MCP 서버

HANRIA agent mandate check

ai.hanria/agent-mandate-check
법률 및 컴플라이언스 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Evaluates proposed agent actions against an operator's written mandate and returns permit, deny, or escalate guidance.

check_action
Check an agent action against a mandate
Advisory check of one proposed action against an operator's written mandate. Returns permit, deny or escalate with the governing clause, a reason and an action digest. It cannot stop an action; it keeps no request content. Templates and documentation: https://hanria.ai/llms.txt
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'examples': [{'action': {'operation': {'kind': 'file', 'verb': 'read', 'target': '/tmp/example'}, 'requested_by': {'agent': 'example-agent'}, 'justification': 'Read the permitted file.', 'schema_version': '0.1-draft'}, 'mandate': {'clauses': [{'id': 'permit-file', 'match': {'kind': ['file']}, 'effect': 'permit'}], 'default': 'deny', 'purpose': 'Permit one file action.', 'mandate_id': 'minimal-permit', 'schema_version': '0.2-draft'}}], 'required': ['mandate', 'action'], 'properties': {'action': {'type': 'object', 'title': 'HANRIA action request', '$comment': 'Forbidden anywhere in an instance: credential, secret, private_key, token, password, api_key. A runtime is expected to refuse a request containing them rather than strip them.', 'required': ['schema_version', 'requested_by', 'operation', 'justification'], 'properties': {'operation': {'type': 'object', 'required': ['kind', 'verb', 'target'], 'properties': {'kind': {'enum': ['file', 'process', 'package', 'network', 'device', 'credential_use', 'transaction', 'administrative']}, 'verb': {'type': 'string', 'minLength': 1, 'description': 'What is to be done to the target, e.g. read, write, execute, install, connect, sign, transfer. Required: an operation named only by its kind does not describe a proposed action well enough to be judged.'}, 'amount': {'type': 'object', 'required': ['value', 'currency'], 'properties': {'value': {'type': 'string', 'minLength': 1, 'description': 'Decimal as a string, to avoid float error.'}, 'currency': {'type': 'string', 'minLength': 1}}, 'description': 'An amount. Both fields are required: a bare amount object describes nothing a ceiling could be compared against.', 'additionalProperties': False}, 'target': {'type': 'string', 'minLength': 1, 'description': 'What the operation acts on. A path, host, package name, or resource identifier. NEVER a secret. Required for the same reason as the verb.'}, 'parameters': {'type': 'object', 'description': 'Non-secret parameters. A runtime MUST reject any request whose parameters appear to contain a credential.'}, 'counterparty': {'type': 'string'}}, 'additionalProperties': False}, 'mandate_ref': {'type': 'string', 'description': 'Optional reference to the owner-defined mandate the agent believes authorizes this.'}, 'requested_by': {'type': 'object', 'required': ['agent'], 'properties': {'agent': {'type': 'string', 'description': 'Identifier of the requesting agent.'}, 'session': {'type': 'string', 'description': 'Optional session or task identifier.'}, 'on_behalf_of': {'type': 'string', 'description': 'Optional identifier of the human or system the agent acts for.'}}, 'additionalProperties': False}, 'justification': {'type': 'string', 'minLength': 1, 'description': 'Why the agent believes this is within its mandate. Free text, for the record.'}, 'schema_version': {'const': '0.1-draft', 'description': 'Draft. The runtime does not exist; this shape may change.'}, 'idempotency_key': {'type': 'string', 'description': 'Optional. Lets a runtime refuse a duplicate rather than perform an operation twice.'}}, 'description': 'A typed description of a proposed operation, submitted by an agent to a local HANRIA runtime. MUST NOT contain credentials, secrets, private keys, or tokens.', 'additionalProperties': False}, 'mandate': {'type': 'object', 'title': 'HANRIA mandate', '$comment': 'A mandate names what may be done, not the means of doing it, and must never contain a credential, secret, key or token. The checker refuses a mandate carrying recognizable credential material rather than evaluating it, because anything in a clause note is copied into the decision record. That detection is a heuristic and cannot be complete.', 'required': ['schema_version', 'mandate_id', 'purpose', 'default', 'clauses'], 'properties': {'clauses': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'effect', 'match'], 'properties': {'id': {'type': 'string', 'minLength': 1, 'description': 'Identifier for this clause. Returned with every decision so a reviewer can see which sentence of the mandate was relied on.'}, 'note': {'type': 'string', 'description': 'Why this clause exists. Carried into the decision record verbatim.'}, 'match': {'type': 'object', 'required': ['kind'], 'properties': {'kind': {'type': 'array', 'items': {'enum': ['file', 'process', 'package', 'network', 'device', 'credential_use', 'transaction', 'administrative']}, 'minItems': 1, 'description': 'Operation kinds this clause covers.'}, 'verb': {'type': 'array', 'items': {'type': 'string'}, 'minItems': 1, 'description': 'Permitted verbs, matched case-insensitively and exactly. Absent means any verb.'}, 'max_amount': {'type': 'object', 'required': ['value', 'currency'], 'properties': {'value': {'type': 'string', 'description': 'Decimal as a string, to avoid float error.'}, 'currency': {'type': 'string'}}, 'description': 'Ceiling for an operation carrying an amount. A request above it does not match this clause.', 'additionalProperties': False}, 'counterparty': {'type': 'array', 'items': {'type': 'string'}, 'minItems': 1, 'description': 'Permitted counterparties, matched exactly. Absent means any counterparty.'}, 'target_prefix': {'type': 'array', 'items': {'type': 'string'}, 'minItems': 1, 'description': 'The operation target must begin with one of these strings. Absent means any target. Prefix matching is deliberately literal: it does not resolve symlinks, normalize paths, or understand hostnames, so a target is compared as written.'}}, 'description': 'All present conditions must hold for the clause to match.', 'additionalProperties': False}, 'effect': {'enum': ['permit', 'deny', 'escalate'], 'description': 'What this clause does when it matches.'}}, 'additionalProperties': False}, 'minItems': 1, 'description': 'Evaluated in order. The first matching clause decides. A request matching no clause takes the mandate default.'}, 'default': {'enum': ['deny', 'escalate'], 'description': "What happens when no clause matches. 'permit' is deliberately not an option: a mandate that permits by default cannot express a limit."}, 'purpose': {'type': 'string', 'minLength': 1, 'description': "What the agent is authorized to accomplish, in the operator's own words. Not evaluated mechanically; it is the human-readable statement against which a reviewer judges whether the clauses actually express the intent."}, 'issued_by': {'type': 'string', 'description': 'Who wrote this mandate. Free text; not authenticated by anything in this skill.'}, 'mandate_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for this mandate. Appears in every decision record made against it.'}, 'requires_human': {'type': 'array', 'items': {'enum': ['file', 'process', 'package', 'network', 'device', 'credential_use', 'transaction', 'administrative']}, 'minItems': 0, 'description': 'Operation kinds that always require a person, even where a clause permits them. These escalate rather than permit.'}, 'schema_version': {'const': '0.2-draft', 'description': 'Draft. The shape may change while the runtime is in development.'}, 'not_valid_after': {'type': 'string', 'format': 'date-time', 'description': 'RFC 3339 timestamp. After this instant every action is denied. Absent means no expiry, which is discouraged: an unbounded mandate is the condition that lets delegated authority outlive the task it was granted for.'}}, 'description': 'An operator-authored statement of what an agent may do. Written by a person, read by an agent, evaluated locally. A mandate is advisory: it describes intended authority and supports a local check, but it does not enforce anything. Enforcement requires a component that exclusively holds the credentials and can refuse.', 'additionalProperties': False}}, 'additionalProperties': False}
추가됨
check_action
2026년 10월 1일 2:40 AM