Nobulex MCP Compliance Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Nobulex MCP Compliance ServerSet a rule to forbid all admin actions."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Prior direction, kept rather than deleted. Nobulex is now the independent reliability registry for agent tools: nobulex-registry and nobulex.com. This repository is from the covenant and receipts era of the same name. Nothing below is retracted. It is simply not what is being built now.
@nobulex/mcp-server
Nobulex MCP compliance server — covenant rule checking, hash-chained audit logs, and integrity verification for any MCP-compatible agent.
Tools
Tool | Description |
| Set covenant rules using |
| Check if an action is allowed or blocked by current rules |
| Return the full hash-chained audit trail |
| Verify integrity of the audit chain (detect tampering) |
Related MCP server: gov-mcp
Rule Syntax
forbid delete_user Users cannot be deleted
permit read_data Safe to read
require approval Must get approval first
forbid admin.* All admin actions blocked
forbid * Lockdown modeRules are evaluated in order — first match wins. Unmatched actions are allowed by default.
Setup
Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"nobulex": {
"command": "npx",
"args": ["-y", "@nobulex/mcp-server"]
}
}
}Config file locations:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.json
Cursor
Add to your Cursor MCP settings:
{
"mcpServers": {
"nobulex": {
"command": "npx",
"args": ["-y", "@nobulex/mcp-server"]
}
}
}Any MCP Client
The server uses stdio transport. Run it with:
npx @nobulex/mcp-serverDevelopment
npm install
npm run build
npm testLicense
MIT
Available Tools
4 toolscheck_actionC
Check whether an action is allowed or blocked by the current covenant rules.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | The action name to check, e.g. 'delete_user' | |
| params | No | Optional parameters for the action |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the tool checks action permissions but lacks details on what 'covenant rules' entail, whether this is a read-only operation, if it has side effects, error handling, or performance characteristics. For a tool with zero annotation coverage, this is insufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, clear sentence that efficiently conveys the core purpose without unnecessary words. It's front-loaded with the main function and appropriately sized for the tool's complexity, making it easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of annotations and output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., a boolean, detailed rule match, error messages) or behavioral aspects like idempotency or rate limits. For a permission-checking tool with no structured context, more detail is needed to guide effective use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, so the input schema already documents both parameters ('action' and 'params') thoroughly. The description adds no additional meaning beyond what the schema provides, such as examples of 'covenant rules' or how parameters interact with them. Baseline 3 is appropriate when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Check whether an action is allowed or blocked by the current covenant rules.' It specifies the verb ('check') and the resource/scope ('action' against 'covenant rules'), making it easy to understand what the tool does. However, it doesn't explicitly differentiate from sibling tools like 'verify_log' or 'set_rules', which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention sibling tools like 'get_audit_log', 'set_rules', or 'verify_log', nor does it explain prerequisites, typical use cases, or exclusions. This leaves the agent without context for tool selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_audit_logB
Returns the full hash-chained audit trail of all compliance checks.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions 'full hash-chained audit trail', hinting at data structure and completeness, but fails to address critical aspects like whether this is a read-only operation, potential performance impacts, rate limits, or authentication requirements for a compliance-related tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that front-loads the core purpose ('Returns the full hash-chained audit trail') without any fluff. Every word earns its place, making it highly concise and well-structured for quick comprehension.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of audit trails and compliance checks, the description is insufficient. With no annotations and no output schema, it lacks details on return format (e.g., structure of the hash chain), data volume, or error handling. This leaves significant gaps for an agent to use the tool effectively in a compliance context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description appropriately adds no parameter details, avoiding redundancy. A baseline of 4 is applied since it doesn't need to compensate for any schema gaps.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('Returns') and resource ('full hash-chained audit trail of all compliance checks'), making it immediately understandable. However, it doesn't explicitly distinguish this tool from its siblings like 'verify_log', which might also deal with audit logs, leaving room for ambiguity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'check_action' or 'verify_log'. It lacks context about prerequisites, timing, or scenarios where this tool is preferred, leaving the agent to infer usage from the purpose alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
set_rulesB
Set covenant rules using permit/forbid/require syntax. Each rule is a string like 'forbid delete_user' or 'permit read_data safe to read'.
| Name | Required | Description | Default |
|---|---|---|---|
| rules | Yes | Array of rule strings, e.g. ['forbid delete_user', 'permit read_data'] |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions the syntax but fails to explain critical behaviors: whether this is a destructive overwrite or additive update, if it requires specific permissions, or what happens on success/failure. This leaves significant gaps for a tool that likely modifies system state.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is highly concise with two sentences that directly explain the tool's function and syntax. Every word contributes to understanding, with no redundant or vague phrasing, making it efficiently front-loaded and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of annotations and output schema, the description is incomplete for a tool that sets rules. It omits essential context: expected outcomes, error conditions, side effects, and how it interacts with sibling tools. For a mutation tool with no structured safety hints, this leaves the agent under-informed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents the 'rules' parameter as an array of strings. The description adds minimal value by providing example syntax ('forbid delete_user'), but does not elaborate on semantic rules, validation, or error handling beyond what the schema implies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Set covenant rules') and specifies the syntax format ('permit/forbid/require syntax'), making the purpose specific and actionable. It distinguishes from sibling tools like 'check_action' or 'get_audit_log' by focusing on rule configuration rather than verification or logging.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives like 'check_action' for verifying rules or 'verify_log' for audit purposes. The description lacks context about prerequisites, such as whether rules are applied immediately or require validation, leaving usage unclear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
verify_logB
Independently verify the integrity of the hash-chained audit log. Detects any tampering.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the tool 'verifies integrity' and 'detects tampering,' which implies a read-only, diagnostic operation, but doesn't clarify aspects like performance impact, error handling, or what happens if tampering is found. For a tool with zero annotation coverage, this leaves significant gaps in understanding its behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two concise sentences with zero waste: 'Independently verify the integrity of the hash-chained audit log. Detects any tampering.' It is front-loaded with the core purpose and efficiently adds the outcome. Every sentence earns its place by providing essential information without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (verification of a hash-chained log), lack of annotations, and no output schema, the description is minimally adequate. It states what the tool does but doesn't cover behavioral details like output format, error cases, or side effects. For a diagnostic tool with no structured support, it meets the bare minimum but leaves gaps in completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has 0 parameters, and schema description coverage is 100%, so there are no parameters to document. The description doesn't need to add parameter semantics, but it appropriately avoids mentioning any. A baseline of 4 is applied since no parameters exist, and the description doesn't mislead about inputs.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Independently verify the integrity of the hash-chained audit log. Detects any tampering.' It specifies the verb ('verify'), resource ('hash-chained audit log'), and outcome ('detects any tampering'). However, it doesn't explicitly differentiate from sibling tools like 'get_audit_log' or 'check_action', which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention sibling tools like 'check_action' or 'get_audit_log', nor does it specify prerequisites, timing, or exclusions. The agent must infer usage from the purpose alone, which is insufficient for clear decision-making.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v1.0.0- First observed
check_action - First observed
get_audit_log - First observed
set_rules - First observed
verify_log
TDQS
Each tool has a clearly distinct purpose: check_action evaluates rules, get_audit_log retrieves logs, set_rules configures rules, and verify_log validates log integrity. There is no overlap in functionality, making tool selection straightforward for an agent.
All tool names follow a consistent verb_noun pattern (check_action, get_audit_log, set_rules, verify_log) with clear, descriptive verbs. There are no deviations in naming style, ensuring predictability across the toolset.
With 4 tools, the server is well-scoped for compliance management, covering rule checking, configuration, log retrieval, and integrity verification. Each tool earns its place without redundancy or bloat, fitting typical MCP server ranges.
The toolset provides strong coverage for core compliance workflows: rule management, enforcement, and audit logging. A minor gap exists in lacking tools for rule listing or deletion, but agents can work around this using existing tools like set_rules and get_audit_log.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Tamper-evident proof creation and verification for AI agents via MCP, A2A, and REST.
Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...
- kanonikOAuthai.kanonik
Governance runtime for compliance: verified, human-approved writes to a tamper-evident record.
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
Related MCP Servers
- AlicenseAqualityAmaintenanceProof-of-behavior enforcement for AI agents. Declare behavioral constraints, enforce at runtime, produce SHA-256 hash-chained audit trails. Supports covenants (permit/forbid/require), real-time verification, and cross-agent trust handshakes.439MIT
- AlicenseNot gradedqualityCmaintenanceAn MCP server that enforces runtime governance on AI agent actions — file access, command execution, delegation chains, and permission escalation.MIT
- AlicenseNot gradedqualityCmaintenanceMCP server providing immutable audit logging, policy enforcement, and compliance reporting for AI agent workflows, enabling regulatory compliance and chain integrity verification.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server that evaluates agent actions against a Policy State Machine, emits a tamper-evident audit trail, and dispatches approved transitions to internal or federated handlers.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/arian-gogani/nobulex-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server