MCP 서버

Trust Gate

io.github.CWNApps/trust-gate-mcp
MCP 및 에이전트 인프라 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Creates and verifies tamper-evident, post-quantum receipts for agent actions and CRM record changes.

audit_my_agent_inventory
Rank a CALLER-PROVIDED list of MCP tools by worst-regret if they act (a name-based heuristic that weights a name's first word most). Read-only: it mints no receipt. Cannot auto-discover the inventory -- MCP does not allow that; the caller must pass it in.
입력 스키마
{'type': 'object', 'title': 'audit_my_agent_inventoryArguments', 'required': ['inventory'], 'properties': {'notes': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Notes', 'default': None}, 'inventory': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'title': 'Inventory'}}}
출력 스키마
{'type': 'object', 'title': 'audit_my_agent_inventoryOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
check_egress
Egress classification check. Scans a data sample for a finite list of sensitivity markers and classifies as NO_MARKERS_FOUND / INTERNAL / CONFIDENTIAL / RESTRICTED. RESTRICTED sets blocked=true; this tool cannot block anything itself, and NO_MARKERS_FOUND is not clearance to send. Returns classification, retention info, and a tamper-evident receipt.
입력 스키마
{'type': 'object', 'title': 'check_egressArguments', 'required': ['destination', 'data_sample', 'provider'], 'properties': {'provider': {'type': 'string', 'title': 'Provider'}, 'data_sample': {'type': 'string', 'title': 'Data Sample'}, 'destination': {'type': 'string', 'title': 'Destination'}}}
출력 스키마
{'type': 'object', 'title': 'check_egressOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
gate_decision
Two-phase decision gate with a real verdict. PREVIEW returns ALLOW, DENY or ESCALATE with the risk tier and reasons, plus a preview_id, without acting. COMMIT re-evaluates the same inputs and mints a signed receipt for the verdict. Only ALLOW returns a GRANTED permit; DENY returns DENIED; ESCALATE returns WITHHELD_PENDING_HUMAN and a human must decide outside this tool. Applies only to actions the caller routes through it: it does not observe or block what an agent does. Verb-tier heuristic on the action name and resource, not a proof. Stateless. Optional attestation: triggered_by_type, triggered_by_source, decision_model.
입력 스키마
{'type': 'object', 'title': 'gate_decisionArguments', 'required': ['action', 'resource', 'context'], 'properties': {'phase': {'type': 'string', 'title': 'Phase', 'default': 'PREVIEW'}, 'action': {'type': 'string', 'title': 'Action'}, 'context': {'type': 'object', 'title': 'Context', 'additionalProperties': True}, 'resource': {'type': 'string', 'title': 'Resource'}, 'preview_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Preview Id', 'default': None}, 'decision_model': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Decision Model', 'default': None}, 'triggered_by_type': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Triggered By Type', 'default': None}, 'triggered_by_source': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Triggered By Source', 'default': None}}}
출력 스키마
{'type': 'object', 'title': 'gate_decisionOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
mint_action_receipt
Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for an arbitrary consequential agent action. Optional attestation: triggered_by_type (human/agent/script), triggered_by_source (api/cli/cron), decision_model (the LLM model used). Attestation values are caller claims: allowlisted to safe characters, signed, not verified. Decisions that contain a gate verdict word are reserved for gate_decision.
입력 스키마
{'type': 'object', 'title': 'mint_action_receiptArguments', 'required': ['agent_id', 'operation', 'target'], 'properties': {'inputs': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Inputs', 'default': None}, 'policy': {'type': 'string', 'title': 'Policy', 'default': 'agent action evidence'}, 'target': {'type': 'string', 'title': 'Target'}, 'agent_id': {'type': 'string', 'title': 'Agent Id'}, 'decision': {'type': 'string', 'title': 'Decision', 'default': 'ACTION_GOVERNED'}, 'operation': {'type': 'string', 'title': 'Operation'}, 'decision_model': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Decision Model', 'default': None}, 'triggered_by_type': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Triggered By Type', 'default': None}, 'triggered_by_source': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Triggered By Source', 'default': None}}}
출력 스키마
{'type': 'object', 'title': 'mint_action_receiptOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
mint_receipt_for_record_change
Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for one CRM record change. Old/new values are carried as SHA-256 hashes. Works with any CRM (Relaticle, hosted CRMs, custom).
입력 스키마
{'type': 'object', 'title': 'mint_receipt_for_record_changeArguments', 'required': ['record_id', 'object_type', 'field', 'old_value', 'new_value', 'changed_by_agent'], 'properties': {'field': {'type': 'string', 'title': 'Field'}, 'policy': {'type': 'string', 'title': 'Policy', 'default': 'per-decision CRM change evidence'}, 'tenant': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Tenant', 'default': None}, 'new_value': {'type': 'string', 'title': 'New Value'}, 'old_value': {'type': 'string', 'title': 'Old Value'}, 'record_id': {'type': 'string', 'title': 'Record Id'}, 'object_type': {'type': 'string', 'title': 'Object Type'}, 'changed_by_agent': {'type': 'string', 'title': 'Changed By Agent'}}}
출력 스키마
{'type': 'object', 'title': 'mint_receipt_for_record_changeOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
run_exit_drill
Vendor exit readiness drill. Checks local signing key, local model access (Ollama). Returns step-by-step results and a tamper-evident receipt. Informational; it signs one receipt, which creates the signing key on a host that has none yet.
입력 스키마
{'type': 'object', 'title': 'run_exit_drillArguments', 'properties': {}}
출력 스키마
{'type': 'object', 'title': 'run_exit_drillOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
verify_receipt
Verify a Trust Gate receipt from the certificate alone (offline). ok=true means unchanged since signing, signed, kid consistent with the embedded key, and (require_pq default on) at least one post-quantum leg verified; unsigned receipts fail. It does not prove who signed: pass expected_kid to pin the signer's Ed25519 key; a pin counts only when that key's own signature verifies (see signer_pinned). The post-quantum keys in a receipt are not covered by the kid.
입력 스키마
{'type': 'object', 'title': 'verify_receiptArguments', 'required': ['receipt'], 'properties': {'receipt': {'type': 'object', 'title': 'Receipt', 'additionalProperties': True}, 'require_pq': {'anyOf': [{'type': 'boolean'}, {'type': 'null'}], 'title': 'Require Pq', 'default': None}, 'expected_kid': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Expected Kid', 'default': None}}}
출력 스키마
{'type': 'object', 'title': 'verify_receiptOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
추가됨
run_exit_drill
2026년 10월 3일 2:52 AM
추가됨
check_egress
2026년 10월 3일 2:52 AM
추가됨
gate_decision
2026년 10월 3일 2:52 AM
변경됨
verify_receipt
2026년 10월 3일 2:52 AM
변경됨
mint_action_receipt
2026년 10월 3일 2:52 AM
변경됨
audit_my_agent_inventory
2026년 10월 3일 2:52 AM
변경됨
mint_receipt_for_record_change
2026년 10월 3일 2:52 AM
추가됨
verify_receipt
2026년 9월 17일 12:41 PM
추가됨
mint_action_receipt
2026년 9월 17일 12:41 PM
추가됨
audit_my_agent_inventory
2026년 9월 17일 12:41 PM
추가됨
mint_receipt_for_record_change
2026년 9월 17일 12:41 PM