Nobulex MCP Compliance Server
> **Prior direction, kept rather than deleted.** Nobulex is now the independent reliability registry for agent tools: [nobulex-registry](https://github.com/arian-gogani/nobulex-registry) and [nobulex.com](https://nobulex.com). This repository is from the covenant and receipts era of the same name. Nothing below is retracted. It is simply not what is being built now.
---
# @nobulex/mcp-server
Nobulex MCP compliance server — covenant rule checking, hash-chained audit logs, and integrity verification for any MCP-compatible agent.
## Tools
| Tool | Description |
|------|-------------|
| `set_rules` | Set covenant rules using `permit`/`forbid`/`require` syntax |
| `check_action` | Check if an action is allowed or blocked by current rules |
| `get_audit_log` | Return the full hash-chained audit trail |
| `verify_log` | Verify integrity of the audit chain (detect tampering) |
## Rule Syntax
```
forbid delete_user Users cannot be deleted
permit read_data Safe to read
require approval Must get approval first
forbid admin.* All admin actions blocked
forbid * Lockdown mode
```
Rules are evaluated in order — first match wins. Unmatched actions are allowed by default.
## Setup
### Claude Desktop
Add to your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"nobulex": {
"command": "npx",
"args": ["-y", "@nobulex/mcp-server"]
}
}
}
```
Config file locations:
- macOS: `~/Library/Application Support/Claude/claude_desktop_config.json`
- Windows: `%APPDATA%\Claude\claude_desktop_config.json`
### Cursor
Add to your Cursor MCP settings:
```json
{
"mcpServers": {
"nobulex": {
"command": "npx",
"args": ["-y", "@nobulex/mcp-server"]
}
}
}
```
### Any MCP Client
The server uses stdio transport. Run it with:
```bash
npx @nobulex/mcp-server
```
## Development
```bash
npm install
npm run build
npm test
```
## License
MIT
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: check_action evaluates rules, get_audit_log retrieves logs, set_rules configures rules, and verify_log validates log integrity. There is no overlap in functionality, making tool selection straightforward for an agent.
All tool names follow a consistent verb_noun pattern (check_action, get_audit_log, set_rules, verify_log) with clear, descriptive verbs. There are no deviations in naming style, ensuring predictability across the toolset.
With 4 tools, the server is well-scoped for compliance management, covering rule checking, configuration, log retrieval, and integrity verification. Each tool earns its place without redundancy or bloat, fitting typical MCP server ranges.
The toolset provides strong coverage for core compliance workflows: rule management, enforcement, and audit logging. A minor gap exists in lacking tools for rule listing or deletion, but agents can work around this using existing tools like set_rules and get_audit_log.