MCP server registry
Security & governancePublic source

Fraud MCP Server

A unified fraud layer for ADK-Rust Enterprise agents — combining fraud signals + risk scoring (detection) and case alerts + gated decisions (review) in one server. 19 MCP tools serving both the retail Fraud Review Agent…

What it gives an agent

A purpose-built capability behind one MCP connection.

The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.

01

Provides fraud capabilities through a typed MCP contract.

Architecture

How Fraud MCP Server fits into an agent system.

The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.

01

ADK-Rust agent

Chooses a capability from the reviewed tool catalog.

02

MCP client

Discovers schemas, sends calls, and receives typed content.

03

Fraud MCP Server

Validates the request and owns 19 documented tool contracts.

04

Domain system

Keeps the API, data, credentials, and business rules behind the server.

Connection: stdio · Server framework: ADK MCP SDK + rmcp

From the project documentation

The server’s published architecture

Open the source diagram ↗
Fraud MCP Server architecture diagram from its official repository

Tool catalog

What can an agent ask Fraud MCP Server to do?

Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.

19 named tools

add_signal

Record a fraud signal/indicator on an entity

internal write
get_signals

List signals recorded for an entity

read only
score_entity

Compute an entity's aggregate risk score, band, and contributions

read only
upsert_rule

Create or update a signal-type risk rule (weight, severity)

internal write
list_rules

List configured risk rules

read only
create_case

Open a fraud review case for an entity (scores at creation)

internal write
get_case

Get a fraud case's full detail

read only
search_cases

Search fraud cases (sorted highest-risk first)

read only
rescore_case

Recompute a case's score from current signals and list status

internal write
assign_case

Assign a fraud case to a reviewer

internal write
escalate_case

Escalate a case (e.g. to SIU)

internal write
add_note

Add an investigation note to a case

internal write

Governance

Understand the effect of every tool.

A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.

12 internal write7 read only
  • Gated high-impact writes — decide_case, escalate_case, close_case, and list changes require approval in production; signal/score reads are read_only.
  • Defensible decisions — every case mutation appends to an immutable audit trail.
  • Opaque entities — entities are references/tokens (order:…, claim:…, cust:…), not raw PII.
  • Integration scaffold — the in-memory store and scoring model are for development; back them with your real signals platform and decision store, and bind actors to authenticated identities…

MCP surface

What the current documentation declares.

MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.

The current README concentrates on its tool surface. Check the source and release notes before relying on optional MCP capabilities beyond tool discovery and invocation.
ADK MCP SDKrmcpRegistry manifest

Install and connect

Follow the project’s documented starting point.

Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.

Install
cargo install mcp-fraud
ADK-Rust connection shape
let toolset = McpToolset::from_stdio(
    "mcp-fraud",
    ["mcp-fraud"],
).await?;

let agent = LlmAgentBuilder::new("agent")
    .tools(toolset.tools().await?)
    .build()?;

Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.

Official documentation

Continue with the project maintainers’ source of truth.

This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.

Source record

Release and repository metadata for this catalog entry.

View public repository ↗
Version
1.0.0
License
Apache-2.0
Tools
19
Revision
b144ef4232d2
Updated
Jun 9, 2026
Transportsstdio