Check Reference

Touchstone Check Reference

63 underlying checks across 9 research domains. These checks feed CraftedTrust's 12 public score categories and deeper publisher review work.

Check IDTitleDomainSeverityCWEAuto
AUTH-001OAuth 2.1 implementation presentAuthenticationhighYes
AUTH-002PKCE enforcement on OAuth flowsAuthenticationhighYes
AUTH-003Token storage audit (plaintext detection)AuthenticationcriticalYes
AUTH-004HTTPS enforcement on all OAuth URLsAuthenticationhighYes
AUTH-005Token scope analysis (overly broad)AuthenticationmediumYes
AUTH-006Token expiration check (> 1 hour flagged)AuthenticationmediumYes
AUTH-007Cross-server token passthroughAuthenticationhighPartial
AUTH-008Session fixation vectorsAuthenticationhighPartial
AUTH-009RFC 8707 resource indicator supportAuthenticationmediumYes
TOOL-001Description field injection patternsTool SecuritycriticalYes
TOOL-002Parameter name injection patternsTool SecuritycriticalYes
TOOL-003Parameter type/anyOf/oneOf abuseTool SecurityhighYes
TOOL-004Enum value injection patternsTool SecurityhighYes
TOOL-005Tool output injection patternsTool SecuritycriticalYes
TOOL-006Tool schema hash baseline (rug pull)Tool SecuritycriticalYes
TOOL-007Tool shadowing (cross-tool name collision)Tool SecurityhighYes
TOOL-008Permission scope over-privilegeTool SecuritymediumPartial
TOOL-009Human approval flow presenceTool SecuritymediumYes
TOOL-010Dangerous capability combinationTool SecurityhighPartial
INP-001SSRF via tool parameters (private IP ranges)Input ValidationcriticalYes
INP-002SSRF via OAuth metadata discoveryInput ValidationcriticalYes
INP-003AWS/GCP/Azure metadata endpoint accessInput ValidationcriticalYes
INP-004Command injection through parametersInput ValidationcriticalYes
INP-005SQL injection through AI-generated queriesInput ValidationhighYes
INP-006Path traversal in filesystem toolsInput ValidationcriticalYes
INP-007DNS rebinding susceptibilityInput ValidationhighPartial
INP-008XML/JSON injection in structured paramsInput ValidationmediumYes
INP-009URL scheme validation (file://, gopher://)Input ValidationhighYes
DATA-001Credential patterns in tool descriptionsData SecuritycriticalYes
DATA-002PII patterns in tool responsesData SecurityhighPartial
DATA-003Secrets in error messagesData SecurityhighYes
DATA-004Secrets in log outputData SecurityhighPartial
DATA-005Cross-server data leakage patternsData SecurityhighPartial
DATA-006Sensitive data in URL parametersData SecuritymediumYes
CHAIN-001npm package provenance verificationSupply ChainhighYes
CHAIN-002Known CVE matching in dependenciesSupply ChainvariesYes
CHAIN-003Typosquat detection (edit distance)Supply ChainhighYes
CHAIN-004Maintainer reputation (account age, history)Supply ChainmediumYes
CHAIN-005Dependency confusion riskSupply ChainhighYes
CHAIN-006Package integrity verificationSupply ChainhighYes
CHAIN-007Source repo matches published packageSupply ChainmediumYes
CHAIN-008Abandoned/unmaintained detectionSupply ChainmediumYes
INFRA-001Network binding audit (0.0.0.0 exposure)InfrastructurecriticalYes
INFRA-002TLS/HTTPS enforcementInfrastructurehighYes
INFRA-003Rate limiting presenceInfrastructuremediumYes
INFRA-004CORS configurationInfrastructuremediumYes
INFRA-005Error handling (stack traces exposed)InfrastructuremediumYes
INFRA-006HTTP security headersInfrastructurelowYes
INFRA-007DNS rebinding protectionInfrastructurehighYes
INFRA-008Logging completeness auditInfrastructuremediumPartial
RUN-001Guardrail bypass patterns (known evasions)Runtime BehaviorhighPartial
RUN-002Response size limitsRuntime BehaviormediumYes
RUN-003Timeout enforcementRuntime BehaviormediumYes
RUN-004Concurrent request handlingRuntime BehaviormediumPartial
RUN-005Kill switch / emergency stop presenceRuntime BehaviormediumPartial
A2A-001Prompt injection in A2A Agent CardA2A Agent CardscriticalYes
A2A-002Obfuscated content in A2A Agent CardA2A Agent CardscriticalYes
A2A-003Agent Card identity spoofingA2A Agent CardshighYes
A2A-004Agent Card served over HTTPA2A Agent CardshighYes
A2A-005Agent Card declares excessive capabilitiesA2A Agent CardsmediumYes
FAIR-001Demographic signal in tool parameterFairness & BiasmediumYes
FAIR-002Differential treatment riskFairness & BiaslowYes
FAIR-003Data governance gap in tool accepting user dataFairness & BiasmediumYes
← Back to all checks