{"_id":"protect-mcp","_rev":"59-e9c4295b893cd3cf8d91cd6857c77029","name":"protect-mcp","dist-tags":{"latest":"0.30.0"},"versions":{"0.1.0":{"name":"protect-mcp","version":"0.1.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.1.0","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"6e43ba8deaade2ebafd83482df2f91609fedbc65","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.1.0.tgz","fileCount":11,"integrity":"sha512-HLNOGjFB+IfiWteFmJkiidFdQir5AvSAyRA9D1/n08/O0xZa3lXnXa6WTImip0pJnwtITMBrb0n6z4lYf8X3rA==","signatures":[{"sig":"MEUCIQDkEOS864k/zxdHkJ7U7ryafzj7haH1WBA93aYA8IP4ZwIgIJIiE/31144TOhqDI6Fu/Kgms37Iyj5kzbN9kNuT/LM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49217},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"build":"tsup src/index.ts src/cli.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Tool-level policies, rate limiting, and structured decision logging. Observe-by-default.","directories":{},"_nodeVersion":"22.20.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","typescript":"^5.0.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.1.0_1773482458186_0.8343934561129176","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"protect-mcp","version":"0.1.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.1.1","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"930de5f080395f7eed779609cbeacf8b3102ade2","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.1.1.tgz","fileCount":11,"integrity":"sha512-084vZW3W2KYZAxNOT8t11LrK28sdBs6Lofa8I05BjQHdTAmie7/yZyONX9k/zeRjp0+XHVZsK8AiEIcpIjX/0A==","signatures":[{"sig":"MEYCIQDq8oS3Zyf7LkqDlQfyIPY8QlR12+aSAGMby8WdMilttQIhAMVrDLd9HPJjOeAcg+ebPHAsC6YtytIvi3M1fWh7eSxN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49177},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"build":"tsup src/index.ts src/cli.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Tool-level policies, rate limiting, and structured decision logging. Observe-by-default.","directories":{},"_nodeVersion":"22.20.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","typescript":"^5.0.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.1.1_1773482499788_0.6285632091253044","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"protect-mcp","version":"0.2.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.2.0","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"4eac609a12ffe7459bbdffe57bf2e1576477507f","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.2.0.tgz","fileCount":14,"integrity":"sha512-DumLKmYrdBNczvlBpHqGfmpFhGZC35ZTwEcyeAzjio+5NFyELsr/fzwhEZ4VhPS7WQRSoWG1PMR9DpPEbb8C3A==","signatures":[{"sig":"MEYCIQDsJzneoeJyhJWSdUrhvU/9q+1oOPdsQ7/TDElDGqI5bQIhAJk5XvlyjsnC3xC+QsrgLqmscSk45++KtwSFTpxvnU6x","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":332689},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Tool-level policies, rate limiting, and structured decision logging. Observe-by-default.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/artifacts":"file:../../artifacts"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.2.0_1774148508105_0.8848131826853329","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"protect-mcp","version":"0.2.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.2.1","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"fbe8252b3446c02f180e0d53bf8384efe3ddd0fa","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.2.1.tgz","fileCount":14,"integrity":"sha512-m+XjMtCjIBvApq7VD1e6a8h4S7yYHUwxJtk73eNG/vmAifCaQwdrBs/Cq7mBN4lLjvthcmgIQjyp7atWNuqHFQ==","signatures":[{"sig":"MEUCIGn5IbgTwj+zfu10QYccckfxmDbmAkPmCppHez7yB+hpAiEApSpZxP2Hx3mqSXG5cEkolElm8w+L1djcDSAc9W9qoVg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":333227},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs by default, per-tool policies, optional local signing, and offline-verifiable receipts.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/artifacts":"^0.2.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.2.1_1774173914844_0.8891399260938124","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"protect-mcp","version":"0.2.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.2.2","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"a897a3682cb33f6f095e641353c875ef1301185a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.2.2.tgz","fileCount":14,"integrity":"sha512-G+jw0JQiFEFfG0FETE63bVRmeDx9K1OOWYUiW8vLwWuzW3ExZH3FwyU0FnMoD9Fh/DvXdyieivn6LZWu7VxI+g==","signatures":[{"sig":"MEQCIGfC3TVNFajy4x+yZ3zk8Y8B+pVUsxwp+uGVRh55UxDvAiAinduivC9FaJXVH7voQ6kOGBq+hgpJGpnLxnD937yhXg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":333225},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs by default, per-tool policies, optional local signing, and offline-verifiable receipts.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/artifacts":"^0.2.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.2.2_1774174245969_0.7057800071687126","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"protect-mcp","version":"0.3.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.3.0","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"7faf42939aa3948facf522b76117244e9efbc252","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.3.0.tgz","fileCount":18,"integrity":"sha512-o+ncvWwnNHvOoe+Go/El8yxKLXY9ge2ndOjOnpKO7ZqJqPxV9yoHNJRccLNK80B/k8Jld7atdu3IgIccppbM6w==","signatures":[{"sig":"MEYCIQDGhhwI5+UUme6ZUvoIRue/VvI4VNVYRLaydGcP1V0R2gIhAKOAxZqjxxXjJIwH2Bwfzq0kwq7SADL+bKim+3zV2J1F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":388848},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"af5482ab181e2ccee3a059211ae3b2fcb67141e2","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs by default, per-tool policies, trust-tier gating, credential isolation, BYOPE (OPA/Cerbos), signed receipts, offline verification.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/artifacts":"^0.2.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.3.0_1774182404414_0.8816329192421994","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"protect-mcp","version":"0.3.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.3.1","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"1ab1fc88f42ccf7ae3684e2ddb3d7182f6b1f7eb","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.3.1.tgz","fileCount":20,"integrity":"sha512-VWI7Cf5KPyWDudCFaWV4qsT1nwV865E2ajhGkaM9NX+wUEPMJJolhhaEw/1g4x2ffzhJ2mb8SMykPOEtzfAT/w==","signatures":[{"sig":"MEQCIGwNj/bn2tp7IuVhqX5UYrVfsVXJXg+OvVVqw9OzKTXzAiB2B29nH91pnVnW4mHXM4XKPDRZXkG0/Q5SJ7fTpvhxaA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":425344},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"b3df4f214ba6efb1e3fcb1e18532b0e8e08fc942","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/artifacts":"^0.2.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.3.1_1774238617131_0.9260703886425374","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"protect-mcp","version":"0.3.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.3.2","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"84dccdb54f6511ac2c8c66ddecb747055ae2d7e1","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.3.2.tgz","fileCount":22,"integrity":"sha512-BB1FxPm9gdrTVXocNeZesSMRxbZA5+/+BN9zXI2nM0g8MW9LMSz7R9p43UpiLpSHIhjs0nV9G9tBu4cu1U7K5w==","signatures":[{"sig":"MEUCIQC+XKuzE/Fg6gIKRNRrJJQ4mnGOOAW6aLSGwa+xWAwIQQIgPUdzVRtaTF5FGI6vXwdXNjN1wyr1lUk6/E85ixpcpCI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":500078},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"85cf6c91c1eb404926d72769baecbc375fd89889","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.3.2_1774495573525_0.3811128017128176","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"protect-mcp","version":"0.3.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"FSL-1.1-MIT","_id":"protect-mcp@0.3.3","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"629ffe6c7d3133cb9ee2bb1fdabdc96804499ca5","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.3.3.tgz","fileCount":29,"integrity":"sha512-muF59u1TM49yJ1ivc+UI9LlCGLOvuCrI826ESi67x6pd8aM/oeKtVcZgM144fFdSz9dv9obi8X38ui6g3x7Myg==","signatures":[{"sig":"MEQCIDprX9InJxIOya431OL2v5K38mbsp0UMbQfTjUeVb5rqAiAOqpP0g410P6qNZIsK2KUKFmO+SCgtSaXSf8FkNVBoTg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":516977},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"0216cefaf597a1874e9e52f1e56131ca7aa59659","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.3.3_1774534094562_0.04643646878337382","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"protect-mcp","version":"0.4.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.0","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"d98e90573850bc99d8b5bcd568fd6b166a786ffc","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.0.tgz","fileCount":31,"integrity":"sha512-F2TxDH8RivhSiqnJpRR57q4vIPpTx6Kl/9sYo9BWadfZ5V6ZKAxMT9IJjYCyRZnEopNvCLGD6pWwNxOWlteQMQ==","signatures":[{"sig":"MEYCIQDzIdQHG4YV/KL2lY6R2Wlp6im8CD5unkG6mU771HhRlAIhALrpx83OkKkB8kSg3KVK1imng0UldNz72oBl0lx8PeW8","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":527025},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"c0e90b3977b7c6041eea13834555ea3693c69753","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.0_1774537022833_0.7411475332633894","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"protect-mcp","version":"0.4.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.1","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"06032bddcccc621d07eab2e1f0b0a4e83489bb6a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.1.tgz","fileCount":31,"integrity":"sha512-WorXRN7Vz1PbBlnXPsgBMMRM5t4Luj0l+tqgLhYinSWRjEUQslULdRzL0i2Z4EqpbeaUhxoEvbmu+GG6Tx5faA==","signatures":[{"sig":"MEYCIQCF67XoISlORGpSJN6Yab7fUuyN7Z18XfZSgSrN60ezGQIhAJqyvE8VP+7MaqXwYBzFhfna8Nx3azlYoBaS/kNQ2AZy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":542192},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"f70aa2a4843beafd41fb51cb2199e0156287f56a","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.1_1774609127327_0.8753722402898636","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"protect-mcp","version":"0.4.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.2","maintainers":[{"name":"tomjwxf","email":"tommy@brassproof.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/tomjwxf/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"8426f5b9564fa50681bc5d1454c32fe759d7be06","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.2.tgz","fileCount":31,"integrity":"sha512-ewUiRKvyrFyGfdpJzX5WgB7MojJgL2vMhCcaio8BdI6I/sAY1SClefStZnPljoyAnfTZNjtZKXFj7MFJLZ2RZw==","signatures":[{"sig":"MEUCIQDtNyUhX/GuDB5YnrAcCoqXrkcRa9u/4HaWEmpRQwGN/QIgF2u/1Uh8OPwa65wRGs8g+JHe9Jyx/Ry3xtaG/v/CI+U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":542444},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"2c6e48fab5d813c3fc306027c3d6e0a141a47178","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@brassproof.com"},"repository":{"url":"git+https://github.com/tomjwxf/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.2_1774611340410_0.0958834988304389","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"protect-mcp","version":"0.4.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"ea704fa20ac2621441dce1ac8a2679df90dee478","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.3.tgz","fileCount":33,"integrity":"sha512-ybFsfCdHLaegdUcphwyrOfksViybTSeB9ghN/Mc1JI5e1CXGqCecQErbWzH/mEISfIfAiqouzS3vD40tWE5PCA==","signatures":[{"sig":"MEUCIFQlwTKASxQUA/D2llobBsTeC+BfNzL9r8QEmZihlfNTAiEAxMDtvXfAXl2GY+XnWZOIcHrk9ukTv6Aia2/nffi5P24=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":796728},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"6c744c4a2d7aea1ac407bddaaf707606adb4b61e","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.3_1774929656404_0.27244626592728927","host":"s3://npm-registry-packages-npm-production"}},"0.4.4":{"name":"protect-mcp","version":"0.4.4","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.4","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"e6e9fac46c83f7f6d6be3332c03216bbc2b4ce92","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.4.tgz","fileCount":34,"integrity":"sha512-O3sTRuE4tNgbm1zZSJcn5Kv0kkoRg3e+axhfW1B6WGtL+3TCrQ0GLnvWzPAkx3wzxCL4pgyrYeqM8T9+WlmT4A==","signatures":[{"sig":"MEYCIQCMcDT8+pa59rIgfU1fNF04kVVqPYJpupc97ll7m5ZB3QIhAPUTcghxVas5LMXdRhOXb5/8AVpYOjwliO6EIEQSI01N","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":808374},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"6c744c4a2d7aea1ac407bddaaf707606adb4b61e","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.4_1774941456701_0.35972897728269837","host":"s3://npm-registry-packages-npm-production"}},"0.4.5":{"name":"protect-mcp","version":"0.4.5","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.5","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"1c7675fcaee53efa7043de81826f1eb333e54ce9","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.5.tgz","fileCount":35,"integrity":"sha512-qzSDdH0AaD4CCnPnSgP02/G4U5aurkB7Xup5w8n2SPRYcMkWHnwtz2HN28BbQ7+mxhxBXU5R7+ny17NOuzom7w==","signatures":[{"sig":"MEUCIQCu/xTro1CVYByI4xC3fKIpfd9W+H0wNufj3Kkw3xKTzgIgeY34toFJHRBiZCI3Mt84izXeb2A7p7FZO9ixmmsFBkw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5074382},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"6c744c4a2d7aea1ac407bddaaf707606adb4b61e","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.5_1774941770210_0.03575261270311825","host":"s3://npm-registry-packages-npm-production"}},"0.4.6":{"name":"protect-mcp","version":"0.4.6","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.4.6","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"f5feac3556fab37081ed3bcfe7e2a95a3d027491","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.4.6.tgz","fileCount":36,"integrity":"sha512-TAoMJhVNzqUT/3qqKoOiT9R6aS48Jp6L+QeI+79SRPN9oflH/M/dWeAFeNAbEz1Pd5zKN9yIrkomrdAPt9q9vA==","signatures":[{"sig":"MEYCIQC1w+NXXCzcBNFvMFO2eqIBpJN6B74vjz79CO1+EAuyjgIhALT9Pf5HtGwb3QCm9GKQBhrLSZpQ8eiwB2q7YWJiUVFj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5079123},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"fe3416b7165dddea3fb9a5a7ce46dc552edb52dc","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.4.6_1775055082300_0.5383318396218866","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"protect-mcp","version":"0.5.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"596e496372210f13a136e30efe1f510523d5466b","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.0.tgz","fileCount":47,"integrity":"sha512-D1g/aGBXDYUs0lF5kbN4+BNkkgMSXefWuM6p+8r74w5JEsm3+V5GTYiDmIvT/7GayuzwsqtxblYaFZRuHR0FIg==","signatures":[{"sig":"MEUCIQCFbdQAG7Go48Oe/VIUiZ3R0+TrbFQiEcjNXPwtW7qA2QIgagRXhi+F934Wt/3D2KjmH4VKnUbPoWrHIDxL5whvtt8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5280979},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"fe3416b7165dddea3fb9a5a7ce46dc552edb52dc","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional local Ed25519-signed receipts. Programmatic hooks for trust tiers, credential config, and external policy engines.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.0_1775088618309_0.1474952768365303","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"protect-mcp","version":"0.5.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"9a43d509ffc33740f632e06852609b1f293291f6","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.1.tgz","fileCount":47,"integrity":"sha512-IlzKYrPlMWcZUNREvFvRmCM7lSFJnzn4L5IBLRPo0cCUW876bR00semB+jy5uJfYwH3cSNNK0BuZbL5cVcFpTQ==","signatures":[{"sig":"MEUCICW9gjMXbK2CS/B5Q22AEfCZVDbCTjiQCVpL4RcCpW4VAiEAqif7E3HqspkFPOnM8rBm7LxILEZ4iAaoqCG1vk+5ibs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5279966},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"fe3416b7165dddea3fb9a5a7ce46dc552edb52dc","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.1_1775089701792_0.5704453676097645","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"protect-mcp","version":"0.5.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.2","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://www.scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"35121f53e01839a64014d8e372cb8560d9870728","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.2.tgz","fileCount":47,"integrity":"sha512-LbL5LaaPmeeDUXKtRkLnJuG+YTQn0Eh1u5OZLkohlOMoYYLsqw5LUr5BP3VFGON9eOsUv61flSOpDOlFgK71VQ==","signatures":[{"sig":"MEUCIQC+kxlRQOuvtoFnUG5K11QKXSVY7MpNFW19CsK9NmZa+AIgdjUscNgADzjW8jUEhH+D1LieMXHuDW79F4RQX3nlUKg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5306960},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"2a6eb14e531736a225cf86e8f547db90fb5989d5","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.2_1775095797204_0.9723709436304804","host":"s3://npm-registry-packages-npm-production"}},"0.5.3":{"name":"protect-mcp","version":"0.5.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"1bb7600ccc2a99b1309d0738cff614fe2d5e2d92","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.3.tgz","fileCount":48,"integrity":"sha512-/kUaupcaFmGz06zTL5DaWZPlLGx6mizJ0lzyYof46+XHyG0qnPBVKjufgurnRnvoPC1Yb4Vs0RwurSqeDwlMcw==","signatures":[{"sig":"MEYCIQDDr+oN21FzJz8p8BRXNDcnzfn34vR9TJU1QZQ6NrXz+QIhAKoVaYJjtfLmNE2laDnBzIbR8A+sZyf6CZsIgCy3TmFr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5324824},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"a5210064443c62584bb05a672c7b50818a5c8f30","mcpName":"io.github.tomjwxf/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.3_1775366067578_0.3549939547098391","host":"s3://npm-registry-packages-npm-production"}},"0.5.4":{"name":"protect-mcp","version":"0.5.4","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.4","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"583f79cec60925c8ec0c7439411782e653a030c3","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.4.tgz","fileCount":48,"integrity":"sha512-+Un0he4kRMVjQDqzmQyQJ1A8ayD+F2a7g6naIn6gAqcjbIH5XezCs77KH2GKryJRxUMZR7D7F5HQu9zdyD7Hjw==","signatures":[{"sig":"MEQCIHk2vueeDbC0Sn04lm9MjFMHnslPT4WjNvrsg0Ub7o/KAiA13StI0XJKC6ozROR8dHckgasjDpJ845YXj5vc6dQ13A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5325896},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"a5210064443c62584bb05a672c7b50818a5c8f30","mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.4_1775429341333_0.2553967258508514","host":"s3://npm-registry-packages-npm-production"}},"0.5.5":{"name":"protect-mcp","version":"0.5.5","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.5.5","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"621f6a1b934db6ff2b0e9089c53d5e4de6e58d26","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.5.5.tgz","fileCount":48,"integrity":"sha512-2J9DShqtOfTCXaXTINZ39uOZdy+h6s8gHLsROhMgwWfejq2o2KQn1d2EKO9AwIzK2zv6kee/zX5yuKthGK9L6g==","signatures":[{"sig":"MEYCIQCTyBwSb6+y7S2CcDE9b7UjcRrNDWFj+gyukKMXEm81ggIhAOCbT2dVfuyos3rOEefP3suZsCxKuJ3lMKHNnd1dLzcI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5323540},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"b6e05b692a99c1c1acbc57759b093c8d0ccb00dc","mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.5.5_1775759386797_0.28088105026502186","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"protect-mcp","version":"0.6.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.6.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"01da48797df02dbb00ccf2d90dd5ee309d55efcb","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.6.0.tgz","fileCount":49,"integrity":"sha512-dgpyoeP3OlDqstKSOqnMr4+imqOMvdgd/91OfBP3AMOx6rLXyiT4dzylEtX5Pf93Ul/B17aQRJD/nkpTmqemjg==","signatures":[{"sig":"MEUCIQCIPV8ysbPOrYc1430pJyWf7dKdp9/ROf4MzSfy6N6FXQIgJkqg5Gvdc7RXi0Eeg2dK/wO8mFIDeJ5n3PH4PXXnHyw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5425708},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"ead218015919495ea181e15208da10f26427607e","mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.6.3","description":"Enterprise security gateway for MCP servers and Claude Code hooks. Cedar policies, Ed25519-signed receipts, swarm tracking, and tamper detection. Shadow or enforce mode.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.6.0_1777161993921_0.2450768609686862","host":"s3://npm-registry-packages-npm-production"}},"0.6.2":{"name":"protect-mcp","version":"0.6.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.6.2","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"269c155e0ee9d450e6b5fb4f8544f38d4bb8ab37","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.6.2.tgz","fileCount":49,"integrity":"sha512-WwZ16E4bPudwB50OpXBDQY+v6yAKHEuysauk6VqtWJ5+7heoW4xWKlXZa6/jMiimBJQweiQQIMPb8vMivJh/VQ==","signatures":[{"sig":"MEUCIHX1H6O9Zoz6aPEf/+MnQOaC/nMhkyJgiXozVSn1qbecAiEA8fAF/LTzlC/kxNpAHj6FqXMH8xVSuKjTLkNNnsNL3IE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5471320},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy + signed receipts for AI agent decisions. Same primitive shipping in ScopeBlind cold-chain hardware. scopeblind.com/cold-chain","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.6.2_1781748339935_0.3702283827970434","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"protect-mcp","version":"0.6.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.6.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"218d9929aedbeb80f805c0b7d2d9a0fe24b3aed5","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.6.3.tgz","fileCount":45,"integrity":"sha512-uwVQKORGij+Ko3hrhtcJARg3qlObXuGBJU1na3q2ii8Jw/00HX5UjgCFsTV6p60DH2KYJuYa1YKcWcpTcqHzDg==","signatures":[{"sig":"MEQCIEX7SX/wJeU2DkRmPr59+EvU0mVJII5trGYkYAgyRutXAiB/UOgBVu+pLqo5TtBQB/gVe6dWvMxm+j1Hatk5/cpkFw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5241781},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"e1b156bff7cf2c9dc497d611554843af1a0591d4","mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy + Ed25519 signed receipts for AI agent decisions. The open gate behind Legate by ScopeBlind: enforce before action, verify offline. scopeblind.com","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.8.0","@noble/hashes":"^1.7.0","@veritasacta/protocol":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.6.3_1782188662340_0.36642506282214393","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"protect-mcp","version":"0.7.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"d70b2a17e4ec58c675190dbccab7a84ad8bc46ae","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.0.tgz","fileCount":50,"integrity":"sha512-UPhd/bnqnEdT0b20GWjpf3aED9yfv10uQuwmQrGrPlz7r8wdpZrjHWQ27bO6Rm5JKX/JATRB3TODlqb2yjlEbw==","signatures":[{"sig":"MEUCIQDckuVNwmwLAxH1BTuQDrhcEC2aJuOBFEzyHlZGu6UvkQIgaGooUjMv0s+wDnrc4CZmayHXwVaqZaG5NK7dWCpZKZI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5497317},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.0_1782622235457_0.4702591980238806","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"protect-mcp","version":"0.7.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"b5e6194d1d1b518a720fbab4000b2672b5db636b","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.1.tgz","fileCount":51,"integrity":"sha512-bPKbWOJjTaI9AQyZ2ESOW3JzNi0TpzuRzkneabFwgypennqyCsERJeGgFyO5J7WwOEj+6o7a8Tjw1qj3+W0mrA==","signatures":[{"sig":"MEUCIQC2hHErL77lA4kczqYTFVVCnoaaD2czYHiFA5Qb/KlrmgIgBSaw64AEolggjDny3NCYpy0hbSTefpxD0A9AeWJ10Qs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5487572},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.1_1782626075863_0.06535361337877466","host":"s3://npm-registry-packages-npm-production"}},"0.7.2":{"name":"protect-mcp","version":"0.7.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.2","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"c0ade467799b051de551775d829428211b734085","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.2.tgz","fileCount":51,"integrity":"sha512-jLIBUSbhebQI/2KIfJ5QpDk8JGa7hLUR/mLs0jnlwnLG/VR3Yjqr1WARyo0iaz5rPSkjB9+7+609XcN5wOfIZQ==","signatures":[{"sig":"MEUCIQCjyIygCAcFlshvaSwtPJ5ZitqX7iNqgEXV4TZdUNxlBgIgaZhkqd1sjeHIOOrW31/8INKqSmM3oV+feHmPlDwUTqQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5493535},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.2_1782632668733_0.15283944600630295","host":"s3://npm-registry-packages-npm-production"}},"0.7.3":{"name":"protect-mcp","version":"0.7.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"fd6eda4dd02dbeb73c8e4884166165361f175e86","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.3.tgz","fileCount":51,"integrity":"sha512-RKtMPJauynIVEypLFl5Ku1zrNJWYxOSqdb/h8xpgAF+w3NGns/DXg7blGnBhALsATItUWxP36HPI6THbJY6APg==","signatures":[{"sig":"MEQCIGmjeD0UsRDU2JhiDkY9I/MMWS3bHyLzohiAaAWQSyXBAiAKs/SHiBnGHgJCumJ5xH2G6/acSYehRpgehtjdHkKRTw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5498849},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.3_1782711146013_0.2556405991596782","host":"s3://npm-registry-packages-npm-production"}},"0.7.4":{"name":"protect-mcp","version":"0.7.4","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.4","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"43ab49c9c828639ea2f922d511e4f1442a286321","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.4.tgz","fileCount":54,"integrity":"sha512-zCosHlRE4r7A13/rBS9KHxV2IJpO6ACT6/X1+YhhNYM+PA1WYDxrz41gbLp2pO6TH9oc5ebPaOf+IwnRYeRiAQ==","signatures":[{"sig":"MEQCIE8aS8q1gd71mRAzbiu4bJCsCxtRf71GATBoE298iCc+AiBwCBFFyMAksbJc0hd0sq0jfHQ5Uc/c9YqYp/7n/R7lnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5875742},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.4_1783055949939_0.6130902376481735","host":"s3://npm-registry-packages-npm-production"}},"0.7.5":{"name":"protect-mcp","version":"0.7.5","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.5","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"90bd4f619107eaebba5a0b353aa2434b6834871d","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.5.tgz","fileCount":54,"integrity":"sha512-YGvL0Zkws/VevB9GWMHviSdXgmtSCwlmcZyKjOaap0sLjFKv3rgf6wPto0FYFNEutN924dok2bKOKCJnVpqzTw==","signatures":[{"sig":"MEQCIBruH9nvJIvnGdbnJihp6Cl7bYpmnLuvj6hOo5v2cIshAiBpYNYydsqsn+IcrV2jhaKyz4mBd9f0OG6nrHgKsPxq0w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6044530},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.5_1783288023092_0.36069170056955446","host":"s3://npm-registry-packages-npm-production"}},"0.7.6":{"name":"protect-mcp","version":"0.7.6","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.7.6","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"a9988545489162694f593b364da832e1203be272","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.7.6.tgz","fileCount":55,"integrity":"sha512-0G1lZV/8HdADWi88vyFdE1YzLbXhY3ETdBgD/yL5kZwMoRrS3r02tawzy9zamLHuKcvijbVl7UGkjflrUCG1mQ==","signatures":[{"sig":"MEYCIQDS+CPX3nJdZo+5ixI65NOx2CJJKzLGcxCEX5xweEzfxAIhAKSHMOQ4H1dMj857HH9FDCZugzaNKVVQn8cKKDZ+KdsM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6050498},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.7.6_1783301278407_0.7212799547456821","host":"s3://npm-registry-packages-npm-production"}},"0.9.1":{"name":"protect-mcp","version":"0.9.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"de653dd5f35f9e8c0404acfd09a968c29b08b34f","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.1.tgz","fileCount":59,"integrity":"sha512-o7TPIdc+ElfnbTtd4YOLs/3waA8CAICZ/v/faIW1tFkq7c3kxYgXwaovnNrIDEtcmtT79Wv0ymdsrmMUTR9Utg==","signatures":[{"sig":"MEQCIGzannGhp+tD3839jk/H/gLoKTjwinMKVeq4ybf9P09LAiAxA3sI6C+HtaP04dwt1XDXIKhcswP1dgjB0qu8fnIShg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6126232},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.1_1783343513980_0.7919792238939669","host":"s3://npm-registry-packages-npm-production"}},"0.9.2":{"name":"protect-mcp","version":"0.9.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.2","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"b6ca0a6290d04a9b3390dc213e0e9dc9efe6b64a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.2.tgz","fileCount":58,"integrity":"sha512-pPrDQHvCuExOO44n4xY/A+NV/p8aPdZ/3sBmll46E+K+KhUOyaMi/Ysb95OpHmCndJlBwrAUOqvsDuOAyYt7+A==","signatures":[{"sig":"MEUCIQDqu5IA7DDBz4wz4A5Ngt0wmIgWuKrp6lZyYEv/DQYmhgIgKJAz2CKQyT8Lv+0/LQu/xxnjZGfhARnQiXphDynGIx4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6137904},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.2_1783416779771_0.47160563617356943","host":"s3://npm-registry-packages-npm-production"}},"0.9.3":{"name":"protect-mcp","version":"0.9.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"23fa86047e61d7a922b4677af818edbb76eaf610","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.3.tgz","fileCount":58,"integrity":"sha512-HGvQ1Gp6fIuQHS4h6K+VWJuppC6xt97y9y+1ampCpnomF0MwZx4uwq8PhlFjaosUauthHcDFtZUW3wbNRXUL5A==","signatures":[{"sig":"MEUCIQCjZ/nxNZfSzIf7mKpdS1F41PQ5/rKVp4EkvrjxyfPCMQIgdmvnI1TMrpxmCUyutkv1DY/rcQbhGqQ0KgGaesWATB4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6162301},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.3_1783454958892_0.10921138450443357","host":"s3://npm-registry-packages-npm-production"}},"0.9.4":{"name":"protect-mcp","version":"0.9.4","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.4","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"59d5e849063cb50ae387ab447e6001fa95fcf49e","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.4.tgz","fileCount":58,"integrity":"sha512-BlOVaYiFp3YP62jXz0MxVKdu49WWy3GXS50J3puM83uv9KbMENRh18Skjwf37EsTP5Y6B16tyzV8gEcQXkoe9g==","signatures":[{"sig":"MEYCIQDGgcoTu3OCsAfDawkFM9i21sobi/9DyKG5FA6ef0ynXAIhAL2cTxe4aOxZ3wBjKDCvhomV91c9C9/V8jefqF1i3+HR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6192952},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.4_1783456360090_0.19332985356112586","host":"s3://npm-registry-packages-npm-production"}},"0.9.5":{"name":"protect-mcp","version":"0.9.5","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.5","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"629979a70a66a6c782714998613690dd8452ad8f","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.5.tgz","fileCount":59,"integrity":"sha512-ukvfvxlaZlYfpfxeykTZtprDipdToRk5W0qPnAL5E8G+3c/1WooLRaEH3fhe0QFHUuZQXLQnVco6etAUN5eTAg==","signatures":[{"sig":"MEYCIQDOoVjXrxzwBwgsdBM2o8uKo9eS6SXUIQbZh3yH12Q2RAIhAJSPKKsQo+kVubJFtnX5efqx3AzUDnBnJkqLG4tWUaz5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6207721},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.5_1783469105653_0.056139351010993765","host":"s3://npm-registry-packages-npm-production"}},"0.9.6":{"name":"protect-mcp","version":"0.9.6","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.6","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js"},"dist":{"shasum":"f6ec71ed324dbd534ce221f7f375f07adc1ca91b","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.6.tgz","fileCount":59,"integrity":"sha512-R181A8iuBQw/kJOyqDTEQ5FNfN0NOOW/RjkNzL/UL1ji8WOpKNM0tcx0kenfUi1IEQQhseR0E69mpXobSaluwg==","signatures":[{"sig":"MEUCIQD0woSmW6L7KsTa62xEKcLUqSqC7u6CN0yivFA0yeYtPQIge8pKOdRNKHyqxq+jCuvyoHKwF+sx3AUBq1kd04mRX6k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6227657},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.6_1783477033335_0.2164477408866059","host":"s3://npm-registry-packages-npm-production"}},"0.9.7":{"name":"protect-mcp","version":"0.9.7","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.9.7","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"2a0950a4d34d49fe3155d5f38f108514f860045a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.9.7.tgz","fileCount":64,"integrity":"sha512-EH5Gx50plE8fqxoOHvFYS9lMEkA0BwmX2QKIgMk1KwvPuJduEAqQL/JP6q3JOfTXgkJg7g5MCD3B6DcLNNDZ3w==","signatures":[{"sig":"MEYCIQC9zoYwvLU6Hi9RVy7kJBlqzfPf+CNV/yyt6xL2vI27kQIhALFmS5mIBQP0shb+hMCZ2J4Uq9XnluvovNRtRe9JRsp0","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6279067},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.9.7_1783511965156_0.5345172768465067","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"protect-mcp","version":"0.10.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.10.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"ffd1c738b48165a4981f4b1084e699e0d65f517c","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.10.0.tgz","fileCount":59,"integrity":"sha512-g0Mman2btNlFL8N67tCqQsP5HdBB4go2dz1vUCoEc3kEOxoBcx1/u7wy2xZQx+TNdlzSo9BTwFoxl7BKRWGztg==","signatures":[{"sig":"MEQCICyZXdPX5Ypn0iDNeEOM6PSnRpe3PBuIlkfX9OmkxoW+AiAi4K9+sqEL4b0pUdvCeooIZLdQYqTeTHlOTkfHoMTAjQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5981797},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.10.0_1783553114093_0.26933802875044943","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"protect-mcp","version":"0.11.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.11.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"bb7df97309219c0042908aecf94be4f3424f1d98","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.11.0.tgz","fileCount":61,"integrity":"sha512-gj7A64MVtS0KIP+SE5VouETRrZa48opq6wsE5EM+aLIi5G9a6e+33jAybTfrGuDrwEptNEASAV3t9DEED/7nAQ==","signatures":[{"sig":"MEUCIGr4SSr0D4IF/ox/hjkIUfPILlCwPV/vL5IkcLjFJ0stAiEAigsJfatAECdz9ObsQYmenMLdvph9hYXrT43fX5f0fug=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6025698},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.11.0_1783572723318_0.6688544824215708","host":"s3://npm-registry-packages-npm-production"}},"0.11.1":{"name":"protect-mcp","version":"0.11.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.11.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"9466bead5a74f2049bd6ed14ff66a438efdd3944","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.11.1.tgz","fileCount":61,"integrity":"sha512-Dd8vFgFmTAE3cUYNRKG2OHINmb2OvHCJSNEsfTPcQ5pbdKU5OXxQHg3Mc/GqzoToM+N7DI8ZroPZPDlW2FWdCg==","signatures":[{"sig":"MEQCIAdjfuV/M/4cD5FG9WELspf9+YVGUtfFMWrl48gr+HykAiBYTQoIrl37Sj5e1vee8C6giWo62uszGhnhU4GrNuR5yA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6033961},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.11.1_1783573842510_0.7718635935122393","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"protect-mcp","version":"0.12.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.12.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"5083e374c270dded18499bac71fdc4e24698cb80","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.12.0.tgz","fileCount":67,"integrity":"sha512-nL0/zEPv/bhs8sXXHdjz/vzchtPE2rO1mrFxFtFpKzDBYcNC8oYvRddK2QHdI6VPFyLSRLI/lJ115vmnHBcncA==","signatures":[{"sig":"MEQCIEOdc4qaWVx7oDRQe6VzXf5r7ZPw+AygLoiaSqSVBlZhAiBP459b5glA1PrzJK2wUDxCr7opPpiiWjRXKqBlcYl7NA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6484268},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.12.0_1788088008757_0.10216524059629295","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"protect-mcp","version":"0.13.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.13.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"6dd3dd68ccbf30a517a5e3ef8630c8e11222ea08","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.13.0.tgz","fileCount":67,"integrity":"sha512-0RZQ28lB7D3JevcO6ZvpDtAVZcuGaGKmbI5y9gjkGaeJX1XJytKxKiCx18glnMh1CpxbHXOIQNNihnHhk/Fgqw==","signatures":[{"sig":"MEUCIQD3Vt5QNrrpYx85by/VrQ8di2bi/FVG79QUE/XDLnFLcAIgFYL+i0XmO+3NvBBy/cYss2FJi/Bb4fS9dWUZS3IvU5M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCPgikiRF7AEDyZtfB3lDSqvLr+PtCnMixNW17wAsH4QgIgeJp5Bl75GrKdn/67b7LNuXVNq8RFdnM4XGKh1pYGouM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6535437},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.13.0_1789020332842_0.22535695824405","host":"s3://npm-registry-packages-npm-production"}},"0.13.1":{"name":"protect-mcp","version":"0.13.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.13.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"a49e23fd83994437c7ba6528de0b73ca2bdd852e","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.13.1.tgz","fileCount":67,"integrity":"sha512-zntWeUETiRCtnsiY3/6FplruiH+fmH7pV4Gb2gGpX4j5COySNFM5QZlY+1B/nhkICZvb+h+vQjFVVTM6tRNJoQ==","signatures":[{"sig":"MEYCIQDwzh7O2+BtcnZsBFw4sauFBlTo8DpE2JyAikX9QW7PtQIhALF5v1DBe6BaUBML6frqluGHFt50RL3DNcSxdqYNFL0r","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFKzqASyF1QtT5t6UR9fX3dN6NyHxsf0CXPWi4oCbzrgAiEA5sLAosw2sYwg3wbhdUtUt8T8EwEXpkfif0N5F5sZ4/A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6541895},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.13.1_1789024944114_0.034730172901717093","host":"s3://npm-registry-packages-npm-production"}},"0.13.2":{"name":"protect-mcp","version":"0.13.2","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.13.2","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"e29b8e2dce67862cf3a44c06ef6deb656f82887f","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.13.2.tgz","fileCount":67,"integrity":"sha512-k2YPy4qRpxhmdHtVP5cRfYJcck+jm0Xai3KKasw3Zqq/PJQT99yiHtyZgCcnB881zXY4Q7zZL2neaerDw3RAFg==","signatures":[{"sig":"MEYCIQCGRyuq9vOLGXMN69WNJe0Z95CYah0S3pyQl1Pi/znOeQIhAMiMaSjpGPOSE4YXEAlL6lq5lHqt4xjDzq6Chyyv2c0d","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDmIggsykidmf722an6FPMx02AcLIGtrZWEKsryscjCfQIhAO7W3TwSjU/3p5IrP004GVYe5OD6nbUgxg21xKEyRMQz","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6545382},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.13.2_1789103101039_0.6918667293542242","host":"s3://npm-registry-packages-npm-production"}},"0.13.3":{"name":"protect-mcp","version":"0.13.3","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.13.3","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"5e4beebee0da12aa09dccab60bc8ded79b32b4d1","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.13.3.tgz","fileCount":67,"integrity":"sha512-ll5DcMlha5sszSBHx249YXFO+udVDo8Dd+glWXjcmUhfnkZPWmN1o+Z8BEQ2HDLCBZhMnWCBdlLdMQqEZxXeBw==","signatures":[{"sig":"MEYCIQDOTrIcYBmfay+ZvIjBn7kMNvwWLQFRwbYI9Xch32qKlAIhAKOdnLTy26qR2qFR9LPVsDhagLZCtNcbduon2pGugVcX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCID15XXKzwQWO8Rm37apw8lAmqwVrw3ZacgGO+jS6PShtAiByY0NPNWcMqd7vYWFihsGxxXacLBmfqJ9eNWw2qMqCMw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6548403},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.13.3_1789128682507_0.3547096691965521","host":"s3://npm-registry-packages-npm-production"}},"0.13.4":{"name":"protect-mcp","version":"0.13.4","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.13.4","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"9e257f40d7b58c5665cdacb3abce8b4021061fa6","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.13.4.tgz","fileCount":67,"integrity":"sha512-nKgb79NCbi2pK7E4EqPHcgWRWFYa8MrI+ItAP/SVVKM5mzWst2Meqn8sMtpxO8LqMnlvENFesNDdsebqTL+neg==","signatures":[{"sig":"MEYCIQDGTl+/AEqCXCp1QRXOVE56J6DN73k5uuNtrbkkX0eb+AIhANoDzmqKW1T5VUsFJ/M/ZbHdvdjukGqfMh31cjhPUAP4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCICYClKW1P7x8KJ1JbIp+3OlSXtKA/0OOf23/f7lAIWP5AiEAmn2Uj0RZKR+FZ0KB8tOTGrp70pWGiBU86xf1ah3fIUE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6552415},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.13.4_1789359143479_0.5234328607108047","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"protect-mcp","version":"0.14.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.14.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"27201878181b57d50070ee335c60af0cf9c82395","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.14.0.tgz","fileCount":67,"integrity":"sha512-ggDqpswiry0Y5Ji8WD1rvjrwpi95DdnoaT9Lgx/WsHiX45YN4Zsm0fUPT2k1mUujL6+r4LVoWPvh7/HmsVuGgA==","signatures":[{"sig":"MEUCIQDnFf/z4Pecyol1ttNFwF8vL89EeJFWUYnXgECvO8ynOwIgV/9OEFcj6n4ldJHPtzfUacmdw7LCxXfChuZsM1pQbHM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIEA4hxHaAZziwXM2Tq19buIUHNFpwEANdLNCmUIxfA0uAiAJCAZvoYKNLruzqi1kpuE/JdB+jVYMRyvSiXPXt16RnA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6647619},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/scopeblind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.14.0_1789378522375_0.745760301804899","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"protect-mcp","version":"0.21.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.21.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"7583035b1739939de402bbcd14f9b2854f57a6e2","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.21.0.tgz","fileCount":82,"integrity":"sha512-cS1FI9rB5BterluRKFhv9U17gffp7PCnLMvpUs2GWRVMzGwtgGpv3mnGBpsCVNdmJOC3qg/JmXxxYQqEgHwrKg==","signatures":[{"sig":"MEUCIQD3hJQx6tD9NlDDPWIFH3Cm1l+E/GNwjyRUCn3cY3yh5wIgZuvnVgXWsLtbfSgYf7Q4E0gLRjLVC9RzCtkE2F+HwZc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCkLOBKe3xH978wIcpdZwbccm0VpaFiwy+dCCS/q8X1HAIgWiQ1SFTAFoElhSowmunEotXY44ZS5MoUZWG/ZCfzttY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.21.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7490430},"main":"dist/index.js","_from":"file:protect-mcp-0.21.0.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.21.0.tgz","_integrity":"sha512-cS1FI9rB5BterluRKFhv9U17gffp7PCnLMvpUs2GWRVMzGwtgGpv3mnGBpsCVNdmJOC3qg/JmXxxYQqEgHwrKg==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.21.0_1789535156277_0.2389421324229779","host":"s3://npm-registry-packages-npm-production"}},"0.22.0":{"name":"protect-mcp","version":"0.22.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.22.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"9e7cb693ea4c78408d14e50a495b01e0244dea9b","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.22.0.tgz","fileCount":88,"integrity":"sha512-pWAS0yrAyA+Oikl5GJlwpDmkCZOYjkLyR1U8sQZdy2uhuOBg/5XC3uy8x0ETV+kHp8ZVWGhakTxAdDNmxvHivg==","signatures":[{"sig":"MEQCID5SkudzQ6Mstoc1HbniZKzZwM+MUBir30fod1gH/IIZAiBpvdD+BixWN5AWvRHB+GTpM+duzgLMzcrFl9WOAbejyw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC+PEVPwywb1mO6bZZe/H1/i18kq6Vzs19UckJZf0MzaAIhAKwweMz+4b397URSM1vlY7mZd4WNt4e20IANyB8zS+6n","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.22.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7765053},"main":"dist/index.js","_from":"file:protect-mcp-0.22.0.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.22.0.tgz","_integrity":"sha512-pWAS0yrAyA+Oikl5GJlwpDmkCZOYjkLyR1U8sQZdy2uhuOBg/5XC3uy8x0ETV+kHp8ZVWGhakTxAdDNmxvHivg==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Fail-closed Cedar policy gate + Ed25519 signed receipts for AI agent tool calls. Denies on any policy error, proves the gate is live with a startup self-test, and turns every decision into a local searchable record you own. The open gate behind Legate by ","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.22.0_1789546416618_0.23476014469158346","host":"s3://npm-registry-packages-npm-production"}},"0.23.0":{"name":"protect-mcp","version":"0.23.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.23.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"402c7e94b5264f9f3ac01f0ab5f28b7bb3c22569","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.23.0.tgz","fileCount":87,"integrity":"sha512-LIlC/3b36r8VQ1WnZBbh3ExzOu0TGjBj/lYOxYHsjzxcwFMbvrO/QoiQJma0/67NDNZoBCceCbIIpm8/jMRpCQ==","signatures":[{"sig":"MEUCIQDAOoGj+Yqc9P+F46N9sSB0b8GHd+ERr+fqspW0w0U8agIgJ+LSAgAdKvZGcK5XFt+u4UR1AbXMS8I5MitcFDs4do4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBvshkESF47OwXlI2SuKiVQDNTuM/GERaGJwm4qJree7AiEA1X9R1O0LVuqs/ZSnt1wi976P+njYjPr6jo7nTj3gu0g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.23.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8185840},"main":"dist/index.js","_from":"file:protect-mcp-0.23.0.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.23.0.tgz","_integrity":"sha512-LIlC/3b36r8VQ1WnZBbh3ExzOu0TGjBj/lYOxYHsjzxcwFMbvrO/QoiQJma0/67NDNZoBCceCbIIpm8/jMRpCQ==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, with scoped repository review, bounded agent preparation and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.23.0_1789559916746_0.3646273379622398","host":"s3://npm-registry-packages-npm-production"}},"0.24.0":{"name":"protect-mcp","version":"0.24.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.24.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"8b311bb1d7eea3a78b65edcff55eec274cbddeee","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.24.0.tgz","fileCount":94,"integrity":"sha512-jSmGb8TpmIshhE1ReD7nN2KVLcwzZonZSmog6nqxU4bz0GACB0YFqMVNI6X8AWLCxrIG5i5Rp6NDM7OGMuNwPw==","signatures":[{"sig":"MEUCIBwgfJwVJiKMfLCcp3cA2oEMk2sbRqYCILuZJXrlPFr3AiEAoUu4wc5JMvXjSG2TStnnduPlT8Rrvpbw7T8kAJagpt8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBxvY2sRyhmK8iZ650eKZUbjwkY69jPLYspGo561U/dQAiByn+/Tfo+PrQM2GUPZw3hiPTRlM6jhh+CjJxALQoonVQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.24.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8915225},"main":"dist/index.js","_from":"file:protect-mcp-0.24.0.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.24.0.tgz","_integrity":"sha512-jSmGb8TpmIshhE1ReD7nN2KVLcwzZonZSmog6nqxU4bz0GACB0YFqMVNI6X8AWLCxrIG5i5Rp6NDM7OGMuNwPw==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.24.0_1789607234408_0.28254058007337446","host":"s3://npm-registry-packages-npm-production"}},"0.24.1":{"name":"protect-mcp","version":"0.24.1","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.24.1","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"b9bbe1691a1fbbf45774954937c143ffdbd7a76a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.24.1.tgz","fileCount":94,"integrity":"sha512-wvk2PzADOOSyo1BL7sTLggMZIQYhmfYFnN8i9WiPLoXYIvNxXz3Rt8oPY1U5a7ebtlfeSrO4kPaXU0ytGQoOoA==","signatures":[{"sig":"MEQCICBiOqz/n+95f4Hre+cfeBjYL40ack8xdot6uC6tdyf4AiBttgX2sNrZyJv55TFhDyIH6TRKtLANuBPK7W1IjobL9Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFd/MAg4DOtx3Nvv8qUdhwYc4faY9ZEFen8AomYnW1SzAiEAno3tX6Ucdm2rd24ssD1DMJlwIMKfkBzXFizSFeOMm1c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.24.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8915801},"main":"dist/index.js","_from":"file:protect-mcp-0.24.1.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.24.1.tgz","_integrity":"sha512-wvk2PzADOOSyo1BL7sTLggMZIQYhmfYFnN8i9WiPLoXYIvNxXz3Rt8oPY1U5a7ebtlfeSrO4kPaXU0ytGQoOoA==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.24.1_1789609053140_0.7102458677299011","host":"s3://npm-registry-packages-npm-production"}},"0.25.0":{"name":"protect-mcp","version":"0.25.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.25.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"59542aabc90d045bd9d85b2d1c6bc8213ed2226a","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.25.0.tgz","fileCount":99,"integrity":"sha512-MCFKHXSG1gNCkCqeX2jpVLR4KoIyFwH+40b0uG/aR4oD9Jv+rH2uLt8WNkqqB1BBNNu+0NudrYyfSu75kpj0sg==","signatures":[{"sig":"MEUCIQCx3Ko+trNf9BSSintC4F7YHE0TSx6KTckRz2XH6g0biwIgWBxV3G0A3QbGNX8zmMmysuX9foeOxJgVGBTFMyYZpkU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIB2bBiZt/ZMfbEBaLDCoS3E/Qo6t4/f/5ydyVwNcFOZQAiBwA0YJREm4x/qs160SH8v4LW7BdIQNxM2/kvlqlzxKMQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/protect-mcp@0.25.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9291679},"main":"dist/index.js","_from":"file:protect-mcp-0.25.0.tgz","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts src/repository-trial-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5c820ac4-b90f-4ce0-b2c9-1ee0fd8768dc"}},"_resolved":"/home/runner/work/scopeblind-gateway/scopeblind-gateway/protect-mcp-0.25.0.tgz","_integrity":"sha512-MCFKHXSG1gNCkCqeX2jpVLR4KoIyFwH+40b0uG/aR4oD9Jv+rH2uLt8WNkqqB1BBNNu+0NudrYyfSu75kpj0sg==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"11.19.1","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.25.0_1789642618141_0.8218184836296112","host":"s3://npm-registry-packages-npm-production"}},"0.27.0":{"name":"protect-mcp","version":"0.27.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.27.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"99528f1163ae6f6ffebfdda90d5e59ee872484b9","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.27.0.tgz","fileCount":99,"integrity":"sha512-KiyEJtzVSaUBoJetfYBDxIO86lK8J7fOX1DcXLMAKhCD+0ly4losJ2nm+levqTf7/1pu8br32LTiMHMQIgXMHg==","signatures":[{"sig":"MEQCIBs9Criv8LKL9LRXs+3dXjLbxLkeDiHnwxOyLudBo6c+AiBOm3zVy9HIEgM6VcwjjmO0NfYBrcJpkvunCO5DMIG/tQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDIQHsBo9/d5Lf7IRZ6/oFbaldf6yuK6PS6EvRT12wyAAiEAgz2s0rJK8Do6s4QQ18ro2FdTC3j+vMHBabx8iYSfyeo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9308726},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts src/repository-trial-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.27.0_1789785332675_0.31090934183919194","host":"s3://npm-registry-packages-npm-production"}},"0.28.0":{"name":"protect-mcp","version":"0.28.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.28.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"a4bc75ebae356f047ecfebfbb1fa447a887688a8","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.28.0.tgz","fileCount":99,"integrity":"sha512-ftnk8IC6j0p20jFLHQfWnfKrQe5O6z0hGQaAZGZtc4RyDujTNQLuxYaKiARklOCy09NSZV51Rt3iwnSlOAvPvw==","signatures":[{"sig":"MEYCIQCjuHyQDPBG6cUioHCZhlGNiGcgp5F0TkAvIcrWuK/1jQIhAP/xQMTTv6I4hiwkwzNYqhnNjhw8N/lRZ7N/8mGTRPIL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIF/uEwrV9Y4xkOHQYMzd2umVKWO3sp3kHNAqvTnKucQOAiEAvTf1MjMuJTyAUSTqyplyZDfddJ2xwEM9YAtcgDKkDT0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9317511},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts src/repository-trial-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.28.0_1789809083508_0.6816377206889297","host":"s3://npm-registry-packages-npm-production"}},"0.29.0":{"name":"protect-mcp","version":"0.29.0","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","_id":"protect-mcp@0.29.0","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"homepage":"https://scopeblind.com","bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"dist":{"shasum":"bb1ddaee48fba34a37a549afc2d8aa2bcd975acc","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.29.0.tgz","fileCount":99,"integrity":"sha512-Ms0ly7kF1l2KCFh9plxn/ES74hkh/Br7hP4zVFkP2ACiS+ruIO1twDglCcANCm5HZsmDTBR6M/Qj8Qs1ofoUkQ==","signatures":[{"sig":"MEUCID/h5+JrwL6fG0ATsi/UBog8sWv2P+y8lrqR24MrENp6AiEA8AlvkxjZyx+qRXx1HG/By+1AX8YFCg9erH+/iRrG/QE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICoY0k28d9PoZpnjSOKaKDfDqvVy0HCm/oFQp+VSkSd6AiBg8a37py8phHTYqTMWYt2Ab4QPET+DRxe6r5/24uV0Cg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9332565},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts src/repository-trial-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/protect-mcp_0.29.0_1789817298103_0.9954734976579966","host":"s3://npm-registry-packages-npm-production"}},"0.30.0":{"_id":"protect-mcp@0.30.0","bin":{"protect-mcp":"dist/cli.js","protect-mcp-mcp":"dist/mcp-server.js"},"bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"dist":{"shasum":"ec646fb9b4f902d6d1ac9b28d1cca4840f61e7e2","tarball":"https://registry.npmjs.org/protect-mcp/-/protect-mcp-0.30.0.tgz","fileCount":99,"integrity":"sha512-95vw5/x5bjm+olWHZzpjMpFnvLbADcQKt7xeI5R2bjgfzZQtHyAUgAW1phzB9E8HyxAb9NdmSIQfTqbfuja6cA==","signatures":[{"sig":"MEYCIQCqzRQ8jIjsLAx+WY1b+iv45JQqSwf4PSF17ZeOUZLWXgIhAJXHPF2MsisrAu5uWxJnXBhjXHfCX1xoXZbcxLQ62qKI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGglHiF0WfUP1BwmcRMZ0eEZHk8B0K7qQJedlJL32pi4AiAwtMMlOkNzvR3qa2u8D5S2lLb+dIl5YURxaXEdBWXMVw=="}],"unpackedSize":9355352},"main":"dist/index.js","name":"protect-mcp","_from":"file:protect-mcp-0.30.0.tgz","types":"dist/index.d.ts","author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"module":"dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"license":"MIT","mcpName":"com.scopeblind/protect-mcp","scripts":{"test":"vitest run","build":"tsup src/index.ts src/cli.ts src/demo-server.ts src/hook-server.ts src/hook-patterns.ts src/mcp-server.ts src/repository-receiver-cli.ts src/repository-demo-cli.ts src/repository-coding-cli.ts src/repository-trial-cli.ts --format cjs,esm --dts --clean","pretest":"npm run build","test:docker":"node scripts/coding-docker-smoke.mjs","prepublishOnly":"npm run build"},"version":"0.30.0","_npmUser":{"name":"tomjwxf","email":"tommy@scopeblind.com"},"homepage":"https://scopeblind.com","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"_resolved":"/Users/tomfarley/Projects/New project/.worktrees.nosync/connector-profile/packages/scopeblind-pm/web/public/releases/protect-mcp-0.30.0.tgz","_integrity":"sha512-95vw5/x5bjm+olWHZzpjMpFnvLbADcQKt7xeI5R2bjgfzZQtHyAUgAW1phzB9E8HyxAb9NdmSIQfTqbfuja6cA==","repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"_npmVersion":"10.9.8","description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","directories":{},"maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"_nodeVersion":"22.22.3","dependencies":{"@noble/curves":"^1.9.7","@noble/hashes":"^1.8.0","@veritasacta/protocol":"^0.1.0","@veritasacta/artifacts":"^0.2.2"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.1.9","typescript":"^5.0.0","@types/node":"^20.0.0"},"optionalDependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/protect-mcp_0.30.0_1789957548466_0.4902907072199718"}}},"time":{"created":"2026-03-14T10:00:58.072Z","modified":"2026-09-21T02:25:48.771Z","0.1.0":"2026-03-14T10:00:58.331Z","0.1.1":"2026-03-14T10:01:40.002Z","0.2.0":"2026-03-22T03:01:48.257Z","0.2.1":"2026-03-22T10:05:14.984Z","0.2.2":"2026-03-22T10:10:46.121Z","0.3.0":"2026-03-22T12:26:44.568Z","0.3.1":"2026-03-23T04:03:37.348Z","0.3.2":"2026-03-26T03:26:13.719Z","0.3.3":"2026-03-26T14:08:14.787Z","0.4.0":"2026-03-26T14:57:03.080Z","0.4.1":"2026-03-27T10:58:47.474Z","0.4.2":"2026-03-27T11:35:40.637Z","0.4.3":"2026-03-31T04:00:56.668Z","0.4.4":"2026-03-31T07:17:36.939Z","0.4.5":"2026-03-31T07:22:50.446Z","0.4.6":"2026-04-01T14:51:22.545Z","0.5.0":"2026-04-02T00:10:18.554Z","0.5.1":"2026-04-02T00:28:22.018Z","0.5.2":"2026-04-02T02:09:57.433Z","0.5.3":"2026-04-05T05:14:27.816Z","0.5.4":"2026-04-05T22:49:01.586Z","0.5.5":"2026-04-09T18:29:46.964Z","0.6.0":"2026-04-26T00:06:34.099Z","0.6.2":"2026-06-18T02:05:40.146Z","0.6.3":"2026-06-23T04:24:22.550Z","0.7.0":"2026-06-28T04:50:35.639Z","0.7.1":"2026-06-28T05:54:36.009Z","0.7.2":"2026-06-28T07:44:28.950Z","0.7.3":"2026-06-29T05:32:26.164Z","0.7.4":"2026-07-03T05:19:10.138Z","0.7.5":"2026-07-05T21:47:03.270Z","0.7.6":"2026-07-06T01:27:58.556Z","0.9.1":"2026-07-06T13:11:54.148Z","0.9.2":"2026-07-07T09:32:59.935Z","0.9.3":"2026-07-07T20:09:19.097Z","0.9.4":"2026-07-07T20:32:40.338Z","0.9.5":"2026-07-08T00:05:05.842Z","0.9.6":"2026-07-08T02:17:13.562Z","0.9.7":"2026-07-08T11:59:25.328Z","0.10.0":"2026-07-08T23:25:14.438Z","0.11.0":"2026-07-09T04:52:03.506Z","0.11.1":"2026-07-09T05:10:42.728Z","0.12.0":"2026-08-30T11:06:48.902Z","0.13.0":"2026-09-10T06:05:33.028Z","0.13.1":"2026-09-10T07:22:24.286Z","0.13.2":"2026-09-11T05:05:01.204Z","0.13.3":"2026-09-11T12:11:22.624Z","0.13.4":"2026-09-14T04:12:23.576Z","0.14.0":"2026-09-14T09:35:22.543Z","0.21.0":"2026-09-16T05:05:56.417Z","0.22.0":"2026-09-16T08:13:36.737Z","0.23.0":"2026-09-16T11:58:36.857Z","0.24.0":"2026-09-17T01:07:14.514Z","0.24.1":"2026-09-17T01:37:33.269Z","0.25.0":"2026-09-17T10:56:58.247Z","0.27.0":"2026-09-19T02:35:32.799Z","0.28.0":"2026-09-19T09:11:23.622Z","0.29.0":"2026-09-19T11:28:18.239Z","0.30.0":"2026-09-21T02:25:48.576Z"},"bugs":{"url":"https://github.com/scopeblind/scopeblind-gateway/issues"},"author":{"name":"Tom Farley","email":"tommy@scopeblind.com"},"license":"MIT","homepage":"https://scopeblind.com","keywords":["scopeblind","mcp","model-context-protocol","security","gateway","rate-limiting","policy","audit","decision-log","tool-protection","ai-agent","llm-gateway","owasp","cedar","opa","ed25519","receipts","trust-tiers","agent-governance","claude-code","hooks","swarm","compliance"],"repository":{"url":"git+https://github.com/ScopeBlind/scopeblind-gateway.git","type":"git"},"description":"Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.","maintainers":[{"name":"tomjwxf","email":"tommy@scopeblind.com"}],"readme":"# protect-mcp\n\nFail-closed Cedar policy gate plus signed receipts for AI agent tool calls.\n\n[![npm version](https://img.shields.io/npm/v/protect-mcp)](https://www.npmjs.com/package/protect-mcp)\n[![downloads](https://img.shields.io/npm/dm/protect-mcp)](https://www.npmjs.com/package/protect-mcp)\n[![license](https://img.shields.io/npm/l/protect-mcp)](https://www.npmjs.com/package/protect-mcp)\n[![node](https://img.shields.io/node/v/protect-mcp)](https://www.npmjs.com/package/protect-mcp)\n\n`protect-mcp` is a gate that sits in front of an AI agent's tool calls. It evaluates\neach call against a [Cedar](https://www.cedarpolicy.com/) policy,\nblocks what breaks the rules before it runs, and signs an\noffline-verifiable Ed25519 receipt of every decision. The configured gateway runs locally and sends no decision telemetry. The\nseparate coordination adapter connects to ScopeBlind’s hosted collaboration service;\nits requests and returned records have the data path described below. Both are\nMIT licensed.\n\nFor shared repository work, use [client projects](https://scopeblind.com/standard?trial=new&view=workspace):\npeople agree on the brief and limits, agents prepare reviews, and both people\napprove an exact version before the owner's receiver can change the repository.\nThe [repository workflow below](#recurring-client-reviews-and-agent-preparation)\nincludes setup and the five bounded agent tools.\n\n## Why it is different\n\n- **Fail-closed by default.** On any policy error, a missing engine, or an\n  evaluation failure, the decision is DENY. The gate never silently allows. An\n  observe mode exists for shadow rollout, but even there a call that would be\n  blocked is flagged `would_deny: true`, so a failure is never silent.\n- **It proves its own restraint.** `serve --enforce` and `doctor` run a startup\n  self-test and refuse to arm the gate unless they can show that a known-forbidden\n  action is actually denied. A gate that cannot prove it denies does not start.\n- **Every decision is a receipt anyone can verify.** Decisions are Ed25519-signed\n  and verifiable offline with [`@veritasacta/verify`](https://www.npmjs.com/package/@veritasacta/verify).\n  Signature verification needs no network lookup. Claims about execution still\n  depend on the identified gate operator.\n\n## Quickstart: install to first useful proof\n\n```bash\n# 1. Generate an Ed25519 keypair, config template, and sample policy.\nnpx protect-mcp init\n\n# 2. Print a shadow-mode client configuration, then apply it in your MCP host.\n#    This command prints configuration and exits; it does not launch the server.\nnpx protect-mcp wrap -- node your-mcp-server.js\n\n# 3. Reopen the host and use its tools, then inspect the local-only dashboard.\nnpx protect-mcp dashboard --open\n\n# 4. Draft a reviewable policy from observed calls.\nnpx protect-mcp recommend --write\n\n# 5. When reviewed, restart the wrapper in enforce mode with that policy.\nnpx protect-mcp --policy protect-mcp.recommended.json --enforce -- node your-mcp-server.js\n```\n\nFor Claude Desktop, run a dry-run config patch first, then apply it:\n\n```bash\nnpx protect-mcp wrap --claude-desktop\nnpx protect-mcp wrap --claude-desktop --write\nnpx protect-mcp dashboard --open\n```\n\nThe dashboard binds to `127.0.0.1`, reads only local log/receipt files, and does\nnot upload anything. Use `npx protect-mcp connect` only if you explicitly want a\nhosted ScopeBlind dashboard.\n\n## The gate as an MCP server\n\nIf you would rather call the gate as tools than wire the Claude Code hooks, run\nit as an MCP server:\n\n```bash\nnpx protect-mcp mcp\n```\n\nIt speaks MCP over stdio and exposes four read-only tools, the whole loop:\n\n- **`evaluate_action`**: decide a proposed tool call against an inline Cedar policy, fail-closed (any policy error is DENY). Returns `{ allowed, decision, reason, policy_digest }`.\n- **`sign_decision`**: turn a decision into an Ed25519 signed receipt (a denial signs a `gateway_restraint`, an allow a `decision_receipt`). Returns the receipt and its public key; generates an ephemeral key if you do not supply one.\n- **`verify_receipt`**: verify a signed receipt offline against a public key. Returns `{ valid, error, type, kid, issuer }`.\n- **`self_test`**: prove it, no inputs. A known-forbidden action is denied, then a signed receipt round-trips and a tampered copy fails.\n\nPoint any MCP host at it, for example Claude Desktop:\n\n```json\n{\n  \"mcpServers\": {\n    \"protect-mcp\": { \"command\": \"npx\", \"args\": [\"-y\", \"protect-mcp\", \"mcp\"] }\n  }\n}\n```\n\nReceipts are byte-compatible with the ones the gate signs at runtime, so a\nreceipt minted here uses the same Acta envelope. Verification capabilities and\ncanonicalization compatibility depend on the verifier version; use the gateway's\n`verifyReceipt` API for the conformance behavior described below.\n\n### Receipt canonicalization compatibility\n\nThis source tree fixes the integer-key ordering defect present through 0.14.0: signatures and\nchain hashes now use direct JCS member emission, retaining the gateway's ASCII\nobject-key profile. Numeric-looking keys such as `\"10\"` precede `\"2\"`, including\ninside nested objects. Non-JSON values and invalid Unicode are rejected.\n\nOrdinary JSON receipts whose encodings are unchanged continue to verify.\nHistorical receipts signed with the old numeric-key order are reported as\n`legacy_non_jcs_signature`; strict verification does not call them valid JCS.\nFor an explicit historical compatibility check, use\n`verifyReceipt(receipt, publicKey, { allowLegacyNumericKeys: true })` and inspect\nthe `canonicalization` and `warning` fields. Its `hash` is then the original\nhistorical hash. Preserve original receipts and chain links: recomputing an old\nnumeric-key receipt with `receiptHash` now produces its JCS hash and can break\nthe historical chain. These changes are included in `0.15.0`.\n\n### Start with your agent, then authorize each task\n\nVersion `0.25.0` includes a reusable agent profile. Open\n[Start through your agent](https://scopeblind.com/standard?trial=new&view=agent)\nfor the setup command with the service’s displayed authority key. Check that key\nagainst a trusted source before connecting. For example:\n\n```bash\nnpx --yes protect-mcp@0.25.0 coordination agent setup \\\n  --client claude-code \\\n  --profile ~/.scopeblind/agent.json \\\n  --endpoint https://scopeblind.com/api/coordination \\\n  --authority-key PINNED_64_HEX_AUTHORITY_KEY\n```\n\nUse `--client codex` or `--client json` for those registration instructions.\nSetup prints configuration; apply it in your client, then reopen that client.\nThe private profile holds an agent key and separately scoped connections, with\nfile permissions `600`. Setup grants no task permissions and copies no human\nbrowser key. The registered server runs `coordination agent --profile FILE`.\n\nAsk your agent to prepare a shared invoice task for your review. The tool flow is:\n\n1. `coordination.prepare_task({request_id, draft})` saves an unsigned draft and\n   returns a private review link for you. Keep the same `request_id`\n   when retrying. The draft contains a title, goal, and optional proposed limits,\n   assumptions, and private preferences. It creates no room or human authority.\n2. Review the draft in the browser, edit it, and sign your own limits. Invite\n   the other person, who signs their own limits independently. Separately\n   authorize your agent’s negotiation connection. Review links expire after\n   30 minutes; possession does not give the agent payment or approval powers.\n3. `coordination.inspect_task_request({request_id})` checks that review.\n   `coordination.claim_task_connection({request_id})` claims the exact authorized\n   grant and returns a `connection_id`. Then call\n   `coordination.inspect_negotiation({connection_id})` before proposing or testing.\n4. Both humans approve one exact tested plan. The original organizer creates\n   the separate task and may explicitly authorize the same agent to execute it.\n   `coordination.check_handoffs({connection_id})` discovers that authorization;\n   `coordination.claim_execution_connection({connection_id, handoff_id})` saves\n   a **new execution connection**. Inspect its returned `connection_id` before\n   submitting payments. The negotiation token never becomes a payment token.\n\nEvery scoped tool in the profile requires an explicit `connection_id`; use\n`coordination.connections` to list saved connections without credentials. The\nprofile preserves tokens before claiming so an uncertain reply can be recovered\nwith the same IDs. Initial pairing windows last at most ten minutes. If that\nwindow or a grant expires, the original person must explicitly reconnect the\nsame profile under current limits. Missing profiles require fresh authorization.\nA profile holds at most 50 requests and 50 connections; keep it private.\n\nExisting one-room connections below still work. Import one with\n`coordination agent import --profile FILE --config OLD_PRIVATE_CONFIG` after\nsetting up the profile. Import preserves its scope and cannot reconstruct a\nprivate agent key discarded by older pairing; that connection cannot claim a\nsame-key execution handoff.\n\nDraft text and private instructions are sent to ScopeBlind. Your agent’s model\nprovider may receive tool results, including your own authorized private brief.\nA hosted assistant receives its own principal’s brief plus shared records.\nNeither profile setup nor a stopped client runs a background agent or model.\n\n### Make exact decisions on another device\n\nFrom a task on the original authorized browser, choose **Continue on another\ndevice**. Open or scan its link on your phone, request access, and compare the\nshown code on both devices. The original browser signs the exact phone key,\nroom, permissions, and expiry. A link or QR code alone grants no authority;\neach device retains its own private signing key.\n\nAccess lasts no longer than seven days or the task’s expiry. Depending on the\nchosen scope and the person’s existing role, the phone can inspect the task,\napprove or deny an exact payment, accept or request changes to its exact result,\nand sign its own negotiation mandate or exact tested-plan decision. It cannot\ncreate tasks, invite people or agents, start a hosted model, adopt rules, execute\npayments, or delegate to another device. Future agreement and reviewer-role\nsignatures are allowed only within that exact jointly reviewed proposal. They\ndo not carry phone access into the new task.\n\nThe original browser or the linked device can revoke that device’s access.\nRevocation blocks new actions; it does not erase valid earlier decisions.\nEvidence preserves the actual device signer, the original principal’s signed\nauthorization, and the service’s signed authorization-use receipt. Portable\nnegotiation, result, and rehearsal verification checks the required lineage.\nThese signatures identify keys, not verified real-world identities.\n\n[Your decisions](https://scopeblind.com/standard?trial=new&view=inbox) reads\ncurrent work authenticated by this device. Opening an item checks the current\nrequest again; expired or superseded decisions cannot authorize a changed\npayment or result. Optional browser reminders contain no task details or\ncredentials, open this inbox, and never approve work or wake an external agent.\nDelivery depends on the browser, operating system, and host configuration. On\niPhone or iPad, add ScopeBlind to the Home Screen, link that app’s device key,\nand enable reminders there. Reminders can be turned off without changing task\npermissions.\n\n### Connect your agent to a shared invoice room\n\n`protect-mcp` version `0.25.0` connects your installed agent to the same admission and\nsample-ledger service as the shared room. Start a room at\n[ScopeBlind](https://scopeblind.com/standard?trial=new), then choose **Use your\nown agent → Create pairing code**. It is a fictional invoice sandbox; no real\nmoney moves.\n\nThe release is distributed as a versioned package from scopeblind.com. Its\n[SHA-256 checksum](https://scopeblind.com/releases/protect-mcp-0.20.0.tgz.sha256)\nis published alongside it. Run the room's command in your terminal. For a single connection:\n\n```bash\nnpx --yes protect-mcp@0.25.0 coordination pair\n```\n\nPaste the private code when prompted. It is never a command-line argument or\nURL parameter. The command generates an independent agent key and credential,\nsaves pending state before claiming, verifies the owner authorization and pinned\nservice acknowledgment, then stores the completed connection in\n`~/.scopeblind/coordination.json` with permissions `600`. The pairing code lasts\nat most ten minutes; the resulting connection lasts at most 24 hours. The owner\ncan revoke it in the room. If a response is lost, rerun the same command with\nthe same config file to recover the same enrollment.\n\nFor multiple rooms, use the room-specific `--config` path shown in the browser.\nAn existing config is never replaced with a different room's credential.\n\nSuccessful pairing prints the Claude Code registration command directly. To\nprint it again:\n\n```bash\nnpx --yes protect-mcp@0.25.0 coordination setup --client claude-code\n```\n\nRun the command it prints in the project where you use Claude Code. It registers\nan MCP server in local scope, with the private config's path and no credential\nin the command or client settings. Restart Claude Code and check `/mcp`, then ask:\n\n> Inspect the ScopeBlind invoice room and its purchase orders. Complete the\n> permitted work under the agreed limits. Request exact approval where needed;\n> keep working on other invoices, then use coordination.wait for decisions. Deliver the completed result\n> for the recipient to review.\n\n`setup --client json` prints standard `mcpServers` configuration for manual use\nwith other clients. Use `setup --client codex` for Codex CLI registration. These commands print\nconfiguration and do not edit your client settings. For Claude Code, see its\n[official MCP documentation](https://code.claude.com/docs/en/mcp).\n\nThe MCP tools are:\n\n- `coordination.inspect`: inspect the owner-signed agreement, invoices, purchase\n  orders, budget, current and historical operations, and revision instructions.\n- `ledger.pay`: submit exact `operation_id`, `invoice_id`, `amount_minor`, `currency`\n  (`USD`), and `destination`. Live rooms also require the `fixture_revision` from\n  inspect. The adapter verifies the signed admission before execution and the\n  signed outcome afterward.\n- `coordination.wait`: pass the event `cursor` from inspect as `after_cursor`.\n  The tool waits up to 30 seconds and checks for changes every two seconds,\n  without calling the model between checks. It returns `changed` or `waiting`,\n  the current run/cursor, and what needs attention. On a timeout an active\n  session can wait again; resumption depends on the MCP client. This tool sends no push notifications; optional browser inbox reminders\n  are separate. Cancellation and disconnect stop an active wait.\n- `coordination.deliver`: provide the inspected `run_id` and freeze the result once all work has a recorded\n  disposition. The service refuses unresolved work. The recipient separately\n  accepts the exact result or requests a revision.\n\nRetain the same operation ID across retries and restarts. A changed payload\nunder that ID is refused. After a reviewer approves held work, retry the same\noperation unchanged. The agent cannot approve its own request, change rules,\ncreate a revision, invite people, or accept its own result. Owner-authorized\nrevisions retain the cumulative budget and duplicate-invoice protection.\n\nAn unknown execution outcome keeps its reservation. A repeated confirmed\noperation returns the original signed result; it does not pay twice. Revoking\nan agent stops future admissions and uncommitted effects, including a request\nthat raced with revocation. It does not undo confirmed payments.\n\nFor custom service operators, the original explicit connection remains:\n\n```bash\nnpx --yes protect-mcp@0.25.0 coordination \\\n  --endpoint https://YOUR-HOST/api/coordination \\\n  --room ROOM_ID \\\n  --authority-key PINNED_64_HEX_AUTHORITY_KEY \\\n  --token-env PROTECT_MCP_COORDINATION_TOKEN\n```\n\nThe named environment variable contains the executor credential. HTTPS is\nrequired except for loopback local testing. Redirects are refused. Credentials\nare never printed. The configured service receives the sample requests; your\nagent's model provider may receive records returned by the tools. The adapter\ncovers this sample-ledger path and does not govern other tools in your client.\n\n### Let an agent test the rules\n\nIn **Test these rules**, choose **Let your agent test the rules** to create a\nseparate, explicitly scoped test connection. Use its room-specific command and\nprivate code, then run the printed Claude Code registration command. Version\n`0.20.0` recognizes these version-2 pairing codes; old execution grants remain\nunchanged and do not gain test permissions. Use separate config files for an\nexecution connection and a test connection. Setup registers a test connection as\n`scopeblind-test`, so it does not overwrite the `scopeblind` execution connection.\n\nAsk your agent:\n\n> Inspect this rehearsal. I want a person to review invoices above $400.\n> Add that expectation for Fieldwork, propose the threshold change, and compare\n> the actual gate before and after. Explain which useful work still succeeds and\n> whether all required safety cases pass. Leave adoption to me.\n\nA test connection exposes only these four tools:\n\n- `coordination.inspect_rehearsal`: read the signed source agreement, records,\n  cases, proposals, and reports. Supply `report_digest` to retrieve an exact\n  historical evidence snapshot and verify it.\n- `coordination.propose_case`: add a case with a stable `id`, invoice, expectation,\n  and requirement. Fixed safety cases cannot be replaced or marked optional.\n- `coordination.propose_repair`: propose a review threshold and rationale bound\n  to the source agreement, fixture snapshot, and cases. Other terms cannot change.\n- `coordination.run_rehearsal`: supply a stable test `id` and optional `proposal_id`\n  to run the real gate in separate sample ledgers. The tool continues up to six\n  durable chunks within three minutes; unfinished work returns `pending` with\n  instructions to resume the same ID. Cancellation stops further client requests\n  and completed chunks remain available. If the response is lost or\n  times out, inspect the reports and retry the same test ID to recover its result.\n\nThe test agent cannot pay in the source room, approve exceptions, invite another\nagent, or activate a repair. The owner separately decides whether a passing\ncomparison should become a **new sample task**. That new task has its own ledger;\nsource agreements, budgets, payments, and results remain unchanged. Revocation\nblocks future requests and the final publication of a test still in flight.\n\nReports describe the observed gate behavior for concrete cases. A valid signature\nidentifies the named gate operator and protects the exact record from alteration;\nit does not prove all possible inputs or independently observe the operator.\nThe installed adapter verifies the report and snapshot bindings before returning\ncomparison evidence. Offline applications can check an exported bundle with:\n\n```js\nimport { verifyRehearsalEvidence } from 'protect-mcp';\nconst result = await verifyRehearsalEvidence(bundle, expectedAuthorityPublicKey);\nif (!result.valid) throw new Error(result.errors.join('; '));\nconsole.log(result.checks, result.limitations);\n```\n\nPin the authority key independently; omitting it checks against the key named in\nthe owner-signed source agreement. A verified report is evidence for a human\nadoption decision, not permission to execute a payment.\n\n### Local Action Dashboard\n\n`protect-mcp dashboard` is the operator view for moving from visibility to\nenforcement:\n\n- **Tool inventory:** every observed tool, call count, high/medium/low risk, and\n  whether the active policy has an exact rule, a wildcard fallback, or no rule.\n- **Policy coverage:** one-click local policy edits for `Require approval`,\n  `Block`, or `Observe`. Restart the wrapper after reviewing changes.\n- **Exact-action approval queue:** the exact tool, action, destination, redacted\n  payload preview, payload hash, policy basis, and reason capture before a human\n  approves, denies, edits, or takes over.\n- **Receipt chain:** request ids correlated with signed receipt hashes, so an\n  audit reviewer can see which decisions have cryptographic proof.\n- **Audit export:** downloads the offline-verifiable audit bundle when signed\n  receipts exist. If only unsigned local logs exist, the dashboard explains that\n  signing must be enabled first.\n\nFor live desktop fallback approvals, start the dashboard with the local gateway\napproval endpoint and nonce printed by the wrapper:\n\n```bash\nnpx protect-mcp dashboard --open \\\n  --approval-endpoint http://127.0.0.1:9876 \\\n  --approval-nonce \"$PROTECT_MCP_APPROVAL_NONCE\"\n```\n\n`Approve` forwards to the live local gateway when those flags are present.\n`Deny`, `Edit`, and `Take over` are recorded locally as approval-resolution\nrecords; use them as the operator instruction and rerun the tool when needed.\n\n### Paid Boundary MVP: digest anchoring, not data upload\n\nLocal self-signed receipts stay free and offline-verifiable. The paid boundary is\nindependent evidence that ScopeBlind saw a receipt digest at a time, under an org\nidentity, without receiving the raw prompt, tool payload, output, private key, or\nraw receipt.\n\n```bash\n# Create or refresh a local org identity and public-key directory.\nnpx protect-mcp registry init --org \"Meridian Global Macro\" --billing-account acct_meridian\n\n# Local preview: writes a digest registry and shareable static verifier page.\nnpx protect-mcp registry anchor\n\n# Hosted mode: uploads receipt digests only for independent anchoring.\nSCOPEBLIND_TOKEN=... npx protect-mcp registry anchor \\\n  --hosted \\\n  --endpoint https://api.scopeblind.com \\\n  --verifier-base https://scopeblind.com\n```\n\nThe local preview is deliberately labeled `local-preview-not-independent`.\nHosted mode anchors only receipt hashes, request ids, org public keys, and\nbilling metadata. It does not upload raw receipts or sensitive context.\n\n### Killer Demo: shadow to policy to proof\n\n`protect-mcp killer-demo` generates a complete three-minute sales/demo pack:\n\n```bash\nnpx protect-mcp killer-demo --dir ./scopeblind-demo\n```\n\nIt creates mock filesystem, GitHub, email, and PMS activity; shows risky calls in\nshadow mode; applies a policy pack; requires approval for a sensitive PMS booking;\nexecutes through the gateway; writes a signed receipt; proves the original\nreceipt verifies; proves a tampered receipt fails; and creates a selective\ndisclosure package that hides sensitive context while showing the minimum proof.\n\nOpen the generated `DEMO-RUNBOOK.md` first. Then run the printed dashboard\ncommand to walk a customer through the exact sequence.\n\n### Selective Disclosure v0\n\nCommitment-mode receipts can carry a `committed_fields_root` instead of exposing\nevery field in cleartext. Later, the holder can disclose selected fields only:\n\n```bash\nnpx protect-mcp verify-disclosure \\\n  --receipt ./receipts/selective-disclosure.receipt.json \\\n  --disclosure ./receipts/selective-disclosure.tool-only.json\n```\n\nThe verifier checks the parent receipt hash, Ed25519 signature, commitment root,\nand each disclosed field's Merkle proof. It then explains which fields were\ndisclosed and which committed fields remain hidden. This is salted commitment\ndisclosure, not full zero-knowledge, but it makes the privacy claim concrete:\nauditors can verify selected facts without receiving the full tool payload or\nsensitive desk context.\n\n### Prove a claim over the record (position-blind attestations)\n\nYou can prove a CLAIM over your record without revealing it. Mint a signed,\nposition-blind attestation over the whole record that discloses only per-decision\ncategories (a receipt digest, the verdict, capability tags), never your tool\ninputs, outputs, or data:\n\n```bash\n# \"No action reached the network across the record\":\nnpx protect-mcp claim --no net.egress\n\n# other predicates:\n#   --only fs.read,fs.write     all actions were confined to these capabilities\n#   --no-verdict blocked        no action was blocked\n#   --count blocked             how many were blocked\n```\n\nAnyone verifies it offline, seeing only the categories, never the content:\n\n```bash\nnpx protect-mcp verify-claim claim-<id>.json\n```\n\nThe verifier recomputes a Merkle root over the disclosed set and recomputes the\npredicate independently, so the issuer cannot lie about the claim given the\ndisclosure. Add `--anchor` to record the claim's digest in the public,\nappend-only ScopeBlind transparency log, so a counterparty who does not trust you\ncan confirm the disclosed set is complete and was not quietly re-cut (only the\nhash is sent; the record stays local):\n\n```bash\nnpx protect-mcp claim --no net.egress --anchor\n```\n\nThis is an accountable, position-blind attestation, not full zero-knowledge: it\nreveals the shape, not the content.\n\n## Try it in 60 seconds (no agent required)\n\n[![Watch the two-minute demo film](https://scopeblind.com/media/scopeblind-demo-poster.jpg)](https://scopeblind.com/film)\n\nWatch the two-minute film at [scopeblind.com/film](https://scopeblind.com/film), then replay it against your own copy:\n\n```bash\nnpx protect-mcp sample     # seed a labeled sample record (8 decisions: 1 blocked, 2 payments)\nnpx protect-mcp record     # open it: signatures verified in your browser\n\nnpx protect-mcp claim --payment-under 100 --anchor --output payments-under-100.json\nnpx protect-mcp verify-claim payments-under-100.json\nnpx protect-mcp anchor-record\n```\n\nDrop the generated `demo-tampered.jsonl` into the record page to watch a\npost-signing edit get caught. `sample` refuses to touch an existing record, so\nrun it in an empty folder. When you are ready for the real thing, wire the gate\nbelow and the same commands run against your agent's own record.\n\n## Claude Code hook quickstart\n\n```bash\n# Generate hook config and a sample Cedar policy.\nnpx protect-mcp init-hooks\n\n# Serve the Claude Code hook gate in enforce mode. It runs a restraint self-test\n# first and refuses to start if it cannot prove it denies a forbidden vector.\nnpx protect-mcp serve --enforce --cedar ./cedar\n```\n\nOne-shot evaluation, the way a PreToolUse hook calls it. Exit code 2 means deny\n(the tool is blocked); exit 0 means allow:\n\n```bash\nnpx protect-mcp evaluate --cedar ./cedar --tool Bash --input '{\"command\":\"rm\"}'\necho $?   # 2  -> denied, fail-closed\n\nnpx protect-mcp evaluate --cedar ./cedar --tool Read --input '{\"path\":\"README.md\"}'\necho $?   # 0  -> allowed\n```\n\nA missing or unloadable policy denies (exit 2) unless you explicitly pass\n`--fail-on-missing-policy false`.\n\n## Claude Code hooks\n\n`protect-mcp init-hooks` writes a `.claude/settings.json` for you. To wire the\ngate by hand, the two verbs you need are `evaluate` (PreToolUse, blocks on exit 2)\nand `sign` (PostToolUse, records a receipt). Claude Code hands a hook the call\nas JSON on stdin and sets no `TOOL_NAME` or `TOOL_INPUT` variables, so pass\n`--format claude` and nothing else about the call: the gate reads `tool_name`\nand `tool_input` from the payload, and on a deny it returns the reason to the\nmodel as `hookSpecificOutput.permissionDecisionReason` as well as exit 2. Pin\nthe version so a Claude Code session always runs the gate you tested:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"npx protect-mcp@0.25.0 evaluate --cedar ./cedar --format claude\"\n          }\n        ]\n      }\n    ],\n    \"PostToolUse\": [\n      {\n        \"matcher\": \"\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"npx protect-mcp@0.25.0 sign --format claude --receipts ./receipts --key ./keys/gateway.json\"\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n### Put a signed standard in force, and let the record land on its page\n\nFrom 0.14.0 the gateway can hold the signed standard itself (the `standard.json`\nwritten and signed on [scopeblind.com/write](https://scopeblind.com/write)) next\nto the Cedar policy compiled from it, and report to the standard's own page:\n\n```bash\n# Initialize the signing key once, unless this directory already has one.\nnpx protect-mcp@0.25.0 init\nnpx protect-mcp@0.25.0 --enforce --cedar ./policy --standard ./standard.json \\\n  --report 'https://scopeblind.com/api/standard?s=<standard id>' \\\n  -- <your MCP server command>\n```\n\nWith `--standard`, three of the standard's terms are enforced from the standard\nrather than inferred: a call to a tool the standard does not name is refused\n(`standard_tool_not_allowed`); a call whose amount is over the per-instruction\nlimit, or in another currency, is refused before it runs\n(`standard_amount_over_limit`, `standard_currency_not_permitted`); and a call\nwhose amount is above the approval threshold is **held** for the named person\n(`standard_requires_person`). Amounts are read from the call's `amount_minor`\n(integer minor units) or `amount` (major units) and `currency` fields; a call\nthat carries no amount is not a payment and is not held.\n\nA held call is answered to the model as a tool result, never an error, so the\nconversation continues: `REQUIRES_APPROVAL: ... waiting for the named person at\nhttps://scopeblind.com/standard?s=<id>#held-<hid>`. The person opens that page\nand approves or denies the exact action, signed in the browser with the key the\nstandard accepts. When the model retries the same call (the same payload hash),\nthe gate finds the decision: an approval lets the call through with the decision\nin the receipt (`approval: { hid, approver_key_id, digest, page }`); a denial\nrefuses it (`person_denied`). A changed call is a new action.\n\nWith `--report`, every receipt is appended to the local chain first and posted\nto the page after, in order, best-effort: the page never blocks a call, and a\npage that cannot be reached is logged, not fatal. The token comes from the Sign\ntab on the Write page, shown once; set it in the process environment as\n`PROTECT_MCP_REPORT_TOKEN`. `--run <id>` names the run on the page (default: a\ntimestamp). Receipts carry `standard: { request_id, digest }` so a reader can\ntell which standard was in force.\n\nThe hook server takes the same four flags, so a coding agent's calls through\nClaude Code hooks land on the page and are held under the standard the same way:\n\n```bash\nnpx protect-mcp@0.25.0 serve --enforce --cedar ./policy --standard ./standard.json \\\n  --report 'https://scopeblind.com/api/standard?s=<standard id>'\n```\n\nA hold on the hook path is returned as a deny whose reason names the page; the\nagent retries the same call after the person has decided there.\n\nThe gateway now also passes the call's input to Cedar as `context.input`, so a\npolicy compiled from a standard's amount limit is evaluated at the gate exactly\nas `sign --cedar` and the hook server evaluate it.\n\n### Sign the policy decision itself\n\nFrom 0.13.0, `sign` can evaluate the policy and record the real decision in the\nreceipt instead of an unconditional allow. Pass the policy directory and the\nsame input and context the hook would pass to `evaluate`:\n\n```bash\nnpx protect-mcp@0.25.0 sign --cedar ./cedar --tool Bash \\\n  --input '{\"command\":\"rm -rf /\"}' --context '{\"command_pattern\":\"rm -rf\"}' \\\n  --receipts ./receipts --key ./keys/gateway.json\n```\n\nWithout `--receipts`, the receipt joins the gateway's own log (`.protect-mcp-receipts.jsonl` in `--dir`), so a deployment has one chain and `record` shows every decision; `--receipts <dir>` keeps a separate `receipts.jsonl`.\n\nThe receipt payload then carries `decision` (allow or deny), `reason`\n(`cedar_allow` or `cedar_deny`), and `policy_digest` (the acta-policy-digest-v1\ndigest of the policy set), and cites draft-farley-acta-signed-receipts-03. The\ncommand prints the decision and digest on stdout. A deny is still signed: the\nreceipt is the record of the decision, not permission to proceed.\n\nTwo Cedar action models are supported. The runtime gate evaluates\n`Action::\"MCP::Tool::call\"` with the tool as the resource, which is what the\npolicies in `cedar/` expect and what `sign --cedar` uses by default. Policies\nthat name the tool as the action (`action == Action::\"Bash\"`), such as the\npublished conformance policy in agent-governance-testvectors, need\n`--action-model tool`. `evaluate` accepts the same flag.\n\n`evaluate` exits 2 on deny so Claude Code blocks the tool call, and 0 on allow.\n`sign` is best-effort: it appends an Ed25519-signed receipt when a key is\nconfigured, and if no signer is available it records an honest unsigned line\n(`\"signed\": false`) rather than failing the tool.\n\n## Use it in other agents (Codex, Cursor, Gemini, Hermes)\n\nThe same fail-closed gate runs as a tool hook in any agent that supports them. Add\n`--format <host>` so the verb reads that host's hook payload from stdin and denies\nin its contract:\n\n```bash\n# the PreToolUse / before-tool command for each host\nnpx -y protect-mcp@0.25.0 evaluate --format codex  --cedar ./cedar   # OpenAI Codex\nnpx -y protect-mcp@0.25.0 evaluate --format gemini --cedar ./cedar   # Gemini CLI BeforeTool\nnpx -y protect-mcp@0.25.0 evaluate --format cursor --cedar ./cedar   # Cursor beforeShellExecution\nnpx -y protect-mcp@0.25.0 evaluate --format hermes --cedar ./cedar   # Hermes pre_tool_call\n```\n\nPair each with `sign --format <host>` on the post-tool event for receipts. The\nimportant case is **Hermes**, which ignores hook exit codes and reads the verdict\nfrom stdout, so `--format hermes` denies via `{\"decision\":\"block\"}` rather than\nexit 2 (a raw exit-2 would silently fail open there). Without `--format`, the\nverbs read `--tool`/`--input` flags exactly as in the Claude Code section above.\n\n## Write a policy\n\nCedar policies live in a directory you point at with `--cedar`. A `forbid` rule\ndenies, a `permit` rule allows. To match against a value in the tool input, use\nthe `.contains()` idiom:\n\n```cedar\n// Allow read-only tools.\npermit(\n  principal,\n  action == Action::\"MCP::Tool::call\",\n  resource == Tool::\"Read\"\n);\n\n// Deny dangerous shell commands by matching the command against a list.\nforbid(\n  principal,\n  action == Action::\"MCP::Tool::call\",\n  resource == Tool::\"Bash\"\n) when {\n  [\"rm\", \"dd\", \"mkfs\"].contains(context.command)\n};\n\n// Block destructive tools outright.\nforbid(\n  principal,\n  action == Action::\"MCP::Tool::call\",\n  resource == Tool::\"delete_file\"\n);\n```\n\n> **Hazard:** do NOT write `context.command in [\"rm\", \"dd\"]` to match a string\n> against a list. `in` is for entity hierarchies, not string membership. Cedar\n> treats the expression as a type error and silently discards the whole `forbid`\n> rule, which (under a fail-open gate) leaves a residual `permit` standing. This\n> is the exact defect behind the advisory below. Use `[...].contains(context.command)`\n> instead. From 0.7.0 the gate denies on that error rather than permitting, and a\n> CI tripwire test fails the build if the pattern is reintroduced into a shipped\n> policy. See [GHSA-hm46-7j72-rpv9](https://github.com/ScopeBlind/scopeblind-gateway/security/advisories/GHSA-hm46-7j72-rpv9).\n\n### Starter policy packs\n\nMost teams should not write Cedar from scratch on day one. Install a starter\npack, run in shadow mode, inspect receipts, then tighten or enforce:\n\n```bash\nnpx protect-mcp policy-packs list\nnpx protect-mcp policy-packs show secrets-safe\nnpx protect-mcp policy-packs install filesystem-safe --dir ./cedar\nnpx protect-mcp policy-packs install all --dir ./cedar\nnpx protect-mcp serve --cedar ./cedar\n```\n\nBuilt-in packs:\n\n- `filesystem-safe`: destructive file actions and secret-like path reads.\n- `git-safe`: force pushes, hard resets, destructive cleanup, repo deletion.\n- `email-safe`: allow drafting, block unattended sends.\n- `database-safe`: read-oriented DB posture, block write/admin SQL.\n- `cloud-spend-safe`: obvious cloud spend creation and infrastructure destruction.\n- `secrets-safe`: common file, env, shell, and cloud secret exfiltration.\n- `finance-mandate-safe`: restricted-list and concentration breaches in booking flows.\n\n## Credentials the agent never holds\n\nThe gateway can hold a secret and inject it at dispatch, so the agent works with a label and never sees the value. Configure the vault in `protect-mcp.json`; the value is read from the named environment variable of the gateway process, not the agent's:\n\n```json\n{\n  \"credentials\": {\n    \"github_token\": { \"inject\": \"header\", \"name\": \"Authorization\", \"value_env\": \"GITHUB_TOKEN\" },\n    \"warehouse\":    { \"inject\": \"env\",    \"name\": \"PGPASSWORD\",    \"value_env\": \"WAREHOUSE_PASSWORD\" }\n  }\n}\n```\n\n### The grant travels with the call\n\nA personal-agent platform (Meta Muse, Claude Code, Codex, any MCP client) can present the grant its agent is acting under with each call, in `params._meta[\"veritasacta.com/connector\"]`, as a bare or platform-signed context: platform, agent, grant type (`one_time`, `session`, `task`, `time_bounded`, `perpetual`), an optional purpose and mandate digest. The gateway records it on the decision receipt as `connector`, together with what it could check about the platform's signature and the digest of the call it actually received. List the platform keys you trust in the policy file:\n\n```json\n{ \"connector_platform_keys\": { \"sb:platform:meta-muse\": \"<64 hex Ed25519 public key>\" } }\n```\n\nWithout a key for the signing kid the context is recorded as `unverifiable`, never as `valid`; a verifier with the key can still check the signature itself (`npx @veritasacta/verify receipt.json --platform-key <kid>=<hex>`). The profile is draft-farley-acta-connector-action-00; the vectors are in `vectors/connector-action.v1.json`.\n\n`inject: \"env\"` puts the value in the wrapped server's environment; `inject: \"header\"` and `\"query\"` attach it to the outbound call. A tool whose name matches a label is resolved on every call; if the secret is missing the call is refused with `credential_error` rather than sent without it. Each receipt for such a call carries `credential_ref` with the label, never the value, so a reader can see that the credential the standard names was used through the gateway. What the receipts cannot show is that the agent had no other copy of the secret; that is a property of the deployment.\n\nA ScopeBlind standard states this as `requirements.credentials_held_by_gate`, and the gateway receipt report on scopeblind.com/verify checks the label on every receipt for the tool.\n\n## Verify a receipt\n\nReceipts are signed and verifiable offline by anyone with the public key. No\nnetwork, no vendor, no trust in ScopeBlind:\n\n```bash\nnpx @veritasacta/verify ./receipts/receipts.jsonl --format jsonl\n# Exit 0 = valid, non-zero = tampered or malformed\n```\n\n`npx protect-mcp bundle --output audit.json` exports a self-contained,\noffline-verifiable audit bundle of your receipts plus the public signing key.\n\n## Security\n\n`protect-mcp` 0.7.0 fails closed by design. On any policy-evaluation error, a\nmissing engine, or a policy that errored at evaluation, the decision is DENY,\nnot allow. `serve --enforce` and `doctor` run a boot self-test that proves the\ngate denies a known-forbidden vector before it is trusted, and refuse to arm if\nit cannot.\n\n**Affected versions: 0.5.x and 0.6.x.** Those lines fail open (they return ALLOW\non evaluation error) and do not evaluate Cedar correctly against the pinned\nengine, so a `forbid` rule could fail to block. **Upgrade to >= 0.7.0.**\n\nDetails and remediation: [GHSA-hm46-7j72-rpv9](https://github.com/ScopeBlind/scopeblind-gateway/security/advisories/GHSA-hm46-7j72-rpv9).\nTo report a vulnerability, see [SECURITY.md](./SECURITY.md).\n\n## Commands\n\n| Command | Description |\n|---------|-------------|\n| `serve` | Start the HTTP hook server for Claude Code (port 9377). `--enforce` runs the restraint self-test first; `--cedar <dir>` and `--policy <path>` select the policy. |\n| `init` | Generate an Ed25519 keypair (`keys/gateway.json`), a config template, and a sample policy. |\n| `sample` | Seed a clearly-labeled sample record (8 decisions: one blocked call, two payments; kid `sample-demo`) plus a tampered copy, so `record`, `claim`, `verify-claim`, and `anchor-record` are replayable from scratch before wiring an agent. Refuses to touch an existing record; `--force` overrides. |\n| `policy` | See and change the Cedar policy from the terminal: `policy list` (permit / forbid / default-deny per tool, with how often the gate allowed or denied it), `policy show`, `policy allow <tool>`, `policy deny <tool>`, `policy path`. A running `serve` hot-reloads on the change. |\n| `wrap` | Print a protected MCP command or patch Claude Desktop MCP servers. Dry-run by default; use `--write` to update Claude Desktop config. |\n| `dashboard` | Start a local-only dashboard on `127.0.0.1` showing tool inventory, risk, policy coverage, exact-action approvals, receipt chains, and audit export. |\n| `recommend` | Draft a reviewable JSON policy from observed local calls. Dry-run by default; use `--write` to create `protect-mcp.recommended.json`. |\n| `registry` | Create an org identity, anchor receipt digests, and write a static verifier page. Hosted mode uploads digests only. |\n| `record` | Open a local, searchable viewer over your receipts (`--live` streams as the agent runs): Ed25519 signatures verified in your browser against your gateway key, capability tags, a provenance tree, and one-click signed export. All local, nothing uploaded. |\n| `claim` | Mint a signed, position-blind attestation of a predicate over the record (`--no <cap>` incl. `--no payment`, `--only <c1,c2>`, `--no-verdict <verdict>`, `--count <verdict>`, `--payment-under <cap>`), disclosing only decision categories. Add `--anchor` to record the claim digest in the public transparency log; enrolled keys anchor as a named org. |\n| `anchor-record` | Checkpoint the record's Merkle root + count + time range into the public log (heartbeat-friendly: skips when unchanged). A later claim whose commitment matches an anchored checkpoint is provably over the complete record as of that checkpoint. |\n| `verify-claim` | Verify a claim pack offline: signature, recomputed Merkle root, independently recomputed predicate, and the anchor sidecar when present (binds the anchored envelope to this exact claim, then confirms the public log holds it). `--check-anchor` requires the anchor; `--offline` skips the log hop. |\n| `killer-demo` | Generate a complete shadow-mode to policy to approval to signed-receipt demo pack. |\n| `verify-disclosure` | Verify a `scopeblind.selective_disclosure.v0` package and explain disclosed versus hidden fields. |\n| `policy-packs` | List, inspect, and install starter Cedar policy packs. |\n| `evaluate` | Evaluate one tool call against a Cedar policy (PreToolUse gate). Exit 2 = deny (fail-closed), exit 0 = allow. |\n| `sign` | Sign one tool call into a receipt (PostToolUse). Best-effort: records an honest unsigned line if no key. |\n| `simulate` | Dry-run a policy against a recorded decision log to see what it would have blocked. |\n| `demo` | Start a built-in demo server wrapped with the gate, to see receipts instantly. |\n| `doctor` | Check your setup (keys, policies, Cedar engine, verifier) and run the restraint self-test. |\n| `bundle` | Export an offline-verifiable audit bundle of receipts plus the public key. |\n| `report` | Generate a compliance report (Markdown or JSON) from the decision log and receipts. |\n\nRun `npx protect-mcp --help` for the full flag reference.\n\n## Links\n\n- Protocol (IETF): [draft-farley-acta-signed-receipts](https://datatracker.ietf.org/doc/draft-farley-acta-signed-receipts/)\n- [CHANGELOG](./CHANGELOG.md)\n- [npm](https://www.npmjs.com/package/protect-mcp)\n- [scopeblind.com](https://scopeblind.com)\n\nMIT licensed. Built by [ScopeBlind](https://scopeblind.com).\n\n\n### Let your agent negotiate for you\n\nVersion `0.25.0` supports the two-person agreement at\n[ScopeBlind](https://scopeblind.com/standard?trial=new&view=negotiate). Each person\nsigns their own mandate and creates their own version-3 pairing code. The private\nconfiguration binds one principal and discussion; it does not inherit payment\nor reviewer powers. Existing version-1 and version-2 connections retain their scopes.\n\nAsk your agent:\n\n> Inspect my negotiation mandate and private brief. Seek a review threshold that\n> satisfies both shared mandates and their invoice requirements. Propose, compare,\n> and respond using only the negotiation tools. Leave approval of the exact plan\n> to both people.\n\nTools: `coordination.inspect_negotiation`, `coordination.propose_candidate`,\n`coordination.respond_candidate`, `coordination.compare_candidate`, and\n`coordination.wait_negotiation`. Waiting polls only the scoped discussion and is\ncancelable, bounded to 30 seconds. Each agent can read its own principal's private\nbrief, never the other person's brief. ScopeBlind stores the briefs; your model\nprovider may receive your own agent's tool results. Shared exports omit the briefs.\n\nThe discussion can change the invoice review threshold, with at most three\ncandidates. Both people sign the exact proposal, gate report, future agreement,\nand reviewer enrollment before the organizer creates a separate trial. Agent\nrecommendations cannot substitute for those approvals. The browser verifier\nchecks the shared history offline, including the principal's independently signed\npairing authorization for contributions made by an installed agent.\n\n\n### Review a visible repository change together\n\nOpen [the contact-button demo](https://scopeblind.com/standard?trial=new&view=repository)\nto create an isolated ScopeBlind-owned repository task and invite a second person.\nThe preview renders checked `demo/contact.json` data with a fixed template; it does\nnot execute repository code or claim that a public website was deployed. Both\npeople approve the exact reviewed commits before the trusted receiver applies them.\nThe recipient can accept the observed result or request a linked fresh revision.\n\nFor your own repository, choose **Use your repository** and run the generated\n`protect-mcp@0.25.0 repository setup` command locally. It discovers actual check\nnames/providers, saves a receiver key with owner-only permissions, and prepares a\nhash-pinned workflow for your review. The returned `connection.json` contains public\nkeys and signed discovery evidence. Keep `receiver-key.json` private. Discovery,\nan installed matching workflow, and a signed successful Actions readiness run are\nshown separately. None grants human approval of a task.\n\nThe browser-generated command supplies your public owner key and service authority\npin. Its complete form is below; replace each uppercase placeholder with those\nreviewed values and choose a new output directory. Sign in locally with `gh auth login`,\nor supply `GITHUB_TOKEN` through your local credential manager. Setup does not save\nor print that token.\n\n```sh\nnpx --yes protect-mcp@0.25.0 repository setup \\\n  --repository OWNER/REPOSITORY \\\n  --owner-key YOUR_PUBLIC_OWNER_KEY \\\n  --authority-key REVIEWED_SERVICE_AUTHORITY_KEY \\\n  --endpoint https://scopeblind.com/api/coordination \\\n  --output ./repository-connection\n```\n\nTo inspect the existing CI checks for a particular open, same-repository pull\nrequest, add `--pull NUMBER`. Review the generated `INSTALL.md` before installing\nthe workflow or configuring Actions. Import only the public `connection.json`.\nTo refresh local read-only readiness for this same connection, use a new output file:\n\n```sh\nnpx --yes protect-mcp@0.25.0 repository ready \\\n  --connection ./repository-connection/connection-config.json \\\n  --key-file ./repository-connection/receiver-key.json \\\n  --output ./repository-readiness.json\n```\n\nThis local refresh does not establish that the Actions receiver is responding.\nFor that observation, run the reviewed workflow's `ready` operation and import its\npublic evidence as described in `INSTALL.md`.\n\nYour reusable agent profile exposes its public key through `coordination.connections`.\nAuthorize that exact key in the repository task, then ask the agent to call\n`coordination.inspect_repository` with the task and grant IDs. The returned repository\nconnection supports `coordination.request_repository_revision` with an explicit\ncurrent basis digest and stable request ID. It can suggest bounded contact-page\ndata and a reason; it cannot enroll a reviewer, approve a change, or execute the\nreceiver. Reusing a request ID retries the exact original signed suggestion.\n\n### Recurring client reviews and agent preparation\n\nCreate a client project from the repository review page to reuse its repository,\nreceiver connection and reviewer membership. Each review contains its own brief,\nstable success criteria and exact pull-request snapshot. Both people approve that\nreviewed version; the recipient can separately accept the observed result.\n\nFor recurring preparation, both people can sign a mandate naming one public agent\nkey, repository, branch, permitted paths, required check providers, expiry and\nrequest limits. Obtain the profile's public key with `coordination.connections`,\nthen authorize it in the project's **Agent permissions** panel. A connected agent\nuses these tools:\n\n| Tool | Purpose |\n| --- | --- |\n| `coordination.inspect_workspace` | Verify the project and joint mandate; inspect remaining allowance and existing drafts. |\n| `coordination.prepare_repository_review` | Submit a signed PR review draft to the project inbox for a person to adopt. |\n| `coordination.inspect_repository_review` | Read the assigned task's exact brief, criteria, receiver packet and attributed feedback. |\n| `coordination.report_repository_criteria` | Report `met`, `not_met` or `unknown` against each criterion, citing evidence present in the packet. |\n| `coordination.request_repository_changes` | Record general revision feedback tied to the exact reviewed version. |\n\nUse the exact `workspace_id` and `mandate_id` shown in the project. After inspection,\nthe mandate ID becomes this purpose's `connection_id`. Reuse a stable `request_id`\nafter an interrupted submission; the private profile retains the original signed\nintent. New findings against a changed packet require fresh inspection and a new ID.\nTo prepare a revision from recorded feedback, include the exact `draft.source`\nreference returned by the review: task ID and digest, basis digest, packet digest\nand feedback digest. The project preserves that reference in the new review's\nportable evidence. The new version requires fresh human approvals.\n\nThese permissions prepare and review work. They cannot impersonate a person, adopt\nthe mandate, approve a change, merge a PR or accept a result. ScopeBlind does not\nstart a hosted model or keep an external agent running. The implementer handles\nrequested code changes through their existing development tools and permissions.\n\nA receiver's preview record describes GitHub deployment and check metadata for the\nobserved commit. An external preview URL remains mutable; it is not an immutable\nartifact or proof of the bytes subsequently served. Criterion findings are attributed\nagent recommendations, including explicit unknowns, for the human decision.\n\nProject recovery uses a separately enrolled recovery credential. It rotates that\nproject member's future authority; it never recreates an old browser private key\nor rewrites historical approvals. Start a new review with the current membership\nbefore making further decisions on work assigned to a former key.\n\n\n### Guided connection and bounded code work\n\nOpen [your projects](https://scopeblind.com/standard?trial=new&view=workspace) and connect a repository. The guided route identifies the selected repository and pull request, then supplies a version-pinned installer command. Paste its short-lived setup link into the prompt rather than a shell argument:\n\n```sh\nnpx --yes protect-mcp@0.25.0 repository connect --link-stdin --install\n```\n\nReview the exact workflow, permissions and receiver key before authorizing installation. Keys are generated locally. A GitHub Actions identity proof and receiver signature establish which installed workflow answered the readiness challenge. Existing manual receiver setup remains available.\n\nCoding work is an optional, separate installation and permission. Both project members sign the allowed paths, fixed tests/build, immutable runtime image, public-preview permission, time, file, token and model-call limits. The worker starts from exact recorded feedback. Its untrusted repository programs run in a Docker container without network access or credentials; the trusted controller checks the resulting files and publishes the admitted new branch, PR and preview. The initial runtime supports small Node 22 static sites with self-contained relative assets and fixed Node test/build scripts.\n\nAutomatic job startup requires the GitHub App connection. With an owner-local connection, the queued job shows the exact repository’s `scopeblind-coding.yml` Actions page, branch and job ID. Select **Run workflow** and supply that existing ID as `job_id`; this does not create another job or bypass either person’s permission.\n\nGitHub Actions must be allowed to create pull requests under **Settings → Actions → General → Workflow permissions**. Existing required CI may need **Approve workflows to run** or a configured manual run for the exact new PR head. `GITHUB_TOKEN`-created PRs do not guarantee automatic execution of existing CI; [GitHub documents the current trigger and approval rules](https://docs.github.com/en/actions/how-tos/write-workflows/choose-when-workflows-run/trigger-a-workflow). Every agreed check/provider remains mandatory before review approval or an effect.\n\nThe result requires a fresh review. No coding grant authorizes a merge. After a publication was admitted, cancellation cannot undo effects already sent; an uncertain result is reconciled by reading its deterministic branch and PR. Signed evidence distinguishes these observations from proof that the code meets every criterion.\n\nProject members can also authorize a second browser for selected review actions. Both devices confirm the link. This preserves the original membership key and never grants project setup, recovery, agent delegation or execution permissions. Revocation stops new device access and decisions while preserving already recorded signatures.\n\n\n### Shared managed coding trial\n\nThe hosted [real AI revision trial](https://scopeblind.com/standard?trial=new&view=repository&coding_trial=new) uses a disposable ScopeBlind-owned repository. Two browser identities agree the work, authorize one bounded coding job, inspect the published preview, approve the exact resulting change and accept the recorded result. It does not require visitor GitHub access. The initial styled starter is deterministic; only the separately authorized revision is model-produced.\n\nThe managed controller is shipped as `dist/repository-trial-cli.js`. It is not a general-purpose hosted repository credential or a way to bypass a project's own receiver. Its reviewed workflow pins the repository, template, service authority and worker identities. If publication succeeds but GitHub readiness confirmation is interrupted, users can check the existing publication without changing it, then explicitly finish that same PR’s readiness while both people’s permission remains current. Neither step reruns the model or replaces the PR. Recovery observations describe current provider state; they are not approvals, merge receipts, or code-correctness guarantees.\n","readmeFilename":"README.md"}