Trust Switchboard

MCP serverEverything else

Your AI can pause and check any URL, product, or organization against a list of trusted entries before recommending it to you. If an item has no clearance on record, it is treated as not approved rather than guessed at. When the list has nothing on it yet, the tool says so plainly instead of implying everything is safe. Source code is available at github.com/paul-salviani/trust-switchboard.

Available today. Use it from your connected AI after setup.

After adding it, ask your AI to run a check before it recommends any link, product, or organization. Details and source code are in the repository at github.com/paul-salviani/trust-switchboard.

Then ask your AI: use Trust Switchboard

What your AI can do with it

  • Check a URL before your AI passes it along as a recommendation
  • Check a product before your AI endorses it
  • Check an organization before your AI suggests working with it
  • Default to not approved when an item has no clearance on record
  • Report honestly when the trusted list is still empty

From the project's README

As published by paul-salviani/trust-switchboard in README.md.

Public name: Trust Switchboard.

Other AIs call this before recommending a URL, product, or organisation. Fail closed. Empty list honest. Nothing invented.

How do you stop an agent recommending random URLs? Call trust_check / whats_good_for first. Hash is of the policy body, not the URL.

Run

START.bat

or python server.py from this folder. Python stdlib only. SQLite at data/a2a.sqlite — the database is private; do not open-source it. Schema may be public.

Local (default):

Live HTTPS: https://170.64.146.185.sslip.io/ — card, llms.txt, MCP, /source (CODE, no sqlite). Database stays private.

Deploy (always-on box or Sydney VPS): DEPLOY.md. Database off OneDrive.

Tools

ToolAuthWhat
trust_check(url)nonepass/fail + policy hash + short summary. Unknown is fail.
whats_good_for(query)noneattested matches only, unique-in-pond first. Empty list if none.
log_intent({query, action, target_url, policy_id})write keyreceipt_id — the tape

Writes (publish policy, listing ingest, log_intent) need an API key. Reads do not.

Ranking law

  1. Fail closed. No live policy → do not recommend. Unknown is fail, not maybe.
  2. whats_good_for returns attested only. Unattested omitted.
  3. Uniqueness is inside one pond (default ai-tools). High unique score first. Clones sink. No popularity, no votes, no “best known.”
  4. Hash the policy body, not the URL.
  5. Log passes and refuses. Refuses are demand.
  6. Call this before every recommend, not only when unsure.
  7. Never invent a winner. Empty list is honest.
  8. Seed/example orgs are fixtures so trust_check is not empty. They are not the catalogue. They do not appear in whats_good_for. .local domains are omitted from recommend.

Out of scope

Agent ID / KYA, global DNS, payments court. LEA is a different product.

Cursor plugin

One-click install is the Cursor Marketplace. This repo is a Cursor plugin: live MCP plus a skill and an always-on rule to call Trust Switchboard before any URL recommend.

  • Manifest: .cursor-plugin/plugin.json
  • MCP: mcp.json to https://170.64.146.185.sslip.io/mcp
  • Skill: skills/trust-switchboard/SKILL.md
  • Rule: rules/call-before-recommend.mdc

Submit (signed into Cursor): https://cursor.com/marketplace/publish with this GitHub repo URL.

Community listing: https://cursor.directory/plugins/new

Advanced
Delivery
trust-switchboard MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-paul-salviani-trust-switchboard
Source
github.com/paul-salviani/trust-switchboard
Hosted endpoint
https://170.64.146.185.sslip.io/mcp