{"_id":"@agfpd/totp-presence-mcp","_rev":"5-5dc3552fb35f6723e89a59cfbfc8f85b","name":"@agfpd/totp-presence-mcp","dist-tags":{"latest":"0.2.5"},"versions":{"0.2.0":{"name":"@agfpd/totp-presence-mcp","version":"0.2.0","keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"author":{"url":"https://github.com/agfpd","name":"agfpd"},"license":"Apache-2.0","_id":"@agfpd/totp-presence-mcp@0.2.0","maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"homepage":"https://github.com/agfpd/totp-presence-plugin","bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"bin":{"totp-presence-mcp":"bin/totp-presence-mcp.mjs"},"dist":{"shasum":"29c795995192ef5387f459d31ad714578ff47f1c","tarball":"https://registry.npmjs.org/@agfpd/totp-presence-mcp/-/totp-presence-mcp-0.2.0.tgz","fileCount":6,"integrity":"sha512-p7RdsDT37cbM/OpwpW9QmrJXe9T157ZgC5qQWdBACkzfwsawCdAxDNhQZ4h/esOJabAKabD3Jrf9wbu+xGFocw==","signatures":[{"sig":"MEUCIF8Cb5ht3X8lHzo9BqRpmtMM5dhKK2Ad3mPccopYLrrsAiEAsdIjvLrh5l9c5A2KS9zRlTWiZ6vXb77tZHI9E3xBLhE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36588},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"cfc3cbcf47699e8acc1e687e2d5277d86bfda2c2","scripts":{"test":"node --test tests/*.test.mjs","start":"node bin/totp-presence-mcp.mjs","version":"node scripts/sync-plugin-version.cjs && git add VERSION .claude-plugin/plugin.json .codex-plugin/plugin.json delivery/marketplace-entry.claude.json delivery/marketplace-entry.codex.json","prepublishOnly":"test -z \"$(git status --porcelain)\" || (echo 'release: working tree is dirty — commit or stash before publish' >&2 && exit 1)"},"_npmUser":{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"},"repository":{"url":"git+https://github.com/agfpd/totp-presence-plugin.git","type":"git"},"_npmVersion":"11.12.1","description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Three tools — totp_verify / totp_check_session / totp_status — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky ","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/totp-presence-mcp_0.2.0_1780702082736_0.8981687610802791","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@agfpd/totp-presence-mcp","version":"0.2.1","keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"author":{"url":"https://github.com/agfpd","name":"agfpd"},"license":"Apache-2.0","_id":"@agfpd/totp-presence-mcp@0.2.1","maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"homepage":"https://github.com/agfpd/totp-presence-plugin","bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"bin":{"totp-presence-mcp":"bin/totp-presence-mcp.mjs"},"dist":{"shasum":"158dc9acf7560ee9f24e37a8619f0742851a95e6","tarball":"https://registry.npmjs.org/@agfpd/totp-presence-mcp/-/totp-presence-mcp-0.2.1.tgz","fileCount":6,"integrity":"sha512-PMKSCWuQdfx5v0eDFmGuQ43wprA+6lRzmjrE4BBSMT4rt6NiylcMU3l+kCJ48yJSnh++KlWbrWNMQbeWmElj8g==","signatures":[{"sig":"MEUCIGWpuHPkfKCLOkVe4pDmstqfrc/D/dyaGfOgoIZWQKugAiEAsmdpImdU6vXDrEWVhBp73+5QLWQuPu6Xs2kO0hjxpUk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34519},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"aff6ddad8aac8919e0f9f6f0b4dfc97ff14f4d00","scripts":{"test":"node --test tests/*.test.mjs","start":"node bin/totp-presence-mcp.mjs","version":"node scripts/sync-plugin-version.cjs && git add VERSION .claude-plugin/plugin.json .codex-plugin/plugin.json delivery/marketplace-entry.claude.json delivery/marketplace-entry.codex.json","prepublishOnly":"test -z \"$(git status --porcelain)\" || (echo 'release: working tree is dirty — commit or stash before publish' >&2 && exit 1)"},"_npmUser":{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"},"repository":{"url":"git+https://github.com/agfpd/totp-presence-plugin.git","type":"git"},"_npmVersion":"11.12.1","description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Two tools — totp_verify / totp_check_session — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky actions. The ser","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/totp-presence-mcp_0.2.1_1780737785897_0.46677626136637906","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@agfpd/totp-presence-mcp","version":"0.2.2","keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"author":{"url":"https://github.com/agfpd","name":"agfpd"},"license":"Apache-2.0","_id":"@agfpd/totp-presence-mcp@0.2.2","maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"homepage":"https://github.com/agfpd/totp-presence-plugin","bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"bin":{"totp-presence-mcp":"bin/totp-presence-mcp.mjs"},"dist":{"shasum":"a3be184327335607c8185470114d1880a1484ac8","tarball":"https://registry.npmjs.org/@agfpd/totp-presence-mcp/-/totp-presence-mcp-0.2.2.tgz","fileCount":6,"integrity":"sha512-eBj9re8z7otxNkBLqUQTFKJhhc1hx1meJB+s5aXNvREIqyEht4fesfPn+BrCWWKKOYbQkrr+oDvLnMr6/+Q9xQ==","signatures":[{"sig":"MEYCIQDCiWKJ5+iNhovXWtyPZ9OzHeFKPMANxHHtPQ42zxhDWwIhAK5TeSyckA6BVajkfMf5XRUhqkCqQa7Q8V4X/bBCk12+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34678},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"56320f1489010b59e6f4f74e3a59c676e318a37b","scripts":{"test":"node --test tests/*.test.mjs","start":"node bin/totp-presence-mcp.mjs","version":"node scripts/sync-plugin-version.cjs && git add VERSION .claude-plugin/plugin.json .codex-plugin/plugin.json delivery/marketplace-entry.claude.json delivery/marketplace-entry.codex.json","prepublishOnly":"test -z \"$(git status --porcelain)\" || (echo 'release: working tree is dirty — commit or stash before publish' >&2 && exit 1)"},"_npmUser":{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"},"repository":{"url":"git+https://github.com/agfpd/totp-presence-plugin.git","type":"git"},"_npmVersion":"11.12.1","description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Two tools — totp_verify / totp_check_session — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky actions. The ser","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/totp-presence-mcp_0.2.2_1780759545878_0.04532046604059303","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@agfpd/totp-presence-mcp","version":"0.2.3","keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"author":{"url":"https://github.com/agfpd","name":"agfpd"},"license":"Apache-2.0","_id":"@agfpd/totp-presence-mcp@0.2.3","maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"homepage":"https://github.com/agfpd/totp-presence-plugin","bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"bin":{"totp-presence-mcp":"bin/totp-presence-mcp.mjs"},"dist":{"shasum":"869f371013efe7808b136e2827f82b583e8c3727","tarball":"https://registry.npmjs.org/@agfpd/totp-presence-mcp/-/totp-presence-mcp-0.2.3.tgz","fileCount":6,"integrity":"sha512-eG7bInaLUNEGmHX92TVGRC9xqtG25XAkX3Zn40hRpGtYZlDg7Zd6VeATC35yKg+DO9wFYQJZhaIq97i0HcfbyA==","signatures":[{"sig":"MEYCIQD+MSYx3U9DSsLGdtO48fKwMWUNFUG97nI/cjRCu4XZsgIhAPr1UpzwLL4yhSxSiTU3HnT5WHVGaw8B8odu/aP227iP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34522},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"04658b22f6543ee62c3324183a754cf4910aeb19","scripts":{"test":"node --test tests/*.test.mjs","start":"node bin/totp-presence-mcp.mjs","version":"node scripts/sync-plugin-version.cjs && git add VERSION .claude-plugin/plugin.json .codex-plugin/plugin.json delivery/marketplace-entry.claude.json delivery/marketplace-entry.codex.json","prepublishOnly":"test -z \"$(git status --porcelain)\" || (echo 'release: working tree is dirty — commit or stash before publish' >&2 && exit 1)"},"_npmUser":{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"},"repository":{"url":"git+https://github.com/agfpd/totp-presence-plugin.git","type":"git"},"_npmVersion":"11.12.1","description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Two tools — totp_verify / totp_check_session — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky actions. The ser","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/totp-presence-mcp_0.2.3_1781377671683_0.28558762208611177","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@agfpd/totp-presence-mcp","version":"0.2.5","description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Two tools — totp_verify / totp_check_session — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky actions. The ser","license":"Apache-2.0","author":{"name":"agfpd","url":"https://github.com/agfpd"},"homepage":"https://github.com/agfpd/totp-presence-plugin","repository":{"type":"git","url":"git+https://github.com/agfpd/totp-presence-plugin.git"},"bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"type":"module","bin":{"totp-presence-mcp":"bin/totp-presence-mcp.mjs"},"scripts":{"start":"node bin/totp-presence-mcp.mjs","test":"node --test tests/*.test.mjs","version":"node scripts/sync-plugin-version.cjs && git add VERSION .claude-plugin/plugin.json .codex-plugin/plugin.json delivery/marketplace-entry.claude.json delivery/marketplace-entry.codex.json","prepublishOnly":"test -z \"$(git status --porcelain)\" || (echo 'release: working tree is dirty — commit or stash before publish' >&2 && exit 1)"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"engines":{"node":">=18.0.0"},"gitHead":"0c7b9d2f714272a8718dafb6588271a06215e844","_id":"@agfpd/totp-presence-mcp@0.2.5","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-35fra4K6IV0BdfDJFbkt/XxGSmGY61lt/pY/1ojPG2vcayjrV36OvjvQ2jJg0OeGpmYdIcbugrgN83AhrOAk4g==","shasum":"b353cbcd67774bdf972dde7b4b367f96e1c1c37d","tarball":"https://registry.npmjs.org/@agfpd/totp-presence-mcp/-/totp-presence-mcp-0.2.5.tgz","fileCount":6,"unpackedSize":34550,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDN8UteLSwdx3rAPMjQou2aq71oEYWbx6Jje4L+IitJNAiB5SRChJV2Ps6njBR9pYG8guQZMu5B4YXbBBeuF7mKy6g=="}]},"_npmUser":{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"},"directories":{},"maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/totp-presence-mcp_0.2.5_1781392774407_0.6022685582637608"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-05T23:28:02.550Z","modified":"2026-06-13T23:19:34.688Z","0.2.0":"2026-06-05T23:28:02.871Z","0.2.1":"2026-06-06T09:23:06.042Z","0.2.2":"2026-06-06T15:25:46.070Z","0.2.3":"2026-06-13T19:07:51.822Z","0.2.5":"2026-06-13T23:19:34.545Z"},"bugs":{"url":"https://github.com/agfpd/totp-presence-plugin/issues"},"author":{"name":"agfpd","url":"https://github.com/agfpd"},"license":"Apache-2.0","homepage":"https://github.com/agfpd/totp-presence-plugin","keywords":["claude-code","codex","mcp","model-context-protocol","iapeer","security","totp","prompt-injection","presence","totp-presence"],"repository":{"type":"git","url":"git+https://github.com/agfpd/totp-presence-plugin.git"},"description":"MCP server for the totp-presence identity-gate plugin (Claude Code + Codex CLI). Two tools — totp_verify / totp_check_session — wrap the root-owned /etc/totp-presence/verify so an agent can prove the physical owner is present before risky actions. The ser","maintainers":[{"name":"agfpd-owner","email":"agafapudov.art@gmail.com"}],"readme":"# totp-presence-plugin\n\nPlug-and-play [totp-presence](https://github.com/agfpd/totp-presence) for\n**Claude Code** and **Codex CLI** — a deterministic, channel-independent\nowner-presence gate against prompt injection.\n\n> **STATUS: v0.1.1 — released** via the `agfpd-marketplace`. SOFT live, HARD\n> opt-in. Deferred: Codex HARD beyond best-effort; Windows (WSL only); Linux\n> (experimental until live-tested). Architecture and phase history: `CLAUDE.md`.\n\n## Modes\n\n- **SOFT (default, zero-sudo, one command):** MCP tools\n  (`totp_verify` / `totp_check_session`) the agent calls itself,\n  plus a tiny conditional SessionStart directive. Advisory — cannot DENY a tool\n  call; `tamper_resistant: false`.\n- **HARD (opt-in, two honest actions — one sudo, one phone pairing):** a\n  root-anchored PreToolUse guard fail-closes every gated tool (read-only tools\n  pass by design) until a fresh presence window is open. Claude: full `.*`\n  coverage. Codex: best-effort (Bash/apply_patch/mcp__ only).\n\n## Install\n\n```\n# Claude Code (per-project scope; add the agfpd marketplace once if needed)\nclaude plugin marketplace add agfpd/agfpd-marketplace\nclaude plugin install totp-presence@agfpd --scope project\n# Codex CLI (host-global)\ncodex plugin add totp-presence@agfpd\n```\n\nThe source repo is **private** (`agfpd` org), so installing requires read access\nto the org (git/gh authenticated) — the same access model as every other agfpd\nplugin. The MCP server is published separately on npm as\n[`@agfpd/totp-presence-mcp`](https://www.npmjs.com/package/@agfpd/totp-presence-mcp)\nand `.mcp.json` launches it via `npx`, so **Node ≥18 must be on `PATH`** (npx\nfetches and runs it on first session start).\n\nRestart the session afterward — `hooks.json` / `.mcp.json` are not hot-reload.\nSOFT (advisory MCP) is live immediately. For HARD: `/totp-presence:totp-setup`\n(one guided sudo + pair the phone once), then restart. Confirm with\n`/totp-presence:totp-status`. (Codex has no slash commands — the same operations\nare the `totp-setup` / `totp-status` skills, which Claude also surfaces as those\n`/name`s.)\n\n## Capability matrix\n\n| | SOFT (default) | HARD (opt-in) |\n|---|---|---|\n| Install cost | one command, zero sudo | one guided sudo + one phone pairing |\n| What it does | MCP tools the agent calls itself + a tiny conditional SessionStart directive | root-anchored PreToolUse guard fail-closes every gated tool until a fresh presence window |\n| Can DENY a tool call? | no (advisory) | yes |\n| `tamper_resistant` | `false` | `true` |\n| Claude Code reach | this project (`--scope project`) | this project; full `.*` tool coverage |\n| Codex CLI reach | host-global | host-global; best-effort (Bash + apply_patch + `mcp__` only; headless `codex exec` does not fire the hook) |\n\nThe trust core (`/etc/totp-presence`: seed, verifier, sudoers) is **host-global** —\n`core_installed` / `tamper_resistant` are host properties. But where HARD actually\nfires is asymmetric: on Claude it is per-project; on Codex it is host-global but\npartial. So `tamper_resistant: true` means \"the host has a root anchor,\" not\n\"every agent on this machine is gated.\" `/totp-presence:totp-status` reports the live\nmatrix with no false assurance.\n\n## Honest ceiling\n\nSOFT installs plug-and-play with zero sudo; the two human actions apply only to\nHARD. True zero-step HARD is impossible without gutting the guarantee — granting\nroot once and pairing the phone once ARE the product. Windows native is\nunsupported (WSL only); Linux is experimental until live-tested.\n\nApache-2.0 © Artur Agafapudov. Trust core copied byte-for-byte from the audited\nupstream primitive.\n","readmeFilename":"README.md"}