Moltline Agent Governance
Audit MCP configs and skill files for over-broad scope and injection risk. 6 of 8 free.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"govern": {
"url": "https://mcp.moltlinestudio.com/govern"
}
}
}Puntos de conexión remotos
https://mcp.moltlinestudio.com/governstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (8)
🟢audit_mcp_config(config)
Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"config": {
"type": "string",
"description": "The MCP config to audit, pasted as text or JSON —\nmcpize.yaml, mcp.json, or a Claude/Cursor servers block."
}
},
"required": [
"config"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢scope_check(tools)
Score the blast radius of every tool in a permission manifest. FREE. Ranks each tool by capability risk (command exec > money/delete > file-write/messaging > read > network) and flags the over-privileged ones that need approval gates. Typical input {"tools": "[\"run_shell\", \"read_docs\"]"} returns {"tools_scored": N, "high_risk_tools": N, "ranking": [{"tool": ..., "blast_radius": 0-5, "capabilities": [...]}], "recommendation": ["..."], "note": "..."}. Use on a permission manifest to rank tools by blast radius. Not for the configuration that mounts them (audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"tools": {
"type": "string",
"description": "The manifest as a string — a JSON array of tool names or\n{name, description} objects, a JSON object of name->description,\nor plain newline-separated names."
}
},
"required": [
"tools"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢audit_skill_file(content)
Audit an agent skill or instruction file before you trust it. FREE. Checks for governance smells: prompt-injection and guardrail-bypass phrasing, concealment instructions ('don't tell the user'), exfiltration language, and exposed credential material. Typical input {"content": "<SKILL.md, system prompt, or tool description text>"} returns {"verdict": "reject — do not install" | "no governance red flags on a pattern pass", "findings": [{"severity": 1-5, "issue": "..."}], "note": "..."}. Use before trusting a skill or instruction file that came from outside your own repository. Not for arbitrary untrusted input at run time (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"content": {
"type": "string",
"description": "Full text of the skill file, system prompt, or tool\ndescription to audit."
}
},
"required": [
"content"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢injection_scan(text)
Scan untrusted text for prompt-injection patterns before ingestion. FREE. Use on any web page, email, or document an agent is about to ingest to catch prompt-injection and data-exfiltration patterns before they reach the agent's context. Typical input {"text": "<untrusted content>"} returns {"injection_suspected": bool, "count": N, "hits": [{"line": N, "pattern": "...", "text": "<flagged line>"}], "note": "..."}. Not for reviewing a skill file you control (audit_skill_file), and a clean result is not a guarantee of safety - it reports pattern matches only. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "The untrusted content to scan, pasted as a single string."
}
},
"required": [
"text"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢inventory_report(items)
Build a governance inventory with risk tiers from a raw agent list. FREE. Turns a list of agents / MCP servers / skills into an audit-ready summary with critical/elevated/standard tiers and unowned-agent flags. Typical input {"items": "[{\"name\": \"deploy-bot\", \"owner\": \"ana\"}]"} returns {"total": N, "tiers": {"critical": N, ...}, "unowned_agents": [...], "inventory": [{"name": ..., "owner": ..., "tier": ..., "orphaned": bool}], "reading": "...", "note": "..."}. Use to turn a raw agent list into risk tiers. Not for auditing any single agent in depth (audit_mcp_config, scope_check). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"items": {
"type": "string",
"description": "The fleet as a string — a JSON array of {name, owner?,\ncapabilities?, last_seen?} objects, or plain newline-separated\nagent names."
}
},
"required": [
"items"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢governance_policy(fleet_context)
Generate an audit-ready agent-governance policy for a fleet. PREMIUM (license). Covers inventory cadence, ownership rules, least-privilege approval gates, injection defense, logging/retention, and decommissioning triggers. Typical input {"fleet_context": "20 agents, 3 with shell access, one finance bot"} returns {"policy": ..., "sections": {...}, "context_note": ..., "audit_checklist": ["...", ...]}. Use when a fleet needs a written policy document. Not for assessing what the fleet currently does (inventory_report, audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"fleet_context": {
"default": "",
"type": "string",
"description": "Optional plain-language description of the fleet\n(size, capabilities, sensitive systems) used to tailor the\npolicy; empty returns the generic baseline."
}
},
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢get_auditor_persona
Load the Governance Auditor persona for consistent fleet audits. PREMIUM (license). The persona is methodical, evidence-driven, and allergic to 'it's probably fine'. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated audits consistent in voice and rigor. Not for running an audit - the audit tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢agent_readiness_scan(domain)
Score a public domain against 21 agent-readiness checks. FREE. Use when you need to know whether an autonomous agent can discover, read, use or pay a website - your own, or a vendor you are evaluating before recommending it. Typical input {"domain": "example.com"} returns {"score": 8, "total": 21, "grade": "F", "passed": [...], "failed": [{"title": "...", "detail": "...", "fix": "..."}], "report_url": "..."} where report_url is a permanent shareable page for the same result. Not for auditing an MCP client configuration (audit_mcp_config) and not for scanning text for injection (injection_scan) - this one reaches out over the network and fetches public URLs on a live domain. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "The readiness scanner is not reachable right now."}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Esquema de entrada
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "A public hostname such as example.com. A full URL is accepted\nand reduced to its host. Hostnames that resolve to private or\ninternal addresses are refused."
}
},
"required": [
"domain"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}Comunidad
Evidencia