Skip to main content
Glama

KarmaDue

check_before_acting

Read-onlyIdempotent

Safety check before you install, run, pay, send, delete or connect. One answer: data.decision (allow, no_known_issues, unknown, warn, unverified_existence, require_human_approval, deny), data.enforce (proceed, proceed_with_care, require_human_approval, block), one headline, and reasons, scope (what was checked), evidence and gaps (what was not). The action matters: destructive, payment, send, credential and run-code actions always return require_human_approval (a deny still wins). allow needs a safety-grade check on file; a clean advisory read is no_known_issues. A package name its registry does not list returns unverified_existence (not a malware finding) with close real names. Alternatives (up to 3) are declared successors, fixed releases, or catalog picks that share the job; otherwise none. Compact by default (about 1 KB); pass verbose true for claims, warnings, the signed receipt and provenance. Example: {"target":"npm:express@4.21.2","action":"install","task":"web server"}.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
taskNoOptional: the job you need done (e.g. 'stream processing'). Used only to keep alternatives on topic.
actionNoAlias for intended_action (the REST name).
targetYesRequired. A string (a resource id or an exact locator) or an object with kd_resource_id, url, or github_repo. resource_id is not accepted.
verboseNoDefault false: a compact answer (about 1 KB). true returns the full record: claims, warnings, receipt, provenance.
environmentNoOptional, coarse only: os (linux, macos, windows), arch (x64, arm64), runtime with major.minor (node 22.11, python 3.12) and client (Cursor, Claude Code...). Anything else is ignored and nothing finer is stored. Adds data.setups_like_yours: worked in setups like yours, N of M, last seen DATE, from KarmaDue reference runs and reports.
include_demoNoWhen true, include records marked demo. Default false. Demo records are fixtures, not verification evidence.
intended_actionNoWhat you plan to do, in your own words (install, run the setup script, delete the prod database, pay $500, send an email, authorize OAuth...). The old values install_connector, call, pay, visit, clone and read still work. Default: install.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed8 schema fields changed
    • removedInput schema / properties / action / enum
      Removed value: -[
      -  "install_connector",
      -  "call",
      -  "pay",
      -  "visit",
      -  "clone",
      -  "read"
      -]
    • addedInput schema / properties / action / maxLength
      Added value: +200
    • addedInput schema / properties / environment
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "Optional, coarse only: os (linux, macos, windows), arch (x64, arm64), runtime with major.minor (node 22.11, python 3.12) and client (Cursor, Claude Code...). Anything else is ignored and nothing finer is stored. Adds data.setups_like_yours: worked in setups like yours, N of M, last seen DATE, from KarmaDue reference runs and reports.",
      +  "properties": {
      +    "arch": {
      +      "description": "x64 or arm64.",
      +      "type": "string"
      +    },
      +    "client": {
      +      "description": "MCP client or host, e.g. Cursor 1.7.",
      +      "type": "string"
      +    },
      +    "os": {
      +      "description": "linux, macos or windows (versions are dropped).",
      +      "type": "string"
      +    },
      +    "runtime": {
      +      "description": "Runtime and version, e.g. node 22.11 or python 3.12 (kept to major.minor).",
      +      "type": "string"
      +    }
      +  },
      +  "type": "object"
      +}
    • changedInput schema / properties / intended_action / description
      Previous value: -"What you plan to do with the target. The REST endpoint calls this action; both names work here."New value: +"What you plan to do, in your own words (install, run the setup script, delete the prod database, pay $500, send an email, authorize OAuth...). The old values install_connector, call, pay, visit, clone and read still work. Default: install."
    • removedInput schema / properties / intended_action / enum
      Removed value: -[
      -  "install_connector",
      -  "call",
      -  "pay",
      -  "visit",
      -  "clone",
      -  "read"
      -]
    • addedInput schema / properties / intended_action / maxLength
      Added value: +200
    • addedInput schema / properties / task
      Added value: +{
      +  "description": "Optional: the job you need done (e.g. 'stream processing'). Used only to keep alternatives on topic.",
      +  "maxLength": 300,
      +  "type": "string"
      +}
    • addedInput schema / properties / verbose
      Added value: +{
      +  "description": "Default false: a compact answer (about 1 KB). true returns the full record: claims, warnings, receipt, provenance.",
      +  "type": "boolean"
      +}
  2. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources