MCP 서버

bernstein-mcp

io.github.sipyourdrink-ltd/bernstein-mcp
법률 및 컴플라이언스 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Verifies signed run receipts, hash chains, delegations, compliance presets, and TRACE trust records for audit and provenance validation.

explain_receipt
Explain a run receipt
Verify a run receipt and narrate the result in plain language: what the run recorded, which chains recomputed, where the first divergence is, and what an auditor can and cannot conclude without the producing install's keys.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['receipt'], 'properties': {'receipt': {'anyOf': [{'type': 'string'}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}], 'description': 'The run receipt: pass the file contents as a string for byte-exact verification, or the parsed object.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['verdict', 'explanation', 'receipt_sha256'], 'properties': {'verdict': {'enum': ['valid', 'invalid', 'unverifiable'], 'type': 'string'}, 'explanation': {'type': 'string'}, 'receipt_sha256': {'type': 'string'}}, 'additionalProperties': False}
explain_trace_mapping
Explain the bernstein → TRACE mapping
How a bernstein run maps onto a TRACE v0.2 Trust Record: one row per claim with the journal field it is sourced from and the rule that derives it. Pass a run receipt to fill in the rows its embedded journal can answer (subject, iat, model, data_class, policy digest, tool transcript) alongside the receipt's own verdict.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'receipt': {'anyOf': [{'type': 'string'}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}], 'description': 'Optional run receipt: the file contents as a string, or the parsed object.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['mapping', 'markdown', 'verdict', 'receipt_sha256'], 'properties': {'mapping': {'type': 'array', 'items': {'type': 'object', 'required': ['claim', 'source', 'rule', 'value'], 'properties': {'rule': {'type': 'string'}, 'claim': {'type': 'string'}, 'value': {'type': ['string', 'null']}, 'source': {'type': 'string'}}, 'additionalProperties': False}}, 'verdict': {'anyOf': [{'enum': ['valid', 'invalid', 'unverifiable'], 'type': 'string'}, {'type': 'null'}]}, 'markdown': {'type': 'string'}, 'receipt_sha256': {'type': ['string', 'null']}}, 'additionalProperties': False}
get_preset
Get a compliance preset
Every field of one compliance preset as bernstein v3.19.2 resolves it.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'enum': ['development', 'hipaa', 'regulated', 'standard'], 'type': 'string'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['bernstein_version', 'name', 'config'], 'properties': {'name': {'type': 'string'}, 'config': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'bernstein_version': {'type': 'string'}}, 'additionalProperties': False}
list_adapters
List agent adapters
The agent adapters bundled with bernstein v3.19.2: adapter name, the binary it drives, the module that implements it.
입력 스키마
{'type': 'object', 'properties': {}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['bernstein_version', 'adapters'], 'properties': {'adapters': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'binary', 'module'], 'properties': {'name': {'type': 'string'}, 'binary': {'type': 'string'}, 'module': {'type': 'string'}}, 'additionalProperties': False}}, 'bernstein_version': {'type': 'string'}}, 'additionalProperties': False}
list_presets
List compliance presets
The compliance presets bernstein v3.19.2 ships, with the switches each one turns on.
입력 스키마
{'type': 'object', 'properties': {}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['bernstein_version', 'presets'], 'properties': {'presets': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'enabled'], 'properties': {'name': {'type': 'string'}, 'enabled': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}}, 'bernstein_version': {'type': 'string'}}, 'additionalProperties': False}
server_info
Server info
Identity, version, and request limits for this MCP server.
입력 스키마
{'type': 'object', 'properties': {}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'version', 'limits', 'verdict_key', 'keys_url'], 'properties': {'name': {'type': 'string'}, 'limits': {'type': 'object', 'required': ['max_body_bytes', 'max_chain_entries', 'max_trace_records'], 'properties': {'max_body_bytes': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}, 'max_chain_entries': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}, 'max_trace_records': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}}, 'additionalProperties': False}, 'version': {'type': 'string'}, 'keys_url': {'type': 'string'}, 'verdict_key': {'anyOf': [{'type': 'object', 'required': ['kty', 'crv', 'x', 'kid', 'use', 'alg'], 'properties': {'x': {'type': 'string'}, 'alg': {'type': 'string'}, 'crv': {'type': 'string'}, 'kid': {'type': 'string'}, 'kty': {'type': 'string'}, 'use': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}], 'description': 'Public Ed25519 JWK this deployment signs verdicts with; also at keys_url.'}}, 'additionalProperties': False}
verify_agent_manifest
Verify an Agent Manifest
Agent Manifest v0.2 conformance checks on one manifest, stateless, no account: schema (vendored agent-manifest.schema.json), profile context, version, canonicalization, COSE envelope signature (Ed25519, key identified by kid in the protected header; ML-DSA-65 is reported unverifiable). Optionally checks that a TRACE Trust Record cites this manifest by digest. Nothing is fetched; resolvers are checked as URIs only. The manifest hash is sha256 over the COSE payload bytes (or RFC 8785 canonical JSON for object input).
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['manifest'], 'properties': {'manifest': {'anyOf': [{'type': 'string', 'maxLength': 1048576}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}], 'description': 'The agent manifest: COSE envelope as base64 string, or the parsed JSON object (payload).'}, 'trustRecord': {'type': 'object', 'description': "Optional TRACE v0.2 Trust Record to check if it cites this manifest (references[].rel == 'agent-manifest').", 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['verdict', 'failing_check', 'manifest_sha256', 'checks', 'summary', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'outcome', 'detail'], 'properties': {'name': {'enum': ['parse', 'cose_structure', 'protected_header', 'schema', 'profile', 'version', 'canonicalization', 'signature', 'record_cites_manifest'], 'type': 'string'}, 'detail': {'type': 'string'}, 'outcome': {'enum': ['ok', 'fail', 'unverifiable', 'skipped'], 'type': 'string'}}, 'additionalProperties': False}}, 'summary': {'anyOf': [{'type': 'object', 'required': ['manifest_id', 'agent_id', 'version', 'issued_at', 'expires_at', 'issuer', 'crypto_profile', 'manifest_hash', 'key_kind', 'key_kid'], 'properties': {'issuer': {'type': 'string'}, 'key_kid': {'type': 'string'}, 'version': {'type': 'string'}, 'agent_id': {'type': 'string'}, 'key_kind': {'type': 'string'}, 'issued_at': {'type': 'string'}, 'expires_at': {'type': 'string'}, 'manifest_id': {'type': 'string'}, 'manifest_hash': {'type': 'string'}, 'crypto_profile': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'verdict': {'enum': ['valid', 'invalid', 'unverifiable'], 'type': 'string'}, 'failing_check': {'anyOf': [{'enum': ['parse', 'cose_structure', 'protected_header', 'schema', 'profile', 'version', 'canonicalization', 'signature', 'record_cites_manifest'], 'type': 'string'}, {'type': 'null'}]}, 'manifest_sha256': {'type': 'string'}}, 'additionalProperties': False}
verify_chain
Verify a hash chain
Walk bernstein chain rows and recompute every link: journal rows (event_hash), lineage spine entries (entry_hash) or audit events (prev_hmac linkage). The row kind is detected from the fields, or pass `kind` explicitly. Reports the first divergent index. Pass `entries` as the file text (a JSON array or one row per line, as journal.jsonl is written) for byte-exact hashing; a parsed array also works, but then a float spelled 1.0 or -0.0 in the file cannot be told apart from an integer.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['entries'], 'properties': {'kind': {'enum': ['journal', 'spine', 'audit_linkage'], 'type': 'string'}, 'entries': {'anyOf': [{'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'maxItems': 2000}, {'type': 'string', 'maxLength': 1048576}], 'description': 'Rows in chain order, oldest first: a JSON array, or the raw text of the file.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['kind', 'intact', 'entries', 'head', 'divergent_index', 'detail'], 'properties': {'head': {'type': 'string'}, 'kind': {'enum': ['journal', 'spine', 'audit_linkage'], 'type': 'string'}, 'detail': {'type': 'string'}, 'intact': {'type': 'boolean'}, 'entries': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'divergent_index': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}}, 'additionalProperties': False}
verify_delegation_chain
Verify a TRACE delegation chain
TRACE v0.2 delegation-chain conformance, stateless, no account: index every Trust Record by the RFC 8785 digest of its complete form, start at the leaf, follow delegation.parent_record_hash to the root, and check each hop's signature, the root key against `trusted_root_keys`, the depth bound, the link's digest algorithm, the credential (registered, issuer = parent subject, holder = record subject, window at the hop's own iat) and data_class narrowing under `data_class_lattice`. Classification: provenance-invalid outranks authorization-invalid; an unread link is unverifiable, not broken. Pass `records` as a JSON array or as file text (one record per line or a JSON array).
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['records'], 'properties': {'context': {'type': 'object', 'properties': {'now': {'type': 'number', 'description': "Carried for completeness; credential windows are judged at each hop's own iat."}, 'leaf': {'type': 'string', 'description': 'Digest of the record under appraisal (`sha256:<hex>`); absent → the record no other record names as parent.'}, 'max_depth': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Default 8.'}, 'credentials': {'type': 'object', 'description': "credential_id → {issuer, holder, not_before, not_after}. Default {} → every hop's credential is unknown.", 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'object', 'required': ['issuer', 'holder', 'not_before', 'not_after'], 'properties': {'holder': {'type': 'string'}, 'issuer': {'type': 'string'}, 'not_after': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'not_before': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}}}}, 'trusted_root_keys': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Public JWKs; identity is (kty, crv, x, y). Default [] → the root is untrusted.'}, 'data_class_lattice': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Least to most sensitive; classes outside it are not compared. Default [].'}, 'supported_digest_algorithms': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Default ["sha256"]; "sha384" is also computed.'}}}, 'records': {'anyOf': [{'type': 'array', 'items': {'anyOf': [{'type': 'string'}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}]}}, {'type': 'string', 'maxLength': 1048576}], 'description': 'The record set in any order: a JSON array of records (objects or strings), or the raw text of a file.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['classification', 'codes', 'failures', 'warnings', 'depth', 'walk', 'first_broken_link', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'walk': {'type': 'array', 'items': {'type': 'object', 'required': ['record_sha256', 'subject', 'depth', 'delegation', 'codes'], 'properties': {'codes': {'type': 'array', 'items': {'type': 'string'}}, 'depth': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'subject': {'type': 'string'}, 'delegation': {'anyOf': [{'type': 'object', 'required': ['parent_record_hash', 'credential_id'], 'properties': {'credential_id': {'type': 'string'}, 'parent_record_hash': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'record_sha256': {'type': 'string'}}, 'additionalProperties': False}}, 'codes': {'type': 'array', 'items': {'type': 'string'}}, 'depth': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'failures': {'type': 'array', 'items': {'type': 'string'}}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'classification': {'enum': ['verified', 'provenance-invalid', 'authorization-invalid', 'unverifiable'], 'type': 'string'}, 'first_broken_link': {'anyOf': [{'type': 'object', 'required': ['record_sha256', 'code', 'detail'], 'properties': {'code': {'type': 'string'}, 'detail': {'type': 'string'}, 'record_sha256': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}}, 'additionalProperties': False}
verify_receipt
Verify a run receipt
Recompute every hash chain a bernstein run receipt embeds (journal, lineage spine, optional audit range), rebuild the signed subject from the recomputed heads, and check the Ed25519 signature with the key the receipt carries. Needs no secret and reads nothing but the receipt. Returns the verdict, the first failing check, one line per check, and the same verdict as a DSSE envelope signed by this verifier's Ed25519 key (public key at keys_url) so the outcome can be kept and re-checked offline.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['receipt'], 'properties': {'receipt': {'anyOf': [{'type': 'string'}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}], 'description': 'The run receipt: pass the file contents as a string for byte-exact verification, or the parsed object.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['verdict', 'failing_check', 'divergent_step', 'receipt_sha256', 'checks', 'summary', 'verify_url', 'signed_verdict', 'keys_url', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'outcome', 'detail'], 'properties': {'name': {'enum': ['schema', 'journal_chain', 'journal_head', 'spine_chain', 'spine_head', 'audit_range_head', 'audit_range_linkage', 'audit_range_hmac', 'subject_binding', 'signature'], 'type': 'string'}, 'detail': {'type': 'string'}, 'outcome': {'enum': ['ok', 'fail', 'unverifiable', 'skipped'], 'type': 'string'}}, 'additionalProperties': False}}, 'summary': {'anyOf': [{'type': 'object', 'required': ['run_id', 'schema_version', 'hash_profile', 'journal_events', 'spine_entries', 'audit_events', 'key_id', 'producer', 'tool_calls'], 'properties': {'key_id': {'type': 'string'}, 'run_id': {'type': 'string'}, 'producer': {'type': ['string', 'null']}, 'tool_calls': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'audit_events': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'hash_profile': {'type': 'string'}, 'spine_entries': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'journal_events': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'schema_version': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'verdict': {'enum': ['valid', 'invalid', 'unverifiable'], 'type': 'string'}, 'keys_url': {'type': 'string'}, 'verify_url': {'type': ['string', 'null']}, 'failing_check': {'anyOf': [{'enum': ['schema', 'journal_chain', 'journal_head', 'spine_chain', 'spine_head', 'audit_range_head', 'audit_range_linkage', 'audit_range_hmac', 'subject_binding', 'signature'], 'type': 'string'}, {'type': 'null'}]}, 'divergent_step': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'receipt_sha256': {'type': 'string'}, 'signed_verdict': {'anyOf': [{'type': 'object', 'required': ['payloadType', 'payload', 'signatures'], 'properties': {'payload': {'type': 'string'}, 'signatures': {'type': 'array', 'items': {'type': 'object', 'required': ['keyid', 'sig'], 'properties': {'sig': {'type': 'string'}, 'keyid': {'type': 'string'}}, 'additionalProperties': False}}, 'payloadType': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}], 'description': 'DSSE envelope over the verdict statement (JCS JSON in payload), Ed25519 over the DSSE PAE.'}}, 'additionalProperties': False}
verify_trace_record
Verify a TRACE Trust Record
TRACE v0.2 conformance checks on one Trust Record, stateless, no account: schema (vendored trace-claim.json), profile, subject URI, software-only runtime rule, policy digest, public-only confirmation key, the embedded signature (EdDSA, ES256 or ES384 with the key in cnf.jwk), appraisal, delegation link shape and references. Nothing is fetched: resolvers are checked as URIs only. `record_sha256` is the RFC 8785 digest of the complete record, signature included — the value a child hop puts in delegation.parent_record_hash.
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['record'], 'properties': {'record': {'anyOf': [{'type': 'string', 'maxLength': 1048576}, {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}], 'description': 'A TRACE v0.2 Trust Record: the file contents as a string, or the parsed object.'}}}
출력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['verdict', 'failing_check', 'record_sha256', 'checks', 'summary', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'outcome', 'detail'], 'properties': {'name': {'enum': ['parse', 'schema', 'profile', 'subject', 'runtime', 'policy', 'cnf_key', 'signature', 'appraisal', 'delegation', 'references', 'canonicalization'], 'type': 'string'}, 'detail': {'type': 'string'}, 'outcome': {'enum': ['ok', 'fail', 'unverifiable', 'skipped'], 'type': 'string'}}, 'additionalProperties': False}}, 'summary': {'anyOf': [{'type': 'object', 'required': ['subject', 'eat_profile', 'iat', 'model_id', 'provider', 'data_class', 'key_thumbprint', 'has_delegation', 'references', 'tool_calls'], 'properties': {'iat': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'subject': {'type': 'string'}, 'model_id': {'type': 'string'}, 'provider': {'type': 'string'}, 'data_class': {'type': 'string'}, 'references': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'tool_calls': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}]}, 'eat_profile': {'type': 'string'}, 'has_delegation': {'type': 'boolean'}, 'key_thumbprint': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'verdict': {'enum': ['valid', 'invalid', 'unverifiable'], 'type': 'string'}, 'failing_check': {'anyOf': [{'enum': ['parse', 'schema', 'profile', 'subject', 'runtime', 'policy', 'cnf_key', 'signature', 'appraisal', 'delegation', 'references', 'canonicalization'], 'type': 'string'}, {'type': 'null'}]}, 'record_sha256': {'type': 'string'}}, 'additionalProperties': False}
추가됨
verify_agent_manifest
2026년 9월 25일 2:50 AM
추가됨
explain_trace_mapping
2026년 9월 21일 2:49 AM
추가됨
verify_delegation_chain
2026년 9월 21일 2:49 AM
추가됨
verify_trace_record
2026년 9월 21일 2:49 AM
변경됨
verify_receipt
2026년 9월 21일 2:49 AM
변경됨
server_info
2026년 9월 21일 2:49 AM
추가됨
list_adapters
2026년 9월 19일 2:40 AM
추가됨
get_preset
2026년 9월 19일 2:40 AM
추가됨
list_presets
2026년 9월 19일 2:40 AM
추가됨
verify_chain
2026년 9월 19일 2:40 AM
추가됨
explain_receipt
2026년 9월 19일 2:40 AM
추가됨
verify_receipt
2026년 9월 19일 2:40 AM
추가됨
server_info
2026년 9월 19일 2:40 AM