correctover-mcp-server

correctover-mcp-server

Enables protocol-level runtime verification of AI agent tool calls across six dimensions with a fail-closed guarantee, blocking any action that fails verification before execution.

Category
Visit Server

README

CCS Runtime Evidence MCP Server

A Model Context Protocol (MCP) server that brings CCS runtime verification to any MCP-compatible client — Claude Desktop, Cursor, Windsurf, and more.

It verifies AI agent tool calls at runtime, blocks unsafe ones by default, issues tamper-evident evidence records for every decision, and verifies that actual tool arguments match the agent's declared intent — catching cross-model parameter drift.

Runtime evidence layer, not a static scanner. Every decision is enforced at call time and produces independently verifiable cryptographic evidence.

Quick Start

npx -y ccs-mcp-server

MCP Client Configuration

{
  "mcpServers": {
    "ccs-runtime-evidence": {
      "command": "npx",
      "args": ["-y", "ccs-mcp-server"]
    }
  }
}

Zero dependencies. 44KB. Pure Node.js stdlib. No install scripts.

Tools

Tool Purpose
verify_tool_call 7-dimension runtime verification (Structure/Schema/Security/Identity/Integrity/Latency/Cost) + semantic attack-chain analysis + math overflow detection. Blocks by default.
issue_evidence Issue a tamper-evident evidence record (content_hash + evidence_hash, chainable). Produced for allowed AND denied calls.
audit_mcp_config Audit MCP configuration JSON for security risks.
verify_intent_binding (v1.1.0) Verify actual tool arguments match a declared intent — zero tolerance, zero LLM calls. Catches cross-model parameter drift (planner says amount: 100, executor writes amount: 10000 → DENIED).

Intent Binding — Cross-Model Drift Detection

Agent planners (Claude, GPT) declare one thing; executors (Qwen, DeepSeek) sometimes write another. No existing protocol verifies that actual tool call arguments match the agent's declared intent:

  • AP2 signs human authorization — not LLM intent
  • AgentPay does baseline tolerance (1%) — not zero-tolerance equivalence
  • ACS runs policy decisions — not argument-level equivalence
  • VAP (draft-samal-vap-00) explicitly excludes argument semantics from its wire schema

CCS Intent Binding fills this layer. The agent framework declares a structured intent before execution; CCS verifies actual arguments against it in sub-millisecond, zero-LLM time.

Example: amount drift

// Intent declared by planner
{
  "intent_id": "int-001",
  "intent_type": "payment",
  "fields": {
    "amount": { "value": 100, "binding_mode": "exact" },
    "recipient": { "value": "Alice", "binding_mode": "exact" }
  },
  "issued_at": 1755000000000,
  "ttl_ms": 30000
}

// Actual arguments from executor
{ "amount": 10000, "recipient": "Alice" }

// Result: DENIED — intent_arg_mismatch
// field: amount, expected: 100, actual: 10000

Three binding modes

Mode Behavior Example
exact Deep equality with math normalization 100, 100.0, 1e2 all match; 10000 does not
numeric_tolerance Absolute tolerance 100 ± 0.01 matches 100.005
pattern Regex match on string fields ^[A-Z]{3}$ matches "USD"

No intent declared? Falls through to standard 7-dimension verification. Zero breaking changes.

What It Detects

  • Command injection: shell metacharacters, curl|sh, rm -rf, eval()
  • Path traversal: ../, /etc/passwd, /proc/self/
  • SSRF: 169.254.169.254 (cloud metadata), localhost, private ranges — across any tool
  • Cross-tool attack chains: read sensitive file → network exfil = exfil_chain
  • Environment variable exfiltration: API keys, secrets, credentials
  • Obfuscation: hex encoding, base64, privilege escalation signals
  • Math safety: integer overflow (>2^53-1), NaN/Infinity
  • MCP config risks: plain HTTP, weak secrets, --insecure, TLS disabled

Evidence Chain

Every decision produces evidence with dual hashes (content_hash + evidence_hash) and chain linkage (parent_evidence_hash). Any third party can independently verify that evidence has not been tampered with — without trusting the operator.

evidence 1: allowed  (fs.read_file)       parent: null
evidence 2: denied   (shell.exec curl|sh) parent: ev1
evidence 3: denied   (http.fetch SSRF)    parent: ev2
evidence 4: denied   (fs + curl exfil)    parent: ev3

The 7 CCS Dimensions

  1. Structure — valid tool name, argument format, nesting depth, payload size
  2. Schema — type, required fields, enums, ranges, string lengths
  3. Security — injection, traversal, SSRF, env exfiltration, obfuscation + semantic attack chains
  4. Identity — caller agent ID verification
  5. Integrity — request hash validation
  6. Latency — execution time budget
  7. Cost — cost budget

Interoperability

CCS receipts are Ed25519-signed, JSON-based, and verifiable offline with zero dependencies. If your project produces or verifies signed attestations, receipts, or evidence records, see INTEGRATION.md — a one-page guide covering:

  • Full receipt field schema (22 fields)
  • JCS canonicalization spec
  • Three levels of interop (same crypto → cross-referenced chains → field-aligned)
  • 30-second verification snippets (Node.js + Python)
  • Clear scope boundaries (what CCS does / does not cover)

Join technical discussions in GitHub Discussions — receipt interoperability, field mapping proposals, and protocol feedback welcome.

Protocol Context

Ecosystem

Project What it does
ccs-demo Complete INSPECT→SIGN→VERIFY walkthrough — 6 scenarios, zero dependencies, node demo.js
ccs-verifier-action GitHub Action — verify CCS receipts in CI/CD pipelines
ccs-mcp-server Core MCP server (this repo) — runtime verification + evidence signing
ccs-proxy Commercial — inline enforcement proxy with L2 protocol attestation + L3 execution binding (Ed25519 signed receipts)

Links

  • npm: https://www.npmjs.com/package/ccs-mcp-server
  • GitHub: https://github.com/DSHCorrectover/ccs-mcp-server
  • IETF Draft: https://datatracker.ietf.org/doc/draft-correctover-ccs/
  • PyPI (full verifier): https://pypi.org/project/ccs-verifier/
  • Demo: https://github.com/DSHCorrectover/ccs-demo
  • GitHub Action: https://github.com/DSHCorrectover/ccs-verifier-action
  • Discussions: https://github.com/DSHCorrectover/ccs-mcp-server/discussions
  • CCS Proxy (commercial): https://dshcorrectover.github.io/ccs-proxy/
  • Integration Guide: INTEGRATION.md

License

Elastic License 2.0 (ELv2) — see the full terms. Reference implementation for CCS standard evaluation.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured