HiveAttest
Pre-action attestation perimeter for AI agents — 8 primitives, signed C18 receipt per call.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"hive-mcp-attest": {
"url": "https://hive-mcp-attest.onrender.com/mcp"
}
}
}Remote-Endpunkte
https://hive-mcp-attest.onrender.com/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (18)
⚪attest_passport_issue(action_id, agent_did, intended_op, target_resource, inputs, ...)
Issue a Pre-Action Attestation Manifest (C15: hive-passport). Signs with Ed25519 over RFC 8785 JCS-canonical body. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"action_id": {
"type": "string",
"description": "Caller-supplied action correlation ID"
},
"agent_did": {
"type": "string",
"description": "DID of the attesting agent"
},
"intended_op": {
"type": "string",
"description": "Operation name, e.g. \"tool_invocation\""
},
"target_resource": {
"type": "string",
"description": "URI or identifier of the target resource"
},
"inputs": {
"type": "object",
"description": "Declared inputs (will be hashed)",
"default": {}
},
"ttl_seconds": {
"type": "integer",
"description": "Validity window in seconds (default 300)",
"default": 300
}
},
"required": [
"action_id",
"agent_did",
"intended_op",
"target_resource"
]
}⚪attest_passport_verify(manifest, observed_inputs)
Verify a Pre-Action Attestation Manifest (C15: hive-passport). Checks Ed25519 signature, temporal validity, and optionally observed inputs hash. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"manifest": {
"type": "object",
"description": "Full passport manifest object (from attest_passport_issue)"
},
"observed_inputs": {
"type": "object",
"description": "Optional observed inputs to check against declared hash"
}
},
"required": [
"manifest"
]
}⚪attest_custody_append(chain_id, transform_id, agent_did, payload, taint_status)
Append a node to a custody chain (C16: hive-custody). Taint propagates: once tainted, always tainted. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"chain_id": {
"type": "string",
"description": "Chain identifier (create new by using a fresh ID)"
},
"transform_id": {
"type": "string",
"description": "Transform identifier for this step"
},
"agent_did": {
"type": "string",
"description": "DID of the agent performing the transform"
},
"payload": {
"type": "object",
"description": "Transform payload (will be hashed)",
"default": {}
},
"taint_status": {
"type": "string",
"enum": [
"clean",
"tainted",
"unknown"
],
"default": "clean",
"description": "Declared taint status"
}
},
"required": [
"chain_id",
"transform_id",
"agent_did"
]
}⚪attest_custody_verify(nodes)
Verify a custody chain: hash linkage, Ed25519 signatures, and taint propagation (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"nodes": {
"type": "array",
"description": "Ordered array of custody chain node objects (from attest_custody_append responses)"
}
},
"required": [
"nodes"
]
}🟢attest_custody_proof(chain_id, index)
Retrieve a Merkle inclusion proof for a specific node in a custody chain (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"chain_id": {
"type": "string",
"description": "Chain identifier"
},
"index": {
"type": "integer",
"description": "0-based node index"
}
},
"required": [
"chain_id",
"index"
]
}⚪attest_cargo_register(id, name, version, sensitivity, schema, ...)
Register a versioned cargo type in the HiveAttest registry (C17: hive-cargo-taxonomy). Pins a definition hash for version-anchoring. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Unique cargo type ID, e.g. \"pii\""
},
"name": {
"type": "string",
"description": "Human-readable cargo type name"
},
"version": {
"type": "string",
"description": "Semver version string, e.g. \"1.0.0\""
},
"sensitivity": {
"type": "string",
"enum": [
"public",
"internal",
"confidential",
"restricted",
"critical"
]
},
"schema": {
"type": "object",
"description": "JSON Schema defining the payload shape"
},
"supersedes": {
"type": "object",
"description": "Optional {id, version} of superseded type"
}
},
"required": [
"id",
"name",
"version",
"sensitivity",
"schema"
]
}⚪attest_cargo_validate(cargo_type_id, version, payload)
Validate a payload against a registered cargo type schema (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"cargo_type_id": {
"type": "string",
"description": "Registered cargo type ID"
},
"version": {
"type": "string",
"description": "Cargo type version"
},
"payload": {
"type": "object",
"description": "Payload to validate against the schema"
}
},
"required": [
"cargo_type_id",
"version",
"payload"
]
}🟢attest_cargo_snapshot
Get a registry snapshot with Merkle root for version pinning (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {}
}⚪attest_warranty_issue(agent_did, action_id, claim, scope, expires_at)
Issue an attestation warranty committing an agent to a claim (C18: hive-attestation-warranty). Signed with Ed25519. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_did": {
"type": "string",
"description": "DID of the warranting agent"
},
"action_id": {
"type": "string",
"description": "Action correlation ID being warranted"
},
"claim": {
"type": "string",
"description": "Human-readable warranty claim"
},
"scope": {
"type": "object",
"description": "Scope constraints",
"default": {}
},
"expires_at": {
"type": "string",
"description": "ISO-8601 expiry UTC (optional)"
}
},
"required": [
"agent_did",
"action_id",
"claim"
]
}⚪attest_warranty_breach(warranty_id, breach_description, evidence)
Report a warranty breach. Marks the warranty as breached and returns a signed breach record (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"warranty_id": {
"type": "string",
"description": "Warranty ID to report breach on"
},
"breach_description": {
"type": "string",
"description": "Description of the breach"
},
"evidence": {
"type": "object",
"description": "Optional evidence dict"
}
},
"required": [
"warranty_id",
"breach_description"
]
}🟢attest_warranty_get(warranty_id)
Retrieve a warranty by ID (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"warranty_id": {
"type": "string",
"description": "Warranty ID"
}
},
"required": [
"warranty_id"
]
}⚪attest_gate_evaluate(passport_manifest, cargo_manifest, custody_root, warranty_ids, context)
THE HEADLINE TOOL. Evaluate whether an agent may proceed through the HiveAttest gate (C19: hive-gate-enforcer). Verifies passport signature + expiry, cargo registry membership, and warranty status. Every response (allow OR deny) includes a signed C18-format receipt of the gate decision. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"passport_manifest": {
"type": "object",
"description": "C15 passport manifest from attest_passport_issue"
},
"cargo_manifest": {
"type": "object",
"description": "C17 cargo manifest (optional)"
},
"custody_root": {
"type": "string",
"description": "Expected custody chain Merkle root (optional)"
},
"warranty_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Active warranty IDs to verify",
"default": []
},
"context": {
"type": "object",
"description": "Additional gate evaluation context",
"default": {}
}
},
"required": [
"passport_manifest"
]
}🟢attest_inspect_sample(sample_id, records, sample_rate, seed)
Probabilistic secondary inspection of a record batch (C20: hive-secondary-inspection). Returns a signed inspection record. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"sample_id": {
"type": "string",
"description": "Identifier for the sample batch"
},
"records": {
"type": "array",
"description": "Records to probabilistically inspect"
},
"sample_rate": {
"type": "number",
"minimum": 0,
"maximum": 1,
"default": 0.1,
"description": "Fraction to inspect (0.0 to 1.0)"
},
"seed": {
"type": "integer",
"description": "Optional RNG seed for reproducibility"
}
},
"required": [
"sample_id",
"records"
]
}⚪attest_smsh_verify(receipt, pubkey_b64url, max_age_seconds)
Verify a SMSH-Stamp v1 receipt (C8/C12: smsh-stamp-verifier). Validates schema, version, algorithm, timestamp, and Ed25519 signature. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"receipt": {
"type": "object",
"description": "SMSH-Stamp v1 receipt object"
},
"pubkey_b64url": {
"type": "string",
"description": "Override trust anchor Ed25519 public key (base64url, 32 bytes)"
},
"max_age_seconds": {
"type": "integer",
"description": "Reject receipts older than this many seconds"
}
},
"required": [
"receipt"
]
}⚪attest_absence_build(window_id, events)
Build a sorted Merkle tree for an audit window (enables cryptographic non-membership proofs, C13: prov-absence). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"window_id": {
"type": "string",
"description": "Audit window identifier"
},
"events": {
"type": "array",
"description": "Observed events to commit to the sorted Merkle tree"
}
},
"required": [
"window_id",
"events"
]
}🟢attest_absence_prove(window_id, query)
Prove that a query event is NOT a member of a previously-built audit window (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"window_id": {
"type": "string",
"description": "Audit window identifier (must have been built)"
},
"query": {
"type": "object",
"description": "Event to prove absent"
}
},
"required": [
"window_id",
"query"
]
}⚪attest_absence_verify(proof, root_hex)
Verify a non-membership proof against an expected Merkle root (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {
"proof": {
"type": "object",
"description": "Non-membership proof from attest_absence_prove"
},
"root_hex": {
"type": "string",
"description": "Expected Merkle root (hex)"
}
},
"required": [
"proof",
"root_hex"
]
}⚪attest_meta
Return HiveAttest layer/spec/patent metadata for all claims. Useful for agent introspection. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Eingabe-Schema
{
"type": "object",
"properties": {}
}Community
Nachweis