WORKS Public Verifier

Independent static verification for exact immutable public GitHub commits.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
87%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~1,181token 数(工具定义)
~3.8 KB典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.92%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "works-public": {
      "url": "https://works-runner.vercel.app/mcp-registry"
    }
  }
}

远程端点

https://works-runner.vercel.app/mcp-registrystreamable-http

它能做什么

工具清单

工具(3)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢works_public_eligibility(source_kind, repository_url, repository_visibility, reference, claim)

Fast deterministic preflight for tool-only clients. Call this before any other WORKS tool when eligibility is uncertain, especially for mutable or abbreviated refs, local or private repositories, and build, test, runtime, deployment, or production claims. It does not download a repository or persist data. If eligible is false, stop without calling verification.

输入模式

{
  "type": "object",
  "properties": {
    "source_kind": {
      "type": "string",
      "enum": [
        "public-github",
        "private-github",
        "local",
        "other"
      ],
      "description": "Classify where the requested source lives."
    },
    "repository_url": {
      "description": "Exact repository URL supplied by the user, if any.",
      "type": "string",
      "maxLength": 512
    },
    "repository_visibility": {
      "type": "string",
      "enum": [
        "public",
        "private",
        "unknown"
      ],
      "description": "Use public only when the request identifies a public repository."
    },
    "reference": {
      "description": "Reference exactly as supplied; never expand a branch, tag, or short SHA.",
      "type": "string",
      "maxLength": 128
    },
    "claim": {
      "type": "string",
      "enum": [
        "node-package",
        "env-safety",
        "static-evidence",
        "build",
        "tests",
        "runtime",
        "deployment",
        "production-readiness",
        "other"
      ],
      "description": "Use static-evidence for generic signed or static repository evidence; it maps conservatively to node-package. Never use it for build, tests, runtime, deployment, or production claims."
    }
  },
  "required": [
    "source_kind",
    "repository_visibility",
    "claim"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

输出模式

{
  "type": "object",
  "properties": {
    "eligible": {
      "type": "boolean"
    },
    "reason": {
      "type": "string",
      "enum": [
        "eligible",
        "public_github_required",
        "public_repository_required",
        "valid_repository_url_required",
        "exact_commit_required",
        "supported_static_claim_required"
      ]
    },
    "contract": {
      "anyOf": [
        {
          "type": "string",
          "enum": [
            "node-package",
            "env-safety"
          ]
        },
        {
          "type": "null"
        }
      ]
    },
    "next_tool": {
      "anyOf": [
        {
          "type": "string",
          "const": "works_verify_public_repository"
        },
        {
          "type": "null"
        }
      ]
    },
    "report": {
      "type": "string"
    }
  },
  "required": [
    "eligible",
    "reason",
    "contract",
    "next_tool",
    "report"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#",
  "additionalProperties": false
}
🟢works_public_contract_lint(contract)

After a task is already known to have a public GitHub repository, an exact lowercase 40-character commit SHA, and a matching supported static claim, return the pinned contract digest and scope. Do not call for mutable or abbreviated refs, local or private repositories, runtime, builds, tests, deployments, or broad production-readiness claims.

输入模式

{
  "type": "object",
  "properties": {
    "contract": {
      "type": "string",
      "enum": [
        "node-package",
        "env-safety"
      ]
    }
  },
  "required": [
    "contract"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

输出模式

{
  "type": "object",
  "properties": {
    "valid": {
      "type": "boolean",
      "const": true
    },
    "id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "digest": {
      "type": "string"
    },
    "execution": {
      "type": "string",
      "const": "none"
    },
    "trust": {
      "type": "string"
    }
  },
  "required": [
    "valid",
    "id",
    "title",
    "description",
    "digest",
    "execution",
    "trust"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#",
  "additionalProperties": false
}
🟢works_verify_public_repository(contract, repository_url, commit_sha)

Use only after works_public_eligibility returns eligible. Download that immutable public GitHub snapshot, run the selected pinned static contract without executing repository commands, and return a signed receipt. Return the report field verbatim and stop.

输入模式

{
  "type": "object",
  "properties": {
    "contract": {
      "type": "string",
      "enum": [
        "node-package",
        "env-safety"
      ]
    },
    "repository_url": {
      "type": "string",
      "maxLength": 512,
      "format": "uri"
    },
    "commit_sha": {
      "type": "string",
      "pattern": "^[0-9a-f]{40}$"
    }
  },
  "required": [
    "contract",
    "repository_url",
    "commit_sha"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

输出模式

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "passed",
        "failed",
        "blocked",
        "error"
      ]
    },
    "contract": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "digest": {
          "type": "string"
        },
        "trust": {
          "type": "string"
        }
      },
      "required": [
        "id",
        "digest",
        "trust"
      ],
      "additionalProperties": false
    },
    "source": {
      "type": "object",
      "properties": {
        "kind": {
          "type": "string",
          "const": "github-public"
        },
        "repository": {
          "type": "string"
        },
        "commit": {
          "type": "string",
          "pattern": "^[0-9a-f]{40}$"
        }
      },
      "required": [
        "kind",
        "repository",
        "commit"
      ],
      "additionalProperties": false
    },
    "outcomes": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "pass",
              "fail",
              "blocked"
            ]
          }
        },
        "required": [
          "id",
          "status"
        ],
        "additionalProperties": false
      }
    },
    "trust": {
      "type": "object",
      "properties": {
        "key_id": {
          "type": "string"
        },
        "pinned_key_identity": {
          "type": "string",
          "const": "matched"
        }
      },
      "required": [
        "key_id",
        "pinned_key_identity"
      ],
      "additionalProperties": false
    },
    "report": {
      "type": "string"
    },
    "receipt": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {}
    },
    "limitations": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "status",
    "contract",
    "source",
    "outcomes",
    "trust",
    "report",
    "receipt",
    "limitations"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#",
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本3 个工具
已验证未记录版本3 个工具
已验证未记录版本3 个工具