WORKS Public Verifier
Independent static verification for exact immutable public GitHub commits.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"works-public": {
"url": "https://works-runner.vercel.app/mcp-registry"
}
}
}远程端点
https://works-runner.vercel.app/mcp-registrystreamable-http它能做什么
工具清单
工具(3)
🟢works_public_eligibility(source_kind, repository_url, repository_visibility, reference, claim)
Fast deterministic preflight for tool-only clients. Call this before any other WORKS tool when eligibility is uncertain, especially for mutable or abbreviated refs, local or private repositories, and build, test, runtime, deployment, or production claims. It does not download a repository or persist data. If eligible is false, stop without calling verification.
输入模式
{
"type": "object",
"properties": {
"source_kind": {
"type": "string",
"enum": [
"public-github",
"private-github",
"local",
"other"
],
"description": "Classify where the requested source lives."
},
"repository_url": {
"description": "Exact repository URL supplied by the user, if any.",
"type": "string",
"maxLength": 512
},
"repository_visibility": {
"type": "string",
"enum": [
"public",
"private",
"unknown"
],
"description": "Use public only when the request identifies a public repository."
},
"reference": {
"description": "Reference exactly as supplied; never expand a branch, tag, or short SHA.",
"type": "string",
"maxLength": 128
},
"claim": {
"type": "string",
"enum": [
"node-package",
"env-safety",
"static-evidence",
"build",
"tests",
"runtime",
"deployment",
"production-readiness",
"other"
],
"description": "Use static-evidence for generic signed or static repository evidence; it maps conservatively to node-package. Never use it for build, tests, runtime, deployment, or production claims."
}
},
"required": [
"source_kind",
"repository_visibility",
"claim"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}输出模式
{
"type": "object",
"properties": {
"eligible": {
"type": "boolean"
},
"reason": {
"type": "string",
"enum": [
"eligible",
"public_github_required",
"public_repository_required",
"valid_repository_url_required",
"exact_commit_required",
"supported_static_claim_required"
]
},
"contract": {
"anyOf": [
{
"type": "string",
"enum": [
"node-package",
"env-safety"
]
},
{
"type": "null"
}
]
},
"next_tool": {
"anyOf": [
{
"type": "string",
"const": "works_verify_public_repository"
},
{
"type": "null"
}
]
},
"report": {
"type": "string"
}
},
"required": [
"eligible",
"reason",
"contract",
"next_tool",
"report"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}🟢works_public_contract_lint(contract)
After a task is already known to have a public GitHub repository, an exact lowercase 40-character commit SHA, and a matching supported static claim, return the pinned contract digest and scope. Do not call for mutable or abbreviated refs, local or private repositories, runtime, builds, tests, deployments, or broad production-readiness claims.
输入模式
{
"type": "object",
"properties": {
"contract": {
"type": "string",
"enum": [
"node-package",
"env-safety"
]
}
},
"required": [
"contract"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}输出模式
{
"type": "object",
"properties": {
"valid": {
"type": "boolean",
"const": true
},
"id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"digest": {
"type": "string"
},
"execution": {
"type": "string",
"const": "none"
},
"trust": {
"type": "string"
}
},
"required": [
"valid",
"id",
"title",
"description",
"digest",
"execution",
"trust"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}🟢works_verify_public_repository(contract, repository_url, commit_sha)
Use only after works_public_eligibility returns eligible. Download that immutable public GitHub snapshot, run the selected pinned static contract without executing repository commands, and return a signed receipt. Return the report field verbatim and stop.
输入模式
{
"type": "object",
"properties": {
"contract": {
"type": "string",
"enum": [
"node-package",
"env-safety"
]
},
"repository_url": {
"type": "string",
"maxLength": 512,
"format": "uri"
},
"commit_sha": {
"type": "string",
"pattern": "^[0-9a-f]{40}$"
}
},
"required": [
"contract",
"repository_url",
"commit_sha"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}输出模式
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"passed",
"failed",
"blocked",
"error"
]
},
"contract": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"digest": {
"type": "string"
},
"trust": {
"type": "string"
}
},
"required": [
"id",
"digest",
"trust"
],
"additionalProperties": false
},
"source": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"const": "github-public"
},
"repository": {
"type": "string"
},
"commit": {
"type": "string",
"pattern": "^[0-9a-f]{40}$"
}
},
"required": [
"kind",
"repository",
"commit"
],
"additionalProperties": false
},
"outcomes": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"pass",
"fail",
"blocked"
]
}
},
"required": [
"id",
"status"
],
"additionalProperties": false
}
},
"trust": {
"type": "object",
"properties": {
"key_id": {
"type": "string"
},
"pinned_key_identity": {
"type": "string",
"const": "matched"
}
},
"required": [
"key_id",
"pinned_key_identity"
],
"additionalProperties": false
},
"report": {
"type": "string"
},
"receipt": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {}
},
"limitations": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"status",
"contract",
"source",
"outcomes",
"trust",
"report",
"receipt",
"limitations"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}社区
证据