MCP governance kernel that evaluates agent actions against 13 constitutional floors and issues auditable verdicts.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We ran the install command below but it didn't respond within our test window β this can mean a slow first-time install rather than a real problem.
uvx arifosNo response to initialize.
This is an experimental automated check and can have false negatives β missing environment variables, a slow cold install, etc. It doesnβt necessarily mean somethingβs wrong. Last checked 7d ago.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Aaa MCP.
arifOS evaluates consequential AI actions against constitutional floors and returns an independent verdict before execution occurs.
When an AI agent proposes to write, delete, deploy, or spend, arifOS inserts a constitutional judgment step: the agent proposes, arifOS evaluates the proposal against the F1βF13 floors, a verdict is returned, and only then does execution proceed. Every consequential verdict is written into an append-only hash chain with its decision context, evidence references, provenance and receipt hashes.
In a world where intelligence is abundant, authority becomes the scarce resource. arifOS exists to keep judgment independent from execution.
This is not an AI model. It is not an agent framework. It is a constitutional authority system β the layer between "agent wants to act" and "action is permitted."
Two invariants hold everywhere in this document:
Proposer β Judge β Executor β Witness Human sovereignty > machine authority
What arifOS is not: not an AI model Β· not an agent framework Β· not an execution engine (A-FORGE executes) Β· not an attention plane (AAA attends) Β· not the independent witness (FRAME witnesses; VAULT999 remembers) Β· not a substitute for authentication, sandboxing, or legal review.
| Audience | What you get |
|---|---|
| Human | A quiet veto: the agent proposes, the kernel records a verdict, you stay sovereign |
| Agent / A2A | MCP tools + receipts. You do not get the keys. A2A v1.0 (a2a_version: 1.0.1 in the agent card), not v1.2 β discovery is owned by AAA, judgment by arifOS, execution by A-FORGE |
| Institution | Policy floors F1βF13, a hash-chained VAULT999 audit trail, model-vendor independence |
| Indexer / Search | Structured metadata, llms.txt, tools.json, CITATION.cff |
| Machine / MCP | Streamable HTTP endpoint, 8 canonical verbs, published input/output schemas |
| Robot / Automation | CI gates (conformance, vault-integrity, drift, governance), Makefile targets, Dockerfile |
Live: https://arifos.arif-fazil.com Β· MCP :8088 Β· sister organs GEOX Β· A-FORGE Β· AAA
AI agents that act are also certifying their own actions. Nothing independent evaluates the proposal against safety, compliance and policy constraints before execution occurs.
The judge never executes. The executor never certifies.
Intelligence proposes. Authority constrains. Execution acts. Reality witnesses. History remembers.
| Plane / class | Component | Role |
|---|---|---|
| Authority | arifOS :8088 | Constitutional judgment β evaluates proposals against F1βF13; owns the gavel and the ledger |
| Attention | AAA :3001 | Attention and routing β what matters, and to whom. Displays, routes, queues; never adjudicates |
| Execution | A-FORGE :7071/:7072 | Governed mutation β leases, gates, receipts; only under a SEAL verdict |
| Witness | FRAME :18085 | Independent observer. Its output is evidence, never a verdict |
| Record | VAULT999 (in-kernel) | Immutable append-only ledger β the memory of what was decided |
| Metabolism | arifFlow :7073 | Receipt ingestion, FQ monitoring, verification cadence; never adjudicates |
| Domain intelligence | GEOX :8081 Β· WEALTH :18082 Β· WELL :18083 | Evidence and computation in a domain. Compute-only: no organ authorises its own action |
| Provider gateway | FED :7074 | Multi-provider model routing (advisory-only) |
| Synthesis | i-ARIF | Seal-B synthesis engine β runs through FED chains, owns no port |
| Boundary services (Tier-3) | HERMES :18087 Β· CHRON :18102 | Semantic boundary (meaning integrity, relay-only) and temporal boundary (episodes, predictions, calibration). Neither is an organ β see the ruling in FEDERATION_CONTRACT.md Β§2.1 |
Authority remains separated at every stage: no component proposes, judges, executes and witnesses the same action. arifOS determines whether and how a routing may proceed; AAA determines what matters.
Requires Python 3.12+ (supported range 3.12β3.14; see
pyproject.toml).Versioning: two schemes coexist. The kernel release (
v2026.08.01, reported by/healthasrelease_name) is the operational identity of the running service. The PyPI package uses epoch versioning (1!β¦) to outrank legacy releases:1!2026.9.2is whatpip install arifosresolves to today, while this tree is1!2026.9.6(staged, not yet released). The kernel release is the operational truth; PyPI is the distribution truth.
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/aaa-mcp)<a href="https://allmcps.com/mcp/aaa-mcp"><img src="https://allmcps.com/api/badge/aaa-mcp?style=directory" alt="Aaa MCP on AllMCPs" /></a>