invinoveritas

Second opinion before an irreversible agent action; signed proofs, free verify, public ledger.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
96%
命名の品質
90%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~3,992トークン数(ツール定義)
~4.8 KB一般的なレスポンスサイズ
注意への影響は大きい(128k コンテキストの 3.12%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "invinoveritas": {
      "url": "https://api.babyblueviper.com/mcp"
    }
  }
}

リモートエンドポイント

https://api.babyblueviper.com/mcpstreamable-http
https://api.babyblueviper.com/mcp/verifystreamable-http

できること

ツール一覧

ツール(8)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢review(artifact, artifact_type, context, concerns, severity_threshold, ...)

Independent verdict on a proposed action before it is taken: a code diff, shell command, deployment plan, configuration change, another agent's output, or a proposed transaction. Returns approve / approve_with_concerns / reject with a confidence score, issues ranked by severity, suggested fixes and alternatives. With sign=true the verdict is returned as a signed proof that anyone can check later with verify_proof. The verdict is a reasoned second opinion, not a guarantee of outcome. Docs: https://api.babyblueviper.com/docs

入力スキーマ

{
  "type": "object",
  "properties": {
    "artifact": {
      "type": "string",
      "description": "The artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text"
    },
    "artifact_type": {
      "type": "string",
      "enum": [
        "code_diff",
        "patch",
        "shell_command",
        "plan",
        "config_change",
        "analysis",
        "agent_output",
        "trade",
        "onchain_action",
        "sanctions_screening",
        "general"
      ],
      "default": "general",
      "description": "Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason."
    },
    "context": {
      "type": "string",
      "description": "What you are trying to accomplish, why now, success criteria"
    },
    "concerns": {
      "type": "string",
      "description": "Specific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')"
    },
    "severity_threshold": {
      "type": "string",
      "enum": [
        "blocker",
        "high",
        "medium",
        "all"
      ],
      "default": "all",
      "description": "Minimum severity to report"
    },
    "sign": {
      "type": "boolean",
      "default": false,
      "description": "Return the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof."
    },
    "related_proof_event": {
      "type": "object",
      "description": "Optional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing."
    },
    "related_claims": {
      "type": "object",
      "description": "Optional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth."
    },
    "intended_audience": {
      "type": "string",
      "description": "Optional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all."
    },
    "confidentiality_tier": {
      "type": "string",
      "enum": [
        "hash_only",
        "partial_disclosure",
        "full_disclosure"
      ],
      "default": "hash_only",
      "description": "Which privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve."
    },
    "disclosed_summary": {
      "type": "string",
      "description": "Only used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values."
    },
    "intended_verifier": {
      "type": "string",
      "description": "Optional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address."
    },
    "request_capture_ref": {
      "type": "string",
      "description": "Optional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in."
    },
    "action_binding": {
      "type": "object",
      "description": "Optional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed."
    },
    "mediator_attestation": {
      "type": "object",
      "description": "Optional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence."
    },
    "external_evidence": {
      "type": "array",
      "description": "Optional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence."
    }
  },
  "required": [
    "artifact"
  ],
  "examples": [
    {
      "artifact": "rm -rf ./build && git push --force origin main",
      "artifact_type": "shell_command",
      "context": "About to force-push a rebuilt main branch that other people pull from.",
      "sign": true
    }
  ]
}
🟢verify_proof(event, proof_id, event_id, expect_artifact_hash, expect_intended_verifier, ...)

Checks a signed invinoveritas proof without trusting whoever handed it over: recomputes the event id, checks the Schnorr signature, and confirms the signing key is invinoveritas's published key. Optionally pass expect_artifact_hash (sha256 of the content you received) to confirm the proof covers that exact content. Accepts the full event, or an event_id to look up. Returns {valid, checks, proof_payload}. Free, no sign-in. Docs: https://api.babyblueviper.com/verify

入力スキーマ

{
  "type": "object",
  "properties": {
    "event": {
      "type": "object",
      "description": "The signed proof event {id,pubkey,created_at,kind,tags,content,sig} the counterparty handed you (from a /prove or /review sign=true response)."
    },
    "proof_id": {
      "type": "string",
      "description": "Alternatively, a stored attestation proof_id to fetch + verify."
    },
    "event_id": {
      "type": "string",
      "description": "Alternatively, the Nostr event id alone (from a /review sign=true, /prove, or /witness proof) — fetches the durably-stored full event, independent of relay retention, and verifies it."
    },
    "expect_artifact_hash": {
      "type": "string",
      "description": "Optional sha256 hex of the output you received — asserts the proof is ABOUT that exact artifact."
    },
    "expect_intended_verifier": {
      "type": "string",
      "description": "Optional (added 2026-08-16) — asserts the proof's declared intended_verifier matches you, the consumption-identity check alongside expect_artifact_hash's content-identity check. A match confirms the issuer's declared intent, not that delivery was actually restricted to you."
    },
    "verifier_signature": {
      "type": "string",
      "description": "Optional (added 2026-08-16) — an EIP-191 personal_sign signature over 'invinoveritas-verify-proof:<event_id>', signed by the key controlling the address in expect_intended_verifier (eip155 CAIP-10 namespace only). Cryptographically PROVES presenter identity rather than just asserting it — sets checks.intended_verifier_authenticated."
    }
  },
  "required": []
}
⚪witness(source, body)

Timestamps and signs a third party's exact claim, unmodified and unjudged: 'we received this text, attributed to source X, at time T', not 'we agree with it'. The source is recorded as self-declared. The resulting proof checks with verify_proof. Docs: https://api.babyblueviper.com/docs

入力スキーマ

{
  "type": "object",
  "properties": {
    "source": {
      "type": "string",
      "description": "Who this claim is attributed to (self-declared, NOT verified by us)"
    },
    "body": {
      "type": "string",
      "description": "The exact claim to anchor, byte-for-byte (max 16000 chars)"
    }
  },
  "required": [
    "source",
    "body"
  ]
}
🟢validate(returns, trades, n_trials, trial_sharpes, k_folds, ...)

Statistical reality-check of a backtest from its realized returns (or trade rows), not the strategy itself. Returns likely_real / borderline / overfit_or_noise using the Deflated Sharpe Ratio (adjusted for the number of variants tried), a sign-flip permutation test, and out-of-sample decay across purged folds. Inputs are not retained beyond a redacted audit hash. Docs: https://api.babyblueviper.com/docs

入力スキーマ

{
  "type": "object",
  "properties": {
    "returns": {
      "type": "array",
      "items": {
        "type": "number"
      },
      "description": "Per-trade (or per-period) realized returns."
    },
    "trades": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "Alternative to 'returns': rows with a return field (ret/pnl/net_bps) and optional 'coin'/'ts'/'entry'/'exit' fields."
    },
    "n_trials": {
      "type": "integer",
      "minimum": 1,
      "maximum": 10000000,
      "default": 1,
      "description": "How many strategy variants/params you tried before selecting this one. Be honest — more trials = bigger Deflated-Sharpe haircut."
    },
    "trial_sharpes": {
      "type": "array",
      "items": {
        "type": "number"
      },
      "description": "Optional: Sharpes of all variants tried → exact DSR variance."
    },
    "k_folds": {
      "type": "integer",
      "minimum": 2,
      "maximum": 20,
      "default": 5
    },
    "n_perms": {
      "type": "integer",
      "minimum": 200,
      "maximum": 3000,
      "default": 2000
    },
    "periods_per_year": {
      "type": "number",
      "exclusiveMinimum": 0,
      "description": "Optional, for annualized-Sharpe display only."
    },
    "agent_id": {
      "type": "string",
      "description": "Optional caller agent ID"
    }
  }
}
🟢ledger(entry)

Reads invinoveritas's public track record of signed verdicts, including ones that turned out wrong. Each entry is a signed Nostr event whose id and signature can be recomputed against invinoveritas's published key; entries are append-only and Bitcoin-timestamped, so they can't be edited after the fact. No arguments returns the index; pass entry to read one. Free, no sign-in. Docs: https://api.babyblueviper.com/ledger

入力スキーマ

{
  "type": "object",
  "properties": {
    "entry": {
      "type": "string",
      "description": "Optional entry number (e.g. '1'); omit for the full index."
    }
  },
  "required": []
}
🟡ledger_submit(event, note)

Publishes one of your own signed review proofs (from review with sign=true) as a public entry on the invinoveritas ledger. Publication is immediate and permanent: the entry is broadcast to Nostr relays and Bitcoin-timestamped. Only genuine invinoveritas-signed proofs are accepted. Docs: https://api.babyblueviper.com/ledger

入力スキーマ

{
  "type": "object",
  "properties": {
    "event": {
      "type": "object",
      "description": "The signed Nostr event from a prior /review(sign=true) call — the exact proof.event object that response returned."
    },
    "note": {
      "type": "string",
      "description": "Optional short context: what this verdict was for, why it's worth featuring."
    }
  },
  "required": [
    "event"
  ]
}
🟡conformance_certify(name, note)

Publishes a verifier's current conformance grade from the public registry (conformance.json) as a permanent, signed ledger entry, labeled 'certified as of this measurement'. It records the registry's existing measurement and cannot change it. Only works for a verifier currently listed as certified. Docs: https://api.babyblueviper.com/conformance

入力スキーマ

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "The verifier's exact name as listed on GET /conformance.json (must currently show certified:true)."
    },
    "note": {
      "type": "string",
      "description": "Optional short context for the ledger entry."
    }
  },
  "required": [
    "name"
  ]
}
🟢audit_agent_readiness(url)

Audits a public agent or API URL for verifiability: discovery files (llms.txt, MCP card, robots, sitemap), handshake endpoints, and whether presented signed proofs validate. Returns a 0-100 score, a grade, ranked fixes, and a signed proof of the audit. Every result re-derives from a public fetch. Docs: https://api.babyblueviper.com/docs

入力スキーマ

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The agent endpoint/site URL to audit (public http(s) only)"
    }
  },
  "required": [
    "url"
  ]
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 8 件
検証済みバージョンは記録されていませんツール 31 件
検証済みバージョンは記録されていませんツール 31 件