Tool verification record, 22 August 2026

What did I actually test, and what did I leave out?

This page separates real open-source examples, downloadable reports, and automated checks. It also calls out the tools that can only be tested safely in a controlled lab.

Catalogue
30 free tools
Real source
6 tools, 4 examples
Live checks
7 GET checks, 3 services
Page check
60/60 bilingual pages
Last run
2026-08-22

Four evidence levels

A test fixture is not the same as a real file from the internet. These labels make the difference clear.

Real public source

I reviewed a real file locally and recorded its source, version, licence, and SHA-256 hash. The resulting report is available on this page.

Live GET check

I checked that the shared service was available using GET requests only. I did not create a record, upload a file, or look up any person or domain.

Automated test

I tested the parser, interface, and error boundaries with safe, repeatable test files. I am not claiming a real public-source report at this level.

Controlled lab

Runtime evidence only means something when it comes from an isolated, harmless lab sample. The tool does not run arbitrary files.

Opening a file successfully does not show that it is safe, malicious, authentic, or ready for production. This page is a repeatable test record, not a certification.

Examples produced from real sources

I do not republish raw third-party files here. Instead, each example keeps the source, version, file hash, observed result, and test boundary together.

mcp-ruby-sdk

Reviewing the MCP Ruby SDK repository

Real public source
Observed
I scanned 279 archive entries. The tool read 56 supported text files and found 2 agent instruction files, 3 GitHub Actions workflows, and 10 review signals. It did not execute any source code.
Boundary
The eight medium-level signals are not vulnerability verdicts. Most of them flag GitHub Action references that are not pinned and need a person to review them.
Real local AI Agent Surface Map summary for the MCP Ruby SDK archive
The real browser run read 279 entries and 56 text files. It found eight medium-level signals and two informational ones. No source code was executed.
Input evidence (2)
  • commit fcb1ac935da20696085b27a869526bb89e7c2ced
  • ZIP SHA-256 dfa30dec9e86ace8b50db7984e739662b57b4304aa709aa0fe710ed582e0c289

Downloadable outputs

JSON

SHA-256: 5546a961a34c6be9f7e347acd5aaf473171a8db35ad31914851f2374b748873f

Markdown

SHA-256: 4bd8cc68a9077c077fa74f0d91d617f6ec716003a6fb979b0ceed7f838e0cf2e

n8n-releaseguard

An open-source n8n workflow change

Real public source
Observed
The tool found one node configuration change and two open items that still need human review. All 13 files in the package matched the SHA-256 manifest.
Boundary
The candidate was not run in staging, and the named human sign-off is still incomplete. The report therefore remains a DRAFT and is not client-ready.
ReleaseGuard draft result for the open-source n8n workflow change
This static report came from two open-source workflows with recorded SHA-256 hashes. No runtime test was performed, so the report remains a draft.
Input evidence (4)
  • baseline cad1f5454fcb66819fae845ff8d267dde7aa69b6
  • candidate 9ccbaf42e007369453acaec60b9808cf8e6cdb44
  • baseline SHA-256 b30e7bcbcb1b1a3fd4f82c9ddc2afdc68fa296ee5014580504f8126808e55f48
  • candidate SHA-256 e4e3112000b61db5fed114b026b000912b90ff832f163c3e7cc0d839bb1b7bad

Downloadable outputs

PDF

SHA-256: d41ce5eca8aa5fb6ecff6dc67dff0d832f7b7932d1b998e4a9fb16f850157e8d

ZIP

SHA-256: 6f0ca201176ca27f1fbb533161c8755d4664f29a31edf42405e9a8e0daca3613

fdroid-client

Comparing the F-Droid 1.23.1 and 1.23.2 APKs

Real public source
Observed
The tool read the package and version details, 29 permissions, and 61 components from the real Android manifest. Comparing the two releases found 17 added, 24 removed, and 630 unchanged structural records.
Boundary
The APK was not installed or run. The text scan reached its 20,000-entry limit, so coverage is limited. The signals do not mean that the app is malicious.
Real local Mobile Exposure Graph summary for the F-Droid 1.23.2 APK
The real browser run found four review signals and 18 evidence records with file locations. It read the package details from the Android manifest and did not run the APK.
Input evidence (2)
  • 1.23.1 SHA-256 1dfce4269081693f10350dbabd26991a59d7c2bb81f870de54e5b113f4785b7a
  • 1.23.2 SHA-256 985f5181d48bb6bafd54083a048b391271e0ab28385881cc41294fb01a222762

Downloadable outputs

Mobile report JSON

SHA-256: efaabfee162e4b9c1120578bf31d80405d97848d14234108daba100ff192ab96

Evidence ZIP

SHA-256: ad2837d8e83df439a72a833590f0a5b0645575bfe1041eb91aa3044c5a86470c

Binary diff JSON

SHA-256: 28e36fee99dc0403a826b790b5b8fd2b7b78c4f3b604b8a3146c4f792a2ed7da

busybox-image

Reviewing the BusyBox 1.36.1 container image

Real public source
Observed
The tool opened the standard Docker export and found one layer, 16 files in the final view, and 11 ELF binaries. It did not find any possible secret records.
Boundary
The image was not started, and no file from its layer was executed. The empty package list is expected because this small image has no supported package database.
Real local inspection summary for the BusyBox 1.36.1 container export
The real browser run read a Docker export built for linux/amd64. It found one layer, 16 final entries, and 11 ELF binaries. The image was not started.
Input evidence (2)
  • linux/amd64 manifest sha256:b7f3d86d6e84fc17718c48bcde1450807faa2d56704205c697b4bd5df7b9e29f
  • local docker-save SHA-256 89ae99dc39bec03aacc844da3603c8828add26cd711341febc483ea7eb3d23dc

Downloadable outputs

Container report JSON

SHA-256: 1797732d8a8cdf81df6f58ff5c74404f7b1052e94b88eda7190543e39a024c80

Verification status for all 30 tools

Each row shows the strongest evidence I can support today. Passing several kinds of tests does not justify a stronger claim on its own.

Live service check report60-page check report

AI intelligence2 · show tools in group
File and visual review7 · show tools in group
Web and domain research7 · show tools in group
Email and IOC review1 · show tools in group
Threat intelligence7 · show tools in group
Archives and change tracking2 · show tools in group
Android and malware review1 · show tools in group
Reporting and evidence3 · show tools in group

Tool verification record, 22 August 2026

Start with the example, then try the local tool with your own file.

If you spot an error or an overclaim, include the source, version, and steps to reproduce it. Do not send private data.