98
Developer ToolsLow Risk8.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Verify URLs, payees, and messages before acting: red/yellow/green trust verdicts for agents.

About

Verify URLs, payees, and messages before acting: red/yellow/green trust verdicts for agents.

Remote endpoints: streamable-http: https://mcp.farofinance.app/mcp

Security Report

8.0
Low Risk8.0Low Risk

Remote MCP endpoint verified (371ms response). 3 trust signals: valid MCP protocol, requires auth, registry import. No security issues detected.

Endpoint verified · Requires authentication · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-vedux98-faro": {
      "url": "https://mcp.farofinance.app/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Faro

Check before an agent pays, clicks, or trusts.

Faro is a trust layer for AI agents and apps. You send a URL, payee, message, or agent-payment payload — Faro returns one clear answer: green, yellow, or red, a one-line reason, and what to do next (allow / warn / block / review).

This repo is the open interface (Apache-2.0): the verdict contract, client SDKs, and auditable payment-protocol adapters. Scoring and the reputation graph stay on Faro’s hosted API, so you can audit what leaves your process without forking a black-box engine.

Get an API key → farofinance.app


What can you do with this package?

You want to…Use
Verify a link before an agent opens or shares itPython/TS SDK verify_url, REST, or MCP verify_url
Check a UPI / payee / account before sending moneyverify_payee
Screen an inbound SMS, email, or chat for scam tacticsverify_message
Gate an AP2 / x402 / ACP payment before settleOpen adapters in adapters/faro_agentpay/ → then verify each artifact
Let Claude / Cursor / any MCP client call FaroHosted MCP at https://mcp.farofinance.app/mcp
Branch in code on a stable contractcontracts/verdict.schema.json + typed SDKs

Typical users: agent builders, wallet/checkout integrators, MCP app authors, and security teams who need a single red/yellow/green decision at the moment of action — not a dashboard full of raw threat intel.


Quick start

pip install faro-client
import asyncio, os
from faro_client import FaroClient

async def main() -> None:
    async with FaroClient(os.environ["FARO_API_KEY"]) as client:
        result = await client.verify_url("https://example.com")
        print(result.verdict, result.reason, result.recommended_action)
        # Branch: allow | warn | block | review
        if result.recommended_action == "block":
            raise SystemExit("blocked by Faro")

asyncio.run(main())
curl -s -X POST https://api.farofinance.app/v1/verify/url \
  -H "Authorization: Bearer $FARO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"value":"https://example.com"}'

TypeScript: see sdk/typescript/.
Payment parsers (no engine inside): adapters/faro_agentpay/.
Recipes: recipes/.


What’s in this repo

PiecePath
Verdict JSON Schemacontracts/verdict.schema.json
OpenAPIsdk/openapi.json
Python SDK (faro-client)sdk/python/
TypeScript SDKsdk/typescript/
AP2 / x402 / ACP adaptersadapters/faro_agentpay/
Verify-before-pay recipesrecipes/
MCP registry manifestserver.json · docs/tools.md

Why open / what’s closed

Open here: schema, SDKs, protocol adapters, recipes, MCP tool docs — so integrators and protocol ecosystems can cite and fork the interface.

Closed (hosted API): signal providers, scoring, reputation graph, prompts. Adapters stop at a documented seam: parse → artifacts → POST /v1/verify (or your own checks) → optional worst_of.


Trust, plainly

Hosted verifies can carry signed trust receipts and a transparency log (hashes and signatures — not your raw PII). Product docs: farofinance.app.


Roadmap / future scope

Shipped or in flight on the hosted product (not all of this lives in this public repo):

  • Stronger verify-before-pay coverage across AP2 / x402 / ACP as specs churn
  • Richer payee / message / URL signals and reputation write-back
  • Watches & webhooks when a previously clean entity flips
  • Trust receipts and day-rooted transparency log verification tooling
  • More SDK languages and framework examples (LangGraph, Crew, etc.)
  • Optional public examples (e.g. agent defense patterns) without opening the engine

Community PRs welcome for adapter/SDK/docs fixes (DCO required). Engine changes are not accepted here — see CONTRIBUTING.md.


What this is not

  • Not a self-hosted scam ML model — default is the hosted API
  • Not a generic prompt-injection detector — Faro verifies artifacts at action time

Branches: BRANCHES.md · Security: SECURITY.md

License

Apache-2.0.

Reviews

No reviews yet

Be the first to review this server!