Fail-closed policy guardrails for AI agents running kubectl, terraform, helm, and argocd.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Flight recorder and reliability scoring for infrastructure automation
Evidra records intent, outcome, and refusal for every infrastructure mutation — across MCP agents, CI pipelines, A2A agents, and scripts. The append-only evidence chain powers behavioral signal detection and reliability scoring. Canonicalization and risk assessment are optional external enrichments, not required core dependencies.
CLI and MCP are the authoritative analytics surfaces today.
Two ways to use it:
| What | How | |
|---|---|---|
| DevOps MCP Server | All-in-one: kubectl/helm/terraform/aws with smart output + auto-evidence | evidra-mcp as your agent's MCP server |
| Flight Recorder | Add evidence to any existing workflow — no MCP required | evidra record, evidra import, webhooks, or proxy mode |
Your agent gets seven default DevOps tools: run_command, collect_diagnostics, write_file, describe_tool, prescribe_smart, report, and get_event. The normal path is still run_command with automatic evidence recording for mutations. Use describe_tool only when you want the full explicit-control schema for prescribe_smart or report. Add --full-prescribe when you also want artifact-aware prescribe_full.
Works with any agent framework, CI system, or script. No MCP required.
Security boundary: Evidra does not sandbox the wrapped command. Treat it with the same trust model as direct shell execution.
Read-only commands (get, describe, logs) execute directly — no overhead.
Install the Evidra skill to give your agent operational discipline: diagnosis before fix, safety boundaries, domain-specific patterns.
| Tool | Description |
|---|---|
run_command | Execute kubectl, helm, terraform, aws — with smart output |
collect_diagnostics | Gather pods, describe output, events, and recent logs for one workload |
write_file | Write config or manifest files under the current workspace or temp directories |
describe_tool | Show the full schema for deferred protocol tools when you want explicit control |
prescribe_smart | Smart Prescribe with deferred schema loading; use describe_tool first when needed |
report | Record outcome; full explicit schema available via describe_tool |
get_event | Look up evidence |
Enable --full-prescribe to add Full Prescribe when your agent has artifact bytes and you want artifact-aware explicit intent capture.
Most agents only need run_command. Use collect_diagnostics when the model would otherwise spend multiple turns on get / describe / events / logs. Use write_file for agent-authored manifests or Terraform snippets without leaving the MCP surface. Use describe_tool only when you deliberately want the explicit prescribe_smart / report flow instead of the default auto-evidence path.
| kubectl-mcp-server | evidra-mcp | |
|---|---|---|
| Tools | 270 specialized | 7 default tools + optional Full Prescribe |
| Output | Raw JSON (~2400 tokens) | Smart summary (~40 tokens) |
| Evidence | None | Auto prescribe/report for mutations |
| Security | Open | Command allowlist + blocked subcommands |
| Skills | None | Installable role guidance |
| Scoring | None | Reliability scorecards + behavioral signals |
Centralize evidence across agents, pipelines, and controllers:
References: Self-hosted setup · CLI reference · API reference
From the evidence chain, Evidra computes:
Risk assessment can be supplied by an external scanner or policy engine as an optional assessment block on prescribe entries. When no assessment is supplied, Evidra still records the intent and outcome and leaves risk fields empty.
Eight behavioral signals documented in the Signal specification.
For agents that want full control over evidence recording:
Three evidence modes:
| Mode | How | Agent awareness |
|---|---|---|
| Proxy Observed | Auto prescribe/report via observed mutation-style tool calls | None needed |
| Smart Prescribe | Agent calls prescribe_smart + report | Minimal (~30 tokens) |
| Full Prescribe | Agent calls prescribe_full with artifact | Full artifact (~300 tokens) |
Most users should use Proxy Observed or the default DevOps surface. Smart Prescribe and Full Prescribe are for teams that want explicit prescribe/report control. If an agent needs risk context before executing, run a scanner or policy engine first and include its result as optional assessment enrichment.
Add evidence to an existing MCP server — zero agent changes:
The proxy records evidence when it sees run_command or other mutation-shaped MCP tool calls it can classify heuristically. Unclassified or read-only tool calls pass through without evidence.
| Variable | Description |
|---|---|
EVIDRA_EVIDENCE_DIR | Evidence storage path (default: ~/.evidra/evidence) |
EVIDRA_SIGNING_MODE | strict (default) or optional (dev mode) |
EVIDRA_SIGNING_KEY | Base64 Ed25519 signing key |
EVIDRA_ENVIRONMENT | Environment label (production, staging) |
Licensed under the Apache License 2.0.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/evidra-2)<a href="https://allmcps.com/mcp/evidra-2"><img src="https://allmcps.com/api/badge/evidra-2?style=directory" alt="Evidra on AllMCPs" /></a>