Skip to main content
Glama
ScopeBlind

verify-mcp

by ScopeBlind
README.md
# @scopeblind/verify-mcp

MCP server for offline verification of ScopeBlind and Veritas Acta artifacts.

It is deliberately narrow:
- verify a single signed receipt or artifact
- verify an audit bundle offline
- explain a signed artifact in normalized form
- run a packaged self-test so clients can prove the verifier works

This is the registry-worthy MCP surface for the verification lane. It is not a gateway, not a builder, and not a hosted verification service.

## Install

```bash
npm install -g @scopeblind/verify-mcp
```

## Claude Desktop / MCP config

```json
{
  "mcpServers": {
    "scopeblind-verify": {
      "command": "npx",
      "args": ["-y", "@scopeblind/verify-mcp"]
    }
  }
}
```

## Tools

### `self_test`
Runs packaged sample verification.

Returns:
- sample receipt valid / invalid
- sample bundle valid / invalid
- total receipts in the sample bundle

### `verify_receipt`
Inputs:
- `artifact_json` or `path`
- optional `public_key_hex`

Returns:
- valid / invalid
- type
- format
- issuer
- kid
- canonical hash

### `verify_bundle`
Inputs:
- `bundle_json` or `path`

Returns:
- valid / invalid
- total receipts
- passed
- failed

### `explain_artifact`
Inputs:
- `artifact_json` or `path`

Returns a normalized summary of:
- type
- format
- issuer
- kid
- issued_at / timestamp
- payload keys

## Notes

- No ScopeBlind servers are contacted.
- This server verifies local JSON artifacts only.
- `protect-mcp` remains the local policy gateway.
- `@scopeblind/passport` remains the local pack builder.
- `@scopeblind/red-team` remains the local benchmark runner.

## License

Apache 2.0 (see LICENSE).

TDQS

A4.6/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: explain_artifact inspects without verifying, self_test runs a built-in test, verify_bundle checks multiple receipts, and verify_receipt checks a single artifact. No functional overlap.

Naming Consistency4/5

Three tools follow a clear verb_noun pattern (explain_artifact, verify_bundle, verify_receipt), while self_test deviates as a noun-based name. This minor inconsistency is acceptable given the tool's special role.

Tool Count5/5

With only 4 tools, the server is well-scoped for its verification purpose. Each tool serves a necessary function without redundancy, making the set efficient and focused.

Completeness4/5

The tool set covers core verification workflows: pre-verification inspection, self-test, single artifact verification, and bundle verification. A minor gap is the lack of a tool to verify multiple individual receipts without forming a bundle, but this is covered by verify_bundle assuming bundles are the primary use case.

Maintenance

ActivityStale
ResponsivenessNo issues