Server definition
- Hash
- sha256:d0df1d07ad020531cc8928f1ff9ddffcbd37e971e2fbb55632f0862eb048a255
- What it is
- What a remote MCP server returned when asked what it offers: 7 tools
The blob, as servednamed by its sha256
{
"instructions": "Trust Gate -- tamper-evident, hybrid-signed receipts for consequential agent actions. All receipts reuse the open-source OpenAgentOntology mint_receipt (Ed25519 + ML-DSA-65). Integrity is verifiable offline from the receipt alone; authenticity needs the signer's Ed25519 kid pinned out of band.",
"tools": [
{
"description": "Rank a CALLER-PROVIDED list of MCP tools by worst-regret if they act (a name-based heuristic that weights a name's first word most). Read-only: it mints no receipt. Cannot auto-discover the inventory -- MCP does not allow that; the caller must pass it in.",
"inputSchema": {
"properties": {
"inventory": {
"items": {
"additionalProperties": true,
"type": "object"
},
"title": "Inventory",
"type": "array"
},
"notes": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Notes"
}
},
"required": [
"inventory"
],
"title": "audit_my_agent_inventoryArguments",
"type": "object"
},
"name": "audit_my_agent_inventory",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "audit_my_agent_inventoryOutput",
"type": "object"
}
},
{
"description": "Egress classification check. Scans a data sample for a finite list of sensitivity markers and classifies as NO_MARKERS_FOUND / INTERNAL / CONFIDENTIAL / RESTRICTED. RESTRICTED sets blocked=true; this tool cannot block anything itself, and NO_MARKERS_FOUND is not clearance to send. Returns classification, retention info, and a tamper-evident receipt.",
"inputSchema": {
"properties": {
"data_sample": {
"title": "Data Sample",
"type": "string"
},
"destination": {
"title": "Destination",
"type": "string"
},
"provider": {
"title": "Provider",
"type": "string"
}
},
"required": [
"destination",
"data_sample",
"provider"
],
"title": "check_egressArguments",
"type": "object"
},
"name": "check_egress",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "check_egressOutput",
"type": "object"
}
},
{
"description": "Two-phase decision gate with a real verdict. PREVIEW returns ALLOW, DENY or ESCALATE with the risk tier and reasons, plus a preview_id, without acting. COMMIT re-evaluates the same inputs and mints a signed receipt for the verdict. Only ALLOW returns a GRANTED permit; DENY returns DENIED; ESCALATE returns WITHHELD_PENDING_HUMAN and a human must decide outside this tool. Applies only to actions the caller routes through it: it does not observe or block what an agent does. Verb-tier heuristic on the action name and resource, not a proof. Stateless. Optional attestation: triggered_by_type, triggered_by_source, decision_model.",
"inputSchema": {
"properties": {
"action": {
"title": "Action",
"type": "string"
},
"context": {
"additionalProperties": true,
"title": "Context",
"type": "object"
},
"decision_model": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Decision Model"
},
"phase": {
"default": "PREVIEW",
"title": "Phase",
"type": "string"
},
"preview_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Preview Id"
},
"resource": {
"title": "Resource",
"type": "string"
},
"triggered_by_source": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Triggered By Source"
},
"triggered_by_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Triggered By Type"
}
},
"required": [
"action",
"resource",
"context"
],
"title": "gate_decisionArguments",
"type": "object"
},
"name": "gate_decision",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "gate_decisionOutput",
"type": "object"
}
},
{
"description": "Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for an arbitrary consequential agent action. Optional attestation: triggered_by_type (human/agent/script), triggered_by_source (api/cli/cron), decision_model (the LLM model used). Attestation values are caller claims: allowlisted to safe characters, signed, not verified. Decisions that contain a gate verdict word are reserved for gate_decision.",
"inputSchema": {
"properties": {
"agent_id": {
"title": "Agent Id",
"type": "string"
},
"decision": {
"default": "ACTION_GOVERNED",
"title": "Decision",
"type": "string"
},
"decision_model": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Decision Model"
},
"inputs": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Inputs"
},
"operation": {
"title": "Operation",
"type": "string"
},
"policy": {
"default": "agent action evidence",
"title": "Policy",
"type": "string"
},
"target": {
"title": "Target",
"type": "string"
},
"triggered_by_source": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Triggered By Source"
},
"triggered_by_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Triggered By Type"
}
},
"required": [
"agent_id",
"operation",
"target"
],
"title": "mint_action_receiptArguments",
"type": "object"
},
"name": "mint_action_receipt",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "mint_action_receiptOutput",
"type": "object"
}
},
{
"description": "Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for one CRM record change. Old/new values are carried as SHA-256 hashes. Works with any CRM (Relaticle, hosted CRMs, custom).",
"inputSchema": {
"properties": {
"changed_by_agent": {
"title": "Changed By Agent",
"type": "string"
},
"field": {
"title": "Field",
"type": "string"
},
"new_value": {
"title": "New Value",
"type": "string"
},
"object_type": {
"title": "Object Type",
"type": "string"
},
"old_value": {
"title": "Old Value",
"type": "string"
},
"policy": {
"default": "per-decision CRM change evidence",
"title": "Policy",
"type": "string"
},
"record_id": {
"title": "Record Id",
"type": "string"
},
"tenant": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Tenant"
}
},
"required": [
"record_id",
"object_type",
"field",
"old_value",
"new_value",
"changed_by_agent"
],
"title": "mint_receipt_for_record_changeArguments",
"type": "object"
},
"name": "mint_receipt_for_record_change",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "mint_receipt_for_record_changeOutput",
"type": "object"
}
},
{
"description": "Vendor exit readiness drill. Checks local signing key, local model access (Ollama). Returns step-by-step results and a tamper-evident receipt. Informational; it signs one receipt, which creates the signing key on a host that has none yet.",
"inputSchema": {
"properties": {},
"title": "run_exit_drillArguments",
"type": "object"
},
"name": "run_exit_drill",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "run_exit_drillOutput",
"type": "object"
}
},
{
"description": "Verify a Trust Gate receipt from the certificate alone (offline). ok=true means unchanged since signing, signed, kid consistent with the embedded key, and (require_pq default on) at least one post-quantum leg verified; unsigned receipts fail. It does not prove who signed: pass expected_kid to pin the signer's Ed25519 key; a pin counts only when that key's own signature verifies (see signer_pinned). The post-quantum keys in a receipt are not covered by the kid.",
"inputSchema": {
"properties": {
"expected_kid": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Expected Kid"
},
"receipt": {
"additionalProperties": true,
"title": "Receipt",
"type": "object"
},
"require_pq": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"title": "Require Pq"
}
},
"required": [
"receipt"
],
"title": "verify_receiptArguments",
"type": "object"
},
"name": "verify_receipt",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "verify_receiptOutput",
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:d0df1d07ad020531cc8928f1ff9ddffcbd37e971e2fbb55632f0862eb048a255 | sha256sum