Constitutional AI governance server with 13 canonical MCP capability tools. Open-source governance decision point for AI agent actions. Evaluates proposed actions against constitutional policy floors (F1-F13) and returns SEAL/HOLD/SABAR/VOID verdicts before execution. Append-only audit ledger (VAULT999), Streamable HTTP transport.
arifOS exhibits significant quality gaps across the tool suite. While the server claims 14 tools with ambitious descriptions, the actual implementation reveals incomplete schemas, missing parameter type definitions, and descriptions that are domain-specific philosophy rather than LLM-actionable guidance. The codebase shows sophisticated backend logic (constitutional AI frameworks, VAULT999 ledger, ZK verification), but the MCP tool interface, what agents actually interact with, lacks rigor. Critical issues: (1) Parameter type definitions are absent or incomplete for most tools; (2) Descriptions read like domain manifestos ('Constitutional verdict engine') rather than actionable usage guides; (3) No visible output schemas documented; (4) Error handling and recovery guidance are absent; (5) Tools like arif_authorize_agent expose credentials as parameters (credentials object), violating secret-injection patterns. The server prioritizes architectural complexity (13 floors, governance verdicts, audit ledgers) over tool usability and LLM comprehension.
Semantic reasoning tool — analyzes intent, evidence quality, and constitutional alignment using embeddings and heuristic ASI floors (F5, F6, F9)
VAULT999 append-only ledger query tool — retrieves immutable evidence chain and governance verdicts from the audit ledger
Agent authentication and authorization gate (AAA organ) — verifies agent identity via JWT, validates authority credentials, and gates tool access based on F11 Authority floors
Wealth/asset calculation tool (WEALTH organ) — calculates portfolio metrics, risk scores, and financial compliance across asset classes
Geoscience discovery tool (GEOX organ) — searches and analyzes geoscience literature, well data, and subsurface models; calculates petrophysical properties
Reversibility analysis tool — determines if a proposed action is reversible, partially reversible, or irreversible; used by F2 TRUTH and F12 DEFENSE floors
Parameter type definitions are incomplete or absent for most tools. Tool schemas show object-level descriptions (e.g., 'Proposed action with intent, evidence, reversibility metadata') but lack explicit field-level typing (required vs optional, string vs array vs object substructure). This violates JSON Schema best practices and forces LLMs to guess parameter structure.
arif_authorize_agent exposes credentials (JWT, OAuth token, API key) as a tool parameter object. This violates secret-injection pattern, credentials MUST be injected server-side via environment or vault, never passed as parameters. Agent call traces will log these secrets, leaking them into logs and prompt history.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | 2026-07-28+ | v2 |
| 2026-03-12 | F | 25 | - | v1 |
Fetch remote content with sanitization — retrieves and parses HTML, JSON, or document content from URLs with defusing and HTML sanitization
Constitutional verdict engine — evaluates action against all 13 floors (F1-F13) and returns SEAL/HOLD/SABAR/VOID verdict with reasoning
Structured audit logging tool — writes immutable log entries to VAULT999 ledger with cryptographic proof-of-chain (BLAKE3)
Well integrity measurement tool (WELL organ) — analyzes well logs, petrophysics, and subsurface measurements from LAS/SEG-Y data
Ground truth verification tool — queries external reality state (fact-checking, web search, API calls) to establish evidence baseline before reasoning
Document parsing and extraction tool (IO organ) — extracts structured data from PDFs, DOCX, XLSX, and images using OCR and semantic understanding
Semantic knowledge search — queries vector database (Qdrant) for semantically similar experiences, precedents, and floor evaluations from prior governance decisions
Zero-knowledge proof verification tool (ZKPC v2) — verifies Groth16 proofs and other ZK circuits using snarkjs for cryptographic proof validation
Output schemas are not documented. Tool descriptions mention return values ('returns SEAL/HOLD/SABAR/VOID verdict with reasoning', 'retrieves immutable evidence chain') but provide no structured schema. LLMs cannot plan downstream tool calls or extract specific fields without knowing the response structure. No evidence of a documented 'returns' section in any tool definition.
Descriptions are domain-philosophy rather than LLM-actionable. E.g., 'Constitutional verdict engine, evaluates action against all 13 floors (F1-F13) and returns SEAL/HOLD/SABAR/VOID verdict with reasoning'. A user/LLM unfamiliar with the arifOS framework cannot understand WHEN to call this, WHAT the 13 floors are, or what SEAL/HOLD/SABAR/VOID mean. Baseline: good descriptions answer what, when, and how. These answer only what in domain jargon.
No error handling or recovery guidance. None of the tool descriptions include error classification, retry guidance, or actionable error messages. E.g., arif_search_knowledge provides no guidance on what to do if the semantic query returns no results. Pattern guidance: errors must tell the LLM what to do next.
Enum constraints are underutilized. Several tools accept 'enum' parameters (e.g., arif_fetch_remote has format=[html|json|text|markdown|pdf], arif_calculate_wealth has calculation_type=[portfolio_value|risk_score|compliance_check]) but most tools with categorical parameters (e.g., arif_audit_vault query_type, arif_measure_well log_type, arif_discover_geox scope) define enums but no validation or enforcement is visible in the schema definitions provided.
No pagination or result-limiting guidance. Tools like arif_audit_vault (queries an append-only ledger), arif_search_knowledge (semantic search over vector DB), and arif_discover_geox (literature search) could return hundreds or thousands of results, but descriptions provide no mention of pagination, limits, or result caps. Without pagination, large result sets exhaust context windows.
Parameter naming inconsistency and clarity. Some tools accept generic object parameters (e.g., 'action' object in arif_invoke_judgment, 'filters' object in arif_audit_vault, 'credentials' object in arif_authorize_agent) with no guidance on required vs optional subfields or expected structure. LLMs cannot construct these without trial-and-error.