CausalLayer MCP
Deterministic AI liability attribution with Bitcoin-anchored proof certificates.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"causallayer": {
"command": "npx",
"args": [
"causallayer-mcp"
]
}
}
}実行可能なパッケージ
0.4.0stdioリモートエンドポイント
https://mcp.faultkey.com/mcpstreamable-httpできること
ツール一覧
ツール(10)
🟡submit_incident(title, description, category, severity, jurisdiction, ...)
Submit an AI incident for deterministic causal liability attribution. Returns a signed CausalCertificate, per-agent liability allocation, evidence-chain completeness, regulatory mapping, and (where keys are configured) a Bitcoin-anchored proof. Cost: 50 credits. Three guardrails apply: PII scan, deterministic-only acknowledgement, and minimum evidence.
入力スキーマ
{
"type": "object",
"properties": {
"title": {
"type": "string",
"minLength": 3
},
"description": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"low",
"medium",
"high",
"critical"
]
},
"jurisdiction": {
"type": "string"
},
"financial_impact_cents": {
"anyOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "null"
}
]
},
"currency": {
"type": "string",
"minLength": 3,
"maxLength": 3
},
"agents": {
"minItems": 1,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"minLength": 1
},
"name": {
"type": "string",
"minLength": 1
},
"type": {
"type": "string",
"enum": [
"ai_system",
"human_operator",
"vendor",
"deployer",
"user",
"third_party"
]
},
"operator_role": {
"type": "string",
"enum": [
"provider",
"deployer",
"user",
"vendor",
"regulator",
"auditor"
]
},
"vendor_name": {
"type": "string"
},
"model_id": {
"type": "string"
}
},
"required": [
"id",
"name",
"type"
]
}
},
"events": {
"minItems": 1,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"minLength": 1
},
"type": {
"type": "string",
"minLength": 1
},
"timestamp": {
"type": "string",
"minLength": 1
},
"actor_id": {
"type": "string"
},
"description": {
"type": "string",
"minLength": 1
},
"trace_id": {
"type": "string",
"pattern": "^[0-9a-f]{32}$"
},
"span_id": {
"type": "string",
"pattern": "^[0-9a-f]{16}$"
},
"trace_source": {
"type": "string",
"enum": [
"opentelemetry",
"jaeger",
"zipkin",
"datadog",
"newrelic",
"other"
]
}
},
"required": [
"id",
"type",
"timestamp",
"description"
]
}
},
"deterministic_only": {
"type": "boolean",
"const": true,
"description": "G2: Must be true. Acknowledges CausalLayer is deterministic and not LLM-based."
},
"pii_acknowledged": {
"default": false,
"description": "G1: Set to true ONLY if caller has confirmed PII handling is permitted by their data agreement. False payloads with detected PII will be rejected.",
"type": "boolean"
}
},
"required": [
"title",
"agents",
"events",
"deterministic_only"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪verify_certificate(certificate)
Independently verify a CausalCertificate end-to-end (signature, Merkle integrity, issuer status against the registry). Cost: 1 credit. In production env, certificates from non-active issuers are rejected.
入力スキーマ
{
"type": "object",
"properties": {
"certificate": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "CausalCertificateV1 object as returned by submit_incident.certificate"
}
},
"required": [
"certificate"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪verify_certificate_recompute(certificate, canonicalInput)
Independently re-derive a CausalCertificate from its canonical input and compare byte-for-byte against the claimed certificate. This is the strongest verification path: it requires no trust in the issuer or signing key. Cost: 1 credit (same price as verify_certificate). Returns PASS only if every checked field (certificateId, request_hash, merkleRoot, verdict, causalGraph, fourFactorScoring, deviationTaxonomy, euRuleOverlay, cascadeAttenuation, damages, underwriting) matches identically.
入力スキーマ
{
"type": "object",
"properties": {
"certificate": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "The CausalCertificate object claimed by the issuer."
},
"canonicalInput": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "The original incident body that produced the certificate — the same JSON originally posted to submit_incident or submit_otel_trace."
}
},
"required": [
"certificate",
"canonicalInput"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡submit_otel_trace(title, otlp, category, jurisdiction, financial_impact_cents, ...)
Convert an OpenTelemetry OTLP JSON trace into a FaultKey incident and return the same deterministic CausalCertificate as submit_incident. Each span becomes an event; service.name groups spans into agents; W3C trace_id and span_id propagate as evidence pointers on the causal graph edges. Cost: 50 credits (same as submit_incident). Three guardrails apply: PII scan, deterministic-only acknowledgement, and minimum evidence (auto-satisfied when the trace has at least 1 span).
入力スキーマ
{
"type": "object",
"properties": {
"title": {
"type": "string",
"minLength": 3
},
"otlp": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "OTLP JSON payload with resourceSpans[]. See https://opentelemetry.io/docs/specs/otlp/#json-protobuf-encoding"
},
"category": {
"type": "string"
},
"jurisdiction": {
"type": "string"
},
"financial_impact_cents": {
"anyOf": [
{
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
{
"type": "null"
}
]
},
"currency": {
"type": "string",
"minLength": 3,
"maxLength": 3
},
"deterministic_only": {
"type": "boolean",
"const": true,
"description": "G2: Must be true. Acknowledges CausalLayer is deterministic."
},
"pii_acknowledged": {
"default": false,
"description": "G1: Set to true ONLY if PII handling is permitted by your data agreement. OTLP traces frequently leak user/session ids in attributes.",
"type": "boolean"
}
},
"required": [
"title",
"otlp",
"deterministic_only"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢simulate_remediation(verdict, fourFactorScoring, agents, remediations)
Counterfactual remediation simulator. Given a certificate's verdict + fourFactorScoring + agents and a list of remediation IDs from the FK-METHOD-2026-003 catalog, return the apportioned shares each remediation would have produced (in isolation) and the composite shares if they all stack. Every remediation cites a specific statute or standard. GET /api/v2/remediation/catalog for the list of IDs. Cost: 1 credit (same price as verify_certificate). Pure deterministic; same inputs produce a byte-identical result.
入力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"type": "object",
"properties": {
"primaryParty": {
"type": "string"
},
"primaryShare": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"secondary": {
"type": "array",
"items": {
"type": "object",
"properties": {
"party": {
"type": "string"
},
"share": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"party",
"share"
]
}
}
},
"required": [
"primaryParty",
"primaryShare",
"secondary"
],
"description": "The verdict block from the CausalCertificate."
},
"fourFactorScoring": {
"type": "object",
"properties": {
"primaryAgent": {
"type": "string"
},
"causalProximity": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"behaviouralDeviation": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"controllability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"regulatoryAlignment": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"weights": {
"type": "object",
"properties": {
"causalProximity": {
"type": "number"
},
"behaviouralDeviation": {
"type": "number"
},
"controllability": {
"type": "number"
},
"regulatoryAlignment": {
"type": "number"
}
},
"required": [
"causalProximity",
"behaviouralDeviation",
"controllability",
"regulatoryAlignment"
]
}
},
"required": [
"primaryAgent",
"causalProximity",
"behaviouralDeviation",
"controllability",
"regulatoryAlignment",
"weights"
],
"description": "The fourFactorScoring block from the CausalCertificate."
},
"agents": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"type": {
"type": "string"
}
},
"required": [
"id"
]
},
"description": "Agent registry (id + type) so the simulator can map remediation targetType to specific party ids."
},
"remediations": {
"minItems": 1,
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"appliedToParty": {
"type": "string"
}
},
"required": [
"id"
]
},
"description": "List of remediation IDs from the catalog (e.g. vendor_adversarial_eval_suite, deployer_human_in_loop). Each may optionally pin appliedToParty to a specific agent id."
}
},
"required": [
"verdict",
"fourFactorScoring",
"agents",
"remediations"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡query_jurisdiction_overlay(attributable, actors, flags, jurisdictions, primaryJurisdiction)
Multi-jurisdiction overlay (FK-METHOD-2026-004). Given a canonical attributable apportionment (party-id -> share), the union of all jurisdiction role tags on each actor, and the union of jurisdiction-specific flags, return side-by-side post-overlay shares for AU, EU, US, UK, CA (or a chosen subset) with the specific rules that fired in each, citation URLs, and a parties × jurisdictions matrix. v1 ships full implementations for AU and EU; US/UK/CA are research stubs marked `is_stub: true`. Use GET /api/v2/jurisdiction/catalog to discover support and stub status. Cost: 1 credit. Pure deterministic.
入力スキーマ
{
"type": "object",
"properties": {
"attributable": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"description": "Canonical pre-overlay apportionment as { party_id: share }. Sum should approximate 1.0; the function renormalises within tolerance."
},
"actors": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"type": {
"type": "string",
"enum": [
"ai_system",
"vendor",
"deployer",
"human_operator",
"user",
"third_party"
]
},
"eu_chain_member": {
"type": "array",
"items": {
"type": "string",
"enum": [
"manufacturer",
"authorised_representative",
"importer",
"fulfilment_service_provider",
"distributor",
"online_platform_self_supplier",
"substantial_modifier"
]
}
},
"eu_resident": {
"type": "boolean"
},
"apra_regulated": {
"type": "boolean"
},
"acl_supplier": {
"type": "boolean"
},
"unrecoverable": {
"type": "boolean"
}
},
"required": [
"id",
"type"
]
},
"description": "All actors with the union of jurisdiction-specific role tags. EU and AU tags coexist on the same actor record."
},
"flags": {
"type": "object",
"properties": {
"high_risk_ai": {
"type": "boolean"
},
"pld_compensable_damage": {
"type": "boolean"
},
"deployer_used_contrary_to_instructions": {
"type": "boolean"
},
"human_oversight_unassigned_or_unqualified": {
"type": "boolean"
},
"human_oversight_nominally_assigned_not_present": {
"type": "boolean"
},
"deployer_input_data_unrepresentative": {
"type": "boolean"
},
"deployer_ignored_risk_signal": {
"type": "boolean"
},
"deployer_failed_serious_incident_notification": {
"type": "boolean"
},
"deployer_destroyed_logs": {
"type": "boolean"
},
"deployer_employer_no_worker_notice": {
"type": "boolean"
},
"deployer_public_authority_unregistered": {
"type": "boolean"
},
"provider_failed_to_supply_instructions": {
"type": "boolean"
},
"provider_breach_was_unforeseeable": {
"type": "boolean"
},
"ai_is_opaque_black_box": {
"type": "boolean"
},
"defendant_failed_disclosure_order": {
"type": "boolean"
},
"substantial_modification_present": {
"type": "boolean"
},
"substantial_modification_severity": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"acl_major_failure": {
"type": "boolean"
},
"is_apra_regulated_service": {
"type": "boolean"
},
"cps230_thirdparty_breach": {
"type": "boolean"
},
"cps230_operational_breach": {
"type": "boolean"
},
"vaiss_adherent": {
"type": "boolean"
},
"vendor_no_docs": {
"type": "boolean"
}
},
"description": "Union of jurisdiction-specific flags. AI Act / PLD flags drive the EU overlay; ACL / CPS 230 / VAISS flags drive the AU overlay."
},
"jurisdictions": {
"description": "Optional subset to compute. Defaults to all five.",
"type": "array",
"items": {
"type": "string",
"enum": [
"AU",
"EU",
"US",
"UK",
"CA"
]
}
},
"primaryJurisdiction": {
"description": "Engine-level jurisdiction string (e.g. 'EU', 'DE', 'AU'). Used by the EU gate to decide engagement.",
"type": "string"
}
},
"required": [
"attributable",
"actors",
"flags"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡evaluate_prospective_response(action, overrides)
Deterministic prospective-evaluation gate (FK-METHOD-2026-006). Pass a ProposedAction BEFORE the agent delivers a response; receive one of three verdicts: 'allow', 'require_revision' (with specific factor-keyed directives), or 'block'. Uses the same four-factor engine that issues post-hoc certificates, so a single incident chains: prospective_pre_image -> response -> certificate -> anchor. This is a policy gate on structured action metadata, NOT a content safety classifier on raw prose. Thresholds are per-jurisdiction (EU strictest, US most permissive); read via GET /api/v2/gate/thresholds. Overrides are allowed but REQUIRE a governance rationale so the audit trail is complete. Cost: 1 credit. Pure deterministic.
入力スキーマ
{
"type": "object",
"properties": {
"action": {
"type": "object",
"properties": {
"action_id": {
"type": "string",
"description": "Stable id for this action; echoed back."
},
"action_type": {
"type": "string",
"enum": [
"llm_response",
"tool_call",
"code_execution",
"external_api_call",
"human_handoff",
"data_modification",
"financial_transaction",
"medical_advice",
"legal_advice",
"financial_advice",
"content_moderation",
"autonomous_decision",
"other"
],
"description": "The action category. Carries inherent regulatory weight."
},
"acting_agent_id": {
"type": "string",
"description": "Free-form id of the agent issuing the action."
},
"acting_agent_type": {
"type": "string",
"enum": [
"ai_system",
"vendor",
"deployer",
"operator",
"human_user",
"third_party"
],
"description": "Liability-bias category of the acting agent."
},
"severity_estimate": {
"type": "string",
"enum": [
"low",
"medium",
"high",
"critical"
],
"description": "The estimated severity if the action goes wrong."
},
"jurisdiction": {
"description": "Jurisdiction overlay; defaults to AU.",
"type": "string",
"enum": [
"AU",
"EU",
"US",
"UK",
"CA"
]
},
"cascade_depth": {
"description": "How many upstream agents this action is downstream of. 0 = root; 3 = LLM->agent->tool->this. Applies cascade attenuation.",
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"eu_flags": {
"description": "Optional EU AI Act flags; only used when jurisdiction === 'EU'.",
"type": "object",
"properties": {
"high_risk_ai": {
"type": "boolean"
},
"pld_compensable_damage": {
"type": "boolean"
},
"human_oversight_unassigned_or_unqualified": {
"type": "boolean"
}
}
},
"context_flags": {
"description": "Context flags that inform the regulatoryAlignment and controllability sub-scores.",
"type": "object",
"properties": {
"affects_vulnerable_population": {
"type": "boolean"
},
"regulated_domain": {
"type": "boolean"
},
"irreversible_if_executed": {
"type": "boolean"
},
"human_in_the_loop_present": {
"type": "boolean"
}
}
},
"upstream_incident_id": {
"description": "Optional chain to an existing incident trace.",
"type": "string"
}
},
"required": [
"action_id",
"action_type",
"acting_agent_id",
"acting_agent_type",
"severity_estimate"
],
"description": "The structured ProposedAction to evaluate."
},
"overrides": {
"description": "Optional per-call threshold override. Rationale REQUIRED for audit.",
"type": "object",
"properties": {
"allow_below": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"block_at_or_above": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"rationale": {
"type": "string",
"description": "REQUIRED when overrides are provided. Cite the governance basis (e.g. 'ISO/IEC 42001 SoA §3.2 approval')."
}
},
"required": [
"rationale"
]
}
},
"required": [
"action"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_anchor_status(version)
Return the index of all CausalLayer Tessera anchor batches, or one batch's full JSON (signed Merkle root, leaves, OpenTimestamps proof reference). FREE.
入力スキーマ
{
"type": "object",
"properties": {
"version": {
"description": "Optional anchor version, e.g. '2026-05-16-v1.6.4-simulation-calibration'.",
"type": "string"
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢query_issuer_registry(issuer_id)
Return the CausalLayer issuer registry, or one issuer record. The registry lists all trusted public-key fingerprints, key algorithms, validity windows, and the anchor-log repo for each active issuer. FREE — no API key required.
入力スキーマ
{
"type": "object",
"properties": {
"issuer_id": {
"description": "Optional issuer id, e.g. 'causallayer-prod-2026-q2'. If omitted, returns the full registry.",
"type": "string"
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡extract_incident(text, context_hint, jurisdiction_hint)
Claude-powered structured extractor. Parses unstructured text (news articles, court filings, emails, PDFs, incident reports, logs) into the typed JSON schema required by submit_incident. Returns a ready-to-submit incident object with extracted agents, events, severity, jurisdiction, and financial impact. NOTE: This is a pre-processing convenience tool — the deterministic scoring engine itself remains LLM-free. Cost: 10 credits.
入力スキーマ
{
"type": "object",
"properties": {
"text": {
"type": "string",
"minLength": 20,
"maxLength": 50000,
"description": "Unstructured text to extract from. Can be a news article, court filing, incident report, email, PDF text, log output, or any description of an AI incident."
},
"context_hint": {
"description": "Optional hint about the source type (e.g., 'court filing', 'news article', 'internal incident report') to improve extraction accuracy.",
"type": "string"
},
"jurisdiction_hint": {
"description": "Optional ISO country code hint if the jurisdiction is known (e.g., 'AU', 'US', 'EU').",
"type": "string"
}
},
"required": [
"text"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}コミュニティ
エビデンス