MCPサーバー

Moltline Agent Governance

com.moltlinestudio/govern
MCP・エージェント基盤 セキュリティ 公開・接続可能 MCP 2025-11-25

このMCPでできること

Audits MCP configurations, agent skills, permissions, domains, and untrusted text for injection risks, excessive scope, exposed credentials, and governance weaknesses.

agent_readiness_scan
Agent Readiness Scan
Score a public domain against 21 agent-readiness checks. FREE. Use when you need to know whether an autonomous agent can discover, read, use or pay a website - your own, or a vendor you are evaluating before recommending it. Typical input {"domain": "example.com"} returns {"score": 8, "total": 21, "grade": "F", "passed": [...], "failed": [{"title": "...", "detail": "...", "fix": "..."}], "report_url": "..."} where report_url is a permanent shareable page for the same result. Not for auditing an MCP client configuration (audit_mcp_config) and not for scanning text for injection (injection_scan) - this one reaches out over the network and fetches public URLs on a live domain. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "The readiness scanner is not reachable right now."}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'A public hostname such as example.com. A full URL is accepted\nand reduced to its host. Hostnames that resolve to private or\ninternal addresses are refused.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
audit_mcp_config
Audit Mcp Config
Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['config'], 'properties': {'config': {'type': 'string', 'description': 'The MCP config to audit, pasted as text or JSON —\nmcpize.yaml, mcp.json, or a Claude/Cursor servers block.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
audit_skill_file
Audit Skill File
Audit an agent skill or instruction file before you trust it. FREE. Checks for governance smells: prompt-injection and guardrail-bypass phrasing, concealment instructions ('don't tell the user'), exfiltration language, and exposed credential material. Typical input {"content": "<SKILL.md, system prompt, or tool description text>"} returns {"verdict": "reject — do not install" | "no governance red flags on a pattern pass", "findings": [{"severity": 1-5, "issue": "..."}], "note": "..."}. Use before trusting a skill or instruction file that came from outside your own repository. Not for arbitrary untrusted input at run time (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['content'], 'properties': {'content': {'type': 'string', 'description': 'Full text of the skill file, system prompt, or tool\ndescription to audit.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
get_auditor_persona
Get Auditor Persona
Load the Governance Auditor persona for consistent fleet audits. PREMIUM (license). The persona is methodical, evidence-driven, and allergic to 'it's probably fine'. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated audits consistent in voice and rigor. Not for running an audit - the audit tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'properties': {}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
governance_policy
Governance Policy
Generate an audit-ready agent-governance policy for a fleet. PREMIUM (license). Covers inventory cadence, ownership rules, least-privilege approval gates, injection defense, logging/retention, and decommissioning triggers. Typical input {"fleet_context": "20 agents, 3 with shell access, one finance bot"} returns {"policy": ..., "sections": {...}, "context_note": ..., "audit_checklist": ["...", ...]}. Use when a fleet needs a written policy document. Not for assessing what the fleet currently does (inventory_report, audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'properties': {'fleet_context': {'type': 'string', 'default': '', 'description': 'Optional plain-language description of the fleet\n(size, capabilities, sensitive systems) used to tailor the\npolicy; empty returns the generic baseline.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
injection_scan
Injection Scan
Scan untrusted text for prompt-injection patterns before ingestion. FREE. Use on any web page, email, or document an agent is about to ingest to catch prompt-injection and data-exfiltration patterns before they reach the agent's context. Typical input {"text": "<untrusted content>"} returns {"injection_suspected": bool, "count": N, "hits": [{"line": N, "pattern": "...", "text": "<flagged line>"}], "note": "..."}. Not for reviewing a skill file you control (audit_skill_file), and a clean result is not a guarantee of safety - it reports pattern matches only. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string', 'description': 'The untrusted content to scan, pasted as a single string.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
inventory_report
Inventory Report
Build a governance inventory with risk tiers from a raw agent list. FREE. Turns a list of agents / MCP servers / skills into an audit-ready summary with critical/elevated/standard tiers and unowned-agent flags. Typical input {"items": "[{\"name\": \"deploy-bot\", \"owner\": \"ana\"}]"} returns {"total": N, "tiers": {"critical": N, ...}, "unowned_agents": [...], "inventory": [{"name": ..., "owner": ..., "tier": ..., "orphaned": bool}], "reading": "...", "note": "..."}. Use to turn a raw agent list into risk tiers. Not for auditing any single agent in depth (audit_mcp_config, scope_check). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['items'], 'properties': {'items': {'type': 'string', 'description': 'The fleet as a string — a JSON array of {name, owner?,\ncapabilities?, last_seen?} objects, or plain newline-separated\nagent names.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
scope_check
Scope Check
Score the blast radius of every tool in a permission manifest. FREE. Ranks each tool by capability risk (command exec > money/delete > file-write/messaging > read > network) and flags the over-privileged ones that need approval gates. Typical input {"tools": "[\"run_shell\", \"read_docs\"]"} returns {"tools_scored": N, "high_risk_tools": N, "ranking": [{"tool": ..., "blast_radius": 0-5, "capabilities": [...]}], "recommendation": ["..."], "note": "..."}. Use on a permission manifest to rank tools by blast radius. Not for the configuration that mounts them (audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['tools'], 'properties': {'tools': {'type': 'string', 'description': 'The manifest as a string — a JSON array of tool names or\n{name, description} objects, a JSON object of name->description,\nor plain newline-separated names.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'additionalProperties': True}
追加
agent_readiness_scan
2026年9月17日12:36
追加
get_auditor_persona
2026年9月17日12:36
追加
governance_policy
2026年9月17日12:36
追加
inventory_report
2026年9月17日12:36
追加
injection_scan
2026年9月17日12:36
追加
audit_skill_file
2026年9月17日12:36
追加
scope_check
2026年9月17日12:36
追加
audit_mcp_config
2026年9月17日12:36