{"_id":"@civaapple/qi-mcp","_rev":"2-5f5496a2615997a332ec4eb96c4ad9ff","name":"@civaapple/qi-mcp","dist-tags":{"latest":"0.5.1"},"versions":{"0.5.0":{"name":"@civaapple/qi-mcp","version":"0.5.0","license":"MIT","_id":"@civaapple/qi-mcp@0.5.0","maintainers":[{"name":"civaapple","email":"civaapple@gmail.com"}],"homepage":"https://github.com/civaapple-alt/qi#readme","bugs":{"url":"https://github.com/civaapple-alt/qi/issues"},"dist":{"shasum":"2508f90a84e7e34305c748ef9e80ceb9f4801d81","tarball":"https://registry.npmjs.org/@civaapple/qi-mcp/-/qi-mcp-0.5.0.tgz","fileCount":12,"integrity":"sha512-RyFp4YQByAUSs2iCHlhVkIxrNbM0LlPX3XBAgSB3s9YdFttSbyBX4CktGP0q8IAPtOviwI7MliEznGY0RecsIQ==","signatures":[{"sig":"MEUCIBrjtRHAUoc9ELkJwbnc86fQAZ5nErwHnXEp5NYsi/frAiEAy5O03bNlgPzB2tG2aHDP/TttHLgkwGiFOZVwu+tmc5s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@civaapple%2fqi-mcp@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":128890},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"9ae76a92cdcce130958d3f93c6ab5ba20149d424","_npmUser":{"name":"civaapple","email":"civaapple@gmail.com"},"repository":{"url":"git+https://github.com/civaapple-alt/qi.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.16.0","description":"Quarantine and explicit binding boundary between MCP discovery and Qi Tools","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@sinclair/typebox":"0.34.52","@civaapple/qi-tools":"0.5.0","@civaapple/qi-capability":"0.5.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/qi-mcp_0.5.0_1785137665131_0.28843323675088617","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@civaapple/qi-mcp","version":"0.5.1","description":"Quarantine and explicit binding boundary between MCP discovery and Qi Tools","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"engines":{"node":">=22.19.0"},"dependencies":{"@civaapple/qi-capability":"0.5.1","@civaapple/qi-tools":"0.5.1","@sinclair/typebox":"0.34.52"},"repository":{"type":"git","url":"git+https://github.com/civaapple-alt/qi.git","directory":"packages/mcp"},"homepage":"https://github.com/civaapple-alt/qi#readme","bugs":{"url":"https://github.com/civaapple-alt/qi/issues"},"license":"MIT","publishConfig":{"access":"public","provenance":true},"gitHead":"8b042be6fb43eda223b619286e9b3e5cb1e1c439","_id":"@civaapple/qi-mcp@0.5.1","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-pYFN1Ke9oSpZFJBWUiL4j56hVKoQJh9cDMzwuaFR8F07tcnMIWVSACFJYOgzYGWfZ7WwwoFcimKxPG3CaQ3GHw==","shasum":"22f51de5cbd13baf05c0f93364e14c6662664a11","tarball":"https://registry.npmjs.org/@civaapple/qi-mcp/-/qi-mcp-0.5.1.tgz","fileCount":12,"unpackedSize":128890,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@civaapple%2fqi-mcp@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEbsmBHtCVI2dLaUuF0y0ckzJvecmoNFsX1nPzp8INf6AiEAjAcF5FkOkLwM8Ey0wTcVzApn7gdQsthiO/FzCViSeMw="}]},"_npmUser":{"name":"civaapple","email":"civaapple@gmail.com"},"directories":{},"maintainers":[{"name":"civaapple","email":"civaapple@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/qi-mcp_0.5.1_1785149325730_0.10840360721133968"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-27T07:34:24.960Z","modified":"2026-07-27T10:48:46.164Z","0.5.0":"2026-07-27T07:34:25.284Z","0.5.1":"2026-07-27T10:48:45.864Z"},"bugs":{"url":"https://github.com/civaapple-alt/qi/issues"},"license":"MIT","homepage":"https://github.com/civaapple-alt/qi#readme","repository":{"type":"git","url":"git+https://github.com/civaapple-alt/qi.git","directory":"packages/mcp"},"description":"Quarantine and explicit binding boundary between MCP discovery and Qi Tools","maintainers":[{"name":"civaapple","email":"civaapple@gmail.com"}],"readme":"# `@civaapple/qi-mcp`\n\nA quarantine and binding boundary between MCP discovery and Qi's authorized Tool Registry.\n\n## Purpose\n\n`McpBridge` discovers remote tool metadata without making it executable. A separate explicit binding maps a\nreviewed remote candidate into a local tool definition, with normal schema, capability, artifact, and settlement\ncontrols.\n\n## Non-goals\n\n- MCP server availability or discovery does not imply trust.\n- Remote descriptions do not grant local capabilities.\n- The bridge does not bypass the Tool Registry or expose unlimited remote output to context.\n\n## Core model\n\n`McpTransport` lists and invokes remote tools. Discovery creates quarantined `McpToolCandidate` records. Only an\nexplicit `McpToolBinding` enters the local catalog, where every call is independently authorized.\n\n## Behavioral invariants\n\n- Discovered tools are inert until bound.\n- Binding is explicit and schema-aware.\n- Each invocation receives a fresh capability decision.\n- Oversized output becomes an Artifact reference instead of unbounded context.\n\n## Failure semantics\n\nDiscovery, binding, authorization, transport, remote execution, and output-size failures remain separate. A\nremote failure never becomes a trusted local success.\n\n## Install and minimal use\n\n```sh\nnpm install @civaapple/qi-mcp\n```\n\n```ts\nimport { McpBridge } from \"@civaapple/qi-mcp\";\n\nconst bridge = new McpBridge(\"example\", {\n  async listTools() {\n    return [];\n  },\n  async callTool() {\n    throw new Error(\"No remote Tools are bound\");\n  },\n});\n\nconsole.log(await bridge.discover()); // [] — discovery alone registers nothing.\n```\n\n## Public API\n\n`McpBridge` and the remote tool, transport, candidate, and binding interfaces.\n\n## Change guide\n\nTreat every new transport as untrusted input. Preserve quarantine and require an explicit resource/effect mapping\nbefore registry exposure.\n\n## Verification\n\n`tests/mcp-bridge.test.mjs` covers quarantine, explicit binding, per-call authority, and Artifact fallback.\n\n## Further reading\n\n- [Trust boundary](docs/trust-boundary.md)\n- [Tool execution contract](../tools/docs/execution-contract.md)\n","readmeFilename":"README.md"}