Back to Browse

Kinetic Gain MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

Unified MCP server for the 12-spec Kinetic Gain Suite + DefenseTech 6-pack — 75 governance tools.

About

Unified MCP server for the 12-spec Kinetic Gain Suite + DefenseTech 6-pack — 75 governance tools.

Security Report

4.8
Use Caution4.8High Risk

mcp-kinetic-gain is a well-engineered MCP server implementing 12 specification schemas with thoughtful security controls. Network requests are properly guarded with origin validation and response size limits; no credentials are hardcoded; sensitive data handling follows documented principles. Minor concerns around error logging and missing SSRF validation on redirect chains are present but do not pose significant risk given the server's purpose as a developer tool for protocol validation. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

3 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

network_https

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Optional URL of a running audit-stream-py instance to enable the live audit-stream tools (audit_event_emit, audit_events_query, audit_chain_verify_live).Optional

Environment variable: AUDIT_STREAM_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mizcausevic-dev-mcp-kinetic-gain": {
      "env": {
        "AUDIT_STREAM_URL": "your-audit-stream-url-here"
      },
      "args": [
        "-y",
        "mcp-kinetic-gain"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

mcp-kinetic-gain

One MCP server, all twelve Kinetic Gain Protocol Suite specs + the v0.1.0 implementation tooling + the DefenseTech 8-pack. Drop into Claude Desktop, Cursor, or any MCP-compatible client with a single config entry. The agent gains 75 tools (47 spec + 16 implementation-preview + 8 DefenseTech + 4 AI Claims Decision Card, v0.9.0): AEO Protocol, Prompt Provenance, Agent Cards, AI Evidence Format, MCP Tool Cards, AI Tutor Cards, Student AI Disclosure, Classroom AI AUP, Clinical AI Disclosure, AI Incident Card, AI Procurement Decision Card, AI Claims Decision Card - plus hash attestation (ed25519), audit-stream event composition + chain verification (offline AND live against a running audit-stream-py via AUDIT_STREAM_URL), cross-spec drift detection, Decision Intelligence preview, and the DefenseTech vault resolver + invariant checkers. New in v0.9.0: the AI Claims Decision Card (InsurTech, claims_card_version) - claims_card_validate, claims_card_inspect, claims_card_sign, claims_card_chain.

This is the agent-facing companion to kinetic-gain-visualizer: the visualizer renders the specs for humans, while this server exposes validation and workflow tools for agents. The optional audit_event_emit tool writes to a configured audit-stream service.

Tools

  • aeo_fetch - Fetch the full AEO Protocol declaration at an origin's
  • aeo_inspect - Return a structured summary of an AEO declaration: entity
  • aeo_get_claim - Extract a single AEO claim by ID
  • aeo_well_known_url - Compute the canonical AEO well-known URL for an origin
  • prompt_provenance_validate - Validate a Prompt Provenance JSON document against the v0.1
  • prompt_provenance_inspect - Structured summary of a Prompt Provenance document: prompt
  • prompt_provenance_eval_result - Extract a single evaluation suite's result from a Prompt
  • agent_card_well_known_url - Compute the canonical Agent Card well-known URL for a given
  • agent_card_inspect - Structured summary of an Agent Card document
  • agent_card_tool_disclosure - Return the list of tools an agent declares, with side-effect
  • agent_card_validate - Validate an Agent Card JSON document against the v0.1 schema.
  • ai_evidence_validate - Validate an AI Evidence object against the v0.1 schema.
  • ai_evidence_inspect - Structured summary of an AI Evidence object: claim text
  • ai_evidence_verify_hash - Compute SHA-256 over the canonical UTF-8 form of
  • tool_card_well_known_url - Compute the canonical MCP Tool Card well-known URL
  • tool_card_inspect - Structured summary of an MCP Tool Card: tool identity, safety
  • tool_card_tested_with - Return the tested-LLM entries for a tool, optionally filtered
  • tool_card_validate - Validate an MCP Tool Card JSON document against the v0.1
  • tutor_card_well_known_url - Compute the canonical AI Tutor Card well-known URL
  • tutor_card_fetch - Fetch a Tutor Card from a URL
  • tutor_card_validate - Validate an AI Tutor Card JSON document against the v0.1
  • tutor_card_inspect - Structured summary of a Tutor Card: tutor identity, audience
  • tutor_card_subject_check - Classify a topic against the tutor's subject scope
  • tutor_card_coppa_check - Enforce the spec's COPPA conditional rule: if
  • disclosure_validate - Validate a Student AI Disclosure JSON document against the
  • disclosure_inspect - Structured summary of a Student AI Disclosure: assignment
  • disclosure_verify_artifact_hash - Recompute SHA-256 over a candidate artifact and compare to
  • disclosure_verify_prompt_hash - Verify a single prompt hash in a hashed-mode disclosure
  • disclosure_aup_check - Surface the disclosure's policy posture: whether an aup_uri
  • aup_well_known_url - Compute the canonical Classroom AI AUP well-known URL
  • aup_fetch - Fetch a Classroom AI AUP from a URL
  • aup_validate - Validate a Classroom AI AUP JSON document against the v0.1
  • aup_inspect - Structured summary of a Classroom AI AUP: policy identity
  • aup_check_compliance - HEADLINE TOOL, joins an AUP with a Student AI Disclosure and
  • clinical_ai_well_known_url - Compute the canonical Clinical AI Card well-known URL
  • clinical_ai_fetch - Fetch a Clinical AI Card from a URL
  • clinical_ai_validate - Validate a Clinical AI Card JSON document against the v0.1
  • clinical_ai_inspect - Structured summary of a Clinical AI Card: system identity
  • incident_well_known_url - Compute the canonical AI Incident Card well-known URL
  • incident_fetch - Fetch an AI Incident Card from a URL
  • incident_validate - Validate an AI Incident Card JSON document against the v0.1
  • incident_inspect - Structured summary of an AI Incident Card: incident identity
  • incident_index_fetch - HEADLINE TOOL, fetch a vendor's
  • decision_card_well_known_url - Compute the canonical AI Procurement Decision Card well-known
  • decision_card_fetch - Fetch an AI Procurement Decision Card from a URL
  • decision_card_validate - Validate an AI Procurement Decision Card JSON document
  • decision_card_inspect - Structured summary of an AI Procurement Decision Card: buyer
  • decision_card_infer_status - Given a rubric, infer the right decision.status
  • decision_card_to_policy_bundle - Translate a Decision Card into the PolicyBundle that
  • decision_card_signature_check - Structural check on a Decision Card's signatures[] block
  • incident_affected_walk - Walk an Incident Card's affected block and return every
  • incident_remediation_plan - Map each affected URI in an Incident Card to a recommended
  • attestation_canonical_hash - Compute the SHA-256 canonical-JSON hash of an arbitrary value
  • attestation_verify - Verify an ed25519 Attestation envelope against a body and
  • attestation_inspect - Pretty-print an Attestation envelope with structural
  • audit_event_compose - Build a ready-to-POST audit-stream-py GovernanceEvent
  • audit_chain_verify - Walk an array of GovernanceEvents top-to-bottom and verify
  • audit_event_inspect - Pretty-print one GovernanceEvent with structural validation
  • audit_event_emit - Writes a governance event to the audit-stream-py instance
  • audit_events_query - GET recent governance events from a running audit-stream-py
  • audit_chain_verify_live - Ask a running audit-stream-py instance to walk its own chain
  • suite_doc_detect_spec - Detect which Kinetic Gain Suite spec a JSON document is by
  • suite_doc_drift - Structural diff between two versions of the same Suite
  • defensetech_vault_resolve_3axis - Resolve a (CUI tier, export-control status, foreign-person
  • defensetech_audit_event_check_invariants - Run all 3 DefenseTech audit-stream invariants against a
  • defensetech_check_dfars_72h_clock - Check DFARS 252.204-7012(c)(1)(ii) 72-hour cyber-incident
  • defensetech_check_cui_distribution_statement - Check that a CUI-Specified+ tier event carries the required
  • defensetech_check_itar_us_person - Check that an ITAR resource event has US-PERSON-VERIFIED (or
  • defensetech_incident_classify_event_type - Given a freeform description of a defense-AI incident
  • defensetech_summarize_cmmc_evidence_bundle - Summarize a CMMC L2/L3 readiness evidence bundle: target
  • defensetech_vault_contract_cross_binding_check - Verify the cross_binding_refs block on a DefenseTech vault
  • claims_card_validate - Validate an AI Claims Decision Card against the bundled v0.1
  • claims_card_inspect - Structured summary of an AI Claims Decision Card: claim type
  • claims_card_sign - Compute the canonical SHA-256 hash of an AI Claims Decision
  • claims_card_chain - Link a new AI Claims Decision Card to its predecessor: sets

Specs with a well-known URL convention (AEO, Agent Cards, Tool Cards) get fetch tools. Specs without one (Prompt Provenance, AI Evidence - these usually travel inline with answers or in repos, not at fixed paths) get parse tools that take a document_json string.

Network and data boundaries

URL fetch tools make outbound HTTP(S) requests to user-supplied origins. The server rejects local and nonpublic destinations, rechecks redirects, and limits JSON responses to 1 MB. AUDIT_STREAM_URL optionally enables live event queries and audit_event_emit, which sends and persists kind, source, and payload at the configured service. Approve that write before calling it; avoid secrets and personal data unless the service is approved to store them. Use HTTPS for a remote audit-stream service.

Schema validation checks the document shape and selected rules. A passing result is not proof of FERPA, COPPA, HIPAA, FDA, EU AI Act, CMMC, or other legal compliance. attestation_verify checks a signature against the public key supplied by the caller; it does not establish the key owner's identity.

Start with a task

  • Review a card: pass a parsed document to claims_card_validate, then use claims_card_inspect to summarize its declared decision. Investigate any validation failure before relying on the summary.
  • Compare drafts: call suite_doc_drift with two versions of the same Suite document to see structural changes before publication.
  • Check a signature: call attestation_verify with a public key obtained through a trusted channel; separately confirm that the key belongs to the claimed signer.
  • Record an event: prepare the payload with audit_event_compose, review it for sensitive data, then call audit_event_emit only when the configured audit-stream service and write are approved.

Install

npm install -g mcp-kinetic-gain

Or run without installing via npx:

npx mcp-kinetic-gain

For a controlled deployment, pin a reviewed package version in the client config (mcp-kinetic-gain@<version>) and upgrade deliberately.

Claude Desktop config

Add to your claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\):

{
  "mcpServers": {
    "kinetic-gain": {
      "command": "npx",
      "args": ["-y", "mcp-kinetic-gain"]
    }
  }
}

Restart Claude. All 75 tools appear in the tools panel. Try:

"Use aeo_inspect on https://mizcausevic-dev.github.io to summarize the entity declaration, then use ai_evidence_verify_hash to check the content_hash of an evidence object against my candidate text."

CLI mode (v0.5.1+)

The same binary doubles as a Suite JSON validator outside any MCP host. Useful in CI, pre-commit hooks, or local sanity-checks.

# Validate a single document
npx mcp-kinetic-gain validate path/to/ai-entity.json

# Validate a tree of well-known files
npx mcp-kinetic-gain validate ".well-known/**/*.json"

# Multiple paths or globs
npx mcp-kinetic-gain validate cards/clinical-*.json cards/incident-*.json

# Other commands
npx mcp-kinetic-gain --version
npx mcp-kinetic-gain --help

The CLI auto-detects which Suite spec each file belongs to via its top-level version field (aeo_version, clinical_ai_card_version, aup_version, etc.) and validates it against the same zod schemas the MCP tools use. Output is GitHub-Actions-aware: when GITHUB_ACTIONS=true, failures emit ::error:: workflow commands so they surface as PR annotations.

Exit codes:

CodeMeaning
0Every matched file passed validation
1At least one file failed validation, failed to parse, or no files matched
2No file in the input matched a known Suite spec
3Usage error (missing arg, unknown command or flag)

Running mcp-kinetic-gain with no arguments still launches the stdio MCP server - existing Claude Desktop / Cursor configs are unaffected.

Why one server instead of five?

  • One Claude Desktop config entry instead of five
  • Cross-spec workflows are atomic - an agent can agent_card_tool_disclosure to find a Tool Card URI, then call tool_card_inspect on that URI in the same conversation, all through one server
  • Shared schemas + utilities keep the implementation cohesive
  • Deprecation path - if mcp-aeo-server (the AEO-only predecessor) gets retired, the AEO tools live on here with the same names and contracts

Architecture

src/
├── server.ts              # MCP entrypoint and handler dispatch
├── cli.ts                 # JSON validation CLI
├── tools.ts               # 75 tool descriptors (JSON Schema inputs)
├── schemas.ts             # Zod schemas for the 12 specs
├── common.ts              # guarded fetch and canonical hashes
└── handlers/              # one module per spec plus cross-spec and live tools

Each handler module is independent and could be split into a separate package if needed.

Hash canonicalization

ai_evidence_verify_hash follows the AI Evidence Format spec's canonical SHA-256 rules:

  1. Read content as UTF-8
  2. Normalize line endings to \n
  3. Strip a single trailing newline
  4. SHA-256, lowercase hex, prefixed sha256:

If your candidate_text produces an unexpected mismatch, check CRLF vs LF and trailing newlines first.

Tests

Run the unit and local HTTP tests without an external service:

npm install
npm run typecheck
npm test
npm run build

License

This server: AGPL-3.0. If a modified version serves users over a network, the AGPL requires an offer of Corresponding Source to those users under its terms. See the GNU AGPL FAQ and LICENSE.

The specs themselves: MIT. Maximally permissive. Anyone may implement, validate against, or extend any Kinetic Gain Protocol Suite specification. The dual-license split is deliberate: the protocol stays open, the reference server is copyleft.

Kinetic Gain Protocol Suite

75 tools total across the twelve specs below plus cross-cutting ops (hash attestation, audit-stream events, cross-spec drift) and the DefenseTech tooling. See the Tools catalog above for the full per-tool list (47 spec + 16 implementation-preview + 8 DefenseTech + 4 AI Claims Decision Card).

SpecVertical
AEO ProtocolCore
Prompt ProvenanceCore
Agent CardsCore
AI Evidence FormatCore
MCP Tool CardsCore
AI Tutor CardsEdTech
Student AI DisclosureEdTech (FERPA/COPPA)
Classroom AI AUPEdTech
Clinical AI DisclosureHealthTech (FDA SaMD + HIPAA)
AI Incident CardCross-cutting (EU AI Act Article 73)
AI Procurement Decision CardCross-cutting (buyer-side, OMB M-24-10 / NIST AI RMF rubric-friendly)
AI Claims Decision CardInsurTech

Suite hub: suite.kineticgain.com Companion visualizer: kinetic-gain-visualizer Red-team bench: prompt-injection-bench Reference library: kgp-verify (npm kinetic-gain-protocol, zero-dep MIT hash/sign/verify for KGP)


Connect: LinkedIn · Kinetic Gain · Medium · Skills

Reviews

No reviews yet

Be the first to review this server!