Leash Index

Index / payments

ai.duvera/gateway

ai-duvera-gateway declares 52 capabilities across 52 tools, with 3 critical issues.

86/100 exposureHigh exposure

Manifest retrieved 2026-09-14 from tools/list on https://app.duvera.ai/mcp, published in the official MCP registry as ai.duvera/gateway 1.0.0. Not verified by a maintainer.

Issues

These describe what this server's manifest declares. A product can provide controls that MCP has no way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a declaration is not evidence that a control is absent.

critical · no-revocation · All 52 tools

52 of 52 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.

critical · irreversible-uncapped · 1 of 52 tools

1 tool is classified as irreversible and declares no limit.

critical · uncapped-spend · 1 of 52 tools

1 tool is classified as moving money and declares no dollar limit. A cap on the number of payments does not bound their amount.

high · no-expiry · All 52 tools

52 of 52 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.

high · no-audit-trail · All 52 tools

52 of 52 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.

high · uncapped-write · 18 of 52 tools

18 tools can modify data and declare no limit.

low · uncapped-read · 33 of 52 tools

33 tools can read data and declare no limit.

Declared capabilities

How each tool was read. declared means the server's own annotation said so — self-reported and unverified. inferred is from the tool's name. assumed means nothing indicated either way.

ToolRead asBasis
amazon__package_trackwrite assumed
applehealth__heart_rate_readread inferred
applehealth__sleep_readread inferred
applehealth__steps_readread inferred
bluesky__trending_getread inferred
chase__balance_checkwrite assumed
datadog__logs_viewread inferred
delta__boardingpass_showread inferred
duvera__dev_npm_packagewrite assumed
duvera__dev_pypi_packagewrite assumed
duvera__dev_stackoverflow_searchread inferred
duvera__finance_crypto_priceread inferred
duvera__finance_exchange_ratesread inferred
duvera__food_recipe_searchread inferred
duvera__food_restaurant_searchread inferred
duvera__geo_geocodewrite assumed
duvera__github_latest_releasewrite assumed
duvera__github_read_fileread inferred
duvera__github_search_reposread inferred
duvera__news_searchread inferred
duvera__news_top_storieswrite assumed
duvera__reference_dictionarywrite assumed
duvera__reference_public_holidayswrite assumed
duvera__time_nowwrite assumed
duvera__travel_flight_searchread inferred
duvera__weather_air_qualitywrite assumed
duvera__weather_currentwrite assumed
duvera__wiki_searchread inferred
duvera__wiki_summaryread inferred
gmail__mail_readread inferred
google_workspace__mail_searchread inferred
googlecalendar__availability_findread inferred
grubhub__order_trackwrite assumed
hackernews__stories_topwrite assumed
instacart__menu_searchread inferred
maps__eta_sharewrite assumed
microsoft365__calendar_listread inferred
microsoft365__mail_searchread inferred
notion__notes_searchread inferred
obsidian__notes_searchread inferred
open_meteo__weather_forecastwrite assumed
opensky__flights_livewrite assumed
postgres__sql_readread inferred
shazam__audio_identifywrite assumed
slack__message_searchread inferred
southwest__flight_statusread inferred
telegram__message_readread inferred
twitter__tweets_searchread inferred
uber__fare_estimateread inferred
united__flight_statusread inferred
venmo__payment_requestpay inferred
wallet__boardingpass_showread inferred
Answering this question about your own agent? Media Yard LLC runs a fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated artifact you can hand to a customer's security review. See what it includes and costs, or write to support@leashkit.com. Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed, submit its current tools/list response and it will be re-scored and dated. Corrections are published alongside the original, not in place of it.