A local MCP server for trusted NixOS automation that enables inspecting files, applying patch sets, and validating/switching NixOS or Home Manager configurations.
A safety gate for agent-proposed NixOS configuration changes, grading security-relevant option deltas, attesting closures for vulnerabilities, and requiring human approval with a tamper-evident audit ledger.