AGENT SKILLS · PUBLIC DISCOVERY

Give coding agents a safer path to GuGuData APIs

Four public Agent Skills turn GuGuData API contracts into focused workflows for discovery, website quality, document OCR, and stock symbol integration reviews.

4
Public Skills
SHA-256
Artifact integrity
MCP + HTTP
Documented discovery paths
2026-08-17
Compatibility test date
Choose a workflow

Independent entry points for every Skill

Each landing page explains its boundary, intended users, review outcomes, published source, and a traceable path to trial access.

API Discovery

Use GuGuData API

Discover and use GuGuData public APIs through OpenAPI, Remote MCP, developer docs, and agent-readable API Markdown.

Built forAI application developers and agent builders evaluating GuGuData APIs.
  • OpenAPI catalog
  • Remote MCP
  • API details Markdown
Website Quality

Review Website Quality

Review public website releases and SEO monitoring integrations with non-mutating website quality APIs.

Built forWeb, SEO, growth, and platform teams reviewing public-site changes.
  • PageSpeed
  • DNS
  • TLS
  • WHOIS
  • Search visibility
Document OCR

Review Document OCR

Review OCR and document-processing integrations without exposing repository or customer documents.

Built forApplication, backend, security, and privacy teams working with documents.
  • OCR
  • PDF extraction
  • Document conversion
Stock Symbols

Review Stock Symbol Integration

Review US and Hong Kong stock symbol directory integrations as reference-data lookups.

Built forFintech developers and data teams building security directories.
  • US stock symbols
  • Hong Kong stock symbols
Public test report

MCP, OAuth, and Skill compatibility matrix

Production discovery, exact authentication challenges, OAuth metadata and entry points, and all four published Skill artifacts passed. The release gate also covers all 52 API Markdown routes plus exact OAuth callback and token rotation behavior. Real production account invocation and third-party MCP Host interoperability were intentionally not performed.

PASS_WITH_DECLARED_BOUNDARY Tested 2026-08-17 01:01 UTC+08:00 Open machine-readable report
AreaScenarioScopeResultEvidence
MCP 2026-07-28server/discover and stateless negotiationProduction OAuth challenge plus isolated authorized end-to-end PASS Production returned 401 with RFC 9728 resource metadata and no Mcp-Session-Id. The isolated authorized client negotiated 2026-07-28 and rediscovered tools after reconnect.
Initialize-based MCP2025-11-25 and earlier initialization handshakeProduction OAuth challenge plus isolated authorized end-to-end PASS Production returned the same OAuth challenge for initialize traffic. SDK 2.0 legacy mode and the isolated SDK 1.8.0 probe completed discovery and reconnect checks.
OAuth discoveryProtected resource and authorization server metadataProduction PASS The protected resource is bound to https://mcp.gugudata.io/mcp. Authorization, token, registration, revocation, PKCE S256, CIMD, and authorization response issuer metadata were present.
OAuth client entryDynamic client registration and authorization redirectProduction, no account credentials submitted PASS A public client registered without a client secret and the authorization request redirected to the GuGuData login step with no-store caching.
Transport fingerprintsOAuth challenge through Node.js fetch, Python urllib, and curlProduction PASS All tested HTTP clients received the exact Bearer resource metadata challenge with mcp:access scope and no Mcp-Session-Id. The earlier generic urllib edge rejection was not reproduced.
OAuth lifecyclePKCE code, token, refresh, resource binding, and revocationIsolated end-to-end PASS The self-test covered approval and denial responses, exact issuer, token rotation, resource binding, and revocation without using production credentials.
OAuth callback and tokensExact callback URI, PKCE code exchange, access and refresh token issuance, and one-time refresh rotationUnit and isolated end-to-end PASS The registered cursor://oauth-callback URI was preserved exactly through authorization, the callback carried code, state, and issuer, token responses contained the configured lifetime, and refresh rotation invalidated both prior tokens.
API LLM Markdown routesEvery published API identity returns its own raw Markdown documentRelease build and post-deployment production gate PASS All 52 API identities are generated from the shared SSR Markdown builder and must return HTTP 200, text/markdown, a Markdown heading, and identity-specific demo and raw-document links; HTML fallback fails the release gate.
EntitlementsAccount-scoped tools and non-purchased tool rejectionIsolated end-to-end PASS Normal and VIP fixtures exposed only the expected tool set, kept execution keys server-side, and rejected tools outside the entitlement snapshot.
Production account invocationAuthorized tool discovery and call with a real accountProduction NOT_RUN No production credentials or paid API calls were used. This boundary is explicit and is not represented as a protocol failure.
Third-party MCP Host interoperabilityAuthorized discovery and tool calls from external MCP HostsProduction NOT_RUN No real Cursor, Claude, ChatGPT, or other third-party Host was authorized during this refresh. Protocol SDK probes do not replace Host-specific interoperability testing.
PASSuse-gugudata-api

HTTP 200 · text/markdown

sha256:49e8c704e0451e571c2a90ca341455f90ef2abd5e63b5ba3479298e6507e3265
PASSreview-website-quality

HTTP 200 · text/markdown

sha256:117367e085068d36386681c230e6ce28bfed12a36bd01e38b460f4837474cc27
PASSreview-document-ocr

HTTP 200 · text/markdown

sha256:939d78e274c5c42d3afc93498555c322a209f33c30c2d2d0754412b3a77a8d16
PASSreview-stock-symbol-integration

HTTP 200 · text/markdown

sha256:9d922fd95ba3359bd894c3cc80f79f2794ec9efaa8ec08b7b62cdf9003bf2fb9

Declared scope and advisory

  • Node.js fetch, Python urllib, and curl received the expected production OAuth challenge during this refresh. Untested custom HTTP fingerprints remain outside this point-in-time result.
  • Skill artifact checks validate public availability, Markdown content type, discovery membership, and SHA-256 integrity. They do not consume paid API credits.
  • Dynamic client registration creates a persistent public client record, so the live DCR check is opt-in rather than part of every routine run.
  • This report is a point-in-time compatibility result. Re-run the matrix after protocol, OAuth, edge policy, or Skill artifact changes.
Measurement baseline

Track Skill to trial without guessing

Every trial link carries a stable source, medium, campaign, and Skill identifier through sign-in to trial-key creation.

  1. view_skill
  2. begin_skill_trial
  3. view_skill_trial
  4. generate_trial_key

Measure unique users and event conversion by skill from this report date. Pre-launch historical attribution is unavailable and must remain zero or unknown, not backfilled.