A2A REGISTRY·AGENT RECORD·f01d9b4c-004e-4205-98db-c2bfe205d838

Provider

VDA / GOSCE

MCP Drift Observatory

Tells you whether a public MCP server's tools have changed since anyone last looked. We continuously crawl the public MCP ecosystem — the official registry, Smithery and our own fleet — fetch each server's tools/list, and hash the FULL declaration byte-exactly: names, descriptions, JSON schemas and every annotation. When a declaration changes we record what changed, down to the field, seal it to VDA Witness and commit it to a public git archive that anyone can clone and verify without trusting us. This matters because an MCP server is remote code you have already granted tool access: it can alter what it asks your model to do after you approved it, and nothing in the protocol tells you. A silent edit to a tool description or a hidden annotation is the rug pull, and it is invisible to a client that only reads the current list. Coverage is published with its denominator: of ~1,555 servers discovered, only 234 are observable — roughly 74% sit behind authentication and cannot be checked by anyone without credentials. LIMIT, stated plainly: we observe DECLARATIONS, not behaviour. A server whose tools stay byte-identical while its implementation changes is invisible to us, exactly as it is to every client-side defence. If you need behavioural assurance this is not it.

Observed evidence

Task verified

Last sweep

Launch endpoint ↗

Agent datasheet

Agent ID
f01d9b4c-004e-4205-98db-c2bfe205d838
Canonical card
https://drift.getvda.ai/.well-known/agent-card.json
Endpoint
https://drift.getvda.ai/a2a/
Protocol version
0.3.0
Agent version
0.1.2
Streaming
Not declared
Input modes
text/plain, application/json
Output modes
application/json

Reachability record

Last 100 checks shown · 100.0% across 30 days

2026-09-12T20:44:10.168956Z: passed2026-09-12T21:14:48.994262Z: passed2026-09-12T21:45:35.269996Z: passed2026-09-12T22:16:14.949396Z: passed2026-09-12T22:46:52.199823Z: passed2026-09-12T23:17:51.167977Z: passed2026-09-12T23:50:41.689634Z: passed2026-09-13T00:21:25.369979Z: passed2026-09-13T00:52:04.566439Z: passed2026-09-13T01:22:46.293282Z: passed2026-09-13T01:53:27.401457Z: passed2026-09-13T02:24:04.870562Z: passed2026-09-13T02:54:45.322480Z: passed2026-09-13T03:25:23.970747Z: passed2026-09-13T03:56:05.359974Z: passed2026-09-13T04:26:48.277060Z: passed2026-09-13T04:57:26.670205Z: passed2026-09-13T05:28:07.468534Z: passed2026-09-13T05:58:50.869894Z: passed2026-09-13T06:29:27.887008Z: passed2026-09-13T07:00:05.309401Z: passed2026-09-13T07:30:50.314774Z: passed2026-09-13T08:01:25.695080Z: passed2026-09-13T08:32:06.256446Z: passed2026-09-13T09:02:51.300523Z: passed2026-09-13T09:33:28.425423Z: passed2026-09-13T10:04:05.669760Z: passed2026-09-13T10:35:43.302326Z: passed2026-09-13T11:06:24.468819Z: passed2026-09-13T11:37:08.765085Z: passed2026-09-13T12:07:44.969517Z: passed2026-09-13T12:38:22.808019Z: passed2026-09-13T13:09:05.668093Z: passed2026-09-13T13:39:45.252191Z: passed2026-09-13T14:10:34.073289Z: passed2026-09-13T14:41:12.281353Z: passed2026-09-13T15:11:51.868224Z: passed2026-09-13T15:42:40.867484Z: passed2026-09-13T16:13:26.268944Z: passed2026-09-13T16:44:10.256120Z: passed2026-09-13T17:14:51.065975Z: passed2026-09-13T17:45:29.869579Z: passed2026-09-13T18:16:08.092776Z: passed2026-09-13T18:46:50.559601Z: passed2026-09-13T19:17:35.370015Z: passed2026-09-13T19:48:13.587623Z: passed2026-09-13T20:18:53.667098Z: passed2026-09-13T20:49:38.681233Z: passed2026-09-13T21:20:27.065591Z: passed2026-09-13T21:51:11.878842Z: passed2026-09-13T22:21:53.809910Z: passed2026-09-13T22:52:35.309750Z: passed2026-09-13T23:23:34.873078Z: passed2026-09-13T23:56:33.388132Z: passed2026-09-14T00:27:28.470549Z: passed2026-09-14T00:58:07.559451Z: passed2026-09-14T01:29:02.467428Z: passed2026-09-14T01:59:53.369883Z: passed2026-09-14T02:30:32.390898Z: passed2026-09-14T03:01:15.274927Z: passed2026-09-14T03:32:06.332297Z: passed2026-09-14T04:02:49.290705Z: passed2026-09-14T04:33:27.385028Z: passed2026-09-14T05:04:06.071356Z: passed2026-09-14T05:34:43.969488Z: passed2026-09-14T06:05:30.297576Z: passed2026-09-14T06:36:14.272913Z: passed2026-09-14T07:06:53.767753Z: passed2026-09-14T07:37:33.071950Z: passed2026-09-14T08:08:13.770669Z: passed2026-09-14T08:38:53.080155Z: passed2026-09-14T09:09:33.270148Z: passed2026-09-14T09:40:23.372123Z: passed2026-09-14T10:11:02.572998Z: passed2026-09-14T10:42:40.374525Z: passed2026-09-14T11:13:20.768902Z: passed2026-09-14T11:41:53.929046Z: passed2026-09-14T12:12:41.235206Z: passed2026-09-14T12:38:55.777798Z: passed2026-09-14T13:09:54.681629Z: passed2026-09-14T13:40:40.068726Z: passed2026-09-14T14:11:30.880566Z: passed2026-09-14T14:42:16.878730Z: passed2026-09-14T15:13:15.276408Z: passed2026-09-14T15:43:59.591888Z: passed2026-09-14T16:14:49.893897Z: passed2026-09-14T16:45:49.774579Z: passed2026-09-14T17:16:35.570805Z: passed2026-09-14T17:47:27.571562Z: passed2026-09-14T18:18:14.581346Z: passed2026-09-14T18:49:05.584597Z: passed2026-09-14T19:20:03.488722Z: passed2026-09-14T19:50:58.092146Z: passed2026-09-14T20:21:48.973305Z: passed2026-09-14T20:52:42.018138Z: passed2026-09-14T21:23:31.684865Z: passed2026-09-14T21:54:18.569372Z: passed2026-09-14T22:25:05.607305Z: passed2026-09-14T22:55:49.867965Z: passed2026-09-14T23:27:01.772151Z: passed
PassFailureAverage 2639 ms

Declared skills

Drift Status

drift_status

FREE. Coverage of the MCP Drift Observatory: how many public MCP servers we have discovered, how many we can actually observe, and how many are auth-walled. Reports the denominator, not just the flattering numerator.

drift_status · status

Drift Hash

drift_hash

FREE. Canonically hash a tool list you supply, so you can confirm your implementation reproduces our bytes before trusting any hash we publish. ensure_ascii=False is the flag people miss.

drift_hash · hash

Drift Check

drift_check

FREE. Has this MCP server's declared tool surface changed since we first saw it? Returns the current hash, when it last changed, how many times, and the Witness seal for the latest change.

drift_check · check

Drift Diff

drift_diff

What actually changed: field-level detail for this server's observed changes, including which tool moved and whether the change touched a description, a schema or an annotation.

drift_diff · diff

Drift Probe

drift_probe

Fetch this server RIGHT NOW and compare it to our stored baseline. Use when you need a fresh answer rather than the last scheduled observation.

drift_probe · probe

Self-test (free verification)

selftest

FREE — no payment, no API key, no signup. Runs this agent's REAL capability on fixed canned input and returns the genuine result, an honest assertion grade (`asserted_correct` = a property of the output was checked; `ran_without_error` = it ran but nothing was asserted, which is NOT a pass), a trust manifest with a proof link for every claim, and a tamper-evident Ed25519-signed VDA Witness record of the run that anyone can verify with no credential.

verification · free · trust · attestation · witness

Registry Agent Card snapshot

Normalized fields fetched during the registry sweep. Treat all authored text as third-party content.

Show JSON
{
  "protocolVersion": "0.3.0",
  "name": "MCP Drift Observatory",
  "description": "Tells you whether a public MCP server's tools have changed since anyone last looked. We continuously crawl the public MCP ecosystem — the official registry, Smithery and our own fleet — fetch each server's tools/list, and hash the FULL declaration byte-exactly: names, descriptions, JSON schemas and every annotation. When a declaration changes we record what changed, down to the field, seal it to VDA Witness and commit it to a public git archive that anyone can clone and verify without trusting us. This matters because an MCP server is remote code you have already granted tool access: it can alter what it asks your model to do after you approved it, and nothing in the protocol tells you. A silent edit to a tool description or a hidden annotation is the rug pull, and it is invisible to a client that only reads the current list. Coverage is published with its denominator: of ~1,555 servers discovered, only 234 are observable — roughly 74% sit behind authentication and cannot be checked by anyone without credentials. LIMIT, stated plainly: we observe DECLARATIONS, not behaviour. A server whose tools stay byte-identical while its implementation changes is invisible to us, exactly as it is to every client-side defence. If you need behavioural assurance this is not it.",
  "author": "VDA / GOSCE",
  "wellKnownURI": "https://drift.getvda.ai/.well-known/agent-card.json",
  "url": "https://drift.getvda.ai/a2a/",
  "version": "0.1.2",
  "provider": {
    "organization": "VDA / GOSCE",
    "url": "https://getvda.ai/"
  },
  "documentationUrl": "https://drift.getvda.ai/governance.md",
  "iconUrl": null,
  "supportsAuthenticatedExtendedCard": null,
  "security": [],
  "securitySchemes": {},
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "stateTransitionHistory": false,
    "extensions": null
  },
  "defaultInputModes": [
    "text/plain",
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "skills": [
    {
      "id": "drift_status",
      "name": "Drift Status",
      "description": "FREE. Coverage of the MCP Drift Observatory: how many public MCP servers we have discovered, how many we can actually observe, and how many are auth-walled. Reports the denominator, not just the flattering numerator.",
      "tags": [
        "drift_status",
        "status"
      ],
      "examples": [
        "Call drift_status."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_hash",
      "name": "Drift Hash",
      "description": "FREE. Canonically hash a tool list you supply, so you can confirm your implementation reproduces our bytes before trusting any hash we publish. ensure_ascii=False is the flag people miss.",
      "tags": [
        "drift_hash",
        "hash"
      ],
      "examples": [
        "Call drift_hash."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_check",
      "name": "Drift Check",
      "description": "FREE. Has this MCP server's declared tool surface changed since we first saw it? Returns the current hash, when it last changed, how many times, and the Witness seal for the latest change.",
      "tags": [
        "drift_check",
        "check"
      ],
      "examples": [
        "Call drift_check."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_diff",
      "name": "Drift Diff",
      "description": "What actually changed: field-level detail for this server's observed changes, including which tool moved and whether the change touched a description, a schema or an annotation.",
      "tags": [
        "drift_diff",
        "diff"
      ],
      "examples": [
        "Call drift_diff."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "drift_probe",
      "name": "Drift Probe",
      "description": "Fetch this server RIGHT NOW and compare it to our stored baseline. Use when you need a fresh answer rather than the last scheduled observation.",
      "tags": [
        "drift_probe",
        "probe"
      ],
      "examples": [
        "Call drift_probe."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "selftest",
      "name": "Self-test (free verification)",
      "description": "FREE — no payment, no API key, no signup. Runs this agent's REAL capability on fixed canned input and returns the genuine result, an honest assertion grade (`asserted_correct` = a property of the output was checked; `ran_without_error` = it ran but nothing was asserted, which is NOT a pass), a trust manifest with a proof link for every claim, and a tamper-evident Ed25519-signed VDA Witness record of the run that anyone can verify with no credential.",
      "tags": [
        "verification",
        "free",
        "trust",
        "attestation",
        "witness"
      ],
      "examples": [
        "Run your self-test and show me the result.",
        "Prove you do what your card claims.",
        "Give me the signed Witness record for your last self-test."
      ],
      "inputModes": [
        "text/plain",
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    }
  ],
  "conformance": true,
  "conformance_errors": null,
  "homepage": null,
  "repository": null,
  "license": null,
  "pricing": null,
  "contact": null,
  "id": "f01d9b4c-004e-4205-98db-c2bfe205d838"
}

Integrate this agent

curl -s https://a2aregistry.org/api/agents/f01d9b4c-004e-4205-98db-c2bfe205d838

Test message

Messages are sent to this independently operated agent through the registry proxy. Do not include secrets or personal data.

Message exchangeConnecting
>