scv-triage
The scv-triage server provides a trusted-local, read-only simulation for evaluating policy verdicts on server and fleet health in a non-production demo environment. It returns deterministic, bounded outputs from a pre-packaged SQLite database—never live infrastructure.
Tools
triage_server(hostname, at?): Returns a point-in-time policy verdict (e.g.,HEALTHY,CRITICAL,SERVER_OFFLINE,NO_DATA,INDETERMINATE) for a single host, including severity, findings, and non-executable, approval-required actions.fleet_health(at?): Returns a point-in-time health summary for the entire fleet.investigate_timeline(hostname, frm, to): Returns a timeline of bounded results over a half-open[frm, to)window; does not infer root causes or exact state-transition times.
Key Characteristics
Read-only and closed-world: All tools are idempotent, non-destructive, and operate solely on demo data. The server runs only under
SCV_RUNTIME_ENVIRONMENT=demowith profilesINCIDENTorCLEAR(switchable viaSCV_DEMO_PROFILE).Semantic validation: Raw evidence undergoes seven layers of validation before a verdict is produced. Rejected evidence yields an
INDETERMINATEoutcome with a bounded rejection class infindings.kind(e.g.,INVALID_REQUEST,OUT_OF_COVERAGE,REQUIRED_EVIDENCE_DEFECTIVE);NO_DATAindicates a valid empty result.Policy metadata:
severityis categorical policy metadata, not impact or confidence (e.g.,CRITICALmaps toHIGH, andINDETERMINATEseverityHIGHmeans no trustworthy verdict, not high incident impact).Non-executable actions: All actions require approval and are never executed by the server.
Simulation profiles:
INCIDENTandCLEARprofiles demonstrate different fleet states and point verdicts.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@scv-triagetriage server web-01"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Execution Boundaries for MCP
scv-triage-runtime is the Python package that powers this demo. It is a deterministic, trusted-local, non-production, non-live simulation whose three read-only MCP tools return bounded policy verdicts, never live infrastructure state.
Architecture
graph TB
DB[("Shared demo.sqlite3")]
subgraph boundary["Execution-Boundary MCP Server"]
direction TB
R1["MCP request"] --> RT["Runtime<br/>request validation"]
RT -->|"valid request"| PV["SQLite Provider"]
RT -->|"invalid request"| FC["Bounded Result<br/>INDETERMINATE"]
PV -.->|"read-only query"| DB
PV -->|"raw evidence"| EB["Semantic Evidence Boundary<br/>7 validation layers"]
PV -->|"provider failure"| FC
EB -->|"accepted"| NE["Immutable normalized evidence"]
EB -->|"rejected"| FC
NE --> PL["Policy<br/>deterministic verdict"]
PL --> OUT["Bounded Result<br/>outcome + findings + actions"]
end
subgraph thin["Thin-Wrapper MCP Server"]
direction TB
R2["MCP request"] --> SQL["Source-specific SQL query"]
SQL -.->|"read-only query"| DB
SQL --> RAW["Measurement rows<br/>no verdict, no policy"]
endThe semantic evidence boundary is not a pass-through. It independently validates seven layers, then emits immutable normalized evidence for policy evaluation:
SemanticEvidenceBoundary
├── envelope identity schema, tool, profile match the request
├── request identity hostname, at, frm, to match the request
├── coverage the point or window is inside packaged coverage
├── temporal binding evidence timestamps fall within the request window
├── scope host and fleet scope match the requested target
├── row shape and bounds source, fields, types, and numeric ranges are valid
├── ordering / uniqueness / cap no duplicate keys, monotonic order, fixed cap
└── output guarantee immutable normalized evidencePublic MCP tools:
triage_server(hostname, at?)fleet_health(at?)investigate_timeline(hostname, frm, to)
Every result is a simulation snapshot. Lead a point result with its evaluation timestamp; lead a timeline result with its half-open [frm, to) range. Timeline results do not establish an exact state-transition time or root cause.
severity is categorical policy metadata, not a calculation of duration, impact, or confidence. Under the policy, SERVER_OFFLINE maps to HIGH. HEALTHY is not a reservation-availability claim. NO_DATA is a valid empty result; INDETERMINATE means required evidence cannot be reliably evaluated. actions require approval and are non-executable.
Why evidence was rejected
For INDETERMINATE, findings.kind names the bounded validation class that stopped evaluation:
Kind | Meaning |
| typed request semantics are invalid |
| a valid point/window is outside packaged coverage |
| the packaged provider returned its closed unavailability signal |
| required evidence is absent, including an empty fleet |
| required evidence is stale or otherwise unusable |
| raw schema or request identity does not match |
| evidence time/window does not match the request |
| evidence escapes the requested or fleet host scope |
| evidence violates uniqueness, order, or the fixed cap |
| a source, row, type, or bounded value is invalid |
A thin provider pass-through may relay data or structured errors, but it does not independently validate request identity, host scope, time/window, order, uniqueness, caps, and payload bounds. The normalized semantic evidence boundary does, and returns one bounded rejection class without backend disclosure when those invariants do not support a trustworthy verdict.
These fixed categories are rejection classes, not exhaustive root causes. They never expose SQL, paths, database/provider identities, raw exception text, or rejected values. Their severity is always HIGH because no trustworthy verdict can be produced—not because incident impact is high. Synthetic failures retain schema-v1 evidence state defective; normal states remain COMPLETE, EMPTY, and NOT_APPLICABLE. Required missing (and an empty fleet) takes precedence over required stale.
Related MCP server: tracegraph
Getting started
Prerequisites
Python 3.12 or later
SQLite 3.37 or later (pre-installed on macOS and most Linux)
If your system Python is older than 3.12, install 3.12 first. On Linux without sudo, use uv:
curl -LsSf https://astral.sh/uv/install.sh | sh
uv python install 3.12If pipx is not installed:
curl -sSf https://pipx.pypa.dev/install.py | python3Install
If your system Python is 3.12+, install directly:
pipx install git+https://github.com/kc-ml2/mcp-execution-boundaries.gitIf pipx defaults to an older Python, specify 3.12 explicitly:
pipx install --python 3.12 git+https://github.com/kc-ml2/mcp-execution-boundaries.gitThis puts scv-triage-stdio on your PATH. Most MCP clients find it directly. If yours doesn't, run command -v scv-triage-stdio and paste the output as the command value.
Configure an MCP client
Claude Desktop — edit claude_desktop_config.json:
{
"mcpServers": {
"scv-triage": {
"command": "scv-triage-stdio",
"args": [],
"env": {
"SCV_RUNTIME_ENVIRONMENT": "demo",
"SCV_DEMO_PROFILE": "INCIDENT"
}
}
}
}Cursor — see deploy/cursor-mcp.example.json.
Restart and verify
Completely quit and reopen the MCP client. The server is ready when these three tools appear:
triage_serverfleet_healthinvestigate_timeline
Switch profiles
Profile | Fleet state | Point verdicts |
| CRITICAL — storage critical, GPU violation, one server offline | server-01 CRITICAL, server-02 OFFLINE, server-03 HEALTHY |
| HEALTHY — same fleet, no findings | server-01 HEALTHY, server-02 HEALTHY |
At the INCIDENT evaluation point, triage_server(server-01) reports both STORAGE_CRITICAL_ENTRY (CRITICAL) and VIOLATION_PERIOD (HIGH). Co-present findings do not establish causation.
Change SCV_DEMO_PROFILE and restart the client.
Verify in the MCP client
After restarting, the client should list exactly three tools: triage_server, fleet_health, and investigate_timeline. If the server doesn't appear, run command -v scv-triage-stdio and use the printed absolute path as the command value instead.
Update
pipx upgrade scv-triage-runtimeUninstall
pipx uninstall scv-triage-runtimeInstall from source
git clone https://github.com/kc-ml2/mcp-execution-boundaries.git
cd mcp-execution-boundaries
python3.12 -m venv .venv
.venv/bin/pip install .For this method, set command to the absolute <repo>/.venv/bin/scv-triage-stdio path.
Runtime gate
The server starts only when SCV_RUNTIME_ENVIRONMENT=demo and SCV_DEMO_PROFILE is exactly INCIDENT or CLEAR. Missing, production, or unsupported values abort before MCP protocol startup with no fallback.
License
MIT — see LICENSE.
Presentation
Presented at MCP Seoul 2026. See output/ for a structured output comparison between the execution-boundary server and a thin API wrapper on the same query.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers

tracegraphofficial
Alicense-qualityBmaintenanceAn MCP server that induces agent behavior from traces into a spec, then gates MCP calls against that spec to block invalid actions.263Apache 2.0- AlicenseAqualityBmaintenanceAn MCP server that judges hardware behavior against timing or serial contracts, returning pass/marginal/fail verdicts for coding agents to iterate on real signal measurements.6MIT
- Alicense-qualityBmaintenanceAn MCP server for agent authorization that tests the full effect surface and enforces control over consequential actions before dispatch, emitting verifiable execution evidence.Apache 2.0
Related MCP Connectors
Remote MCP for A2A failure replay MCP, structured receipts, audit logs, and reviewer-ready evidence.
Conformance checker for MCP servers. Free, no key, verdicts recomputable and re-measured daily.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/kc-ml2/mcp-execution-boundaries'
If you have feedback or need assistance with the MCP directory API, please join our Discord server