Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
Screen a payee address before an AI agent pays: sanctions, mixers, scam lists, on-chain risk.
Facts
- MCP registry
com.oceanalt/aml· 0.6.1- Endpoint
https://oceanalt.com/api/mcp- Packages
npmoceanalt-aml-mcp stdio- Website
- oceanalt.com/en/api-docs
- npm / week
- 90
- GitHub stars
- 0
- Registry entry
- updated 16 Sep 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under oceanalt.com, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 10 · about 3,186 tokens of context · checked 13 minutes ago
| Tool | What it does | Hint |
|---|---|---|
payment_decisionDecide whether this payment should happen (free) | "Before your agent pays, call OceanAlt once." Pass the payee address the agent is about to pay; get a machine-executable decision: allow | review | decline, plus verifiable evidence and retry semantics — use it as a… | read-only |
screen_addressScreen a payee address for AML risk (free) | Run an AML compliance screen on a single blockchain address BEFORE paying or receiving from it — the pre-payment check on a counterparty. Checks OFAC sanctions, known mixers, community scam/phishing lists, stablecoin… | read-only |
screen_endpointScreen a payment endpoint for phishing (free) | Screen a payment ENDPOINT (URL or domain) before calling it — the half that address screening cannot answer. In x402 the agent discovers a URL first, receives a 402, and only then learns where to pay: if that endpoint… | read-only |
counterparty_control_baselineCheck a counterparty's control baseline before paying (free) | Answers a different question from address screening. Screening asks whether an address is risky; this asks how much damage the agent on the other side could do if it were talked into something. Returns that party's… | read-only |
attest_control_baselineFile your own control-baseline attestation (free) | File your operator's control-baseline attestation — the counterpart to counterparty_control_baseline. That tool asks what controls the OTHER side runs; this one publishes what YOUR side runs, so payers can see it before… | writes |
baseline_controlsList the control-baseline questions (free) | Fetch the OceanAlt Agent Control Baseline: the list of controls an agent operator is expected to run before it is allowed to move money, each answerable yes or no. Call this before attest_control_baseline so you file… | read-only |
resolve_agent_identityResolve an agent's chain of accountability (free) | Resolves who stands behind a paying agent: agent -> principal -> mandate -> credential -> wallet. Each link reports whether it holds; completeness counts how many do (a factual count, not a score). Wherever the chain… | read-only |
recent_flaggedList recently flagged addresses (free) | Return a representative sample of addresses on OceanAlt's reviewed risk list — OFAC-sanctioned, known mixers, and community-reported scam/phishing — each with its source category and reason. Takes no arguments. Free, no… | read-only |
verify_payment_requirementsVerify a signed x402 402 response (free) | Before paying an x402 402 response, check that its payment requirements (payTo, amount, asset, network, resource) were signed by the seller and not altered in transit by a proxy, CDN, SDK or another tool. x402 v2… | read-only |
check_calldata_intentDecode calldata and compare with declared intent (free) | Anti blind-signing. EVM: decodes what a transaction's calldata will actually do (ERC-20 transfer/approve/permit, setApprovalForAll, ownership transfer, native transfer). Solana: decodes a whole base64 transaction (SPL… | read-only |
What https://oceanalt.com/api/mcp answered to tools/list, asked without credentials over MCP 2026-07-28. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 3 warnings · 1 note
- warnTC11check_calldata_intent2 parameters without a description: intent, intent.action
- warnTC12verify_payment_requirementsno type for body
- warnTC13attest_control_baselineanswers (object with no properties)
- noteTC24server10 of 10 tools have no outputSchema
The checks from /check and anchor check, run each day on the list above: about 3,186 tokens of definitions. Not part of the score yet. Check your own server.