Skip to main content
Glama
AhmedKishki

white-box-synthesis

by AhmedKishki

white-box-synthesis

An MCP server that verifies a synthesised passage preserves the human-ness of its source passages.

What it does and does not do

The agent does the synthesis. The server checks the work. It holds no model, no API key and no semantic judgment.

The property under verification is human-ness, not meaning. Meaning is yours to proof. What the server certifies is that every character of the output is either verbatim human text from a source passage, or the product of a declared, bounded transformation of one.

That framing decides which operations need checking:

Operation

What it does to the text

v0 status

COPY

reproduces human text

verified exactly

DELETE

removes human text

legal by construction, logged for your audit

ORDER

moves human text

legal by construction, logged

INFLECT

alters characters

logged, unverified

NORMALISE

alters characters

logged, unverified

Removing and moving cannot introduce machine text, so they are free. INFLECT and NORMALISE are the only places machine text can enter, so they are the only operations that will ever need real verification.

This diverges deliberately from the draft-writing skill, whose DELETE removes repetition only when subject, claim, scope, modality and qualification are identical, and whose ORDER requires an approved original establishing the relation. Both conditions preserve meaning, which is not this server's job. The skill needs updating to match. The two live in separate repositories and can drift, so treat the skill as the definition of the operations and this README as the record of where the verifier knowingly departs from it.

Related MCP server: phionyx-pipeline-mcp

The two checks that carry v0

  1. COPY resolution. The quoted span must exist in the named passage at the stated occurrence, exactly.

  2. Reconstruction. The text of all content-producing operations, joined in list order, must match the submitted output. Whitespace is ignored, because spacing is not content. Every other character difference fails.

Together these mean an invented word cannot pass. Punctuation does not travel for free either: a comma becoming a full stop is a NORMALISE operation and must be declared.

Report

Each operation returns verified, unverified or failed. Citation labels on passages flow through to the report for footnoting. One failure rejects the whole derivation, because the report certifies a derivation rather than a set of parts.

Provenance declaration

Every derivation returns the compact declaration from the provenance contract, derived mechanically:

**Provenance:** Mixed · Human wording: 100% · Method: white-box synthesis · Basis: A4, user-21

Basis is deduplicated in first-use order with the src: prefix stripped. Provenance is Human for a single unaltered span, Mixed for several, Unverified when anything failed.

The honest consequence of v0. The contract allows Human wording: 100% only when every span passes the reconstruction test, which requires a sequence of permitted operations. v0 logs INFLECT and NORMALISE without checking that they are legal. So any derivation using either declares Human wording: Unverified and sets blocks_selection. Only COPY, DELETE and ORDER reach 100%.

That is the roadmap with teeth: until the NORMALISE whitelist and INFLECT morphology exist, no passage using them can be declared clean.

Typed gaps

A gap is a successful outcome. It must carry one of the six types from the skill (Missing user wording, Missing evidence, Unsupported connection, Source-context ambiguity, Arc inconsistency, Constraint conflict) and all six fields: passage_id, argument_id, missing_requirement, authoritative_owner, question, resolution_paths. Untyped gaps are rejected.

Install

This is a working MCP server: one tool, verify_synthesis, and one prompt, white_box_synthesis_process. It speaks stdio, so the client launches it as a subprocess. Nothing is hosted.

Installation goes straight from this repository. There is no clone step and no PyPI release. uv does the work:

uvx --from git+https://github.com/AhmedKishki/mcp-white-box-synthesis white-box-synthesis

Note the two names differ and both are needed. --from takes the repository (mcp-white-box-synthesis); the trailing argument is the console script (white-box-synthesis). Repeating the repo name there fails with an executable not found.

It will sit silently waiting for JSON-RPC on stdin. That is correct. Ctrl-C out.

Pin a tag for reproducibility:

uvx --from git+https://github.com/AhmedKishki/mcp-white-box-synthesis@v0.1.0 white-box-synthesis

Claude Code

stdio is the default transport, so no transport flag is needed. Options go before the name, and -- separates them from the launch command:

claude mcp add white-box-synthesis \
  -- uvx --from git+https://github.com/AhmedKishki/mcp-white-box-synthesis white-box-synthesis

Scope defaults to local. --scope project writes a committable .mcp.json, --scope user makes it available across projects. Confirm with /mcp.

Cline, Claude Desktop, Kimi Code CLI, anything JSON-configured

{
  "mcpServers": {
    "white-box-synthesis": {
      "command": "uvx",
      "args": [
        "--from",
        "git+https://github.com/AhmedKishki/mcp-white-box-synthesis",
        "white-box-synthesis"
      ]
    }
  }
}

Releasing

Bump version in pyproject.toml and the MCPServer(...) call in server.py, then tag:

git tag v0.1.1 && git push --tags

Anyone pinning a tag gets that build. Anyone on the bare URL gets main.

Local development

git clone https://github.com/AhmedKishki/mcp-white-box-synthesis
cd mcp-white-box-synthesis
uvx --from . white-box-synthesis

Verify it handshakes

printf '%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"probe","version":"1"}}}' \
'{"jsonrpc":"2.0","method":"notifications/initialized"}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list"}' \
| uvx --from . white-box-synthesis

Four things that will bite you

  • Use absolute paths. The client spawns the server from its own working directory, not yours.

  • uvx must be on the PATH the client sees. GUI apps often do not inherit your shell PATH. If the server fails to start, replace uvx with the full path from which uvx.

  • Never print to stdout. On stdio transport, stdout is the protocol channel. Any stray print() corrupts the stream. Log to stderr.

  • uvx caches the build. During local development your edits will not appear until you run uv cache clean, or install editable with uv tool install --editable .. The same cache means an unpinned git install will not pick up new commits immediately either.

Tests

python3 tests/test_verify.py

No dependencies. verify.py is deliberately free of MCP, network and model imports.

Backlog

Ordered by dependency weight. Testing decides what actually comes forward.

  1. NORMALISE whitelist. A literal dictionary of substitution pairs, no dependencies. Seed it from what actually appears in testing. Must be lexicalised, not regex: an -ize to -ise rule turns size into sise.

  2. INFLECT morphology. Needs spaCy. Covers tense, number, case, article. The pronoun sub-case is separate: count agreement-filtered antecedent candidates in a local window.

  3. Connectors. The skill requires that every word, including a function word inserted at a join, occurs in an approved fragment. So connectors are drawn from fragments rather than invented, which makes them a constrained COPY and mechanically checkable.

Not yet built, and they change the input schema

  • Argument structure. The skill's Record is one row per argument against a passage plan with a passage claim and ordered argument IDs. The flat operations list cannot produce that table.

  • Protected regions. Direct quotations, code, URLs, titles, citation data and proper names must stay exact, and INFLECT and NORMALISE apply only to unquoted output. Mechanical once regions are marked. Nothing implements it.

  • Locators. The skill addresses fragments by code plus paragraph N or lines N-M, with exact quotations only to resolve ambiguity. This server uses occurrence-numbered quotations instead.

Dropped from the original design once the human-ness framing settled: the DELETE duplicate-overlap check, the DELETE irrelevance embedding check, and the ORDER marker lexicon. All three were checking meaning, which is not this server's job.

Known gap

Because whitespace is ignored, a run-together join like theunion passes. That is a typo rather than a human-ness violation, and it belongs to your proofing pass.

Available Tools

1 tool
verify_synthesisA

Verify a white-box-synthesis derivation, or record a declared gap.

Checks that every character of the output traces to a declared operation on a declared source span. Does not check meaning: that is the human's job.

Args: passages: Source passages. Each needs id and text, and should carry a source citation label, which flows through to the report. output_context: What the output passage is meant to support. candidate: {"output": str, "operations": [...]}. Each operation needs type (COPY, INFLECT, NORMALISE, DELETE or ORDER), passage_id, text quoted verbatim from that passage, and occurrence (1-indexed). INFLECT and NORMALISE also need output_text, and INFLECT needs axis (tense, number, case, article or pronoun). DELETE and ORDER accept an optional note. gap: A typed gap when no legal derivation exists. Needs type (one of the six gap types), passage_id, argument_id, missing_requirement, authoritative_owner, question and resolution_paths. Submit exactly one of candidate or gap.

Returns: A report with an overall status of accepted, rejected or gap, a per-operation verdict of verified, unverified or failed, the reconstruction result, counts, and a compact provenance declaration. Operations marked unverified are recorded claims rather than checked facts, and any derivation containing one declares Human wording: Unverified.

ParametersJSON Schema
NameRequiredDescriptionDefault
gapNo
passagesYes
candidateNo
output_contextYes

Output Schema

ParametersJSON Schema
NameRequiredDescription

No output parameters

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden of behavioral disclosure. It explicitly states that the tool does not check meaning, that operations marked 'unverified' are recorded claims rather than checked facts, and that any derivation containing one declares 'Human wording: Unverified.' It also outlines the report statuses (accepted, rejected, gap). This provides substantial behavioral context, though it does not mention permissions, side effects, or whether the tool is read-only.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-organized: a one-line summary followed by a structured Args section and a Returns section. It is longer than average but justified by the complexity of the parameters and the need to compensate for the sparse schema. Each sentence earns its place, and the most important information (purpose and scope) is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity, the absence of annotations, and the 0% schema coverage, the description is remarkably complete. It covers all parameter requirements, the return format (report with statuses, per-operation verdicts, reconstruction result, counts, provenance declaration), and behavioral caveats. While it could benefit from concrete examples or edge-case handling, nothing critical is missing for an agent to invoke the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description is the sole source of parameter meaning. It thoroughly explains each parameter: passages need id, text, and a source label; output_context is described; candidate requires a structured object with operation types (COPY, INFLECT, NORMALISE, DELETE, ORDER) and their specific required fields; gap is defined with its six required fields. This adds comprehensive meaning far beyond the generic schema definitions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening line states a specific verb and resource: 'Verify a white-box-synthesis derivation, or record a declared gap.' It clearly distinguishes between two modes (verification vs. gap recording) and leaves no ambiguity about the tool's core function. Since there are no sibling tools to differentiate, the purpose is fully clear.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explains the two usage scenarios: verify a derivation when one exists, or record a gap when no legal derivation exists. It also implies the context of use (white-box synthesis) and clarifies that meaning checking is left to humans. However, it does not explicitly state when not to use the tool or provide exclusion criteria, though no alternatives exist to compare against.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev0.1.0
    • First observedverify_synthesis

TDQS

A4.4/5.0
Disambiguation5/5

With only a single tool, there is no possibility of confusing it with another. The purpose is clear and distinct.

Naming Consistency5/5

The single tool name follows a clear verb_noun pattern ('verify_synthesis'). Since there is only one tool, the naming convention is internally consistent.

Tool Count4/5

One tool is slightly below the typical 3-15 range, but it fits the server's narrow, single-purpose scope of verifying synthesis derivations. The tool is substantial and not redundant.

Completeness4/5

The tool covers the core verification workflow, including accepting passages, candidates, and gap declarations. It does not include auxiliary operations like retrieving past reports, but those are not clearly required for the stated purpose.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Enables verification of AI coding agent self-reports against git diff truth and a deterministic gate, producing pass/regenerate/reject directives to ensure claimed work matches actual changes.
    6
    AGPL 3.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables tracking and querying the provenance of AI-generated code, showing which sources influenced each line of code.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables per-claim citation verification for AI-generated text by fetching cited sources and judging whether they support the claim, with verdicts and evidence quotes.
    102
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AhmedKishki/mcp-white-box-synthesis'

If you have feedback or need assistance with the MCP directory API, please join our Discord server