CCS MCP Server — 7-dimension runtime verification receipts for agent tool calls. Public mirror (project home: correctover.com).
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !Licence file present but not machine-readable
- !Install pipes a remote script into a shell (curl | sh)
- !README contains suspicious pattern: eval\s*\(
claude mcp add ccs -- npx -y ccs-mcp-server{
"mcpServers": {
"ccs": {
"command": "npx",
"args": ["-y", "ccs-mcp-server"]
}
}
}Resumen de MCP Servers
# CCS Runtime Evidence MCP Server
[](https://datatracker.ietf.org/doc/draft-correctover-ccs/)
[](https://www.npmjs.com/package/ccs-mcp-server)
A [Model Context Protocol (MCP)](https://modelcontextprotocol.io) server that brings **CCS runtime verification** to any MCP-compatible client — Claude Desktop, Cursor, Windsurf, and more.
It verifies AI agent tool calls at runtime, blocks unsafe ones by default, issues **tamper-evident evidence records** for every decision, and verifies that actual tool arguments match the agent's declared intent — catching cross-model parameter drift.
> **Runtime evidence layer, not a static scanner.** Every decision is enforced at call time and produces independently verifiable cryptographic evidence.
## ⚡ Quick Start — running in 30 seconds
```bash
npx -y ccs-mcp-server
```
Add it to any MCP client — paste this into your `mcpServers` config in Claude Desktop, Cursor or Cline:
```json
{
"mcpServers": {
"ccs-runtime-evidence": {
"command": "npx",
"args": ["-y", "ccs-mcp-server"]
}
}
}
```
Or install from the official MCP Registry: search **"Correctover"** inside your client, or open [registry.modelcontextprotocol.io](https://registry.modelcontextprotocol.io/) and find `io.github.Correctover/ccs`.
No API key, no account, no environment variables required — an Ed25519 signing key is generated automatically on first run (set `CCS_KEY_DIR`, or `CCS_PRIVATE_KEY`/`CCS_PUBLIC_KEY`, only if you want to pin a persistent key). Zero dependencies. Pure Node.js stdlib (Node ≥ 18). No install scripts.
## Tools
| Tool | Purpose |
|---|---|
| `verify_tool_call` | 7-dimension runtime verification (Structure/Schema/Security/Identity/Integrity/Latency/Cost) + semantic attack-chain analysis + math overflow detection. **Blocks by default.** |
| `issue_evidence` | Issue a tamper-evident evidence record (`content_hash` + `evidence_hash`, chainable). Produced for allowed AND denied calls. |
| `audit_mcp_config` | Audit MCP configuration JSON for security risks. |
| `verify_intent_binding` | Verify actual tool arguments match a declared intent — zero tolerance, zero LLM calls. Catches cross-model parameter drift (planner says `amount: 100`, executor writes `amount: 10000` → DENIED). |
| `verify_receipt` | Offline-verify a CCS Ed25519-signed receipt: checks the signature against the embedded signer public key, reports tampering, and optionally pins an expected signer key or fingerprint. |
## Intent Binding — Cross-Model Drift Detection
Agent planners (Claude, GPT) declare one thing; executors (Qwen, DeepSeek) sometimes write another. No existing protocol verifies that actual tool call arguments match the agent's declared intent:
- **AP2** signs human authorization — not LLM intent
- **AgentPay** does baseline tolerance (1%) — not zero-tolerance equivalence
- **ACS** runs policy decisions — not argument-level equivalence
- **VAP** (draft-samal-vap-00) explicitly excludes argument semantics from its wire schema
CCS Intent Binding fills this layer. The agent framework declares a structured intent before execution; CCS verifies actual arguments against it in sub-millisecond, zero-LLM time.
### Example: amount drift
```json
// Intent declared by planner
{
"intent_id": "int-001",
"intent_type": "payment",
"fields": {
"amount": { "value": 100, "binding_mode": "exact" },
"recipient": { "value": "Alice", "binding_mode": "exact" }
},
"issued_at": 1755000000000,
"ttl_ms": 30000
}
// Actual arguments from executor
{ "amount": 10000, "recipient": "Alice" }
// Result: DENIED — intent_arg_mismatch
// field: amount, expected: 100, actual: 10000
```
### Three binding modes
| Mode | Behavior | Example |
|------|----------|---------|
| `exact` | Deep equality with math normalization | `100`, `100.0`, `1e2` all match; `10000` does not |
| `numeric_tolerance` | Absolute tolerance | `100 ± 0.01` matches `100.005` |
| `pattern` | Regex match on string fields | `^[A-Z]{3}$` matches `"USD"` |
No intent declared? Falls through to standard 7-dimension verification. Zero breaking changes.
## What It Detects
- **Command injection**: shell metacharacters, `curl|sh`, `rm -rf`, `eval()`
- **Path traversal**: `../`, `/etc/passwd`, `/proc/self/`
- **SSRF**: `169.254.169.254` (cloud metadata), localhost, private ranges — across any tool
- **Cross-tool attack chains**: read sensitive file → network exfil = `exfil_chain`
- **Environment variable exfiltration**: API keys, secrets, credentials
- **Obfuscation**: hex encoding, base64, privilege escalation signals
- **Math safety**: integer overflow (>2^53-1), NaN/Infinity
- **MCP config risks**: plain HTTP, weak secrets, `--insecure`, TLS disabled
## Evidence Chain
Every decision produces evidence with dual hashes (`content_hash` + `evidence_hash`) and chain linkage (`parent_evidence_hash`). Any third party can independently verify that evidence has not been tampered with — without trusting the operator.
```
evidence 1: allowed (fs.read_file) parent: null
evidence 2: denied (shell.exec curl|sh) parent: ev1
evidence 3: denied (http.fetch SSRF) parent: ev2
evidence 4: denied (fs + curl exfil) parent: ev3
```
Receipts are Ed25519-signed and JSON-based: verify them offline with the built-in `verify_receipt` tool, or independently with any Ed25519 library. Cross-tool receipt verification (same crypto, chain linkage, field mapping) is designed to work without this package installed.
## The 7 CCS Dimensions
1. **Structure** — valid tool name, argument format, nesting depth, payload size
2. **Schema** — type, required fields, enums, ranges, string lengths
3. **Security** — injection, traversal, SSRF, env exfiltration, obfuscation + semantic attack chains
4. **Identity** — caller agent ID verification
5. **Integrity** — request hash validation
6. **Latency** — execution time budget
7. **Cost** — cost budget
## Protocol Context
- **IETF**: [draft-correctover-ccs](https://datatracker.ietf.org/doc/draft-correctover-ccs/) — an individual Internet-Draft; not an RFC or IETF endorsement, and the Datatracker page is authoritative for revision and status
- **Complements**: [VAP draft-samal-vap-00](https://datatracker.ietf.org/doc/draft-samal-vap/) (scope/budget/purpose), [Microsoft ACS](https://github.com/microsoft/agent-governance-toolkit) (policy decisions), AP2 (human authorization)
- **Does not replace**: authentication, payment networks, policy engines
## Links
- npm: https://www.npmjs.com/package/ccs-mcp-server
- GitHub: https://github.com/DSHCorrectover/ccs-mcp-server
- IETF Draft: https://datatracker.ietf.org/doc/draft-correctover-ccs/
- PyPI (full verifier): https://pypi.org/project/ccs-verifier/
## License
Elastic License 2.0 (ELv2). See [LICENSE](LICENSE).
Lo que la gente pregunta sobre ccs-mcp-server
¿Qué es DSHCorrectover/ccs-mcp-server?
+
DSHCorrectover/ccs-mcp-server es mcp servers para el ecosistema de Claude AI. CCS MCP Server — 7-dimension runtime verification receipts for agent tool calls. Public mirror (project home: correctover.com). Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-09-09.
¿Cómo se instala ccs-mcp-server?
+
Puedes instalar ccs-mcp-server clonando el repositorio (https://github.com/DSHCorrectover/ccs-mcp-server) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar DSHCorrectover/ccs-mcp-server?
+
Nuestro agente de seguridad ha analizado DSHCorrectover/ccs-mcp-server y le ha asignado un Trust Score de 62/100 (tier: OK). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene DSHCorrectover/ccs-mcp-server?
+
DSHCorrectover/ccs-mcp-server es mantenido por DSHCorrectover. La última actividad registrada en GitHub es del 2026-09-09, con 0 issues abiertos.
¿Hay alternativas a ccs-mcp-server?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega ccs-mcp-server en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/dshcorrectover-ccs-mcp-server)<a href="https://claudewave.com/repo/dshcorrectover-ccs-mcp-server"><img src="https://claudewave.com/api/badge/dshcorrectover-ccs-mcp-server" alt="Featured on ClaudeWave: DSHCorrectover/ccs-mcp-server" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!