Serveur MCP

GAIP Trust & Assurance Agent

io.github.tjcgraham-rgb/gaip-trust-assurance
Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Verifies GAIP receipts and compiles evidence packs or incident timelines with hash-chain and Merkle proofs.

gaip_check_sar_receipt
Check an x402 SAR receipt
Use this when handed an x402 SAR-shaped receipt (draft proposal shape; may change). Pass `sar_receipt`, optionally the issuer's `public_key`. Returns missing fields, whether receipt_id matches the core and whether the signature checks out against that key. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'public_key': 'Y8BpzlWPH3EPRQziEPRBeLS1lJBF4xEo9WaxTNbzNp0', 'sar_receipt': {'ts': '2026-10-01T09:00:00Z', 'sig': 'ogilW-bjlCbYkwwUAIrg_zm_Wuoc6EiRgeErs0RL7llP7FWyX43-LgozZFyCjCXgsViK-A4_aroOo16Q4uvTCg', 'sig_alg': 'Ed25519', 'verdict': 'PASS', 'confidence': 1.0, 'receipt_id': 'sha256:17146cdeb5aba1c269130348cdc7d3d96ae55f6e048b81d3baa59d4e3f3b188b', 'reason_code': 'SPEC_MATCH', 'task_id_hash': 'sha256:c8b36982316351a28e040a6520df2092c2c87a4ea611c123d04993074b2b6f1d', 'verifier_kid': 'ef654fc8b615b51c', 'receipt_version': '0.1'}}], 'required': ['sar_receipt'], 'properties': {'public_key': {'oneOf': [{'type': 'string', 'maxLength': 512}, {'type': 'object'}], 'description': "Optional: the issuer's Ed25519 public key, raw 32 bytes base64url or a JWK {kty: OKP, crv: Ed25519, x}. Omit to use GAIP's published keys."}, 'sar_receipt': {'type': 'object', 'description': 'The SAR receipt object (or a whole gaip_receipt_export x402 result).'}}, 'additionalProperties': False}
gaip_evidence_pack
Build an evidence pack
Use this when an insurer, auditor or buyer asks what evidence exists about an agent or supplier. Pass its `subject` (public id or https URL). Returns conformance, watch, witness, repair and incident records with Merkle proofs, plus gaps. A compilation, not certification or advice. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'scope': {'since': '2026-09-01', 'max_items': 50}, 'subject': {'counterparty_id': 'example-weather-agent'}, 'requester': {'purpose': 'INSURER'}}], 'required': ['subject'], 'properties': {'scope': {'type': 'object', 'properties': {'since': {'type': 'string'}, 'until': {'type': 'string'}, 'max_items': {'type': 'integer', 'maximum': 200, 'minimum': 1}, 'categories': {'type': 'array', 'items': {'enum': ['conformance', 'watch', 'witness', 'repair', 'incident', 'supplier_checks'], 'type': 'string'}}, 'receipt_ids': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 50}}, 'description': 'Optional: {receipt_ids, since, until, categories, max_items}.', 'additionalProperties': False}, 'subject': {'oneOf': [{'type': 'string', 'maxLength': 256}, {'type': 'object', 'properties': {'ref': {'type': 'string'}, 'url': {'type': 'string', 'format': 'uri'}, 'seller_ref': {'type': 'string'}, 'counterparty_id': {'type': 'string'}}, 'additionalProperties': False}], 'description': 'The agent or supplier: its public id or https URL. Never a person.'}, 'requester': {'type': 'object', 'properties': {'purpose': {'enum': ['INSURER', 'AUDITOR', 'OPERATOR', 'BUYER', 'UNSPECIFIED'], 'type': 'string'}, 'continuity_handle': {'type': 'object', 'required': ['continuity_id', 'token'], 'properties': {'token': {'type': 'string'}, 'continuity_id': {'type': 'string'}}}}, 'description': 'Optional: {purpose, continuity_handle} to include your own receipts.', 'additionalProperties': False}}, 'additionalProperties': False}
gaip_incident_bundle
Build an incident evidence bundle
Use this when something went wrong with an agent and you need the facts in order. Pass the `receipt_ids` you hold and attributed `observations`. Returns a verified, source-attributed timeline with an EU AI Act Art. 73 reference aid. No fault, cause or liability finding. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'title': 'Forecast endpoint returned errors', 'receipt_ids': ['<receipt_id returned by any GAIP tool>'], 'observations': [{'source': 'our uptime monitor', 'statement': 'HTTP 503 from the forecast endpoint for 12 minutes', 'source_type': 'AUTOMATED_MONITOR', 'observed_at_utc': '2026-09-27T10:00:00Z'}], 'ai_system_ref': 'example-weather-agent'}], 'properties': {'title': {'type': 'string', 'maxLength': 120, 'description': 'Optional: short incident title.'}, 'receipt_ids': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 50, 'description': 'GAIP receipt ids you hold about the incident.'}, 'observations': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'statement'], 'properties': {'source': {'type': 'string', 'maxLength': 120}, 'statement': {'type': 'string', 'maxLength': 2000}, 'receipt_id': {'type': 'string'}, 'source_type': {'enum': ['AUTOMATED_MONITOR', 'PUBLIC_RECORD', 'REQUESTER', 'THIRD_PARTY'], 'type': 'string'}, 'observed_at_utc': {'type': 'string'}}, 'additionalProperties': False}, 'maxItems': 50, 'description': 'Attributed observations, each {source, statement, observed_at_utc}.'}, 'ai_system_ref': {'type': 'string', 'maxLength': 256, 'description': 'Optional: public id or URL of the AI system involved.'}, 'data_classification': {'enum': ['PUBLIC', 'NON_PERSONAL_PUBLIC'], 'type': 'string', 'default': 'PUBLIC', 'description': 'PUBLIC (default) or NON_PERSONAL_PUBLIC. Never send personal data.'}}, 'additionalProperties': False}
gaip_receipt_export
Export a GAIP receipt
Use this when you need a GAIP receipt in another format. Pass `receipt_id` and `format`: x402 (attestation style), erc8004 (validation-response shape) or vc (W3C-VC-like JSON-LD). Ed25519-signed when the runtime key is available; hash chain and Merkle proof; no on-chain write. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'format': 'x402', 'receipt_id': '<receipt_id returned by any GAIP tool>'}], 'required': ['receipt_id', 'format'], 'properties': {'format': {'enum': ['x402', 'erc8004', 'vc'], 'type': 'string', 'description': 'x402, erc8004 or vc.'}, 'receipt_id': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'A receipt_id returned by an earlier GAIP call.'}}, 'additionalProperties': False}
inspect_counterparty_evidence
What evidence exists about this agent?
Use this when asked what evidence exists about an agent before delegating to it. Pass its `counterparty_id` and any `observations`. Returns task-specific evidence coverage, conflicts, gaps and GAIP's own earlier checks of it, with a receipt. Never a trust score or recommendation. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'task_class': 'weather_forecast', 'observations': [{'claim': 'Publishes a public weather_forecast skill', 'source': 'https://forecast.example.com/.well-known/agent-card.json', 'observed_at': '2026-09-27T12:00:00Z', 'evidence_digest': '3f0a9c1e5b7d2468ace013579bdf2468ace013579bdf2468ace013579bdf2468', 'lifecycle_state': 'observed'}, {'claim': 'Returned a London forecast in 1.2 s', 'source': 'caller_task_log', 'observed_at': '2026-09-27T12:05:00Z', 'lifecycle_state': 'OBSERVED'}], 'counterparty_id': 'example-weather-agent'}], 'properties': {'synthetic': {'type': 'boolean', 'description': 'Optional: true marks a test call.'}, 'episode_id': {'type': 'string', 'description': 'Optional: your own id to group related calls.'}, 'task_class': {'type': 'string', 'default': 'COUNTERPARTY_EVIDENCE', 'description': 'Task you want evidence for. Optional.'}, 'max_age_days': {'type': 'integer', 'maximum': 365, 'minimum': 1, 'description': 'Optional freshness window (default 30): GAIP history records older than this are STALE and do not count toward evidence_sufficiency.'}, 'observations': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Optional: observations about it, each {source, observed_at, evidence_digest, lifecycle_state, claim}.'}, 'counterparty_id': {'type': 'string', 'description': 'Name or URL of the agent or service.'}, 'continuity_handle': {'type': 'object', 'required': ['continuity_id', 'token'], 'properties': {'token': {'type': 'string'}, 'continuity_id': {'type': 'string'}}, 'description': 'Optional: the continuity_handle from an earlier GAIP result; links this call to your earlier ones.', 'additionalProperties': False}, 'data_classification': {'enum': ['PUBLIC', 'NON_PERSONAL_PUBLIC'], 'type': 'string', 'default': 'PUBLIC', 'description': 'PUBLIC (default) or NON_PERSONAL_PUBLIC. Never send personal data.'}, 'independent_operator_id': {'type': 'string', 'description': 'Optional: your operator id (recorded as a claim, not verified).'}}, 'additionalProperties': True}
verify_gaip_receipt
Verify a GAIP receipt
Use this when you hold a GAIP receipt_id and want to confirm it ("is this receipt genuine?"). Returns the retained record, hash chain and Merkle inclusion proof. Integrity only: it does not make the underlying claim true. Free, read-only, no account; inputs must be public and non-personal.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'examples': [{'receipt_id': '<receipt_id returned by any GAIP tool>'}], 'required': ['receipt_id'], 'properties': {'synthetic': {'type': 'boolean', 'description': 'Optional: true marks a test call.'}, 'episode_id': {'type': 'string', 'description': 'Optional: your own id to group related calls.'}, 'receipt_id': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'A receipt_id returned by an earlier GAIP call.'}, 'continuity_handle': {'type': 'object', 'required': ['continuity_id', 'token'], 'properties': {'token': {'type': 'string'}, 'continuity_id': {'type': 'string'}}, 'description': 'Optional: the continuity_handle from an earlier GAIP result; links this call to your earlier ones.', 'additionalProperties': False}, 'data_classification': {'enum': ['PUBLIC', 'NON_PERSONAL_PUBLIC'], 'type': 'string', 'description': 'PUBLIC (default) or NON_PERSONAL_PUBLIC. Never send personal data.'}, 'independent_operator_id': {'type': 'string', 'description': 'Optional: your operator id (recorded as a claim, not verified).'}}, 'additionalProperties': True}
Ajouté
gaip_check_sar_receipt
2 October 2026 02:41
Modifié
gaip_receipt_export
2 October 2026 02:41
Modifié
inspect_counterparty_evidence
2 October 2026 02:41
Ajouté
gaip_incident_bundle
30 September 2026 02:40
Ajouté
gaip_evidence_pack
30 September 2026 02:40
Modifié
verify_gaip_receipt
30 September 2026 02:40
Ajouté
gaip_receipt_export
30 September 2026 02:40
Modifié
inspect_counterparty_evidence
30 September 2026 02:40
Ajouté
verify_gaip_receipt
28 September 2026 02:40
Ajouté
inspect_counterparty_evidence
28 September 2026 02:40