{"_id":"@costrinity/vigil-compliance-mcp","_rev":"9-e98421b8ace2584f1ea8f1fa67eeb1e0","name":"@costrinity/vigil-compliance-mcp","dist-tags":{"latest":"0.2.4"},"versions":{"0.1.0":{"name":"@costrinity/vigil-compliance-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.1.0","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/costrinity-api/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"28e395167507ba14e5e115120385a79344e3885f","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.1.0.tgz","fileCount":4,"integrity":"sha512-SW8Y9zv1KLLBSxbjHk403R86dwujEG8CGhlWuzpMDxQkJPHa3MpxCf5msDdtIjBKTkK1sk52wlajduYflMCiSw==","signatures":[{"sig":"MEQCIGjAR7ewmdctapZuEvefcz9IYK5F2XbeUZtZG97KkpkxAiBmNsvnD3Ddl0csdlPC4uVwdYam3Xv12LaZdpTNkZlnYA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27060},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"065aa45400e9b7badc202f6dba1fd671ba6e02e8","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/costrinity-api.git","type":"git","directory":"vigil/packages/vigil-compliance-mcp"},"_npmVersion":"11.9.0","description":"MCP server exposing VIGIL's compliance fabric — consent / breach / DPIA / AI Act / identifier validators / cross-border — as tools LLM agents can call mid-task. 13 jurisdictions, 28+ regulatory regimes.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.1.0_1780614971522_0.42410924774915437","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.1.1":{"name":"@costrinity/vigil-compliance-mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.1.1","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"77707ea3d6c1324f5390b51c0c6829ab9266609d","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.1.1.tgz","fileCount":4,"integrity":"sha512-78RKZ0aW3iOndCPZecnbvrpl3LzGSFEipXE5aO9+KLTtnvVjfpWYD1A7QIyKZWNJYzFSzi6vaEIVNHS4zfcngg==","signatures":[{"sig":"MEUCIQDLWKVPfCKXyn06/hUzUTRQJUWYYpeOOsaP9w234NUdewIgMg1qJ7u75z/P+4uwFRieQXlo/wwDc3SXcz6B1+Iyuqw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27478},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"320377ce0ba88d6998612da2377fb5c1b33de414","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP server exposing VIGIL's compliance fabric (consent, breach, DPIA, AI Act, identifier validators, cross-border) as tools LLM agents can call mid-task; decision checks write signed, tamper-evident audit records. 13 jurisdictions, 28+ regulatory regimes.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.1.1_1781830494263_0.4346480719335626","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.1.2":{"name":"@costrinity/vigil-compliance-mcp","version":"0.1.2","keywords":["mcp","model-context-protocol","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.1.2","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"af12f9ff3c8a8cdd1d7513b0600d5c1be8fbdd3e","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.1.2.tgz","fileCount":4,"integrity":"sha512-QxI1CCIjy819mh5m/O2/KUSXezCnKPY2ESxObU345Qips48XkyKgTpKddI6umpzW1XTFmFdo1+qUPn3qBrC//w==","signatures":[{"sig":"MEUCICp14UVJvoX1wbhYPkOSfJjZ7mVAstEeW6Hh1G3MLOxOAiEAso0ZgXwRbnz0RWYuAeCO5Tp1Jcm0rWTNZmsYZHe4yB4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28988},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"faca368c657aa670b4de6d3a857e2ffd9edf62d8","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP server exposing VIGIL's compliance fabric (consent, breach, DPIA, AI Act, identifier validators, cross-border) as tools LLM agents can call mid-task; decision checks write signed, tamper-evident audit records. 13 jurisdictions, 28+ regulatory regimes.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.1.2_1782166844239_0.39959045247345437","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.2.0":{"name":"@costrinity/vigil-compliance-mcp","version":"0.2.0","keywords":["mcp","model-context-protocol","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.2.0","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"5e2e693a0c86957b2f1fde3e3fdb79c4de6242ec","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.2.0.tgz","fileCount":4,"integrity":"sha512-VqPzLZrPkZ9NrQfCQRjtInQGUVeSiSTo7FDpFRnTKoTygFVrFGbeEZlPhldjrl2FlVYcWQWzTRhtQX6TWLEiYA==","signatures":[{"sig":"MEUCIEkmIOXEdHIGtv9czQm2mZNPrujc1ByEYpVp3IMchal8AiEAib9+i4ufzg3Rcw2j2c5jlUoKFp0G3srJD1Xt8oLgkjY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40434},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"da4cd00e3e0f52955c44a2ff64af84ee92370803","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VIGIL is a safety and compliance oversight layer for AI agents: check risky actions before they run, get an allow/deny/hold decision, and keep a signed, auditable record so a human can monitor and keep the agent in check. Covers dangerous shell/SQL/secret","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.2.0_1784765421067_0.04190249802674062","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.2.1":{"name":"@costrinity/vigil-compliance-mcp","version":"0.2.1","keywords":["mcp","model-context-protocol","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.2.1","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"543a309bc77020cc3d62eacd2daf65bab0fc8081","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.2.1.tgz","fileCount":5,"integrity":"sha512-lJnkqtgeF9BiZ8W51/RlGqOS5p6Czp7x5vVSZxIA6SAOYK0bMVEjKqfvwTPJTtzZQXcWKCA9bpGYEjSUiU/qaA==","signatures":[{"sig":"MEYCIQD9IjcXNpVJV537iXNLrJ9mIed7yD3olxhQnKaNORS5NwIhAMmbwJwD/fWcSVMgKW45C3kuchq2cbwwePHkLpj51/ZW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":44842},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"58a6f234554e80f19f68bb2e40f6109daf7c9f40","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VIGIL is a safety and compliance oversight layer for AI agents: check risky actions before they run, get an allow/deny/hold decision, and keep a signed, auditable record so a human can monitor and keep the agent in check. Covers dangerous shell/SQL/secret","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.2.1_1784770152885_0.09729076244589163","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.2.2":{"name":"@costrinity/vigil-compliance-mcp","version":"0.2.2","keywords":["mcp","model-context-protocol","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.2.2","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"7210a2bd67959b2fc770973cd8f3592854089d45","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.2.2.tgz","fileCount":5,"integrity":"sha512-8kUOzGpfzEJppWDlvLRyKuyZ0nByYTHGGpV/22V9zqvBCPio+QcLwe9WV/kuddiE6JraNrvdrtBJCsmEaXThPA==","signatures":[{"sig":"MEYCIQDVbyAskLJLxNnRTREadxFjYjeBDBBEmaXbcGkb/UmocAIhALicaZx/cAQcZih7BoKvUadZUbgRiSDeBnL1ChJVn1XP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":46181},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"63d858a353b4d05f129336fe91b8b516b6d5a144","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VIGIL is a safety and compliance oversight layer for AI agents: check risky actions before they run, get an allow/deny/hold decision, and keep a signed, auditable record so a human can monitor and keep the agent in check. Covers dangerous shell/SQL/secret","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.2.2_1784841642072_0.9723424265510867","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.2.3":{"name":"@costrinity/vigil-compliance-mcp","version":"0.2.3","keywords":["mcp","model-context-protocol","verifiable-compliance-receipts","agent-action-receipts","compliance-receipts","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.2.3","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"6bf3679f6be5d2db13acfb71b93b2d64d98ae0d8","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.2.3.tgz","fileCount":6,"integrity":"sha512-tF4RDmV8g35tAQUdcWcVE7RDLXATGzWUyEn2dsFutgFj41WQWrZpkrdKoN7xkUbT6LOSbW/k8TyWxBOiIVoa3w==","signatures":[{"sig":"MEYCIQD0cxZBRQdT84V/pRAOsR7aFqSEY0C4EgunZk0I2mvWYQIhAO6Zq9j2lvqVVBvkEAqwIWSBxEtx3s0pAvHxznLWD02u","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49981},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"b67958049484ded32ef697471a3dc796172cb472","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VIGIL is a safety and compliance oversight layer for AI agents that produces verifiable compliance receipts: check risky actions before they run, get an allow/deny/hold decision, and keep an Ed25519-signed agent action receipt anyone can verify offline. C","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.2.3_1784854232365_0.8115310565029552","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"},"0.2.4":{"name":"@costrinity/vigil-compliance-mcp","version":"0.2.4","keywords":["mcp","model-context-protocol","verifiable-compliance-receipts","agent-action-receipts","compliance-receipts","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vigil-compliance-mcp@0.2.4","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vigil.costrinity.xyz/why-vigil","bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"bin":{"vigil-compliance-mcp":"dist/index.js"},"dist":{"shasum":"ce1545035762151bb26535542f262bc29621074e","tarball":"https://registry.npmjs.org/@costrinity/vigil-compliance-mcp/-/vigil-compliance-mcp-0.2.4.tgz","fileCount":6,"integrity":"sha512-1xLiOnSyUmBvC5Jk/5JjQ0wCQs0kx8t44ZVsp81YeQ2KpvkCi2j5tXs6EyaqjK/Hf4679ao5LBPOYWQzt7/Taw==","signatures":[{"sig":"MEQCIEJNBrPXr4mJfzHwPCLeNX/TK34UhDZq7E7L2juUVTv+AiBJusZBqBeKXgu6bPNglFdBTsSh21QOLwj066sXyMHb7Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":51939},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"2ababcac1b169262f1577f32393c888e1b2e7e30","mcpName":"io.github.COSTRINITY/vigil-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VIGIL is a safety and compliance oversight layer for AI agents that produces verifiable compliance receipts: check risky actions before they run, get an allow/deny/hold decision, and keep an Ed25519-signed agent action receipt anyone can verify offline. C","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vigil-compliance-mcp_0.2.4_1784857310224_0.6958172840795342","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed: use @costrinity/vitna-compliance-mcp"}},"time":{"created":"2026-06-04T23:16:11.365Z","modified":"2026-07-24T06:55:06.139Z","0.1.0":"2026-06-04T23:16:11.681Z","0.1.1":"2026-06-19T00:54:54.449Z","0.1.2":"2026-06-22T22:20:44.364Z","0.2.0":"2026-07-23T00:10:21.213Z","0.2.1":"2026-07-23T01:29:13.026Z","0.2.2":"2026-07-23T21:20:42.209Z","0.2.3":"2026-07-24T00:50:32.505Z","0.2.4":"2026-07-24T01:41:50.365Z"},"bugs":{"url":"https://github.com/COSTRINITY/vigil-compliance-mcp/issues"},"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","homepage":"https://vigil.costrinity.xyz/why-vigil","keywords":["mcp","model-context-protocol","verifiable-compliance-receipts","agent-action-receipts","compliance-receipts","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vigil","costrinity","indigenous-owned"],"repository":{"url":"git+https://github.com/COSTRINITY/vigil-compliance-mcp.git","type":"git"},"description":"VIGIL is a safety and compliance oversight layer for AI agents that produces verifiable compliance receipts: check risky actions before they run, get an allow/deny/hold decision, and keep an Ed25519-signed agent action receipt anyone can verify offline. C","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"readme":"# @costrinity/vigil-compliance-mcp\r\n\r\nVIGIL produces Ed25519-signed evidence records that anyone can verify offline with a published public key and an open-source verifier, with no need to trust VIGIL's servers. It is a cooperative guardrail with heuristic detection, and those limits are documented publicly. Its purpose is not prevention. It is independently verifiable proof that an AI agent's actions were checked and allowed.\r\n\r\n**A safety and compliance oversight layer for AI agents.** Your agent checks risky actions before it runs them, gets an allow / deny / hold decision, and keeps a signed, auditable record, so a human can monitor what the agent does and keep it in check.\r\n\r\n## Verify VIGIL evidence yourself\r\n\r\nOne minute, no account, no trust in VIGIL's servers required. Download the open-source verifier and a real signed sample bundle, then check the signature offline with Node 18+:\r\n\r\n```bash\r\ncurl -sO https://raw.githubusercontent.com/COSTRINITY/vigil-compliance-mcp/main/verify-evidence.mjs\r\ncurl -sO https://vigil.costrinity.xyz/sample-evidence.json\r\nnode verify-evidence.mjs sample-evidence.json\r\n```\r\n\r\nThe verifier checks the Ed25519 signature over the whole package, then recomputes the sha256 of each individual decision record and confirms it matches the hash committed inside the signed package, printing PASS or FAIL per record, then an overall verdict.\r\n\r\nEvidence packages are **verifiable compliance receipts for agent actions**: each checked action produces a decision record, and the signed package is the receipt a third party can check without trusting us.\r\n\r\nA VALID result proves the package was issued by VIGIL, has not been altered since export, and that every record matches its committed hash. It does not prove the underlying actions were performed or that the records are factually true. Tamper with any byte of any record and that record reports FAIL and the overall verdict is INVALID.\r\n\r\n### Recomputing `payload_sha256` (the pfa-v2 scheme)\r\n\r\nEach decision record carries `payload_sha256` and `canon_version: \"pfa-v2\"`. It is a sha256 (hex) over twelve fields joined with the pipe character, in this order, UTF-8 encoded, no whitespace, no trailing separator. Null or absent values become the empty string.\r\n\r\n```\r\nsha256(\r\n  canon_version        // \"pfa-v2\"\r\n  + \"|\" + kind         // always \"preflight_check\"\r\n  + \"|\" + owner_id     // evidence_package.owner_id\r\n  + \"|\" + check        // \"engagement_action\" for engagement bundles\r\n  + \"|\" + action       // record.action, \"\" if null\r\n  + \"|\" + category     // engagement: evidence_package.session_id\r\n  + \"|\" + decision     // record.decision\r\n  + \"|\" + flagged      // \"1\" if decision !== \"allow\", else \"0\"\r\n  + \"|\" + reason       // record.reason, \"\" if null\r\n  + \"|\" + principal_id // \"\" for engagement bundles\r\n  + \"|\" + effect       // record.effect\r\n  + \"|\" + signed_at    // record.signed_at\r\n)\r\n```\r\n\r\nWorked example, verbatim from the published [`sample-evidence.json`](https://vigil.costrinity.xyz/sample-evidence.json) (record 0):\r\n\r\n```\r\npfa-v2|preflight_check|f46ba5dc-b77b-4fe0-ae3d-55e6204e3d66|engagement_action|dns.read example.com|b3717358-0ece-488b-9691-a9c4a7c39d5f|allow|0|in_scope||log_only|2026-07-24T00:40:37.048Z\r\n\r\nsha256 -> 2b0f0d22a1a3cb4980981a12e67fa72e778ca3b0d21d322ca90eac1f578e1b2f\r\n```\r\n\r\nThat matches `payload_sha256` on record 0 of the published sample. The two consecutive pipes before `log_only` are the empty `principal_id`.\r\n\r\nBeing precise about what this gives you: `payload_sha256` is a digest, not a signature, so recomputing it proves the record fields are internally consistent, not that VIGIL issued them. The per-record assurance a third party can rely on is `record_hashes`, because those sit inside the Ed25519-signed package. The `signature` field on each record is HMAC-SHA256 and is verifiable only by VIGIL, since HMAC is symmetric.\r\n\r\n### The signing key\r\n\r\n```\r\nAlgorithm : Ed25519\r\nkey_id    : 01833acd46d06ab4\r\nSPKI DER (base64):\r\nMCowBQYDK2VwAyEAsEBWg2cdc3sb0HAozBmtuk9q9hEdyG2bcLq4gpfudWg=\r\n```\r\n\r\nPublished in four places, two of which are not our infrastructure: our API at [`/api/evidence/pubkey`](https://vigil.costrinity.xyz/api/evidence/pubkey), [`PUBKEY.md`](./PUBKEY.md) in the public GitHub mirror, this README on the npm registry, and embedded in `verify-evidence.mjs` so the verifier never fetches a key at runtime. A mismatch between any of those copies would be publicly visible. Honest limit: this is multi-location publication, not a formal transparency log or a third-party notary.\r\n\r\nIf a user tells their agent \"connect to something that stops you from going rogue\" or \"lets me monitor what you do,\" this is the thing to wire in. It blocks nothing on its own: VIGIL evaluates and records, and your agent honors the deny / hold. **Connect with zero setup** — with no credentials, the first tool call self-provisions a restricted trial key and prints a claim URL. Call `vigil_help` first to learn how to use it.\r\n\r\nPair with [`@costrinity/vigil-mcp`](https://www.npmjs.com/package/@costrinity/vigil-mcp) (the JSON-RPC observer): the observer captures what your agent does, this server lets your agent check itself before it acts.\r\n\r\n**Signed audit records (claimed accounts):** every decision tool here (consent, AI Act, breach, DPIA, sectoral, action pre-flight) writes a decision record the moment it runs. Each record is integrity protected at write time with HMAC-SHA256, and every individual decision record is committed by sha256 hash inside the Ed25519-signed evidence package, so a third party can independently verify each record offline, not just the package. Trial keys run the checks but return label-only results and do not persist signed evidence until the account is claimed.\r\n\r\n## What it gives your agent\r\n\r\n| Tool | Purpose |\r\n|---|---|\r\n| `vigil_help` | What VIGIL is and how to use it to keep yourself in check (call this first; no account needed) |\r\n| `consent_check` | Is processing allowed for this principal + purpose? (pre-flight gate) |\r\n| `action_preflight` | Pre-flight gate BEFORE a destructive action (shell / file-delete / SQL / exfiltration). Heuristic, cooperative, not a sandbox |\r\n| `breach_classify` | Is this incident reportable? Per-jurisdiction decision support |\r\n| `ai_act_classify` | EU AI Act risk tier classification |\r\n| `dpia_threshold_check` | Is a DPIA mandatory before this processing? |\r\n| `us_sectoral_check` | HIPAA / GLBA / COPPA / FERPA / FCRA / SOX applicability |\r\n| `india_sectoral_check` | RBI / SEBI / IRDAI / TRAI / PFRDA applicability |\r\n| `india_cross_border_status` | DPDP §16 status for a destination country |\r\n| `japan_cross_border_status` | APPI Art 28 status for a destination country |\r\n| `us_state_breach_deadline` | US state breach window + AG recipient |\r\n| `aadhaar_mask` / `pan_classify` / `gstin_validate` / `cpf_validate` / `sin_validate` / `iban_validate` | Identifier validators with masking + reference token |\r\n| `pii_test` | Dry-run threat detection on a sample event |\r\n| `privacy_notice_get` | Generate operator's jurisdiction-templated privacy notice |\r\n| `sub_processors_register` | Sub-processor disclosure register |\r\n| `global_compliance_map` | 28+ regimes VIGIL has fabric for |\r\n| `india_regulators_directory` | Indian regulators + sectoral filter |\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g @costrinity/vigil-compliance-mcp\r\n```\r\n\r\nOr use directly via `npx`.\r\n\r\n### Docker\r\n\r\n```bash\r\ndocker build -t costrinity/vigil-compliance-mcp .\r\ndocker run --rm -i costrinity/vigil-compliance-mcp\r\n```\r\n\r\nA stdio MCP server (no port; run with `-i`). Self-provisions a restricted trial\r\nkey on first use, same as `npx`.\r\n\r\n## Configure your MCP client\r\n\r\n### Zero-config (self-provisioning)\r\n\r\nYou can add the server with **no credentials at all**:\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"vigil-compliance\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"@costrinity/vigil-compliance-mcp\"]\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nOn the first tool call, the server provisions a **restricted trial key** for you\r\n(via `/api/setup`), caches it at `~/.vigil/credentials.json`, and prints a\r\n**claim URL** to stderr. The trial key runs the compliance decision checks but is\r\ncapped (checks per day + lifetime), short-lived, and does **not** write signed\r\nevidence. Visit the claim URL and verify a real email to lift the limits and\r\nunlock full access + signed evidence. Set `VIGIL_EMAIL` to own the trial account\r\nunder a real address from the start; otherwise a throwaway is used and you can\r\nbind a real email later by claiming.\r\n\r\n### With your own key\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"vigil-compliance\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"@costrinity/vigil-compliance-mcp\"],\r\n      \"env\": {\r\n        \"VIGIL_OWNER_ID\": \"<your-owner-uuid>\",\r\n        \"VIGIL_API_KEY\": \"vigil_<your-key>\",\r\n        \"VIGIL_BASE_URL\": \"https://vigil.costrinity.xyz\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### What the env vars do\r\n\r\n- `VIGIL_OWNER_ID` — your operator UUID. Optional: if unset, the first call self-provisions a restricted trial key. Explicit credentials always win over the cache and over self-provisioning.\r\n- `VIGIL_API_KEY` — optional. Authenticates the tool calls. Self-provisioned if unset.\r\n- `VIGIL_EMAIL` — optional. Email to own the self-provisioned trial account. A throwaway is used if unset (claim later to bind a real email).\r\n- `VIGIL_BASE_URL` — defaults to `https://vigil.costrinity.xyz`. Point at your own VIGIL instance if self-hosted.\r\n\r\n## Example agent interactions\r\n\r\n**Agent considering cross-border transfer:**\r\n\r\n> User: Move this Indian user's profile to our US analytics warehouse.\r\n\r\n> Agent: Let me check DPDP §16 status first.\r\n> *Calls `india_cross_border_status({ country: \"US\" })`*\r\n> Result: `permitted, but RBI Digital Lending Guidelines require India-only storage for fintech lending data`.\r\n> \r\n> Agent: This transfer is permitted under DPDP §16 (US is not on India's negative list). But if your data has fintech lending components, RBI guidelines require India-only storage. Do you want me to filter those fields out first?\r\n\r\n**Agent reviewing a new AI use case:**\r\n\r\n> User: We're building an AI tool to evaluate job applicants.\r\n\r\n> Agent: *Calls `ai_act_classify({ use_case: \"AI evaluation of job applicants\", sectors: [\"employment\"], automated_decisions: true })`*\r\n> Result: `high-risk, Art 35(3)(a) + Annex III, requires conformity assessment + human oversight + bias monitoring`.\r\n>\r\n> Agent: This is a **high-risk** AI system under the EU AI Act Annex III (employment / HR). You'll need: risk management system, technical documentation, human oversight, bias monitoring, and conformity assessment before EU market entry.\r\n\r\n**Agent handling a breach:**\r\n\r\n> User: We just discovered 1200 user records were exposed.\r\n\r\n> Agent: *Calls `breach_classify({ affected_count: 1200, data_categories: [\"email\", \"phone\"], sensitivity: \"medium\", recovery_state: \"exposed\" })`*\r\n> Result: `reportable=true, window_hours=72, deadline=..., recipient=\"Data Protection Board of India\"`.\r\n>\r\n> Agent: This is reportable to the Data Protection Board of India within 72 hours (deadline: 2026-06-05). Should I prepare the §8 notification draft?\r\n\r\n## Why this exists\r\n\r\nCompliance lives in the operator's runtime, not their planning stage. An agent about to:\r\n- Send a user record cross-border\r\n- Decide on a high-risk action affecting an individual\r\n- Classify a breach for severity\r\n- Validate an identifier before storing it\r\n\r\n...should be able to **ask** VIGIL whether that's allowed *at request time*, not in a yearly DPIA.\r\n\r\nMCP turns VIGIL from \"a dashboard the operator visits\" into \"a synchronous decision-support layer the agent calls.\"\r\n\r\n## License\r\n\r\nMIT © COSTRINITY (Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory)\r\n","readmeFilename":"README.md"}