1. Conduid
  2. Security
  3. ScopeBlind/verify-mcp
MCP server · Security

ScopeBlind/verify-mcp

2.0.

34Low

Scored 5 months ago · breakdown

About ScopeBlind/verify-mcp

ScopeBlind/verify-mcp is an MCP server in the Security category: 2.0. It has been installed 0 times through Conduid.

Install

Clone
git clone https://github.com/ScopeBlind/verify-mcp

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about ScopeBlind/verify-mcp

Powered by Claude · Grounded in docs

I know everything about ScopeBlind/verify-mcp. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • ·Scoped permissionsNot checked yet.

README

@scopeblind/verify-mcp

MCP server for offline verification of ScopeBlind and Veritas Acta artifacts.

It is deliberately narrow:

  • verify a single signed receipt or artifact
  • verify an audit bundle offline
  • explain a signed artifact in normalized form
  • run a packaged self-test so clients can prove the verifier works

This is the registry-worthy MCP surface for the verification lane. It is not a gateway, not a builder, and not a hosted verification service.

Install

npm install -g @scopeblind/verify-mcp

Claude Desktop / MCP config

{
  "mcpServers": {
    "scopeblind-verify": {
      "command": "npx",
      "args": ["-y", "@scopeblind/verify-mcp"]
    }
  }
}

Tools

self_test

Runs packaged sample verification.

Returns:

  • sample receipt valid / invalid
  • sample bundle valid / invalid
  • total receipts in the sample bundle

verify_receipt

Inputs:

  • artifact_json or path
  • optional public_key_hex

Returns:

  • valid / invalid
  • type
  • format
  • issuer
  • kid
  • canonical hash

verify_bundle

Inputs:

  • bundle_json or path

Returns:

  • valid / invalid
  • total receipts
  • passed
  • failed

explain_artifact

Inputs:

  • artifact_json or path

Returns a normalized summary of:

  • type
  • format
  • issuer
  • kid
  • issued_at / timestamp
  • payload keys

Notes

  • No ScopeBlind servers are contacted.
  • This server verifies local JSON artifacts only.
  • protect-mcp remains the local policy gateway.
  • @scopeblind/passport remains the local pack builder.
  • @scopeblind/red-team remains the local benchmark runner.

License

MIT

README mirrored from the source repository 5 months ago. The original is authoritative.

Questions

About ScopeBlind/verify-mcp

How do I install ScopeBlind/verify-mcp?

Run git clone https://github.com/ScopeBlind/verify-mcp, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is ScopeBlind/verify-mcp safe to use with an AI agent?

Its trust score is 34 out of 100 (low). Conduid hasn't run static security checks on this repository yet, so review the source yourself before granting it credentials. It has no ConduID identity yet, so agent calls to it are not receipted.

Is ScopeBlind/verify-mcp still maintained?

Conduid hasn't recorded a commit date for this repository yet. Check the repository directly for recent activity.