MCP 서버

HiveAttest

io.github.srotzin/hive-mcp-attest
MCP 및 에이전트 인프라 보안 공개 · 연결 가능 MCP 2026-07-28

이 MCP로 할 수 있는 일

Implements signed agent attestation primitives for passports, warranties, custody chains, cargo schemas, gate decisions, inspections, and Merkle proofs.

attest_absence_build
Build a sorted Merkle tree for an audit window (enables cryptographic non-membership proofs, C13: prov-absence). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['window_id', 'events'], 'properties': {'events': {'type': 'array', 'description': 'Observed events to commit to the sorted Merkle tree'}, 'window_id': {'type': 'string', 'description': 'Audit window identifier'}}}
attest_absence_prove
Prove that a query event is NOT a member of a previously-built audit window (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['window_id', 'query'], 'properties': {'query': {'type': 'object', 'description': 'Event to prove absent'}, 'window_id': {'type': 'string', 'description': 'Audit window identifier (must have been built)'}}}
attest_absence_verify
Verify a non-membership proof against an expected Merkle root (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['proof', 'root_hex'], 'properties': {'proof': {'type': 'object', 'description': 'Non-membership proof from attest_absence_prove'}, 'root_hex': {'type': 'string', 'description': 'Expected Merkle root (hex)'}}}
attest_cargo_register
Register a versioned cargo type in the HiveAttest registry (C17: hive-cargo-taxonomy). Pins a definition hash for version-anchoring. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['id', 'name', 'version', 'sensitivity', 'schema'], 'properties': {'id': {'type': 'string', 'description': 'Unique cargo type ID, e.g. "pii"'}, 'name': {'type': 'string', 'description': 'Human-readable cargo type name'}, 'schema': {'type': 'object', 'description': 'JSON Schema defining the payload shape'}, 'version': {'type': 'string', 'description': 'Semver version string, e.g. "1.0.0"'}, 'supersedes': {'type': 'object', 'description': 'Optional {id, version} of superseded type'}, 'sensitivity': {'enum': ['public', 'internal', 'confidential', 'restricted', 'critical'], 'type': 'string'}}}
attest_cargo_snapshot
Get a registry snapshot with Merkle root for version pinning (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'properties': {}}
attest_cargo_validate
Validate a payload against a registered cargo type schema (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['cargo_type_id', 'version', 'payload'], 'properties': {'payload': {'type': 'object', 'description': 'Payload to validate against the schema'}, 'version': {'type': 'string', 'description': 'Cargo type version'}, 'cargo_type_id': {'type': 'string', 'description': 'Registered cargo type ID'}}}
attest_custody_append
Append a node to a custody chain (C16: hive-custody). Taint propagates: once tainted, always tainted. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['chain_id', 'transform_id', 'agent_did'], 'properties': {'payload': {'type': 'object', 'default': {}, 'description': 'Transform payload (will be hashed)'}, 'chain_id': {'type': 'string', 'description': 'Chain identifier (create new by using a fresh ID)'}, 'agent_did': {'type': 'string', 'description': 'DID of the agent performing the transform'}, 'taint_status': {'enum': ['clean', 'tainted', 'unknown'], 'type': 'string', 'default': 'clean', 'description': 'Declared taint status'}, 'transform_id': {'type': 'string', 'description': 'Transform identifier for this step'}}}
attest_custody_proof
Retrieve a Merkle inclusion proof for a specific node in a custody chain (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['chain_id', 'index'], 'properties': {'index': {'type': 'integer', 'description': '0-based node index'}, 'chain_id': {'type': 'string', 'description': 'Chain identifier'}}}
attest_custody_verify
Verify a custody chain: hash linkage, Ed25519 signatures, and taint propagation (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['nodes'], 'properties': {'nodes': {'type': 'array', 'description': 'Ordered array of custody chain node objects (from attest_custody_append responses)'}}}
attest_gate_evaluate
THE HEADLINE TOOL. Evaluate whether an agent may proceed through the HiveAttest gate (C19: hive-gate-enforcer). Verifies passport signature + expiry, cargo registry membership, and warranty status. Every response (allow OR deny) includes a signed C18-format receipt of the gate decision. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['passport_manifest'], 'properties': {'context': {'type': 'object', 'default': {}, 'description': 'Additional gate evaluation context'}, 'custody_root': {'type': 'string', 'description': 'Expected custody chain Merkle root (optional)'}, 'warranty_ids': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'Active warranty IDs to verify'}, 'cargo_manifest': {'type': 'object', 'description': 'C17 cargo manifest (optional)'}, 'passport_manifest': {'type': 'object', 'description': 'C15 passport manifest from attest_passport_issue'}}}
attest_inspect_sample
Probabilistic secondary inspection of a record batch (C20: hive-secondary-inspection). Returns a signed inspection record. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['sample_id', 'records'], 'properties': {'seed': {'type': 'integer', 'description': 'Optional RNG seed for reproducibility'}, 'records': {'type': 'array', 'description': 'Records to probabilistically inspect'}, 'sample_id': {'type': 'string', 'description': 'Identifier for the sample batch'}, 'sample_rate': {'type': 'number', 'default': 0.1, 'maximum': 1, 'minimum': 0, 'description': 'Fraction to inspect (0.0 to 1.0)'}}}
attest_meta
Return HiveAttest layer/spec/patent metadata for all claims. Useful for agent introspection. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'properties': {}}
attest_passport_issue
Issue a Pre-Action Attestation Manifest (C15: hive-passport). Signs with Ed25519 over RFC 8785 JCS-canonical body. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['action_id', 'agent_did', 'intended_op', 'target_resource'], 'properties': {'inputs': {'type': 'object', 'default': {}, 'description': 'Declared inputs (will be hashed)'}, 'action_id': {'type': 'string', 'description': 'Caller-supplied action correlation ID'}, 'agent_did': {'type': 'string', 'description': 'DID of the attesting agent'}, 'intended_op': {'type': 'string', 'description': 'Operation name, e.g. "tool_invocation"'}, 'ttl_seconds': {'type': 'integer', 'default': 300, 'description': 'Validity window in seconds (default 300)'}, 'target_resource': {'type': 'string', 'description': 'URI or identifier of the target resource'}}}
attest_passport_verify
Verify a Pre-Action Attestation Manifest (C15: hive-passport). Checks Ed25519 signature, temporal validity, and optionally observed inputs hash. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['manifest'], 'properties': {'manifest': {'type': 'object', 'description': 'Full passport manifest object (from attest_passport_issue)'}, 'observed_inputs': {'type': 'object', 'description': 'Optional observed inputs to check against declared hash'}}}
attest_smsh_verify
Verify a SMSH-Stamp v1 receipt (C8/C12: smsh-stamp-verifier). Validates schema, version, algorithm, timestamp, and Ed25519 signature. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['receipt'], 'properties': {'receipt': {'type': 'object', 'description': 'SMSH-Stamp v1 receipt object'}, 'pubkey_b64url': {'type': 'string', 'description': 'Override trust anchor Ed25519 public key (base64url, 32 bytes)'}, 'max_age_seconds': {'type': 'integer', 'description': 'Reject receipts older than this many seconds'}}}
attest_warranty_breach
Report a warranty breach. Marks the warranty as breached and returns a signed breach record (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['warranty_id', 'breach_description'], 'properties': {'evidence': {'type': 'object', 'description': 'Optional evidence dict'}, 'warranty_id': {'type': 'string', 'description': 'Warranty ID to report breach on'}, 'breach_description': {'type': 'string', 'description': 'Description of the breach'}}}
attest_warranty_get
Retrieve a warranty by ID (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['warranty_id'], 'properties': {'warranty_id': {'type': 'string', 'description': 'Warranty ID'}}}
attest_warranty_issue
Issue an attestation warranty committing an agent to a claim (C18: hive-attestation-warranty). Signed with Ed25519. Reference-grade implementation. Wire format normative; production-grade is Layer B.
입력 스키마
{'type': 'object', 'required': ['agent_did', 'action_id', 'claim'], 'properties': {'claim': {'type': 'string', 'description': 'Human-readable warranty claim'}, 'scope': {'type': 'object', 'default': {}, 'description': 'Scope constraints'}, 'action_id': {'type': 'string', 'description': 'Action correlation ID being warranted'}, 'agent_did': {'type': 'string', 'description': 'DID of the warranting agent'}, 'expires_at': {'type': 'string', 'description': 'ISO-8601 expiry UTC (optional)'}}}
추가됨
attest_meta
2026년 9월 17일 12:52 PM
추가됨
attest_absence_verify
2026년 9월 17일 12:52 PM
추가됨
attest_absence_prove
2026년 9월 17일 12:52 PM
추가됨
attest_absence_build
2026년 9월 17일 12:52 PM
추가됨
attest_smsh_verify
2026년 9월 17일 12:52 PM
추가됨
attest_inspect_sample
2026년 9월 17일 12:52 PM
추가됨
attest_gate_evaluate
2026년 9월 17일 12:52 PM
추가됨
attest_warranty_get
2026년 9월 17일 12:52 PM
추가됨
attest_warranty_breach
2026년 9월 17일 12:52 PM
추가됨
attest_warranty_issue
2026년 9월 17일 12:52 PM
추가됨
attest_cargo_snapshot
2026년 9월 17일 12:52 PM
추가됨
attest_cargo_validate
2026년 9월 17일 12:52 PM
추가됨
attest_cargo_register
2026년 9월 17일 12:52 PM
추가됨
attest_custody_proof
2026년 9월 17일 12:52 PM
추가됨
attest_custody_verify
2026년 9월 17일 12:52 PM
추가됨
attest_custody_append
2026년 9월 17일 12:52 PM
추가됨
attest_passport_verify
2026년 9월 17일 12:52 PM
추가됨
attest_passport_issue
2026년 9월 17일 12:52 PM