trust-lattice
Evidence-weighted trust graph for multi-agent systems. Enables querying trust and gating high-risk actions based on time-decayed evidence and endorsements.
README
Trust Lattice
Evidence-weighted trust graph / reputation lattice for multi-agent systems. Nodes are agents, tools, and claim-sources. Edges carry time-decayed evidence (attestations, challenges, endorsements). High-risk actions are gated until trust thresholds and endorsement quorums are met.
Full MCP surface so orchestrators (Cursor, Claude Desktop, custom agents) can query trust before tool calls.
Features
- Beta / Bayesian-ish trust updates with exponential evidence decay
- Path-trust aggregation (noisy-OR of path products)
- Sybil-resistance basics via identity verification stubs + influence caps
- JSON policy DSL for risk tiers:
read|write|irreversible - Explainable gate decisions (“why was this gated?”)
- Export: JSON, Mermaid, Graphviz DOT
- SQLite persistence, CLI, Vitest suite, optional Vite dashboard
See docs/ARCHITECTURE.md for the math and model.
Quick start
npm install
npm run build
npm run seed -- --force
npm test
MCP server (stdio)
npm run serve
# or after build:
node dist/index.js
Cursor MCP config
Add to your Cursor MCP settings (path may vary by OS):
{
"mcpServers": {
"trust-lattice": {
"command": "node",
"args": ["/ABS/PATH/TO/trust-lattice/dist/index.js"],
"env": {
"TRUST_LATTICE_DB": "/ABS/PATH/TO/trust-lattice/data/trust-lattice.db",
"TRUST_LATTICE_ADMIN_TOKEN": "replace-with-a-long-random-secret"
}
}
}
}
Or during development:
{
"mcpServers": {
"trust-lattice": {
"command": "npx",
"args": ["tsx", "/ABS/PATH/TO/trust-lattice/src/index.ts"],
"env": {
"TRUST_LATTICE_DB": "/ABS/PATH/TO/trust-lattice/data/trust-lattice.db",
"TRUST_LATTICE_ADMIN_TOKEN": "replace-with-a-long-random-secret"
}
}
}
}
Mutating tools (tl_register_node, tl_attest, tl_challenge, tl_endorse, tl_promote_identity, pubkey challenge tools) require an adminToken argument that matches TRUST_LATTICE_ADMIN_TOKEN (min 16 chars). Writes fail closed when the env token is unset.
CLI
npx tsx src/cli.ts seed --force
npx tsx src/cli.ts query agent:planner tool:web-search
npx tsx src/cli.ts gate agent:planner tool:shell write "run sandbox command"
npx tsx src/cli.ts export mermaid
npx tsx src/cli.ts promote agent:researcher email --issuer research@acme.test
Dashboard
npm run dev
# → http://127.0.0.1:5173
MCP tools
| Tool | Description |
|---|---|
tl_register_node |
Register/update node (always unverified; needs adminToken) |
tl_promote_identity |
Operator promote verification level (adminToken) |
tl_begin_pubkey_challenge / tl_complete_pubkey_challenge |
Ed25519 proof → pubkey |
tl_attest |
Positive evidence on an edge (adminToken) |
tl_challenge |
Negative evidence on an edge (adminToken) |
tl_endorse |
Path-scaled endorsement (adminToken) |
tl_query_trust |
Decayed trust + paths (read) |
tl_gate_action |
Allow/deny with explanation (read; advisory) |
tl_explain_path |
Supporting paths (read) |
tl_export_graph |
json | mermaid | dot (read) |
Policy
Default policy lives in policies/default.json. Override with TRUST_LATTICE_POLICY or --policy.
Security
- Set
TRUST_LATTICE_ADMIN_TOKEN(≥16 chars) for MCP writes; mutating tools fail closed without it. - Clients cannot set
identity.verificationviaregisterNode/tl_register_node— only operatorpromote/tl_promote_identityor a completed Ed25519 pubkey challenge. - Email/org verification remain operator stubs (no external IdP); pubkey requires a signature challenge.
- Treat the SQLite DB as sensitive operational state.
- MCP logs only to stderr (stdio transport).
- Dashboard binds to
127.0.0.1by default. - Gate decisions are advisory — orchestrators must enforce deny.
License
MIT
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.