{"_id":"@aumos/trusted-mcp","name":"@aumos/trusted-mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@aumos/trusted-mcp","version":"0.1.0","description":"TypeScript client for the AumOS TrustedMCP security proxy — policy management, audit log access, and tool allowlist control","license":"Apache-2.0","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","typecheck":"tsc --noEmit"},"devDependencies":{"typescript":"^5.3.0"},"keywords":["aumos","trusted-mcp","mcp","security-proxy","policy","typescript"],"repository":{"type":"git","url":"git+https://github.com/invincible-jha/trusted-mcp.git"},"_id":"@aumos/trusted-mcp@0.1.0","gitHead":"132f524a1f5dd4dea06a2465628e1ad52494c90f","bugs":{"url":"https://github.com/invincible-jha/trusted-mcp/issues"},"homepage":"https://github.com/invincible-jha/trusted-mcp#readme","_nodeVersion":"22.18.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-NFjQ4bT3/GEybhO30pJrAd40b1KkMfMGHyoHmgeGjEECgWiLpocxsWengMs4XWy+mny97VjtgcughCaLo8ZLig==","shasum":"45bf21cc976eeaa54fc65ffa536975d83e5ba9d7","tarball":"https://registry.npmjs.org/@aumos/trusted-mcp/-/trusted-mcp-0.1.0.tgz","fileCount":23,"unpackedSize":72933,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCcFZP9p0lDgXinlCyXk6fLaVAORQvcHMR8qVc7SXxdnwIgHJ4GE3iublZ099JSBpeimLlLGD5mSepRa6m8tcCHAWM="}]},"_npmUser":{"name":"invinciblejha","email":"vikram@muveraai.com"},"directories":{},"maintainers":[{"name":"invinciblejha","email":"vikram@muveraai.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/trusted-mcp_0.1.0_1772243817054_0.995871451469976"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-28T01:56:56.963Z","0.1.0":"2026-02-28T01:56:57.214Z","modified":"2026-02-28T01:56:57.457Z"},"maintainers":[{"name":"invinciblejha","email":"vikram@muveraai.com"}],"description":"TypeScript client for the AumOS TrustedMCP security proxy — policy management, audit log access, and tool allowlist control","homepage":"https://github.com/invincible-jha/trusted-mcp#readme","keywords":["aumos","trusted-mcp","mcp","security-proxy","policy","typescript"],"repository":{"type":"git","url":"git+https://github.com/invincible-jha/trusted-mcp.git"},"bugs":{"url":"https://github.com/invincible-jha/trusted-mcp/issues"},"license":"Apache-2.0","readme":"# @aumos/trusted-mcp\n\nTypeScript client for the [AumOS TrustedMCP](https://github.com/invincible-jha/trusted-mcp)\nsecurity proxy. Manage policies, inspect audit logs, control tool allowlists, and build\nYAML scan policies programmatically.\n\n## Requirements\n\n- Node.js 18+ (uses native Fetch API)\n- TypeScript 5.3+ (strict mode)\n\n## Installation\n\n```bash\nnpm install @aumos/trusted-mcp\n```\n\n## Usage\n\n### HTTP client\n\n```ts\nimport { createTrustedMCPClient } from \"@aumos/trusted-mcp\";\n\nconst client = createTrustedMCPClient({\n  baseUrl: \"http://localhost:8092\",\n  timeoutMs: 10_000,\n});\n\n// Check proxy health\nconst status = await client.getProxyStatus();\nif (status.ok) {\n  console.log(\"Healthy:\", status.data.healthy);\n  console.log(\"Blocked today:\", status.data.blocked_calls_today);\n}\n\n// Retrieve current proxy configuration\nconst config = await client.getProxyConfig();\n\n// Retrieve audit log with filtering\nconst log = await client.getAuditLog({\n  agentId: \"my-agent\",\n  outcome: \"blocked\",\n  limit: 50,\n});\nif (log.ok) {\n  for (const entry of log.data.entries) {\n    console.log(`[${entry.timestamp}] ${entry.tool_name} → ${entry.outcome}`);\n  }\n  // Paginate if there are more results\n  if (log.data.next_cursor !== null) {\n    const nextPage = await client.getAuditLog({ cursor: log.data.next_cursor });\n  }\n}\n\n// Update the active scan policy\nconst updatedPolicy = await client.updatePolicy({\n  name: \"strict-prod\",\n  prompt_injection_enabled: true,\n  pii_detection_enabled: true,\n  malicious_payload_enabled: true,\n  block_threshold: \"high\",\n  scan_tool_inputs: true,\n  scan_tool_outputs: false,\n  custom_patterns: [],\n});\n\n// Manage tool allowlist\nconst allowlist = await client.getToolAllowlist({ enabledOnly: true });\n\nconst newRule = await client.addAllowlistRule({\n  tool_pattern: \"web_search\",\n  action: \"allow\",\n  agent_id: \"*\",\n  enabled: true,\n  description: \"Allow web search for all agents\",\n  priority: 10,\n});\n\nawait client.deleteAllowlistRule(\"rule-id-to-remove\");\n```\n\n### Policy builder\n\n```ts\nimport { createPolicyBuilder } from \"@aumos/trusted-mcp\";\n\n// Build a policy object for the update API\nconst policy = createPolicyBuilder(\"strict-prod\")\n  .withPromptInjectionScanning(true)\n  .withPiiDetection(true)\n  .withMaliciousPayloadScanning(true)\n  .withBlockThreshold(\"high\")\n  .withToolInputScanning(true)\n  .withToolOutputScanning(false)\n  .addCustomPattern(\"(?i)internal_api_key\")\n  .build();\n\nawait client.updatePolicy(policy);\n\n// Serialise to YAML for GitOps / policy-as-code workflows\nconst lenient = createPolicyBuilder(\"dev-lenient\")\n  .withBlockThreshold(\"critical\")\n  .withPiiDetection(false)\n  .toYaml();\n\nconsole.log(lenient);\n// # TrustedMCP Scan Policy\n// ---\n// name: dev-lenient\n// prompt_injection_enabled: true\n// pii_detection_enabled: false\n// ...\n\n// Clone and branch a policy\nconst stricterPolicy = createPolicyBuilder(\"base\")\n  .withBlockThreshold(\"medium\")\n  .clone()\n  .withToolOutputScanning(true)\n  .addCustomPattern(\"CONFIDENTIAL\")\n  .build();\n```\n\n## API reference\n\n### `createTrustedMCPClient(config)`\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `baseUrl` | `string` | required | TrustedMCP proxy URL |\n| `timeoutMs` | `number` | `10000` | Request timeout (ms) |\n| `headers` | `Record<string, string>` | `{}` | Extra HTTP headers |\n\n#### Methods\n\n| Method | Description |\n|--------|-------------|\n| `getProxyStatus()` | Live health and call-count metrics |\n| `getProxyConfig()` | Active runtime configuration |\n| `getAuditLog(options?)` | Paginated, filtered audit log |\n| `updatePolicy(policy)` | Replace the active scan policy |\n| `getToolAllowlist(options?)` | Retrieve all allowlist rules |\n| `addAllowlistRule(rule)` | Add a new allowlist rule |\n| `deleteAllowlistRule(ruleId)` | Remove an allowlist rule |\n| `getToolCallResult(entryId)` | Retrieve the result of a specific proxied call |\n\n### `createPolicyBuilder(name)`\n\n| Method | Description |\n|--------|-------------|\n| `withPromptInjectionScanning(enabled)` | Toggle prompt-injection scanning |\n| `withPiiDetection(enabled)` | Toggle PII detection |\n| `withMaliciousPayloadScanning(enabled)` | Toggle malicious-payload scanning |\n| `withBlockThreshold(threshold)` | Set minimum severity for block action |\n| `withToolInputScanning(enabled)` | Toggle scanning of tool-call inputs |\n| `withToolOutputScanning(enabled)` | Toggle scanning of tool-call outputs |\n| `addCustomPattern(pattern)` | Add a custom regex pattern |\n| `clearCustomPatterns()` | Remove all custom patterns |\n| `build()` | Return a `ScanPolicy` object (without server-assigned fields) |\n| `toYaml()` | Serialise to YAML string for policy-as-code |\n| `clone()` | Deep-copy the builder for branched derivation |\n\n### Allowlist actions\n\n| Action | Description |\n|--------|-------------|\n| `allow` | Permit the tool call unconditionally |\n| `deny` | Block the tool call unconditionally |\n| `require_approval` | Gate the tool call on human approval |\n\n## License\n\nApache-2.0. See [LICENSE](../../LICENSE) for details.\n","readmeFilename":"README.md","_rev":"1-bd5d215e9aee32fff5476042c79a6596"}