Moltline Agent Governance

Audit MCP configs and skill files for over-broad scope and injection risk. 6 of 8 free.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
90%
命名品質
87%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~2,648Token(工具定義)
~803 B典型回應大小
顯著的注意力影響(128k 上下文的 2.07%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "govern": {
      "url": "https://mcp.moltlinestudio.com/govern"
    }
  }
}

遠端端點

https://mcp.moltlinestudio.com/governstreamable-http

它能做什麼

工具清單

工具(8)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢audit_mcp_config(config)

Audit an MCP server config for risk-ranked posture findings. FREE. Flags exposed machine credentials in the config, required inputs that aren't gated/optional, unpinned versions, over-broad env access, and dangerous auto-run flags. It never echoes any matched secret value back. Typical input {"config": "<mcpize.yaml, mcp.json, or a Claude/Cursor servers block>"} returns {"posture_score": 0-100, "verdict": "...", "findings": [{"line": N, "severity": 1-5, "issue": "...", "fix": "..."}], "note": "..."}. Use on a server configuration document. Not for a skill or instruction file (audit_skill_file) and not for untrusted content an agent is about to read (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "config": {
      "type": "string",
      "description": "The MCP config to audit, pasted as text or JSON —\nmcpize.yaml, mcp.json, or a Claude/Cursor servers block."
    }
  },
  "required": [
    "config"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢scope_check(tools)

Score the blast radius of every tool in a permission manifest. FREE. Ranks each tool by capability risk (command exec > money/delete > file-write/messaging > read > network) and flags the over-privileged ones that need approval gates. Typical input {"tools": "[\"run_shell\", \"read_docs\"]"} returns {"tools_scored": N, "high_risk_tools": N, "ranking": [{"tool": ..., "blast_radius": 0-5, "capabilities": [...]}], "recommendation": ["..."], "note": "..."}. Use on a permission manifest to rank tools by blast radius. Not for the configuration that mounts them (audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "tools": {
      "type": "string",
      "description": "The manifest as a string — a JSON array of tool names or\n{name, description} objects, a JSON object of name->description,\nor plain newline-separated names."
    }
  },
  "required": [
    "tools"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢audit_skill_file(content)

Audit an agent skill or instruction file before you trust it. FREE. Checks for governance smells: prompt-injection and guardrail-bypass phrasing, concealment instructions ('don't tell the user'), exfiltration language, and exposed credential material. Typical input {"content": "<SKILL.md, system prompt, or tool description text>"} returns {"verdict": "reject — do not install" | "no governance red flags on a pattern pass", "findings": [{"severity": 1-5, "issue": "..."}], "note": "..."}. Use before trusting a skill or instruction file that came from outside your own repository. Not for arbitrary untrusted input at run time (injection_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "Full text of the skill file, system prompt, or tool\ndescription to audit."
    }
  },
  "required": [
    "content"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢injection_scan(text)

Scan untrusted text for prompt-injection patterns before ingestion. FREE. Use on any web page, email, or document an agent is about to ingest to catch prompt-injection and data-exfiltration patterns before they reach the agent's context. Typical input {"text": "<untrusted content>"} returns {"injection_suspected": bool, "count": N, "hits": [{"line": N, "pattern": "...", "text": "<flagged line>"}], "note": "..."}. Not for reviewing a skill file you control (audit_skill_file), and a clean result is not a guarantee of safety - it reports pattern matches only. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "The untrusted content to scan, pasted as a single string."
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢inventory_report(items)

Build a governance inventory with risk tiers from a raw agent list. FREE. Turns a list of agents / MCP servers / skills into an audit-ready summary with critical/elevated/standard tiers and unowned-agent flags. Typical input {"items": "[{\"name\": \"deploy-bot\", \"owner\": \"ana\"}]"} returns {"total": N, "tiers": {"critical": N, ...}, "unowned_agents": [...], "inventory": [{"name": ..., "owner": ..., "tier": ..., "orphaned": bool}], "reading": "...", "note": "..."}. Use to turn a raw agent list into risk tiers. Not for auditing any single agent in depth (audit_mcp_config, scope_check). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "items": {
      "type": "string",
      "description": "The fleet as a string — a JSON array of {name, owner?,\ncapabilities?, last_seen?} objects, or plain newline-separated\nagent names."
    }
  },
  "required": [
    "items"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢governance_policy(fleet_context)

Generate an audit-ready agent-governance policy for a fleet. PREMIUM (license). Covers inventory cadence, ownership rules, least-privilege approval gates, injection defense, logging/retention, and decommissioning triggers. Typical input {"fleet_context": "20 agents, 3 with shell access, one finance bot"} returns {"policy": ..., "sections": {...}, "context_note": ..., "audit_checklist": ["...", ...]}. Use when a fleet needs a written policy document. Not for assessing what the fleet currently does (inventory_report, audit_mcp_config). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "fleet_context": {
      "default": "",
      "type": "string",
      "description": "Optional plain-language description of the fleet\n(size, capabilities, sensitive systems) used to tailor the\npolicy; empty returns the generic baseline."
    }
  },
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢get_auditor_persona

Load the Governance Auditor persona for consistent fleet audits. PREMIUM (license). The persona is methodical, evidence-driven, and allergic to 'it's probably fine'. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated audits consistent in voice and rigor. Not for running an audit - the audit tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢agent_readiness_scan(domain)

Score a public domain against 21 agent-readiness checks. FREE. Use when you need to know whether an autonomous agent can discover, read, use or pay a website - your own, or a vendor you are evaluating before recommending it. Typical input {"domain": "example.com"} returns {"score": 8, "total": 21, "grade": "F", "passed": [...], "failed": [{"title": "...", "detail": "...", "fix": "..."}], "report_url": "..."} where report_url is a permanent shareable page for the same result. Not for auditing an MCP client configuration (audit_mcp_config) and not for scanning text for injection (injection_scan) - this one reaches out over the network and fetches public URLs on a live domain. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "The readiness scanner is not reachable right now."}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "A public hostname such as example.com. A full URL is accepted\nand reduced to its host. Hostnames that resolve to private or\ninternal addresses are refused."
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本8 個工具
已驗證未記錄版本8 個工具