attest-mcp-remote

Zero-install remote MCP server for proof-of-existence file attestation.

我該用這個嗎

品質與安全性

B
說明品質
100%
結構描述完整度
74%
命名品質
87%
汙染風險
80%
權限相符程度
100%
協定合規性
100%

發現項目(2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domain在 attest_hash 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,875Token(工具定義)
~1.8 KB典型回應大小
中等的注意力影響(128k 上下文的 1.46%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "attest-mcp-remote": {
      "url": "https://attest-mcp-remote.it-e3f.workers.dev/mcp"
    }
  }
}

遠端端點

https://attest-mcp-remote.it-e3f.workers.dev/mcpstreamable-http

它能做什麼

工具清單

工具(8)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪service_status

Health of the Spazio Genesi attestation service components: worker (attestation engine), archive (certificate storage), signer (PDF cryptographic signature), anchor (Bitcoin/OpenTimestamps calendars). Values: ok | degraded | down | n/d.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_anchor(sha256)

Check whether a work's SHA-256 fingerprint has an OpenTimestamps proof anchored in Bitcoin. The proof is created at attestation time and matures (pending → Bitcoin-confirmed) within a few hours.

輸入結構描述

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot."
    }
  },
  "required": [
    "sha256"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪verify_attestation(sha256, attestazione, hmac, titolo, autore, ...)

Verify the server HMAC signature of an attestation issued by the Spazio Genesi service. Confirms that the attestation string (fingerprint + timestamp) and any declared metadata are authentic and untampered. Note: this checks the SIGNATURE only. Whether a given file matches the fingerprint must be checked locally by re-hashing the file. If the certificate carried declared metadata (title/author/year/notes), they must be provided EXACTLY as printed for the signature to verify.

輸入結構描述

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot."
    },
    "attestazione": {
      "type": "string",
      "description": "The attestation string exactly as printed on the certificate: \"SHA-256:<hash>@<ISO timestamp>Z\""
    },
    "hmac": {
      "type": "string",
      "description": "The server HMAC signature exactly as printed on the certificate (base64, 44 characters ending with '=')."
    },
    "titolo": {
      "description": "Declared title, exactly as printed (only if the certificate shows it).",
      "type": "string"
    },
    "autore": {
      "description": "Declared author, exactly as printed (only if the certificate shows it).",
      "type": "string"
    },
    "anno": {
      "description": "Declared year/version, exactly as printed (only if the certificate shows it).",
      "type": "string"
    },
    "note": {
      "description": "Declared notes, exactly as printed (only if the certificate shows them).",
      "type": "string"
    }
  },
  "required": [
    "sha256",
    "attestazione",
    "hmac"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢lookup_certificate(sha256)

Look up whether a work's SHA-256 fingerprint has an attestation certificate in the public archive, and get its permanent links (public certificate page, PDF download, OpenTimestamps proof, browser verification). Trust model: this information is reachable only by whoever knows the fingerprint.

輸入結構描述

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot."
    }
  },
  "required": [
    "sha256"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢authorize

Start the device-flow authorization to attest works in this session (up to 20 attestations, 24h). Returns a link the USER must open in a browser and approve (anti-bot check included). After the user approves, call `complete_authorization`. Not needed if the connection already carries an API key header, or for verification tools.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪complete_authorization

Complete the device-flow authorization after the user approved in the browser. Polls the service briefly; if approval hasn't happened yet, just call this tool again.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡attest_hash(sha256, name, size, type, titolo, ...)

Attest a work: the service binds the SHA-256 fingerprint to a server-side timestamp and signs it (HMAC). Requires a credential (device flow via `authorize`, or an API key header). Optional declared metadata (title/author/year/notes) are normalized and BOUND by the signature — immutable after issuance, but they remain self-declared (they don't prove authorship). Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.

輸入結構描述

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot."
    },
    "name": {
      "description": "File name (descriptive only, shown on the certificate).",
      "type": "string"
    },
    "size": {
      "description": "File size in bytes (descriptive only).",
      "type": "integer",
      "exclusiveMinimum": 0,
      "maximum": 9007199254740991
    },
    "type": {
      "description": "MIME type (descriptive only).",
      "type": "string"
    },
    "titolo": {
      "description": "Declared title of the work (bound by the signature).",
      "type": "string"
    },
    "autore": {
      "description": "Declared author (bound by the signature).",
      "type": "string"
    },
    "anno": {
      "description": "Declared year/version (bound by the signature).",
      "type": "string"
    },
    "note": {
      "description": "Declared notes (bound by the signature).",
      "type": "string"
    }
  },
  "required": [
    "sha256"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡create_certificate_pdf(sha256)

Generate and archive the certificate PDF for a fingerprint attested in this session with `attest_hash`. The PDF is cryptographically signed, anchored in Bitcoin (OpenTimestamps) and archived server-side; this tool returns the permanent links (the PDF itself is downloadable from its URL — it is never inlined here).

輸入結構描述

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot."
    }
  },
  "required": [
    "sha256"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本8 個工具
已驗證未記錄版本8 個工具
已驗證未記錄版本8 個工具