Kenwea Notary

Signed third-party verdict on what an npm package or file does when run. No key, no signup.

我该使用它吗

质量与安全性

B
描述质量
100%
模式完整度
73%
命名质量
50%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(3)

  • LOWTool 'kenwea.notary.check' doesn't follow camelCase/snake_case在 kenwea.notary.check 中
  • LOWTool 'kenwea.notary.verify' doesn't follow camelCase/snake_case在 kenwea.notary.verify 中
  • LOWTool 'kenwea.notary.getPublicKey' doesn't follow camelCase/snake_case在 kenwea.notary.getPublicKey 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~1,211token 数(工具定义)
~884 B典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.95%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "notary": {
      "url": "https://mcp.kenwea.com/notary/v1"
    }
  }
}

远程端点

https://mcp.kenwea.com/notary/v1streamable-http

它能做什么

工具清单

工具(3)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢kenwea.notary.check(artifactRef, package)

Notarize what a file or npm package does at the moment Kenwea fetches it, and get a signed record anyone can check. Input: exactly one of artifactRef, a public https URL of a single file, npm tarball or Python wheel, or package, an npm package name such as [email protected] (resolved to the exact tarball npm install would download; no version means latest). Behavior: Kenwea downloads the bytes (up to 10 MiB) and runs executable content in isolation: no network, all capabilities dropped, read-only filesystem, 15 seconds for a file and 45 for a package. Returns: a verdict (approved, manual_review or rejected), the sha256 of what was read, and signedAttestation, an Ed25519 signature over those facts. A URL that cannot be fetched returns checked false with the reason instead of a verdict; a limit of our runner comes back as manual_review stated as ours. Limits: no key or signup; 20 checks per hour per network address within a shared hourly ceiling, refused with rate_limited and the reset time. A Kenwea API key sent as a Bearer token uses that key's own quota. Stores nothing about the artifact or what you asked; only a rate counter and a log line with a short hash of your address. Not for: checking a record you already have (use kenwea.notary.verify, which runs nothing and does not spend your quota).

输入模式

{
  "type": "object",
  "properties": {
    "artifactRef": {
      "description": "Public https URL of the artifact: a single .js, .mjs, .cjs or .py file, a shebang script, an npm tarball (.tgz) or a Python wheel or zip. Omit when using package.",
      "format": "uri",
      "type": "string"
    },
    "package": {
      "description": "npm package name with an optional version or dist-tag, for example express, [email protected] or @types/[email protected]. Omit when using artifactRef.",
      "type": "string"
    }
  }
}
🟢kenwea.notary.verify(contentSha256, payload, signature)

Check a signed record produced by kenwea.notary.check: whether its signature is valid under Kenwea's published Ed25519 key, and what it attests. Input: payload and signature exactly as they appear in the record's signedAttestation. payload is a JSON string and must be passed byte for byte; re-serialising it (reordering keys, changing spacing) breaks the signature. signature is standard base64 with padding. Optionally contentSha256, the hex sha256 of bytes you hold, compared without regard to letter case. Behavior: runs nothing and makes no request except fetching the public key, which it caches for an hour. It checks against the key published now, so a record signed before a key rotation returns valid false; compare the returned keyId with the record's keyId to tell that apart from tampering. Read-only and idempotent; it never counts against the check quota. Returns: valid, the keyId, and the signed facts (artifactRef, contentSha256, verdict, ran, exitCode, issuedAt); with contentSha256, also matchesContentSha256. An altered or re-serialised record returns valid false with the reason, not an error. If the key cannot be fetched the call fails with key_unavailable and says why. Not for: learning what an artifact does (use kenwea.notary.check). To verify without this tool, take the key from kenwea.notary.getPublicKey and use any Ed25519 library.

输入模式

{
  "type": "object",
  "properties": {
    "contentSha256": {
      "description": "Optional sha256 (hex) of the bytes you hold; the answer then says whether the record is about them.",
      "type": "string"
    },
    "payload": {
      "description": "signedAttestation.payload from a check result, byte for byte.",
      "type": "string"
    },
    "signature": {
      "description": "signedAttestation.signature, base64.",
      "type": "string"
    }
  },
  "required": [
    "payload",
    "signature"
  ]
}
🟢kenwea.notary.getPublicKey

Return Kenwea's published Ed25519 notary key, so a signed record can be verified with your own code instead of kenwea.notary.verify. Input: none. Behavior: reads the key from https://www.kenwea.com/.well-known/kenwea-attestation-key, the address every signed record names, and caches it for an hour. Runs nothing, read-only, never counts against the check quota. Fails with key_unavailable if the key cannot be fetched. Returns: keyId (compare it with a record's signedAttestation.keyId), algorithm ed25519, the key as base64 (32 raw bytes) and as PEM, and keyUrl. To verify, check signedAttestation.signature (base64) over the exact bytes of signedAttestation.payload with this key. Not for: checking an artifact (use kenwea.notary.check) or having the check done for you (use kenwea.notary.verify).

输入模式

{
  "type": "object",
  "properties": {}
}

社区

评价此服务器

证据

最近观测

已验证未记录版本3 个工具