Server data from the Official MCP Registry
Deterministic AI audit layer for LLM/agent outputs: policy checks, tamper-evident log, x402.
About
Deterministic AI audit layer for LLM/agent outputs: policy checks, tamper-evident log, x402.
Remote endpoints: streamable-http: https://mcp.fronesislabs.com/mcp
Security Report
DCL Trust Oracle is a deterministic audit system with reasonable security architecture, but has several code quality and permission scope concerns that warrant attention. The codebase includes proper authentication via x402 protocol, stateless crypto detectors with appropriate regex-based patterns, and metadata-only storage design. However, incomplete input validation in regex patterns, overly broad exception handling, potential information leakage through verbose error messages, and excessive permissions for the stated purpose lower the score into the moderate range. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity).
3 files analyzed · 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
DCL Trust Oracle — x402 MCP Server
Deterministic AI audit layer with cryptographic micropayments via x402 protocol.
What It Does
DCL Trust Oracle provides deterministic policy evaluation for LLM outputs with a tamper-evident audit chain. The system stores only cryptographic hashes and decision metadata — never raw content — enabling verifiable, post-action forensic analysis across distributed AI agents.
Available two ways, both metered per call via x402:
- REST API (
webhook_server.py) — direct HTTP integration, x402-gated withfastapi-x402. - MCP Server (
mcp_server.py) — native Model Context Protocol integration for AI agents, hosted on Smithery, x402-gated withpaymcp.
Both servers share the same evaluation logic and tamper-evident chain (dcl_core.py), and are priced identically.
Quick Start
REST API
pip install -r requirements.txt
python webhook_server.py
Server runs on http://localhost:8080
MCP Server
pip install -r requirements.txt
python mcp_server.py
Server runs on http://localhost:8081 (streamable-http transport)
Tools & Endpoints
Pre-Action Evaluation
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
POST /evaluate/fast | dcl_evaluate_fast | $0.01 | Fast policy check for low-risk outputs. Returns tamper-evident tx_hash. |
POST /evaluate/strict | dcl_evaluate_strict | $0.05 | Deep analysis for high-stakes outputs with higher confidence thresholds. |
POST /evaluate/jailbreak | dcl_evaluate_jailbreak | $0.02 | Instruction adherence check — detects prompt injection patterns and role-hijacking attempts. |
POST /evaluate/safety | dcl_evaluate_safety | $0.01 | Baseline screening for known harmful text patterns. Optimized for high throughput. |
POST /evaluate/quality | dcl_evaluate_quality | $0.03 | Content quality & drift check — evaluates format adherence and contextual drift. |
POST /evaluate/batch | dcl_evaluate_batch | $0.10 | Bulk processing — up to 20 items per transaction. Cost-effective for multi-turn history. |
Session Management
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
POST /pipeline/start | dcl_pipeline_start | $0.05 | Initializes a long-running audit session for continuous drift tracking. Returns pipeline_id. |
Post-Action Forensics
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
GET /audit/{tx_hash} | dcl_audit_decode | $0.10 | Basic post-action audit — returns verdict, confidence, agent_id, reason by tx_hash. |
GET /audit/{tx_hash}/deep | dcl_audit_decode_deep | $0.50 | Deep forensic audit — includes drift context, tamper-evidence indices, environmental metadata. |
Utility (free, REST only)
| Endpoint | Description |
|---|---|
GET /health | Service status and chain length |
GET /policies | List of built-in policy names |
GET /chain/status | Chain integrity, drift mode, drift score |
GET /chain/export | Full chain export with integrity verification |
Example Response
{
"verdict": "COMMIT",
"confidence": 0.95,
"reason": "All policy checks passed",
"tx_hash": "0x7a8f3b2c...",
"chain_index": 42,
"input_hash": "0x9d4e1f...",
"policy_version": "1.0.0",
"timestamp": 1721635200.123,
"pipeline_id": "abc123",
"drift_mode": "NORMAL",
"drift_score": 0.15
}
x402 Integration
All paid endpoints and tools require payment via the x402 protocol before returning a result — no free tier, no bypass. Both the REST API and MCP server settle to the same wallet.
- Networks: Base, Avalanche, IoTeX
- Asset: USDC
- Facilitator (REST):
https://x402.org/facilitator(viafastapi-x402) - Facilitator (MCP):
paymcpinMode.AUTO— automatic on-chain payment for x402-aware MCP clients, guided payment link (ELICITATION/RESUBMIT) for clients without a wallet. No path skips payment.
Metadata-Only Architecture
DCL Trust Oracle is designed around a hash-based audit trail:
- Raw content never stored — only SHA-256 hashes and decision metadata
- Tamper-evident cryptographic chain (SQLite-backed, WAL mode)
- Chain survives server restarts — audit records persist indefinitely
- Verifiable integrity via
GET /chain/status - Full export via
GET /chain/export - Shared chain across REST and MCP — a
tx_hashreturned by one interface can be audited through the other
Each audit record contains: tx_hash, prev_hash, verdict, input_hash, policy_hash, agent_id, reason, confidence, task_type, timestamp, and drift_context.
Built-in Policies
| Policy | Min Confidence | Purpose |
|---|---|---|
default | 0.70 | General-purpose evaluation |
anti_jailbreak | 0.80 | Detects prompt injection, role-hijacking, DAN-style attacks |
safety | 0.75 | Baseline harmful-pattern screening |
content_quality | 0.85 | Quality assurance, format adherence, drift detection |
Custom policies can be passed inline as YAML via the policy field.
Links
- Live API: https://fronesislabs.com/docs
- MCP Server: https://mcp.fronesislabs.com
- MCP Manifest: https://fronesislabs.com/.well-known/agent.json
- GitHub: https://github.com/Fronesis-Labs/dcl-webhook
- Smithery.ai: https://smithery.ai/servers/fronesislabs/dcl-trust-oracle
- Glama.ai: https://glama.ai/mcp/servers/Fronesis-Labs/dcl-webhook
Contact
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
