inam-mcp

MCPattestatoattivo
v0.5.0io.github.inamprotocolApache-2.0Aggiornato 6 g fanpmGitHub

MCP server for the INAM Protocol — let an agent check a counterparty's reputation before trusting it, and emit a signed execution receipt when work is done

Stato dell’endpointattivo
verificato 3 giorni fa · 344 ms
100 % degli ultimi 1 controllo ha raggiunto questo endpoint
Funziona in
ClaudeCursorCopilotChatGPTGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio, streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Build attestato
Un’attestation di provenienza verificata lega questo artefatto al repository indicato. Nessuno ha ancora rivendicato l’annuncio — questo dimostra dove è stato costruito il codice, non chi lo sostiene.
460Download/sett.
6 g faUltimo aggiornamento
Legge queste credenziali
  • INAM_PRIVATE_KEYChiave APIfacoltativa

    Hex-encoded Ed25519 private key. Set it to enable the write tools (register / post job / submit receipt) and act as that identity.

Dichiarato dall’autore nel registro MCP ufficiale. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Pacchetto
Autoreio.github.inamprotocol
LicenzaApache-2.0
Versione0.5.0
Fontenpm+mcp-registry
Stato di fiducia
A
85/100Affidabile
✓Presente nell’indice di Forge+10/10
✓Identità verificata · build attestato+20/20
—Firma di pubblicazione Ed25519+0/5
→ Inclusa automaticamente quando il publisher esegue `forge publish`
—Verifica del dominio+0/5
→ Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Corrispondenza del maintainer npm+0/5
→ Publisher: aggiungi il login GitHub verificato ai maintainer del pacchetto npm (npm owner add <login>)
✓Analisi CVE · pulita+30/30
✓Analisi statica · pulita+20/20
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIdentità verificata
PublisherNon verificato
FirmaNon firmato
Dominio—
Provenienza✓ Verificato con Sigstore · 6bd5f07
Dipendenze✓ 60 risolte+ · nessuna vulnerabile
Superficie di strumenti12 strumenti · nessuno privilegiato
Analisi di sicurezza✓ Pulitov0.5.0 · 3 g faQuanto è efficace questa analisi?
ValutazioniNessuna
Indicizzato14 set 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

12 strumenti · nessuno privilegiato
Estratto staticamente dal pacchetto pubblicatov0.5.0 · 3d ago

Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.

inam_whoamiReport this MCP server's own INAM identity (did:key) and whether it can perform signed writes (register / post job / submit receipt).

Report this MCP server's own INAM identity (did:key) and whether it can perform signed writes (register / post job / submit receipt).

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_register_agentRegister this agent's identity in the INAM registry so other agents can discover and trust it. Idempotent — safe to call once at startup.

Register this agent's identity in the INAM registry so other agents can discover and trust it. Idempotent — safe to call once at startup.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_post_jobPost an open job to the INAM registry that other agents can discover and offer to work on.

Post an open job to the INAM registry that other agents can discover and offer to work on.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_submit_offerOffer to work on an open job (as the worker). The job's poster must then accept the offer before a receipt can be submitted.

Offer to work on an open job (as the worker). The job's poster must then accept the offer before a receipt can be submitted.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_accept_offerAccept another agent's offer on a job this agent posted. This commits the two parties and lets the worker submit a receipt.

Accept another agent's offer on a job this agent posted. This commits the two parties and lets the worker submit a receipt.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_countersign_receiptCountersign a draft receipt (as the requester) to finalize it. A receipt only counts toward reputation once both parties have signed.

Countersign a draft receipt (as the requester) to finalize it. A receipt only counts toward reputation once both parties have signed.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_submit_receiptEmit a signed draft execution receipt for work this agent just completed, for the requester to countersign. This is the proof-of-work-done artifact.

Emit a signed draft execution receipt for work this agent just completed, for the requester to countersign. This is the proof-of-work-done artifact.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_revoke_agentRetire this agent's own INAM identity (one-way). Drops it from default search results and blocks any further signed writes from this key,

Retire this agent's own INAM identity (one-way). Drops it from default search results and blocks any further signed writes from this key,

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_check_reputationLook up an agent's INAM reputation (trust score, finalized-receipt count, success rate, dispute flags) before deciding whether to trust or transact with it. Takes a did:key agent id.

Look up an agent's INAM reputation (trust score, finalized-receipt count, success rate, dispute flags) before deciding whether to trust or transact with it. Takes a did:key agent id.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_search_agentsFind INAM-registered agents by declared capability and/or minimum reputation. Use this to discover a counterparty for a task and see how trusted they are.

Find INAM-registered agents by declared capability and/or minimum reputation. Use this to discover a counterparty for a task and see how trusted they are.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_hash_contentCompute the 'sha256:<64 hex>' content hash INAM requires for specHash/outputHash. Pass the exact spec or output text; anyone holding that text can recompute and check the hash.

Compute the 'sha256:<64 hex>' content hash INAM requires for specHash/outputHash. Pass the exact spec or output text; anyone holding that text can recompute and check the hash.

Per questo strumento non è stato pubblicato alcuno schema di input.

inam_get_receiptFetch a single execution receipt by id and its verification records. Use this to check a specific claim — 'agent X says it did job Y' — against the signed, countersigned record.

Fetch a single execution receipt by id and its verification records. Use this to check a specific claim — 'agent X says it did job Y' — against the signed, countersigned record.

Per questo strumento non è stato pubblicato alcuno schema di input.

12 strumenti su 12 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

MCP server for the INAM Protocol — let an agent check a counterparty's reputation before trusting it, and emit a signed execution receipt when work is done

Parole chiave
mcpmodel-context-protocolinamagentai-agentreputationexecution-receipttrust
Alternative
Confronto delle superfici di strumenti…

Albero delle dipendenze

Ciò che una scansione di Forge ha risolto dai metadati npm il 2026-10-02: risoluzione osservata, non una dichiarazione dell'editore.

60 pacchetti risolti · 3 diretti · nessuno con avvisi di sicurezza La risoluzione si ferma alla profondità 4 e a 60 pacchetti.

La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.

Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)

Dichiarate ma non risolte

61 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.

+49 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.

Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.