Moltline Agent Governance
Audit MCP configs and skill files for over-broad scope and injection risk. 6 of 8 free.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"govern": {
"url": "https://mcp.moltlinestudio.com/govern"
}
}
}遠端端點
https://mcp.moltlinestudio.com/governstreamable-http它能做什麼
工具清單
工具(8)
🟢audit_mcp_config(config)
Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"config": {
"type": "string",
"description": "The MCP config to audit, pasted as text or JSON —\nmcpize.yaml, mcp.json, or a Claude/Cursor servers block."
}
},
"required": [
"config"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢scope_check(tools)
Score the blast radius of every tool in a permission manifest. FREE. Ranks each tool by capability risk (command exec > money/delete > file-write/messaging > read > network) and flags the over-privileged ones that need approval gates. Typical input {"tools": "[\"run_shell\", \"read_docs\"]"} returns {"tools_scored": N, "high_risk_tools": N, "ranking": [{"tool": ..., "blast_radius": 0-5, "capabilities": [...]}], "recommendation": ["..."], "note": "..."}. Use on a permission manifest to rank tools by blast radius. Not for the configuration that mounts them (audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"tools": {
"type": "string",
"description": "The manifest as a string — a JSON array of tool names or\n{name, description} objects, a JSON object of name->description,\nor plain newline-separated names."
}
},
"required": [
"tools"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢audit_skill_file(content)
Audit an agent skill or instruction file before you trust it. FREE. Checks for governance smells: prompt-injection and guardrail-bypass phrasing, concealment instructions ('don't tell the user'), exfiltration language, and exposed credential material. Typical input {"content": "<SKILL.md, system prompt, or tool description text>"} returns {"verdict": "reject — do not install" | "no governance red flags on a pattern pass", "findings": [{"severity": 1-5, "issue": "..."}], "note": "..."}. Use before trusting a skill or instruction file that came from outside your own repository. Not for arbitrary untrusted input at run time (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"content": {
"type": "string",
"description": "Full text of the skill file, system prompt, or tool\ndescription to audit."
}
},
"required": [
"content"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢injection_scan(text)
Scan untrusted text for prompt-injection patterns before ingestion. FREE. Use on any web page, email, or document an agent is about to ingest to catch prompt-injection and data-exfiltration patterns before they reach the agent's context. Typical input {"text": "<untrusted content>"} returns {"injection_suspected": bool, "count": N, "hits": [{"line": N, "pattern": "...", "text": "<flagged line>"}], "note": "..."}. Not for reviewing a skill file you control (audit_skill_file), and a clean result is not a guarantee of safety - it reports pattern matches only. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "The untrusted content to scan, pasted as a single string."
}
},
"required": [
"text"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢inventory_report(items)
Build a governance inventory with risk tiers from a raw agent list. FREE. Turns a list of agents / MCP servers / skills into an audit-ready summary with critical/elevated/standard tiers and unowned-agent flags. Typical input {"items": "[{\"name\": \"deploy-bot\", \"owner\": \"ana\"}]"} returns {"total": N, "tiers": {"critical": N, ...}, "unowned_agents": [...], "inventory": [{"name": ..., "owner": ..., "tier": ..., "orphaned": bool}], "reading": "...", "note": "..."}. Use to turn a raw agent list into risk tiers. Not for auditing any single agent in depth (audit_mcp_config, scope_check). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"items": {
"type": "string",
"description": "The fleet as a string — a JSON array of {name, owner?,\ncapabilities?, last_seen?} objects, or plain newline-separated\nagent names."
}
},
"required": [
"items"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢governance_policy(fleet_context)
Generate an audit-ready agent-governance policy for a fleet. PREMIUM (license). Covers inventory cadence, ownership rules, least-privilege approval gates, injection defense, logging/retention, and decommissioning triggers. Typical input {"fleet_context": "20 agents, 3 with shell access, one finance bot"} returns {"policy": ..., "sections": {...}, "context_note": ..., "audit_checklist": ["...", ...]}. Use when a fleet needs a written policy document. Not for assessing what the fleet currently does (inventory_report, audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"fleet_context": {
"default": "",
"type": "string",
"description": "Optional plain-language description of the fleet\n(size, capabilities, sensitive systems) used to tailor the\npolicy; empty returns the generic baseline."
}
},
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_auditor_persona
Load the Governance Auditor persona for consistent fleet audits. PREMIUM (license). The persona is methodical, evidence-driven, and allergic to 'it's probably fine'. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated audits consistent in voice and rigor. Not for running an audit - the audit tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢agent_readiness_scan(domain)
Score a public domain against 21 agent-readiness checks. FREE. Use when you need to know whether an autonomous agent can discover, read, use or pay a website - your own, or a vendor you are evaluating before recommending it. Typical input {"domain": "example.com"} returns {"score": 8, "total": 21, "grade": "F", "passed": [...], "failed": [{"title": "...", "detail": "...", "fix": "..."}], "report_url": "..."} where report_url is a permanent shareable page for the same result. Not for auditing an MCP client configuration (audit_mcp_config) and not for scanning text for injection (injection_scan) - this one reaches out over the network and fetches public URLs on a live domain. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "The readiness scanner is not reachable right now."}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
輸入結構描述
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "A public hostname such as example.com. A full URL is accepted\nand reduced to its host. Hostnames that resolve to private or\ninternal addresses are refused."
}
},
"required": [
"domain"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}社群
證據