MCPLow riskUnclaimed

VITNA – Containment for rogue AI agents

Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records.

costrinity.xyzcostrinity.xyz/vitna-compliance-preflightUpdated Oct 7, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "xyz.costrinity/vitna-compliance-preflight",
  "description": "Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records.",
  "title": "VITNA – Containment for rogue AI agents",
  "repository": {
    "url": "https://github.com/COSTRINITY/vitna-compliance-mcp",
    "source": "github"
  },
  "version": "0.5.4",
  "websiteUrl": "https://vitna.costrinity.xyz",
  "packages": [
    {
      "registryType": "npm",
      "registryBaseUrl": "https://registry.npmjs.org",
      "identifier": "@costrinity/vitna-compliance-mcp",
      "version": "0.5.4",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Your VITNA operator UUID. Optional: if unset, the first tool call self-provisions a restricted trial key. The old VIGIL_OWNER_ID name is still accepted.",
          "name": "VITNA_OWNER_ID"
        },
        {
          "description": "Your VITNA API key (new keys vitna_..., legacy vigil_... keys remain valid). Optional: self-provisioned if unset. The old VIGIL_API_KEY name is still accepted.",
          "isSecret": true,
          "name": "VITNA_API_KEY"
        },
        {
          "description": "Email to own the self-provisioned trial account. Optional: a throwaway is used if unset. It does not claim the account: claim it with GitHub or a passkey. The old VIGIL_EMAIL name is still accepted.",
          "name": "VITNA_EMAIL"
        },
        {
          "description": "VITNA base URL; override only for self-hosted. The old VIGIL_BASE_URL name is still accepted.",
          "default": "https://vitna.costrinity.xyz",
          "name": "VITNA_BASE_URL"
        },
        {
          "description": "Set to 1 to have the trial's claim link opened in your default browser when a trial starts. Either way the link is printed in the MCP server log, and the agent is never sent it.",
          "name": "VITNA_OPEN_CLAIM"
        }
      ]
    }
  ],
  "remotes": [
    {
      "type": "streamable-http",
      "url": "https://vitna.costrinity.xyz/api/mcp",
      "headers": [
        {
          "description": "Bearer <your VITNA API key>. Discovery (initialize, tools/list) and vitna_help work without it; every governed decision tool requires it. Get a key free at https://vitna.costrinity.xyz/dashboard. X-API-Key is also accepted.",
          "isSecret": true,
          "name": "Authorization"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@costrinity/vitna-compliance-mcp@0.5.4
Runs install scripts—None
Networkvitna.costrinity.xyzvitna.costrinity.xyz
Needs credentialsAuthorizationVITNA_API_KEYAuthorizationVITNA_API_KEY
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.5.4latestOct 7, 2026