noor-governance-mcp
Server Details
The first covenant-governed trust protocol for AI agents. Screen → Attest → Certify → Verify → Reputation → Revoke. Open-source SDK. MIT license.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 4 tools
Each tool targets a distinct governance function: budget enforcement, identity registration, legal screening, and approval requests. Boundaries are mostly clear, though lawful_check and request_approval could overlap in risk-handling contexts.
Three tools use a noun_verb pattern (budget_enforce, identity_register, lawful_check) while request_approval uses verb_noun. All are snake_case, but the verb placement is inconsistent.
Four tools is a well-scoped set for a minimal governance surface, with each tool covering a distinct concern. No obvious bloat or missing tool count.
The surface lacks key lifecycle operations: no way to set budget limits, check approval status, or update/delete identities. These gaps will hinder agent workflows that require feedback or configuration.
Available Tools
4 toolsbudget_enforceCInspect
Check if an agent spending amount exceeds its monthly limit.
| Name | Required | Description | Default |
|---|---|---|---|
| amount | Yes | ||
| agent_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden. The name 'budget_enforce' implies enforcement (blocking/denying) while the description only says 'Check', leaving it unclear whether this is a pure read or a gate that fails a request, and there is no mention of auth needs, side effects, or what a failing result means.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, front-loaded sentence with no filler. It is efficient, though its brevity is partly under-specification rather than tight editing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no annotations, no output schema, and no parameter descriptions, an agent cannot tell whether an over-limit result is a boolean, an error, or a side effect, nor what the preconditions are. More detail is needed for a tool whose name implies enforcement semantics.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% for both parameters. The description hints that 'amount' is the spending amount being tested and that the limit is monthly, but it never defines the units/currency, whether 'amount' is a single transaction or cumulative spend, or what 'agent_id' refers to.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Check') and resource (an agent's spending vs its monthly limit), so the intent is unambiguous. It does not explicitly distinguish itself from siblings like request_approval or lawful_check, but the budget scope is clear enough to route correctly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description says what is checked but never when to call it — e.g. before a spend, as a pre-flight gate, or on a schedule. No alternatives or preconditions (existing budget, registered agent) are mentioned, leaving the agent to infer usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
identity_registerCInspect
Register or retrieve an agent persistent identity.
| Name | Required | Description | Default |
|---|---|---|---|
| role | No | ||
| agent_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden and falls short. It does not disclose whether registration overwrites an existing identity, whether the call is idempotent, what permissions are required, or what happens if the agent_id already exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The single short sentence is front-loaded and free of padding, which is structurally good. But it reads as under-specification rather than true conciseness, since so much essential information is absent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations, no output schema, and 0% parameter description coverage, the definition is not complete enough for an agent to invoke it confidently. Missing are the distinction between the two verbs, the role parameter's meaning, and any return or error behavior.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must explain both parameters. It implies agent_id from 'agent identity' but provides no guidance on the 'role' parameter at all, leaving half the inputs undocumented. The description does not compensate for the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a resource (agent persistent identity) and two possible verbs (register/retrieve), so the general domain is clear. However, it does not say which operation actually occurs or when, and the dual 'register or retrieve' phrasing leaves the core behavior ambiguous. It also draws no distinction from siblings like budget_enforce or lawful_check.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no statement of when to call this tool, what prerequisites exist, or how it relates to the sibling tools. An agent must infer everything about timing and context from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
lawful_checkBInspect
Screen a task for unlawful-adjacent elements.
Returns tier (CLEAR/FLAGGED/BLOCKED), categories, reasoning, and disclaimer.
| Name | Required | Description | Default |
|---|---|---|---|
| agent_id | Yes | ||
| description | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are supplied, so the description carries the full burden. It does usefully disclose the response shape (tier CLEAR/FLAGGED/BLOCKED, categories, reasoning, disclaimer), which is valuable given there is no output schema, but it says nothing about whether a FLAGGED/BLOCKED result actually halts execution, permission requirements, or side effects. Partial disclosure only.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the action and scope, followed by the return shape. No filler, no repetition of the tool name or title.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The output preview compensates for the missing output schema, but with no annotations and no schema descriptions for any parameter, the definition leaves the agent guessing about the required agent_id and any permission or blocking behavior. Adequate but with clear gaps for a 2-required-param tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Two required parameters (description, agent_id) with 0% schema description coverage, and the description explains neither. 'A task' loosely maps to the description parameter, but agent_id is completely unexplained and there is no hint about expected format, length, or how agent_id affects the check.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb and resource ('Screen a task') and names the scope ('unlawful-adjacent elements'), so an agent can immediately tell this is a legality/policy screening tool. It does not need to be distinguished from its siblings (budget_enforce, identity_register, request_approval) because the domains are obviously disjoint, but it also does not explicitly do so.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied ('screen a task' before acting), but there is no explicit statement of when to call it versus alternatives such as request_approval, nor any exclusion or ordering guidance. An agent must infer the call site from the verb alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
request_approvalBInspect
Request human approval for a risky action.
Returns an approval_id. The action stays pending until a human approves or denies.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | ||
| reason | Yes | ||
| agent_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full disclosure burden, and it does add real value: it explains the asynchronous pattern (returns an approval_id, action stays pending until a human decides). It omits what happens on denial, any timeout/expiry semantics, and how to poll or resume the pending action, so coverage is partial.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences with the core behavior front-loaded and zero filler. Every clause ('risky action', 'returns an approval_id', 'stays pending') carries information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For an async approval tool with no output schema and no annotation coverage, the description covers the essential contract (submit request, receive approval_id, pending state) but leaves the agent without the post-request path — how to check approval status, what denial yields, or whether the action must be re-issued after approval.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
All three parameters (action, reason, agent_id) have 0% schema description coverage, so the description is the only place meaning could be added — yet it says nothing about any of them. The field names are largely self-explanatory, which prevents a 1, but no format, constraint, or expected content is supplied.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Request human approval') plus the scope qualifier 'for a risky action', so the purpose is immediately clear. It does not explicitly differentiate itself from the siblings (budget_enforce, identity_register, lawful_check), but those are obviously distinct domains, so the gap is minor.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'For a risky action' implies the trigger condition, but there is no explicit guidance on when this is required versus when an action can proceed, nor any stated prerequisite such as what constitutes 'risky'. Usage is inferable but not spelled out.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
- First observed
budget_enforce - First observed
identity_register - First observed
lawful_check - First observed
request_approval
Publisher details
- Operator
- Noor Systems
- Operator website
- https://github.com/highriseliving777/noor-governance-protocol
- Vendor relationship
- First-party
- Documentation
- https://github.com/highriseliving777/noor-mcp-server
- Restrictions
- None. Free tier available. No authentication required for basic tools.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables brand visibility monitoring across major AI platforms like ChatGPT, Claude, Gemini, and Perplexity. It allows users to track visibility scores, analyze competitor data, and receive actionable insights to improve AI-generated brand recommendations.1622 npm1MIT
- AlicenseCqualityAmaintenanceCompetitor Monitor AI - MCP server providing AI-powered tools and automation by MEOK AI Labs119 npmMIT
- AlicenseAqualityCmaintenanceRevnuvo Company Intelligence tells AI agents what changed at a company, with evidence. It observes company websites, technologies, and DNS over time and returns timestamped, confidence-aware changes, signals, and monitoring.9MIT

industrylens-mcpofficial
AlicenseNot gradedqualityBmaintenanceBrowse IndustryLens's published competitive-intelligence reports and head-to-head competitor comparisons from any AI agent — real, source-backed data.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.