invinoveritas
What this MCP does
Provides agent governance, independent decision reviews, signed proofs, audit trails, persistent memory, code execution, and verification services.
Tools
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The agent endpoint/site URL to audit (public http(s) only)'}}}
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': "The verifier's exact name as listed on GET /conformance.json (must currently show certified:true)."}, 'note': {'type': 'string', 'description': 'Optional short context for the ledger entry.'}}}
Input schema
{'type': 'object', 'required': [], 'properties': {'entry': {'type': 'string', 'description': "Optional entry number (e.g. '1'); omit for the full index."}}}
Input schema
{'type': 'object', 'required': ['event'], 'properties': {'note': {'type': 'string', 'description': "Optional short context: what this verdict was for, why it's worth featuring."}, 'event': {'type': 'object', 'description': 'The signed Nostr event from a prior /review(sign=true) call — the exact proof.event object that response returned.'}}}
Input schema
{'type': 'object', 'examples': [{'sign': True, 'context': 'About to force-push a rebuilt main branch that other people pull from.', 'artifact': 'rm -rf ./build && git push --force origin main', 'artifact_type': 'shell_command'}], 'required': ['artifact'], 'properties': {'sign': {'type': 'boolean', 'default': False, 'description': "Return the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof."}, 'context': {'type': 'string', 'description': 'What you are trying to accomplish, why now, success criteria'}, 'artifact': {'type': 'string', 'description': 'The artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text'}, 'concerns': {'type': 'string', 'description': "Specific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')"}, 'artifact_type': {'enum': ['code_diff', 'patch', 'shell_command', 'plan', 'config_change', 'analysis', 'agent_output', 'trade', 'onchain_action', 'sanctions_screening', 'general'], 'type': 'string', 'default': 'general', 'description': "Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason."}, 'verdict_relay': {'type': 'object', 'description': "Optional (verdict-relay/v2): also return a BIP-340 signature an ERC-8414 InvinoveritasVerdictAuthoritySigned contract verifies on-chain (garyyang-finchip/task-token-standard#2). {chain_id, authority, task_contract, token_id, submission_id, task_version, result_hash, task_document}. Requires sign=true. result_hash must be sha256 of the exact artifact; task_document is the plaintext task document (sha256 = the kernel's tdHash) and is put into the review context. approved/decision_ref come from our own verdict (approve->true, reject->false; concerns/defer unsigned). Checked before any charge. Result field verdict_relay."}, 'action_binding': {'type': 'object', 'description': "Optional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed."}, 'related_claims': {'type': 'object', 'description': 'Optional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth.'}, 'disclosed_summary': {'type': 'string', 'description': "Only used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values."}, 'external_evidence': {'type': 'array', 'description': "Optional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence."}, 'intended_audience': {'type': 'string', 'description': "Optional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all."}, 'intended_verifier': {'type': 'string', 'description': "Optional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address."}, 'severity_threshold': {'enum': ['blocker', 'high', 'medium', 'all'], 'type': 'string', 'default': 'all', 'description': 'Minimum severity to report'}, 'related_proof_event': {'type': 'object', 'description': "Optional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing."}, 'request_capture_ref': {'type': 'string', 'description': "Optional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in."}, 'confidentiality_tier': {'enum': ['hash_only', 'partial_disclosure', 'full_disclosure'], 'type': 'string', 'default': 'hash_only', 'description': "Which privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve."}, 'mediator_attestation': {'type': 'object', 'description': "Optional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence."}}}
Input schema
{'type': 'object', 'properties': {'trades': {'type': 'array', 'items': {'type': 'object'}, 'description': "Alternative to 'returns': rows with a return field (ret/pnl/net_bps) and optional 'coin'/'ts'/'entry'/'exit' fields."}, 'k_folds': {'type': 'integer', 'default': 5, 'maximum': 20, 'minimum': 2}, 'n_perms': {'type': 'integer', 'default': 2000, 'maximum': 3000, 'minimum': 200}, 'returns': {'type': 'array', 'items': {'type': 'number'}, 'description': 'Per-trade (or per-period) realized returns.'}, 'agent_id': {'type': 'string', 'description': 'Optional caller agent ID'}, 'n_trials': {'type': 'integer', 'default': 1, 'maximum': 10000000, 'minimum': 1, 'description': 'How many strategy variants/params you tried before selecting this one. Be honest — more trials = bigger Deflated-Sharpe haircut.'}, 'trial_sharpes': {'type': 'array', 'items': {'type': 'number'}, 'description': 'Optional: Sharpes of all variants tried → exact DSR variance.'}, 'periods_per_year': {'type': 'number', 'description': 'Optional, for annualized-Sharpe display only.', 'exclusiveMinimum': 0}}}
Input schema
{'type': 'object', 'required': [], 'properties': {'event': {'type': 'object', 'description': 'The signed proof event {id,pubkey,created_at,kind,tags,content,sig} the counterparty handed you (from a /prove or /review sign=true response).'}, 'event_id': {'type': 'string', 'description': 'Alternatively, the Nostr event id alone (from a /review sign=true, /prove, or /witness proof) — fetches the durably-stored full event, independent of relay retention, and verifies it.'}, 'proof_id': {'type': 'string', 'description': 'Alternatively, a stored attestation proof_id to fetch + verify.'}, 'verifier_signature': {'type': 'string', 'description': "Optional (added 2026-08-16) — an EIP-191 personal_sign signature over 'invinoveritas-verify-proof:<event_id>', signed by the key controlling the address in expect_intended_verifier (eip155 CAIP-10 namespace only). Cryptographically PROVES presenter identity rather than just asserting it — sets checks.intended_verifier_authenticated."}, 'expect_artifact_hash': {'type': 'string', 'description': 'Optional sha256 hex of the output you received — asserts the proof is ABOUT that exact artifact.'}, 'expect_intended_verifier': {'type': 'string', 'description': "Optional (added 2026-08-16) — asserts the proof's declared intended_verifier matches you, the consumption-identity check alongside expect_artifact_hash's content-identity check. A match confirms the issuer's declared intent, not that delivery was actually restricted to you."}}}
Input schema
{'type': 'object', 'required': ['source', 'body'], 'properties': {'body': {'type': 'string', 'description': 'The exact claim to anchor, byte-for-byte (max 16000 chars)'}, 'source': {'type': 'string', 'description': 'Who this claim is attributed to (self-declared, NOT verified by us)'}}}
Recent tool changes
Similar MCP servers
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Andreax
Offers pay-per-call AI services for inference, agent and workflow design, OCR and transcription, code generation and review, clas…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…