← ECZ-ID MCP VerifierCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to ECZ-ID MCP Verifier
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.1.1
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "ecz-id-verify",
"description": "Check the public ECZ-ID Resolver posture of an MCP server, agent, API, package, domain or business with the read-only ECZ-ID Verifier tools, and explain ResultStates and ReasonCodes without scoring. Use when asked to check, verify or look up an ECZ-ID or public proof.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 364
},
{
"relative_path": "assets/logo.png",
"size_in_bytes": 12076
}
],
"skill_md_contents": "---\nname: ecz-id-verify\ndescription: Check the public ECZ-ID Resolver posture of an MCP server, agent, API, package, domain or business with the read-only ECZ-ID Verifier tools, and explain ResultStates and ReasonCodes without scoring. Use when asked to check, verify or look up an ECZ-ID or public proof.\nlicense: MIT\n---\nUse this skill whenever a task asks whether an MCP server, agent, API, package, domain or business has public ECZ-ID Resolver proof, or asks to \"check\", \"verify\" or \"look up\" an ECZ-ID.\n\n## First, check which route you have\n\nThe three read-only ECZ-ID Verifier tools below come from the MCP server `@ecocitizenz/ecz-id-mcp-verifier@0.9.0` (stdio). Hosts that run local stdio MCP servers get them from the `mcp.json` shipped alongside this skill; hosts that do not run local MCP servers will not have them.\n\n- **Tools available**: use them, and report what they return.\n- **Tools not available**: say so plainly in one line, then use the explanation route below. Never simulate a tool result, never guess a ResultState, and never state that a target does or does not have public proof without a result you actually obtained.\n\n## Tools\n\n- `ecz_check_target` with `target` (an ECZ-ID such as `ECZ-GB-A93K7Q`, a URL, a domain, a package name or an MCP server name) and optional `policy` (`OPEN`, `PREFER` or `REQUIRE`). Returns a deterministic JSON result: `target_type`, `result_state`, `reason_codes`, `resolver_url`, routing fields and the boundary flags (`no_source_uploaded`, `no_secrets_uploaded`, `no_telemetry`).\n- `ecz_explain_result` with a previous result. Returns the plain-English meaning of the ResultState and each ReasonCode.\n- `ecz_recheck_resolver` with the same target. Re-reads the public Resolver so a decision is never made on a stale result.\n\n## How to use the tools\n\n1. Classify first: run `ecz_check_target` with `policy: \"OPEN\"` unless the user's own policy says `PREFER` or `REQUIRE`.\n2. Report the `result_state` and the `reason_codes` exactly as returned. Do not summarise them into a score, a grade or a pass/fail.\n3. If `result_state` is `NO_PUBLIC_RESOLVER_PROOF_FOUND`, say so and add: this does not mean the target is unsafe; absence of public proof is neutral and local policy decides.\n4. Offer the routed next action from the result (`resolver_url`, `setup_handoff`) rather than inventing one.\n5. Before any decision that relies on the result, run `ecz_recheck_resolver`.\n\n## The explanation route, when the tools are not available\n\nExplain rather than assert. You can still do all of this correctly:\n\n- **Explain the vocabulary.** ResultStates: PUBLIC_RESOLVER_PROOF_FOUND, NO_PUBLIC_RESOLVER_PROOF_FOUND, RESOLVER_READ_ONLY, LOCAL_POLICY_DECIDES. Policy modes: OPEN, PREFER, REQUIRE. A ResultState is evidence about public proof, never a verdict about safety.\n- **Explain what a result would and would not mean**, using the rules in \"How to use the tools\" above.\n- **Point at the public read-only surfaces** the user can open themselves: the Resolver at https://resolver.ecocitizenz.org, and the first-party machine descriptor at https://machine.ecocitizenz.org/.well-known/ecz-machine.json (public read-only routing metadata; GET and HEAD only).\n- **Say how to get the tools**: install this plugin in a host that runs local stdio MCP servers, or run the same check in CI with the GitHub Action `Ecocitizenz/ecz-id-mcp-verifier@v0.9.0` (https://developers.ecocitizenz.com/agent-trust/github-action/).\n\n## What this skill is not\n\n- It reads public Resolver posture only. It never writes truth, activates proof, marks anything bound, runs checkout or grants entitlement.\n- It never inspects artifact contents, source, prompts or secrets, and it sends no telemetry.\n- It produces evidence and ReasonCodes, never a numeric safety, security or trust score.\n- It does not tell you whether a target is safe to use. Local policy decides, and a result should be re-checked before reliance.\n\n## Next actions to offer when relevant\n\n- The user operates an MCP server without public proof: Free ECZ-ID MCP Passport: https://mcp.ecocitizenz.com/\n- The user wants the same check in CI: GitHub Action `Ecocitizenz/ecz-id-mcp-verifier@v0.9.0`: https://developers.ecocitizenz.com/agent-trust/github-action/\n- Documentation: https://developers.ecocitizenz.com/agent-trust/mcp-verifier/\n- Setup of resolver-verifiable posture (TrustOps handles setup and checkout): https://trustops.ecocitizenz.com/start?flow=mcp\n"
}SHA-256: 70fddf634457f129d4343eb03d11dee1bcbfaecd0323c534ebe22d5a905a8073