Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. Developer Tools
  3. Kcp Harness — KCP compliance proxy
  4. README

Kcp Harness — KCP compliance proxy README

The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Kcp Harness — KCP compliance proxy listing page.

Back to Kcp Harness — KCP compliance proxy View source on GitHub

kcp-harness

🧾 See it run — interactive KCP playground · read the reveal

Deterministic knowledge governance for any AI agent.

Your agent can read every file in your project. Can it prove why it read what it read?

KCP Harness is an MCP compliance proxy that sits between an AI coding agent and its tools. It intercepts knowledge-related calls, routes them through the kcp-agent deterministic planner (14-gate cascade, no LLM), and produces compliance artifacts — decision traces, audit logs, budget ledgers — as a side effect of normal agent operation.

The agent can't bypass governance because it only talks to the proxy's MCP interface. The proxy decides what knowledge is accessible, tracks spend, and logs every decision. Fail-closed: if the harness can't verify a request, the agent gets nothing.

Code
Agent (Claude Code / Cursor / Copilot / Windsurf / Cline / Crush / OpenClaw / ...)
  │
  │  MCP tool call
  v
┌─────────────────────────────────────────────────────────┐
│  kcp-harness                                            │
│                                                         │
│  classify → govern (14 gates) → execute → audit         │
│                                                         │
│  Side outputs:                                          │
│  · Decision traces     (per-request, deterministic)     │
│  · Audit log           (append-only JSONL)              │
│  · Budget ledger       (itemized, ceiling-enforced)     │
│  · Temporal drift      (plan validity over time)        │
│  · Approval tickets    (named-human sign-off, durable)  │
│  · Confidence verdicts (post-synthesis gate)            │
└─────────────────────────────────────────────────────────┘
  │
  v
Knowledge manifests (knowledge.yaml)

Documentation →

Why

Enterprises need agents that are defensible — auditable, reproducible, budget-controlled, temporally pinned. Today's agents can't prove why they read what they read. The harness adds a compliance layer without replacing the agent.

What you keepWhat the harness adds
Your agent (Claude Code, Cursor, Copilot, ...)Deterministic knowledge selection
Your workflow (coding, reviewing, shipping)Decision traces (14 gates per unit)
Your tools (MCP servers, shell, browser)Budget enforcement (ceiling, per-currency)
Temporal governance (drift detection)
Append-only audit log
Replay / cross-examination
Human-approval gates (named reviewer + policy citation)
Confidence gating (post-synthesis, route-to-human)

You sell the compliance layer. The agents are pluggable.

Install

Terminal
npm install -g kcp-harness

Or use without installing:

Terminal
npx kcp-harness --help

Native executables

Pre-built binaries (no Node/Deno required) for Linux x64/arm64, macOS x64/arm64, and Windows x64 — grab them from a release. To build one yourself:

Terminal
npm ci && npm run build
deno compile --allow-read --allow-env --allow-net --allow-run \
  --node-modules-dir=auto --output kcp-harness dist/cli.js

Quick start

1. Initialize

bash
kcp-harness init          # creates harness.yaml

2. Generate agent integration

bash
kcp-harness integrate claude-code    # or: pi, cursor, copilot, windsurf, cline, continue, crush, openclaw

3. Start coding

Your agent now routes knowledge access through the harness. Every decision is logged.

Supported agents

AgentConfigIntegration
Claude Code.mcp.json + PreToolUse hookskcp-harness integrate claude-code
Cursor.cursor/mcp.json + .mdc ruleskcp-harness integrate cursor
GitHub Copilot.vscode/mcp.json (uses "servers" key)kcp-harness integrate copilot
Windsurfglobal config + .windsurfruleskcp-harness integrate windsurf
ClineMCP settings + .clineruleskcp-harness integrate cline
Continue.continue/mcpServers/*.yamlkcp-harness integrate continue
Crushcrush.json + PrepareStepkcp-harness integrate crush
OpenClawopenclaw.json + plugin hookskcp-harness integrate openclaw
Pi.pi/mcp.json + project skillskcp-harness integrate pi

Each agent has its own MCP config format, rules file, and quirks. The integrate command handles them all — one governance layer, any agent.

How it works

Every tool call flows through a five-stage pipeline:

Code
1. RECEIVE      MCP JSON-RPC request from agent
2. CLASSIFY     Knowledge-navigation or pass-through?
3. GOVERN       14-gate cascade (audience → temporal → budget → ...)
4. EXECUTE      Call downstream tool / return content
5. AUDIT        Log decision to append-only audit log

Classifier

The classifier examines each tool call and determines whether it targets governed knowledge. Read("docs/api.md") where docs/ is governed? Route through the planner. Read("package.json") where package.json isn't governed? Pass through. KCP tools (kcp_plan, kcp_load) are always governed.

Governor

Two automated modes, plus a human gate that outranks both:

  • Plan-first (fast path) — the agent calls kcp_plan first. The harness caches the approved plan. Subsequent reads are checked against the cached plan — no re-planning.
  • Auto-plan (fallback) — the agent reads a governed path without planning. The harness runs the planner automatically. Slower, but governance is enforced even for agents that don't know about kcp_plan.
  • Human approval — calls matching a governance.approvals rule are held for a named reviewer (pending), no matter what the automated paths would decide. Tickets survive restarts and resolve via the kcp-harness approvals CLI (or any custom ApprovalProvider channel). Resolutions require a named reviewer and a policy citation.

The 14-gate cascade

Every knowledge unit is evaluated through 14 deterministic gates, in order:

Code
audience → not_for → temporal → deprecated → supersession → relevance →
skill_eligibility → attestation → payment → access → strict → max_units →
money_budget → context_budget

A unit must pass all gates. The gate that blocks it is recorded in the decision trace. Same inputs → same plan. No model involved.

For the skill_eligibility gate's subject matter — governed kind: skill units — the authoring conventions, linter, and conformance vectors live in Cantara/kcp-skill.

MCP tools

Once connected, agents can use these governance tools:

ToolDescription
kcp_planDeterministic load plan — which units, in what order, which skipped and why
kcp_loadPlan + load eligible unit content
kcp_traceFull 14-gate decision trace
kcp_validateLint a knowledge.yaml
harness_statusCurrent governance state
harness_sessionApproved plans + known units for this session
harness_budgetItemized spend tracking
harness_temporal_checkPlan drift detection
harness_approvalsHuman-approval tickets (pending / approved / dismissed / expired)
harness_assessConfidence-gate a synthesized answer before acting on it

Compliance artifacts

Audit log

Append-only JSONL. Every decision — governed or pass-through — is logged with sequence number, timestamp, tool, targets, and governance decision:

bash
cat .kcp-harness/audit.jsonl | jq 'select(.governed == true)'

Budget ledger

Append-only itemized spend tracking. Per-currency running totals. Ceiling enforcement — a load that would exceed the budget is rejected atomically (no partial loads).

Temporal governance

Plans are registered with a temporal watcher. On subsequent calls, the watcher re-evaluates against the current time. If units have drifted (expired, newly valid), the harness emits a drift event. Long-running sessions stay honest.

Approval tickets

Calls matching an approval rule open a durable ticket (pending_review → approved | dismissed | expired). The ticket store survives restarts — sessions are ephemeral, human review is not. Every resolution records who approved, when, and which policy it satisfies — evidence generated at approval time, never reconstructed from logs.

Confidence verdicts

harness_assess runs kcp-agent's post-synthesis assess() over a synthesized answer before it may be acted on. The planner gates loading, grounding gates asserting, this gates acting. Below-threshold verdicts on routed configs open an approval ticket with the full verdict embedded as evidence.

Configuration

yaml
# harness.yaml
version: "1.0"

governance:
  domains:
    - manifest: "./knowledge.yaml"
      paths: ["docs/", "src/"]

  policy:
    fail_closed: true
    audit_all: true
    max_units: 5
    budget:
      amount: 1.00
      currency: USDC

  confidence:                  # optional post-synthesis gate (harness_assess)
    threshold: 0.7
    severity: critical
    route_to_role: account-owner

  approvals:                   # optional human-approval gates
    provider: file
    rules:
      - match: { tools: [Write, Edit], paths: [records/] }
        required_role: account-owner
        expires_after: 72h
        policy_ref: POL-7.2

audit:
  path: ".kcp-harness/audit.jsonl"

CLI

server.ts
kcp-harness serve  [--config harness.yaml]   Start the MCP proxy
kcp-harness init                             Create a harness.yaml template
kcp-harness check  [--config harness.yaml]   Validate configuration
kcp-harness integrate <agent> [options]       Generate agent integration files
kcp-harness integrate --list                  List supported agents
kcp-harness export   [options]               Export compliance evidence (SOC 2 / ISO 27001)
kcp-harness dashboard [options]              Launch the live compliance dashboard
kcp-harness approvals list [--state s]        List human-approval tickets
kcp-harness approvals approve <id> --reviewer <name> --policy-ref <ref>
kcp-harness approvals dismiss <id> --reviewer <name> --policy-ref <ref>

Library

server.ts
import { classify, govern, BudgetLedger, TemporalWatch } from "kcp-harness";
import { generate, listAgents } from "kcp-harness";

// Classify a tool call
const result = classify("Read", { file_path: "docs/api.md" }, governedDomains);

// Generate integration files
const output = generate("claude-code", { manifest: "./knowledge.yaml", paths: ["docs/"] });

Architecture

Code
┌──────────────────────────────────────────────┐
│  Layer 3: Integration Packages               │
│  Agent-specific configs + rules files        │
│  (claude-code, cursor, copilot, ...)         │
├──────────────────────────────────────────────┤
│  Layer 2: KCP Compliance Harness             │  ← THIS
│  MCP proxy — deterministic governance        │
├──────────────────────────────────────────────┤
│  Layer 1: kcp-agent (planner core)           │
│  14-gate cascade, decision traces            │
└──────────────────────────────────────────────┘

Forking agents puts you in competition. A harness puts you in composition.

Tests

Terminal
npm test     # 314 tests across 20 test files

Covers the classifier, governor (incl. approval precedence), approval state machine + providers, confidence-gate wiring, proxy, audit, budget ledger, temporal watch, evidence export, dashboard, and all agent integrations.

License

Apache-2.0 · By eXOReaction AS, hosted under Cantara.