MCP低风险未认领

policyvault

Non-custodial Kaspa policy enforcement for AI agents; signers retain custody.

zapsoblige-hashzapsoblige-hash/policyvault★ 1更新于 2026年9月15日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.zapsoblige-hash/policyvault",
  "description": "Non-custodial Kaspa policy enforcement for AI agents; signers retain custody.",
  "repository": {
    "url": "https://github.com/zapsoblige-hash/PolicyVault",
    "source": "github"
  },
  "version": "1.6.2",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "policyvault-mcp",
      "version": "1.6.2",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Bare origin of the PolicyVault server (e.g. https://app.policy-vault.org, or your self-hosted origin). Refused if it embeds credentials or a path.",
          "isRequired": true,
          "format": "string",
          "name": "POLICYVAULT_MCP_SERVER_URL"
        },
        {
          "description": "Machine-identity bearer credential (pvmk_...), minted by the vault operator in the PolicyVault app with exactly the scopes the agent should hold. Never logged; deleted from the process environment after being read.",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "POLICYVAULT_MCP_TOKEN"
        },
        {
          "description": "Optional comma-separated scope list to narrow which tools are advertised (display-side only; enforcement is always server-side).",
          "format": "string",
          "name": "POLICYVAULT_MCP_SCOPES"
        }
      ]
    }
  ],
  "_meta": {
    "io.modelcontextprotocol.registry/publisher-provided": {
      "authorityStatement": "AI MAY REQUEST. POLICYVAULT DETERMINISTICALLY DECIDES. THE COVENANT ENFORCES. SIGNERS RETAIN CUSTODY.",
      "custody": "This server holds no keys, signs nothing, broadcasts nothing. Every tool call is an ordinary authenticated HTTP request subject to server-side tenancy, scope, governance, risk, and covenant decisions.",
      "protocolRevisions": [
        "2025-11-25",
        "2025-06-18"
      ]
    }
  }
}

权限

声明检测
运行代码—node
安装—npm:policyvault-mcp@1.6.2
安装时运行脚本—无
网络无无
需要的凭据POLICYVAULT_MCP_TOKENPOLICYVAULT_MCP_TOKEN
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #11.6.2最新2026年10月7日