Runtime verification for agent tool calls: Ed25519 signed receipts, fail-closed RCE/SSRF checks.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A Model Context Protocol (MCP) server that brings CCS runtime verification to any MCP-compatible client β Claude Desktop, Cursor, Windsurf, and more.
It verifies AI agent tool calls at runtime, blocks unsafe ones by default, issues tamper-evident evidence records for every decision, and verifies that actual tool arguments match the agent's declared intent β catching cross-model parameter drift.
Runtime evidence layer, not a static scanner. Every decision is enforced at call time and produces independently verifiable cryptographic evidence.
Add it to any MCP client β paste this into your mcpServers config in Claude Desktop, Cursor or Cline:
Or install from the official MCP Registry: search "Correctover" inside your client, or open registry.modelcontextprotocol.io and find io.github.Correctover/ccs.
No API key, no account, no environment variables required β an Ed25519 signing key is generated automatically on first run (set CCS_KEY_DIR, or CCS_PRIVATE_KEY/CCS_PUBLIC_KEY, only if you want to pin a persistent key). Zero dependencies. Pure Node.js stdlib (Node β₯ 18). No install scripts.
| Tool | Purpose |
|---|---|
verify_tool_call | 7-dimension runtime verification (Structure/Schema/Security/Identity/Integrity/Latency/Cost) + semantic attack-chain analysis + math overflow detection. Blocks by default. |
issue_evidence | Issue a tamper-evident evidence record (content_hash + evidence_hash, chainable). Produced for allowed AND denied calls. |
audit_mcp_config | Audit MCP configuration JSON for security risks. |
verify_intent_binding | Verify actual tool arguments match a declared intent β zero tolerance, zero LLM calls. Catches cross-model parameter drift (planner says amount: 100, executor writes amount: 10000 β DENIED). |
verify_receipt | Offline-verify a CCS Ed25519-signed receipt: checks the signature against the embedded signer public key, reports tampering, and optionally pins an expected signer key or fingerprint. |
Agent planners (Claude, GPT) declare one thing; executors (Qwen, DeepSeek) sometimes write another. No existing protocol verifies that actual tool call arguments match the agent's declared intent:
CCS Intent Binding fills this layer. The agent framework declares a structured intent before execution; CCS verifies actual arguments against it in sub-millisecond, zero-LLM time.
| Mode | Behavior | Example |
|---|---|---|
exact | Deep equality with math normalization | 100, 100.0, 1e2 all match; 10000 does not |
numeric_tolerance | Absolute tolerance | 100 Β± 0.01 matches 100.005 |
pattern | Regex match on string fields | ^[A-Z]{3}$ matches "USD" |
No intent declared? Falls through to standard 7-dimension verification. Zero breaking changes.
curl|sh, rm -rf, eval()../, /etc/passwd, /proc/self/169.254.169.254 (cloud metadata), localhost, private ranges β across any toolexfil_chain--insecure, TLS disabledEvery decision produces evidence with dual hashes (content_hash + evidence_hash) and chain linkage (parent_evidence_hash). Any third party can independently verify that evidence has not been tampered with β without trusting the operator.
Receipts are Ed25519-signed and JSON-based: verify them offline with the built-in verify_receipt tool, or independently with any Ed25519 library. Cross-tool receipt verification (same crypto, chain linkage, field mapping) is designed to work without this package installed.
Elastic License 2.0 (ELv2). See LICENSE.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ccs-mcp-server)<a href="https://allmcps.com/mcp/ccs-mcp-server"><img src="https://allmcps.com/api/badge/ccs-mcp-server?style=directory" alt="Ccs MCP Server on AllMCPs" /></a>