Skip to content
Official MCP RegistryListed

Trust Gate

Part ofTrust Gatelisted on 4 directories

Post-quantum, tamper-evident receipts for agent actions. Ed25519 + ML-DSA-65, offline verify.

First seen 2 Oct 2026. Evidence as of 9 Oct 2026.

7
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
audit_my_agent_inventoryRank a CALLER-PROVIDED list of MCP tools by worst-regret if they act (a name-based heuristic that weights a name's first word most). Read-only: it mints no receipt. Cannot auto-discover the inventory -- MCP does not allow that; the caller must pass it in.Not declared
check_egressEgress classification check. Scans a data sample for a finite list of sensitivity markers and classifies as NO_MARKERS_FOUND / INTERNAL / CONFIDENTIAL / RESTRICTED. RESTRICTED sets blocked=true; this tool cannot block anything itself, and NO_MARKERS_FOUND is not clearance to send. Returns classification, retention info, and a tamper-evident receipt.Not declared
gate_decisionTwo-phase decision gate with a real verdict. PREVIEW returns ALLOW, DENY or ESCALATE with the risk tier and reasons, plus a preview_id, without acting. COMMIT re-evaluates the same inputs and mints a signed receipt for the verdict. Only ALLOW returns a GRANTED permit; DENY returns DENIED; ESCALATE returns WITHHELD_PENDING_HUMAN and a human must decide outside this tool. Applies only to actions the caller routes through it: it does not observe or block what an agent does. Verb-tier heuristic on the action name and resource, not a proof. Stateless. Optional attestation: triggered_by_type, triggered_by_source, decision_model.Not declared
mint_action_receiptMint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for an arbitrary consequential agent action. Optional attestation: triggered_by_type (human/agent/script), triggered_by_source (api/cli/cron), decision_model (the LLM model used). Attestation values are caller claims: allowlisted to safe characters, signed, not verified. Decisions that contain a gate verdict word are reserved for gate_decision.Not declared
mint_receipt_for_record_changeMint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for one CRM record change. Old/new values are carried as SHA-256 hashes. Works with any CRM (Relaticle, hosted CRMs, custom).Not declared
run_exit_drillVendor exit readiness drill. Checks local signing key, local model access (Ollama). Returns step-by-step results and a tamper-evident receipt. Informational; it signs one receipt, which creates the signing key on a host that has none yet.Not declared
verify_receiptVerify a Trust Gate receipt from the certificate alone (offline). ok=true means unchanged since signing, signed, kid consistent with the embedded key, and (require_pq default on) at least one post-quantum leg verified; unsigned receipts fail. It does not prove who signed: pass expected_kid to pin the signer's Ed25519 key; a pin counts only when that key's own signature verifies (see signer_pinned). The post-quantum keys in a receipt are not covered by the kid.Not declared

Change history

No changes since the first observation. The first snapshot is the baseline.

Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryio.github.CWNApps/trust-gate-mcp2 Oct 20269 Oct 20261
Trust Gate on Official MCP Registry | InvokeRank