MCPサーバー

agent-covenant

io.github.jdhart81/agent-covenant
MCP・エージェント基盤 セキュリティ 公開・接続可能 MCP 2025-11-25

このMCPでできること

Manages deny-by-default authority covenants for agents, including scoped permissions, spending limits, revocation, act checks, and tamper-evident audit verification.

check_act
Check (and if allowed, record) a proposed act against a covenant. Deny-by-default. Idempotent on act_id — retries never double-consume budget. Every check lands on the audit chain.
入力スキーマ
{'type': 'object', 'title': 'check_actArguments', 'required': ['covenant_id', 'act_id', 'scope'], 'properties': {'scope': {'type': 'string', 'title': 'Scope'}, 'act_id': {'type': 'string', 'title': 'Act Id'}, 'covenant_id': {'type': 'string', 'title': 'Covenant Id'}, 'amount_minor': {'type': 'integer', 'title': 'Amount Minor', 'default': 0}}}
出力スキーマ
{'type': 'object', 'title': 'check_actOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
covenant_status
Current state, consumed/remaining budget, and check count.
入力スキーマ
{'type': 'object', 'title': 'covenant_statusArguments', 'required': ['covenant_id'], 'properties': {'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
出力スキーマ
{'type': 'object', 'title': 'covenant_statusOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
describe_agent
Fleet-standard self-description.
入力スキーマ
{'type': 'object', 'title': 'describe_agentArguments', 'properties': {}}
出力スキーマ
{'type': 'object', 'title': 'describe_agentOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
grant_covenant
Grant an agent a covenant: an explicit lease of authority. scopes support wildcards ('payments.*', '*'); budget_minor is the total spend ceiling in minor units; expires_at is ISO-8601. Returns the covenant_id.
入力スキーマ
{'type': 'object', 'title': 'grant_covenantArguments', 'required': ['principal', 'agent_id', 'scopes', 'budget_minor', 'expires_at'], 'properties': {'scopes': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Scopes'}, 'agent_id': {'type': 'string', 'title': 'Agent Id'}, 'principal': {'type': 'string', 'title': 'Principal'}, 'expires_at': {'type': 'string', 'title': 'Expires At'}, 'budget_minor': {'type': 'integer', 'title': 'Budget Minor'}}}
出力スキーマ
{'type': 'object', 'title': 'grant_covenantOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
list_covenants
List covenants, optionally filtered by state (ACTIVE|REVOKED|EXPIRED) and/or the bound agent.
入力スキーマ
{'type': 'object', 'title': 'list_covenantsArguments', 'properties': {'state': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'State', 'default': None}, 'agent_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Agent Id', 'default': None}}}
出力スキーマ
{'type': 'object', 'title': 'list_covenantsOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
revoke_covenant
Revoke a covenant immediately and terminally. All subsequent checks deny.
入力スキーマ
{'type': 'object', 'title': 'revoke_covenantArguments', 'required': ['covenant_id'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'default': ''}, 'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
出力スキーマ
{'type': 'object', 'title': 'revoke_covenantOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
verify_audit
Verify the tamper-evident audit chain of allowed/denied acts.
入力スキーマ
{'type': 'object', 'title': 'verify_auditArguments', 'required': ['covenant_id'], 'properties': {'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
出力スキーマ
{'type': 'object', 'title': 'verify_auditOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
追加
describe_agent
2026年9月17日12:42
追加
list_covenants
2026年9月17日12:42
追加
verify_audit
2026年9月17日12:42
追加
covenant_status
2026年9月17日12:42
追加
revoke_covenant
2026年9月17日12:42
追加
check_act
2026年9月17日12:42
追加
grant_covenant
2026年9月17日12:42