MCP Server

invinoveritas

com.babyblueviper/invinoveritas
AI & Agents Developer Tools Security Public & reachable MCP 2026-07-28

What this MCP does

Provides agent governance, independent decision reviews, signed proofs, audit trails, persistent memory, code execution, and verification services.

audit_agent_readiness
Audits a public agent or API URL for verifiability: discovery files (llms.txt, MCP card, robots, sitemap), handshake endpoints, and whether presented signed proofs validate. Returns a 0-100 score, a grade, ranked fixes, and a signed proof of the audit. Every result re-derives from a public fetch. Docs: https://api.babyblueviper.com/docs
Read only Open world
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The agent endpoint/site URL to audit (public http(s) only)'}}}
conformance_certify
Publishes a verifier's current conformance grade from the public registry (conformance.json) as a permanent, signed ledger entry, labeled 'certified as of this measurement'. It records the registry's existing measurement and cannot change it. Only works for a verifier currently listed as certified. Docs: https://api.babyblueviper.com/conformance
Open world Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': "The verifier's exact name as listed on GET /conformance.json (must currently show certified:true)."}, 'note': {'type': 'string', 'description': 'Optional short context for the ledger entry.'}}}
ledger
Reads invinoveritas's public track record of signed verdicts, including ones that turned out wrong. Each entry is a signed Nostr event whose id and signature can be recomputed against invinoveritas's published key; entries are append-only and Bitcoin-timestamped, so they can't be edited after the fact. No arguments returns the index; pass entry to read one. Free, no sign-in. Docs: https://api.babyblueviper.com/ledger
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {'entry': {'type': 'string', 'description': "Optional entry number (e.g. '1'); omit for the full index."}}}
ledger_submit
Publishes one of your own signed review proofs (from review with sign=true) as a public entry on the invinoveritas ledger. Publication is immediate and permanent: the entry is broadcast to Nostr relays and Bitcoin-timestamped. Only genuine invinoveritas-signed proofs are accepted. Docs: https://api.babyblueviper.com/ledger
Open world
Input schema
{'type': 'object', 'required': ['event'], 'properties': {'note': {'type': 'string', 'description': "Optional short context: what this verdict was for, why it's worth featuring."}, 'event': {'type': 'object', 'description': 'The signed Nostr event from a prior /review(sign=true) call — the exact proof.event object that response returned.'}}}
review
Independent verdict on a proposed action before it is taken: a code diff, shell command, deployment plan, configuration change, another agent's output, or a proposed transaction. Returns approve / approve_with_concerns / reject with a confidence score, issues ranked by severity, suggested fixes and alternatives. With sign=true the verdict is returned as a signed proof that anyone can check later with verify_proof. The verdict is a reasoned second opinion, not a guarantee of outcome. Docs: https://api.babyblueviper.com/docs
Read only
Input schema
{'type': 'object', 'examples': [{'sign': True, 'context': 'About to force-push a rebuilt main branch that other people pull from.', 'artifact': 'rm -rf ./build && git push --force origin main', 'artifact_type': 'shell_command'}], 'required': ['artifact'], 'properties': {'sign': {'type': 'boolean', 'default': False, 'description': "Return the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof."}, 'context': {'type': 'string', 'description': 'What you are trying to accomplish, why now, success criteria'}, 'artifact': {'type': 'string', 'description': 'The artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text'}, 'concerns': {'type': 'string', 'description': "Specific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')"}, 'artifact_type': {'enum': ['code_diff', 'patch', 'shell_command', 'plan', 'config_change', 'analysis', 'agent_output', 'trade', 'onchain_action', 'sanctions_screening', 'general'], 'type': 'string', 'default': 'general', 'description': "Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason."}, 'verdict_relay': {'type': 'object', 'description': "Optional (verdict-relay/v2): also return a BIP-340 signature an ERC-8414 InvinoveritasVerdictAuthoritySigned contract verifies on-chain (garyyang-finchip/task-token-standard#2). {chain_id, authority, task_contract, token_id, submission_id, task_version, result_hash, task_document}. Requires sign=true. result_hash must be sha256 of the exact artifact; task_document is the plaintext task document (sha256 = the kernel's tdHash) and is put into the review context. approved/decision_ref come from our own verdict (approve->true, reject->false; concerns/defer unsigned). Checked before any charge. Result field verdict_relay."}, 'action_binding': {'type': 'object', 'description': "Optional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed."}, 'related_claims': {'type': 'object', 'description': 'Optional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth.'}, 'disclosed_summary': {'type': 'string', 'description': "Only used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values."}, 'external_evidence': {'type': 'array', 'description': "Optional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence."}, 'intended_audience': {'type': 'string', 'description': "Optional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all."}, 'intended_verifier': {'type': 'string', 'description': "Optional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address."}, 'severity_threshold': {'enum': ['blocker', 'high', 'medium', 'all'], 'type': 'string', 'default': 'all', 'description': 'Minimum severity to report'}, 'related_proof_event': {'type': 'object', 'description': "Optional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing."}, 'request_capture_ref': {'type': 'string', 'description': "Optional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in."}, 'confidentiality_tier': {'enum': ['hash_only', 'partial_disclosure', 'full_disclosure'], 'type': 'string', 'default': 'hash_only', 'description': "Which privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve."}, 'mediator_attestation': {'type': 'object', 'description': "Optional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence."}}}
validate
Statistical reality-check of a backtest from its realized returns (or trade rows), not the strategy itself. Returns likely_real / borderline / overfit_or_noise using the Deflated Sharpe Ratio (adjusted for the number of variants tried), a sign-flip permutation test, and out-of-sample decay across purged folds. Inputs are not retained beyond a redacted audit hash. Docs: https://api.babyblueviper.com/docs
Read only
Input schema
{'type': 'object', 'properties': {'trades': {'type': 'array', 'items': {'type': 'object'}, 'description': "Alternative to 'returns': rows with a return field (ret/pnl/net_bps) and optional 'coin'/'ts'/'entry'/'exit' fields."}, 'k_folds': {'type': 'integer', 'default': 5, 'maximum': 20, 'minimum': 2}, 'n_perms': {'type': 'integer', 'default': 2000, 'maximum': 3000, 'minimum': 200}, 'returns': {'type': 'array', 'items': {'type': 'number'}, 'description': 'Per-trade (or per-period) realized returns.'}, 'agent_id': {'type': 'string', 'description': 'Optional caller agent ID'}, 'n_trials': {'type': 'integer', 'default': 1, 'maximum': 10000000, 'minimum': 1, 'description': 'How many strategy variants/params you tried before selecting this one. Be honest — more trials = bigger Deflated-Sharpe haircut.'}, 'trial_sharpes': {'type': 'array', 'items': {'type': 'number'}, 'description': 'Optional: Sharpes of all variants tried → exact DSR variance.'}, 'periods_per_year': {'type': 'number', 'description': 'Optional, for annualized-Sharpe display only.', 'exclusiveMinimum': 0}}}
verify_proof
Checks a signed invinoveritas proof without trusting whoever handed it over: recomputes the event id, checks the Schnorr signature, and confirms the signing key is invinoveritas's published key. Optionally pass expect_artifact_hash (sha256 of the content you received) to confirm the proof covers that exact content. Accepts the full event, or an event_id to look up. Returns {valid, checks, proof_payload}. Free, no sign-in. Docs: https://api.babyblueviper.com/verify
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {'event': {'type': 'object', 'description': 'The signed proof event {id,pubkey,created_at,kind,tags,content,sig} the counterparty handed you (from a /prove or /review sign=true response).'}, 'event_id': {'type': 'string', 'description': 'Alternatively, the Nostr event id alone (from a /review sign=true, /prove, or /witness proof) — fetches the durably-stored full event, independent of relay retention, and verifies it.'}, 'proof_id': {'type': 'string', 'description': 'Alternatively, a stored attestation proof_id to fetch + verify.'}, 'verifier_signature': {'type': 'string', 'description': "Optional (added 2026-08-16) — an EIP-191 personal_sign signature over 'invinoveritas-verify-proof:<event_id>', signed by the key controlling the address in expect_intended_verifier (eip155 CAIP-10 namespace only). Cryptographically PROVES presenter identity rather than just asserting it — sets checks.intended_verifier_authenticated."}, 'expect_artifact_hash': {'type': 'string', 'description': 'Optional sha256 hex of the output you received — asserts the proof is ABOUT that exact artifact.'}, 'expect_intended_verifier': {'type': 'string', 'description': "Optional (added 2026-08-16) — asserts the proof's declared intended_verifier matches you, the consumption-identity check alongside expect_artifact_hash's content-identity check. A match confirms the issuer's declared intent, not that delivery was actually restricted to you."}}}
witness
Timestamps and signs a third party's exact claim, unmodified and unjudged: 'we received this text, attributed to source X, at time T', not 'we agree with it'. The source is recorded as self-declared. The resulting proof checks with verify_proof. Docs: https://api.babyblueviper.com/docs
Input schema
{'type': 'object', 'required': ['source', 'body'], 'properties': {'body': {'type': 'string', 'description': 'The exact claim to anchor, byte-for-byte (max 16000 chars)'}, 'source': {'type': 'string', 'description': 'Who this claim is attributed to (self-declared, NOT verified by us)'}}}
Changed
review
Oct. 1, 2026, 2:52 a.m.
Removed
workspace_status
Sept. 29, 2026, 3:01 a.m.
Removed
workspace_list
Sept. 29, 2026, 3:01 a.m.
Removed
workspace_delete
Sept. 29, 2026, 3:01 a.m.
Removed
signals
Sept. 29, 2026, 3:01 a.m.
Removed
seller_intel
Sept. 29, 2026, 3:01 a.m.
Removed
residence_me
Sept. 29, 2026, 3:01 a.m.
Removed
reason
Sept. 29, 2026, 3:01 a.m.
Removed
prove
Sept. 29, 2026, 3:01 a.m.
Removed
message_post
Sept. 29, 2026, 3:01 a.m.
Removed
memory_store
Sept. 29, 2026, 3:01 a.m.
Removed
memory_search
Sept. 29, 2026, 3:01 a.m.
Removed
memory_list
Sept. 29, 2026, 3:01 a.m.
Removed
memory_get
Sept. 29, 2026, 3:01 a.m.
Removed
memory_delete
Sept. 29, 2026, 3:01 a.m.
Removed
markets_act
Sept. 29, 2026, 3:01 a.m.
Removed
marketplace_buy
Sept. 29, 2026, 3:01 a.m.
Removed
feedback_vote
Sept. 29, 2026, 3:01 a.m.
Removed
feedback_submit
Sept. 29, 2026, 3:01 a.m.
Removed
feedback_list
Sept. 29, 2026, 3:01 a.m.
Removed
execute
Sept. 29, 2026, 3:01 a.m.
Removed
decision
Sept. 29, 2026, 3:01 a.m.
Removed
browse
Sept. 29, 2026, 3:01 a.m.
Removed
agent_economy_brief
Sept. 29, 2026, 3:01 a.m.
Changed
audit_agent_readiness
Sept. 29, 2026, 3:01 a.m.
Changed
conformance_certify
Sept. 29, 2026, 3:01 a.m.
Changed
ledger_submit
Sept. 29, 2026, 3:01 a.m.
Changed
ledger
Sept. 29, 2026, 3:01 a.m.
Changed
validate
Sept. 29, 2026, 3:01 a.m.
Changed
witness
Sept. 29, 2026, 3:01 a.m.

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Andreax

io.github.moralito311-andr/andreax

Offers pay-per-call AI services for inference, agent and workflow design, OCR and transcription, code generation and review, clas…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

GoCreative Agent API

io.github.ColinHughes2121/gocreative-agent-api

Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…