MCP Server

Korext: AI Code Governance

io.github.Korext/governance
Developer Tools Security Public & reachable MCP 2025-11-25

What this MCP does

Checks code against governance policy packs, exposes security and regulatory directives, and generates verifiable signed proof bundles.

check_code
Check a code snippet against one or more policy packs. Returns violations with severity, governance context (CWE, MITRE, regulatory), and line numbers.
Input schema
{'type': 'object', 'required': ['code'], 'properties': {'code': {'type': 'string', 'description': 'The code snippet to check.'}, 'packId': {'oneOf': [{'type': 'string'}, {'type': 'array', 'items': {'type': 'string'}}], 'description': "Policy pack ID or array of IDs. Defaults to 'web'."}}}
generate_proof
Scan code against policy packs and generate a cryptographically signed proof bundle. Returns the bundle ID, decision (PASS/BLOCK), violation count, and verification URL.
Input schema
{'type': 'object', 'required': ['code'], 'properties': {'code': {'type': 'string', 'description': 'The code to scan.'}, 'packId': {'oneOf': [{'type': 'string'}, {'type': 'array', 'items': {'type': 'string'}}], 'description': "Policy pack ID(s). Defaults to 'web'."}, 'fileName': {'type': 'string', 'description': 'File name for context'}, 'language': {'type': 'string', 'description': 'Programming language (typescript, python, etc.)'}}}
get_directives
Get enriched policy directives and living standards for one or more policy packs. Returns rules with governance context (CWE, MITRE, regulatory references) for inference time enforcement.
Input schema
{'type': 'object', 'properties': {'packId': {'oneOf': [{'type': 'string'}, {'type': 'array', 'items': {'type': 'string'}}], 'description': "Policy pack ID or array of IDs (e.g. 'web', ['web', 'pci-dss-v1']). Defaults to 'web'."}}}
get_proof
Retrieve an existing proof bundle by ID. Returns the decision, violations, packs, and verification status.
Input schema
{'type': 'object', 'required': ['bundleId'], 'properties': {'bundleId': {'type': 'string', 'description': 'The proof bundle ID (kpb_...)'}}}
list_packs
List available policy packs with industry and region tags.
Input schema
{'type': 'object', 'properties': {'region': {'type': 'string', 'description': 'Filter by region (e.g. us, eu, uk, global)'}, 'industry': {'type': 'string', 'description': 'Filter by industry (e.g. finance, healthcare, defense, aerospace, energy, technology)'}}}
Added
get_proof
Sept. 17, 2026, 12:42 p.m.
Added
generate_proof
Sept. 17, 2026, 12:42 p.m.
Added
list_packs
Sept. 17, 2026, 12:42 p.m.
Added
check_code
Sept. 17, 2026, 12:42 p.m.
Added
get_directives
Sept. 17, 2026, 12:42 p.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…