VerditNxtGen
A cryptographic sidecar proxy that tests MCP tools for OWASP vulnerabilities before deployment. Automatically sandbox and audit your AI agents' tool calls to ensure secure infrastructure.
README
VerditNxtGen MCP Suite
Add cryptographic compliance logging to any MCP server in one line.
VerditNxtGen runs a daily Ghost Swarm that sandbox-tests 190+ open-source MCP tools in Docker, scores them for deployment reliability, detects OWASP vulnerabilities at runtime, and generates HMAC-SHA256 signed manifests for SOC2 compliance.
This repository contains the client-side SDKs and proxy that connect your MCP infrastructure to the VerditNxtGen compliance ledger.
Packages
| Package | Language | Install |
|---|---|---|
| verditnxtgen-mcp-middleware | TypeScript | npm install verditnxtgen-mcp-middleware |
| verditnxtgen-mcp | Python | pip install verditnxtgen-mcp |
| Sidecar Proxy | Docker | docker pull ghcr.io/shopfarnow/verditnxtgen-sidecar |
Get an API key at verditnxtgen.com/connect-mcp — free tier, no credit card.
TypeScript — one line
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { withVerditLedger } from "verditnxtgen-mcp-middleware";
const server = withVerditLedger(
new McpServer({ name: "my-server", version: "1.0" }),
{ apiKey: process.env.VERDIT_API_KEY }
);
// Every tool call is now HMAC-signed and logged to the compliance ledger.
// Zero latency impact — telemetry posts fire-and-forget in the background.
Python — one decorator
from mcp.server.fastmcp import FastMCP
from verditnxtgen_mcp import verdit_ledger
mcp = FastMCP("my-server")
@mcp.tool()
@verdit_ledger(api_key="YOUR_VERDIT_API_KEY")
async def query_database(sql: str) -> str:
...
Docker Sidecar — zero code changes
services:
verdit-sidecar:
image: ghcr.io/shopfarnow/verditnxtgen-sidecar:latest
environment:
VERDIT_API_KEY: "${VERDIT_API_KEY}"
DOWNSTREAM_URL: "http://your-mcp-tool:3000"
ports:
- "8080:8080"
# Point your gateway at verdit-sidecar:8080 instead of your tool directly
What you get
After logging starts, the VerditNxtGen Intelligence Dashboard shows:
- Compliance Ledger: HMAC-SHA256 signed manifest for every tool — chain-of-custody proof for SOC2 Type II audits
- OWASP scan results: LLM01 prompt injection, LLM06 PII boundary, LLM08 vector weakness detection from live sandbox runs
- pass@k curves: Statistical deployment reliability (pass@1, pass@3, pass@5) across 700+ sandbox runs
- Cost intelligence: Compute cost per run across resource profiles
Links
- Live platform
- Intelligence Dashboard
- Score Methodology
- Get API key
- Main repo (private — proprietary Ghost Swarm engine)
License
MIT — see individual package directories.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.