ScopeProof

Machine-verifiable authorization checks for autonomous AI agents.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
80%
命名质量
93%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~1,428token 数(工具定义)
~5.0 KB典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 1.12%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "scopeproof": {
      "url": "https://scopeproof.davisvillelabs.com/mcp"
    }
  }
}

远程端点

https://scopeproof.davisvillelabs.com/mcpstreamable-http

它能做什么

工具清单

工具(3)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢preflight(authority, action, context)

Validate whether a structured authority envelope contains enough explicit constraints for ScopeProof to evaluate one action. Free. Returns no substantive authorization verdict and accepts no credentials, raw prompts, arbitrary request bodies, or secrets.

输入模式

{
  "type": "object",
  "properties": {
    "authority": {
      "type": "object",
      "required": [
        "allowedActions",
        "allowedResources"
      ],
      "additionalProperties": false,
      "properties": {
        "schemaVersion": {
          "type": "string",
          "maxLength": 64
        },
        "principal": {
          "type": "string",
          "maxLength": 160
        },
        "issuedAt": {
          "type": "string",
          "format": "date-time"
        },
        "notBefore": {
          "type": "string",
          "format": "date-time"
        },
        "expiresAt": {
          "type": "string",
          "format": "date-time"
        },
        "allowedActions": {
          "type": "array",
          "minItems": 1,
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "deniedActions": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "allowedResources": {
          "type": "array",
          "minItems": 1,
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "deniedResources": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "methods": {
          "type": "array",
          "maxItems": 24,
          "items": {
            "type": "string"
          }
        },
        "tools": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "environments": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        },
        "dataClasses": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        },
        "maxSpend": {
          "type": "object",
          "required": [
            "amountMinor",
            "currency"
          ],
          "additionalProperties": false,
          "properties": {
            "amountMinor": {
              "type": "integer",
              "minimum": 0
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Z]{3}$"
            }
          }
        },
        "allowDestructive": {
          "type": "boolean"
        },
        "allowIrreversible": {
          "type": "boolean"
        },
        "approvalRequiredFor": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        }
      }
    },
    "action": {
      "type": "object",
      "required": [
        "type",
        "resource"
      ],
      "additionalProperties": false,
      "properties": {
        "type": {
          "type": "string",
          "maxLength": 64
        },
        "resource": {
          "type": "string",
          "maxLength": 1024
        },
        "method": {
          "type": "string",
          "maxLength": 12
        },
        "tool": {
          "type": "string",
          "maxLength": 200
        },
        "environment": {
          "type": "string",
          "maxLength": 80
        },
        "dataClass": {
          "type": "string",
          "maxLength": 80
        },
        "amount": {
          "type": "object",
          "required": [
            "amountMinor",
            "currency"
          ],
          "additionalProperties": false,
          "properties": {
            "amountMinor": {
              "type": "integer",
              "minimum": 0
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Z]{3}$"
            }
          }
        },
        "destructive": {
          "type": "boolean",
          "description": "Set true when the proposed action is destructive even if its action type or HTTP method is not intrinsically classified as destructive."
        },
        "irreversible": {
          "type": "boolean"
        }
      }
    },
    "context": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "humanApprovalPresent": {
          "type": "boolean",
          "description": "Caller assertion that required human approval has already occurred. ScopeProof records this as caller-asserted and does not independently verify the human identity or approval event."
        }
      }
    }
  },
  "required": [
    "authority",
    "action"
  ],
  "additionalProperties": false
}
🟢check_action(authority, action, context)

Determine whether one proposed action is within explicitly supplied authority. $0.01 stablecoin machine payment. Returns within_scope, outside_scope, or review_required plus deterministic reason codes, policy/action digests, and a tamper-evident receipt. This is scope enforcement against supplied authority, not identity verification, legal authorization, or a safety guarantee.

输入模式

{
  "type": "object",
  "properties": {
    "authority": {
      "type": "object",
      "required": [
        "allowedActions",
        "allowedResources"
      ],
      "additionalProperties": false,
      "properties": {
        "schemaVersion": {
          "type": "string",
          "maxLength": 64
        },
        "principal": {
          "type": "string",
          "maxLength": 160
        },
        "issuedAt": {
          "type": "string",
          "format": "date-time"
        },
        "notBefore": {
          "type": "string",
          "format": "date-time"
        },
        "expiresAt": {
          "type": "string",
          "format": "date-time"
        },
        "allowedActions": {
          "type": "array",
          "minItems": 1,
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "deniedActions": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "allowedResources": {
          "type": "array",
          "minItems": 1,
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "deniedResources": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "methods": {
          "type": "array",
          "maxItems": 24,
          "items": {
            "type": "string"
          }
        },
        "tools": {
          "type": "array",
          "maxItems": 64,
          "items": {
            "type": "string"
          }
        },
        "environments": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        },
        "dataClasses": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        },
        "maxSpend": {
          "type": "object",
          "required": [
            "amountMinor",
            "currency"
          ],
          "additionalProperties": false,
          "properties": {
            "amountMinor": {
              "type": "integer",
              "minimum": 0
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Z]{3}$"
            }
          }
        },
        "allowDestructive": {
          "type": "boolean"
        },
        "allowIrreversible": {
          "type": "boolean"
        },
        "approvalRequiredFor": {
          "type": "array",
          "maxItems": 32,
          "items": {
            "type": "string"
          }
        }
      }
    },
    "action": {
      "type": "object",
      "required": [
        "type",
        "resource"
      ],
      "additionalProperties": false,
      "properties": {
        "type": {
          "type": "string",
          "maxLength": 64
        },
        "resource": {
          "type": "string",
          "maxLength": 1024
        },
        "method": {
          "type": "string",
          "maxLength": 12
        },
        "tool": {
          "type": "string",
          "maxLength": 200
        },
        "environment": {
          "type": "string",
          "maxLength": 80
        },
        "dataClass": {
          "type": "string",
          "maxLength": 80
        },
        "amount": {
          "type": "object",
          "required": [
            "amountMinor",
            "currency"
          ],
          "additionalProperties": false,
          "properties": {
            "amountMinor": {
              "type": "integer",
              "minimum": 0
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Z]{3}$"
            }
          }
        },
        "destructive": {
          "type": "boolean",
          "description": "Set true when the proposed action is destructive even if its action type or HTTP method is not intrinsically classified as destructive."
        },
        "irreversible": {
          "type": "boolean"
        }
      }
    },
    "context": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "humanApprovalPresent": {
          "type": "boolean",
          "description": "Caller assertion that required human approval has already occurred. ScopeProof records this as caller-asserted and does not independently verify the human identity or approval event."
        }
      }
    }
  },
  "required": [
    "authority",
    "action"
  ],
  "additionalProperties": false
}
🟢verify_receipt(receipt)

Verify the cryptographic integrity of one ScopeProof receipt without exposing the server signing key. Free and repeatable.

输入模式

{
  "type": "object",
  "properties": {
    "receipt": {
      "type": "object"
    }
  },
  "required": [
    "receipt"
  ],
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本3 个工具