Proposition 65

dev.toolstopv0.1.0Updated Sep 17, 2026

Is a chemical on California's Proposition 65 list, and does it need a warning?

VerifiedStreamable HTTPWeb executableOther

Installation

In SourceWeft

  1. Open Proposition 65 in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "prop65": {
      "type": "http",
      "url": "https://prop65.toolstop.dev"
    }
  }
}

README

toolstop

Small, stateless MCP servers. Each one does a single narrow job exactly, so an assistant can call it instead of guessing.

Every server runs on Cloudflare Workers at <name>.toolstop.dev, holds no state, and can also run locally over stdio.

Discontinued September 2026. The hosted endpoints are gone and the npm packages are deprecated. The code still runs locally over stdio if you want it; the export-control tables are frozen at their 2026-08-27 edition.

Servers

ServerDoesEndpoint
check-digitsValidates check digits for IBAN, LEI, ISBN, GTIN/UPC/EAN, VIN, NPI, ISIN, ABA routing numbers and payment cardshttps://check-digits.toolstop.dev

Connecting

Remote, over streamable HTTP. No install, no account:

json
{  "mcpServers": {    "check-digits": {      "type": "url",      "url": "https://check-digits.toolstop.dev"    }  }}

Local, over stdio:

bash
npx @toolstop/check-digits

Design

Stateless. No database, no vector index, no metered upstream API. A request is answered from its arguments alone. Servers scale to zero and an idle one costs nothing.

Zero runtime dependencies. No MCP SDK, no schema library. MCP over streamable HTTP is request/response, which makes hand-rolled dispatch small enough to be worth it: faster cold starts, and no supply chain.

Telemetry records shape and outcome, never argument values. A check-digit server that logged its input would be storing real IBANs and card numbers. The transport emits one row per request describing what kind of call happened and whether it succeeded. packages/_shared/transport.test.mjs asserts that no raw argument value can reach it.

The row also carries a session id, and it is derived from the network the request came from, truncated to a /24 or /48 before hashing, never the full address. Hashing the whole IP would not have anonymised it: the IPv4 space is 32 bits and the other inputs are public, so the id was walkable back to one address until this was fixed on 2026-08-10. Each server's README states the complete recorded row rather than only what is left out.

Every tool declares readOnlyHint, a complete inputSchema and an outputSchema, so a client can tell what a call will do before making it and what shape comes back. The transport refuses to start a server whose tools do not state their annotations, rather than defaulting them to something reassuring.

Repo layout

packages/_shared/     shared transport, dispatch and telemetrypackages/mcp-<name>/  one serverscripts/discover.mjs  derives the CI matrix from the filesystemscripts/smoke.mjs     protocol check against a live endpoint

See CLAUDE.md for the operating manual.

Development

bash
npm installnpm test                                # every server plus the shared transportnode scripts/smoke.mjs mcp-check-digits # protocol check against the live endpoint

License

MIT

Source: README.md at commit 5d0d0f8

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestSep 16, 2026