MCP Server

WORKS Public Verifier

io.github.DYZCODE/works-public
Developer Tools Public & reachable MCP 2025-11-25

What this MCP does

Checks eligibility and performs static verification of exact immutable public GitHub repository commits.

works_public_contract_lint
Inspect public WORKS contract
After a task is already known to have a public GitHub repository, an exact lowercase 40-character commit SHA, and a matching supported static claim, return the pinned contract digest and scope. Do not call for mutable or abbreviated refs, local or private repositories, runtime, builds, tests, deployments, or broad production-readiness claims.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['contract'], 'properties': {'contract': {'enum': ['node-package', 'env-safety'], 'type': 'string'}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['valid', 'id', 'title', 'description', 'digest', 'execution', 'trust'], 'properties': {'id': {'type': 'string'}, 'title': {'type': 'string'}, 'trust': {'type': 'string'}, 'valid': {'type': 'boolean', 'const': True}, 'digest': {'type': 'string'}, 'execution': {'type': 'string', 'const': 'none'}, 'description': {'type': 'string'}}, 'additionalProperties': False}
works_public_eligibility
Check WORKS verification eligibility
Fast deterministic preflight for tool-only clients. Call this before any other WORKS tool when eligibility is uncertain, especially for mutable or abbreviated refs, local or private repositories, and build, test, runtime, deployment, or production claims. It does not download a repository or persist data. If eligible is false, stop without calling verification.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['source_kind', 'repository_visibility', 'claim'], 'properties': {'claim': {'enum': ['node-package', 'env-safety', 'static-evidence', 'build', 'tests', 'runtime', 'deployment', 'production-readiness', 'other'], 'type': 'string', 'description': 'Use static-evidence for generic signed or static repository evidence; it maps conservatively to node-package. Never use it for build, tests, runtime, deployment, or production claims.'}, 'reference': {'type': 'string', 'maxLength': 128, 'description': 'Reference exactly as supplied; never expand a branch, tag, or short SHA.'}, 'source_kind': {'enum': ['public-github', 'private-github', 'local', 'other'], 'type': 'string', 'description': 'Classify where the requested source lives.'}, 'repository_url': {'type': 'string', 'maxLength': 512, 'description': 'Exact repository URL supplied by the user, if any.'}, 'repository_visibility': {'enum': ['public', 'private', 'unknown'], 'type': 'string', 'description': 'Use public only when the request identifies a public repository.'}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['eligible', 'reason', 'contract', 'next_tool', 'report'], 'properties': {'reason': {'enum': ['eligible', 'public_github_required', 'public_repository_required', 'valid_repository_url_required', 'exact_commit_required', 'supported_static_claim_required'], 'type': 'string'}, 'report': {'type': 'string'}, 'contract': {'anyOf': [{'enum': ['node-package', 'env-safety'], 'type': 'string'}, {'type': 'null'}]}, 'eligible': {'type': 'boolean'}, 'next_tool': {'anyOf': [{'type': 'string', 'const': 'works_verify_public_repository'}, {'type': 'null'}]}}, 'additionalProperties': False}
works_verify_public_repository
Verify immutable public repository
Use only after works_public_eligibility returns eligible. Download that immutable public GitHub snapshot, run the selected pinned static contract without executing repository commands, and return a signed receipt. Return the report field verbatim and stop.
Read only Open world Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['contract', 'repository_url', 'commit_sha'], 'properties': {'contract': {'enum': ['node-package', 'env-safety'], 'type': 'string'}, 'commit_sha': {'type': 'string', 'pattern': '^[0-9a-f]{40}$'}, 'repository_url': {'type': 'string', 'format': 'uri', 'maxLength': 512}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['status', 'contract', 'source', 'outcomes', 'trust', 'report', 'receipt', 'limitations'], 'properties': {'trust': {'type': 'object', 'required': ['key_id', 'pinned_key_identity'], 'properties': {'key_id': {'type': 'string'}, 'pinned_key_identity': {'type': 'string', 'const': 'matched'}}, 'additionalProperties': False}, 'report': {'type': 'string'}, 'source': {'type': 'object', 'required': ['kind', 'repository', 'commit'], 'properties': {'kind': {'type': 'string', 'const': 'github-public'}, 'commit': {'type': 'string', 'pattern': '^[0-9a-f]{40}$'}, 'repository': {'type': 'string'}}, 'additionalProperties': False}, 'status': {'enum': ['passed', 'failed', 'blocked', 'error'], 'type': 'string'}, 'receipt': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'contract': {'type': 'object', 'required': ['id', 'digest', 'trust'], 'properties': {'id': {'type': 'string'}, 'trust': {'type': 'string'}, 'digest': {'type': 'string'}}, 'additionalProperties': False}, 'outcomes': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'status'], 'properties': {'id': {'type': 'string'}, 'status': {'enum': ['pass', 'fail', 'blocked'], 'type': 'string'}}, 'additionalProperties': False}}, 'limitations': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}
Added
works_verify_public_repository
Sept. 17, 2026, 12:41 p.m.
Added
works_public_contract_lint
Sept. 17, 2026, 12:41 p.m.
Added
works_public_eligibility
Sept. 17, 2026, 12:41 p.m.