MCP server implementing the Attested Governance Artifact protocol — cryptographic compliance for autonomous systems
AGA MCP Server demonstrates solid tool definition practices with consistent naming conventions, descriptive tool purposes, and structured input schemas using Zod. However, there are notable gaps in parameter descriptions, output schema documentation, and error handling guidance. All 13 tools follow a verb_noun naming pattern and include descriptions, but parameter-level documentation is inconsistent, many object properties lack detailed descriptions. Output schemas are returned as JSON text via a generic 'j()' helper but are not formally documented in tool registration. Error handling provides basic error returns but lacks actionable recovery guidance for agents. The server implements core AGA protocol functionality well, but falls short of production-grade tool design in terms of parameter validation documentation and downstream chaining support.
Attest subject, generate sealed Policy Artifact. Auto-loads into portal. (Claims 1a-1d)
Create merkle checkpoint from continuity chain. (Claim 3)
Privacy-preserving claim disclosure with substitution policy. (Claim 2)
Generate offline-verifiable evidence bundle. (Claim 9)
Retrieve continuity chain events with optional filtering.
Get current enforcement parameters and disclosure policy.
Get current portal state, loaded artifact info, and enforcement status.
Parameter descriptions incomplete or missing for nested object properties. 'subject_metadata' object properties (filename, version, author, content_type) have no descriptions, and 'evidence_items' array items lack property documentation.
Output schemas not formally documented in tool registration. All tools return generic JSON via 'j()' helper. LLMs cannot infer response structure without explicit schema documentation, they only see that a 'text' field is returned.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Get AGA server info, public keys, and portal state.
Initialize continuity chain with genesis event. (Claim 3a)
Measure subject state, compare to sealed reference. Generates signed receipt for every measurement. (Claims 1e-1g)
Revoke loaded artifact mid-session. (Claim 3b NCCoE)
Verify evidence bundle offline (no server needed). (Claim 9)
Verify continuity chain cryptographic integrity.
Error handling lacks actionable recovery guidance. Error responses (e.g., 'Chain already initialized', 'User not found' hypothetically) do not indicate whether agents should retry, ask the user, or stop. Missing error classification patterns.
Sensitive operations (revoke_artifact, attest_subject) lack confirmation or dry-run patterns. An agent could invoke revoke_artifact with a casual reason string and immediately revoke mid-session attestations without a confirmation step.
Chain event filtering and pagination not supported. get_chain_events accepts from_sequence and to_sequence but no limit/offset or pagination cursor. Large chains could return unbounded results, exhausting context windows.
Tool-to-tool chaining not optimized. Tools like create_checkpoint and generate_evidence_bundle return data structures but do not include downstream-required IDs. e.g., generate_evidence_bundle result should include receipt_ids for use in subsequent verification calls.