honesty-mcp

MCPcommunity
v0.2.0Lucas KopietzMITUpdated 2d agonpmGitHub

MCP server exposing the eleven-kit 'honesty SDK' family (grounding-kit, corroboration-kit, payout-invariance-kit, mutation-invariance-kit, trust-core, provenance-kit, claims-registry-kit, audit-chain-kit, advice-ledger-kit, agent-receipt-kit, cost-governo

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
489Downloads/wk
2d agoLast update
Package
AuthorLucas Kopietz
LicenseMIT
Version0.2.0
Sourcenpm+mcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface14 tools · none privileged
Security scan✓ Cleanv0.2.0 · todayHow well does this scan work?
EvalsNone
IndexedOct 2, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

14 tools · none privileged
Statically extracted from the published packagev0.2.0 · 17h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

grade_decisionGrades one recommendation-and-decision pair against a before/after observation log. Compares a pre-

Grades one recommendation-and-decision pair against a before/after observation log. Compares a pre-

No input schema was published for this tool.

compute_divergenceComputes how often two independent judges (e.g. an automated engine and a human override) rated the

Computes how often two independent judges (e.g. an automated engine and a human override) rated the

No input schema was published for this tool.

scaffold_agent_receiptsagent-receipt-kit is a RUNTIME LIBRARY your own agent-orchestration code imports and calls at two

agent-receipt-kit is a RUNTIME LIBRARY your own agent-orchestration code imports and calls at two

No input schema was published for this tool.

append_audit_entryAppends one entry to an append-only, hash-chained audit log and returns the new (longer) chain.

Appends one entry to an append-only, hash-chained audit log and returns the new (longer) chain.

No input schema was published for this tool.

verify_audit_chainIndependently re-verifies a hash chain from genesis: recomputes every entry's hash and confirms

Independently re-verifies a hash chain from genesis: recomputes every entry's hash and confirms

No input schema was published for this tool.

check_claims_registryKeeps public-facing product claims honest over time by checking each one against its own claimed

Keeps public-facing product claims honest over time by checking each one against its own claimed

No input schema was published for this tool.

corroborate_evidenceGrades the supplied evidence for a claim and reports two things: the evidence direction

Grades the supplied evidence for a claim and reports two things: the evidence direction

No input schema was published for this tool.

scaffold_cost_governorcost-governor-kit is a RUNTIME LIBRARY your app installs and calls at the moment it's about to make

cost-governor-kit is a RUNTIME LIBRARY your app installs and calls at the moment it's about to make

No input schema was published for this tool.

check_groundingChecks citation markers and lexical support in AI-generated text. Splits `text` into checked units and

Checks citation markers and lexical support in AI-generated text. Splits `text` into checked units and

No input schema was published for this tool.

check_mutation_invarianceChecks -- for the scenarios you supply, not a formal proof for every possible input -- whether a

Checks -- for the scenarios you supply, not a formal proof for every possible input -- whether a

No input schema was published for this tool.

check_payout_invarianceChecks -- for the specific scenarios you supply, not a formal proof for every possible payout

Checks -- for the specific scenarios you supply, not a formal proof for every possible payout

No input schema was published for this tool.

check_provenance_claimsScans reader-facing claims for certainty-implying language ("(verified)", "independently

Scans reader-facing claims for certainty-implying language ("(verified)", "independently

No input schema was published for this tool.

assess_anonymous_authenticityScores how organic a corpus of UNATTRIBUTED, scraped sentiment signals (crawled mentions, imported

Scores how organic a corpus of UNATTRIBUTED, scraped sentiment signals (crawled mentions, imported

No input schema was published for this tool.

score_trust_identifiedScores one entity (or one dimension of one entity -- quality, reliability, communication, ...) from

Scores one entity (or one dimension of one entity -- quality, reliability, communication, ...) from

No input schema was published for this tool.

14 of 14 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

MCP server exposing the eleven-kit 'honesty SDK' family (grounding-kit, corroboration-kit, payout-invariance-kit, mutation-invariance-kit, trust-core, provenance-kit, claims-registry-kit, audit-chain-kit, advice-ledger-kit, agent-receipt-kit, cost-governo

Keywords
mcpmodel-context-protocolhonestygroundingcitation-checkingtrustprovenanceaudit-logai-safetycoding-agent
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-02 — observed resolution, not a publisher declaration.

60 packages resolved · 13 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

63 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+51 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.