Turnproof
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Turnproofstart a household diagnosis for a leaking dishwasher"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Turnproof
Conversation is probabilistic. Meaning does not have to be.
Turnproof is a semantic firewall and adversarial laboratory for Alexa+ add-ons. It compiles a conversational contract into revisioned state rules, protects effects from stale or ambiguous state, and generates multi-turn attacks against the same contract.
It also expresses Armada Ventures' operating principle: LLMs should augment judgment and help design systems, while deterministic contracts and reproducible evidence remain the safe harbor for correctness and authority.
The proof of concept includes two structurally different contracts:
a household diagnosis that retains evidence and accepts corrections;
a household handoff with a recipient, task, time window, and precondition.
Both use the same reducer, revision ledger, semantic digest, proposal boundary, idempotent receipts, and generated laboratory.
Run
Requires Python 3.11+.
python -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt
uvicorn server.app:app --host 127.0.0.1 --port 8000Open http://127.0.0.1:8000. The MCP endpoint is
http://127.0.0.1:8000/mcp and implements protocol version 2025-11-25 over
Streamable HTTP.
Related MCP server: Aura+
Observatory walkthrough
Start the diagnosis.
Record “no,” then correct it to “yes.” The active meaning changes while both revisions remain visible.
Bind an action to the current revision and digest.
Change another piece of evidence.
Try the stale action. The runtime returns
STATE_CHANGEDwithout producing the simulated effect.Switch to the handoff contract to demonstrate reuse.
Run all attacks. The browser displays the generated results from the live
/api/turnproof/labendpoint.
Append ?video=1 to run the paced, captioned submission walkthrough. The
reproducible capture utility is scripts/record_demo.py; its optional packages
are pinned in requirements-video.txt, and the narration is retained in
scripts/demo_narration.txt. Internal voice renders use the bounded,
receipt-producing process in docs/NARRATION_PROTOCOL.md.
Verify
python -m unittest discover -v
python scripts/run_lab.py
python scripts/verify.pyThe current suite contains 26 direct tests and 16 generated adversarial checks
across the two contracts. The six-gate verifier retains a JSON receipt in
evidence/latest.json, tied to a SHA-256 digest of the tested source.
Generated checks currently cover:
partial input and minimum clarification;
explicit unknown values;
correction supersession;
mutation and effect retry idempotency;
stale action rejection;
concurrent stale-write rejection;
semantic convergence when independent facts arrive in different orders.
MCP tools
Turnproof tools:
start_turnproof_diagnosisstart_turnproof_handoffrevise_turnproof_factreview_turnproof_conversationpropose_turnproof_actioncommit_turnproof_action
The original diagnostic tools remain during migration so the existing Bayesian reference engine and its safety tests continue to run.
Trust boundary
Alexa+ owns speech recognition, conversational routing, tool selection, and its verbal response. Turnproof begins where that probabilistic interpretation becomes a proposed structured change.
The model may propose a tool call. Deterministic code owns validation, current meaning, correction history, optimistic concurrency, proposal invalidation, idempotency, and the test verdict. The browser is a clearly labelled custom simulation; this repository does not claim a completed production Alexa+ device session.
License
Apache-2.0. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
Formally-verified injection/exfiltration detector for AI agents (MCP-02).
Compliance frameworks (SOC 2, ISO 27001, CMMC, NIST, more) delivered to AI agents as MCP tools.
Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables Alexa+ agents to maintain auditable operational continuity across shifts by turning speech into verifiable state, persisting unresolved work, refusing unverified actions, and requiring human approval before executing and confirming high-risk tasks.MIT
- AlicenseNot gradedqualityBmaintenanceAn MCP server that enables Alexa+ to autonomously orchestrate multi-step household tasks by decomposing goals into parallel tool calls — cross-session memory and dietary/allergy auditing, culinary planning with wine pairings, Amazon Fresh cart assembly with human-in-the-loop purchase approval, smart-home ambiance and climate control, and calendar scheduling. It pairs AWS Bedrock multi-agent reasoning with Streamable HTTP transport and interactive generative UI cards, carousels, and live IoT sliders.MIT
- AlicenseNot gradedqualityBmaintenanceEnables governed execution of Alexa+ MCP workflows where agents can propose actions but consequential side effects require separate human approval, producing verifiable execution receipts.MIT
- AlicenseNot gradedqualityBmaintenanceEnables Alexa+ assistants to run multi-step personal-ops tasks and produce machine-checkable receipts with per-step evidence, so actions are only claimed done when actually verified.MIT