{"ok":true,"kind":"crawlcheck-rulebook","v":1,"generated_at":"2026-10-07T17:46:30.034Z","score_version":28,"schema":"https://crawlcheck.io/schemas/rulebook.json","counts":{"rules":77,"by_kind":{"scan":52,"answer_correlation":5,"capability_mismatch":6,"self_audit":12,"mcp_server":2},"by_family":{"site":8,"headers":4,"mostly_code":3,"machine_files":11,"robots":13,"delivery":8,"jsonld":3,"nap":2,"answers":5,"capabilities":6,"self_audit":12,"mcp":1,"watch":1},"revised":7,"scored":48},"scans_counted":3137,"severity_scale":[{"level":"info"},{"level":"low"},{"level":"medium"},{"level":"high"},{"level":"critical"}],"method":{"revisions":"A rule that changes what it reports gets a new revision; a record keeps the revision that decided it, and a replay uses that revision, never today's.","share":"Share of counted scans that carried the code at least once, the same numbers /data publishes. Self-scans and opted-out sites are never counted.","grade":"Each finding has a level from info to critical. Open findings at medium and above lower the letter grade; fix them first."},"rules":[{"code":"HIGH_RISK_FIELD_CHANGED","kind":"mcp_server","family":{"id":"watch","label":"High-risk field watch"},"title":"A high-risk field changed and the owner has not confirmed it","meaning":"One of the fields an attacker changes first moved since CrawlCheck last read it: the payment processors loaded on the homepage or checkout page, the host checkout links go to, a cryptocurrency wallet address printed on the page, the OAuth authorization server the site's MCP endpoint names, the domain's MX hosts, or its registry-listed MCP endpoints. Watched fields: payment_processors, checkout_host, wallet_addresses, oauth_authorization_server, mx_hosts, mcp_endpoints. The first reading is the baseline and never alerts.","severity":{"level":"high"},"scored":false,"measured_on":"remote MCP servers in the official MCP Registry (tools/list read during the handshake; no tool is called), and any server or tool list sent to /api/v1/mcp/scan","revision":{"current":1,"revised_at":null},"fix":{"advice":"If the change is yours, confirm it: POST /api/v1/high-risk/confirm {domain} with the key that holds the domain claim. If it is not yours, treat the site as compromised: flip the incident switch (POST /api/v1/incident) and restore the field.","effort":null,"endpoint":null},"share_of_scans":{"pct":null,"scans":null,"of_scans":null,"basis":"measured by the daily high-risk field watch, not per site scan: see https://crawlcheck.io/api/v1/high-risk"},"links":{"self":"https://crawlcheck.io/rules#HIGH_RISK_FIELD_CHANGED","api":"https://crawlcheck.io/api/rules?code=HIGH_RISK_FIELD_CHANGED","glossary":[],"workflow":null,"lineage":"https://crawlcheck.io/docs/lineage-coverage","explain_template":null}}],"filter":{"code":"HIGH_RISK_FIELD_CHANGED"}}