Command Palette

Search for a command to run...

UnylyUnyly
Весь каталог

Mpak Trust Framework

БесплатноНе проверен

MTF: An open security standard for MCP server bundles. Defines compliance levels, controls, and verification methods.

GitHubEmbed

Описание

MTF: An open security standard for MCP server bundles. Defines compliance levels, controls, and verification methods.

README

MTF is an open security standard for describing and verifying the security posture of MCP server bundles.

Status: Draft (v0.1) License: CC BY 4.0

Overview

MCP servers extend AI assistants with powerful capabilities: filesystem access, network requests, database queries, and code execution. This power creates significant security risk. MTF provides a standardized framework for:

  1. Bundle authors to demonstrate security best practices
  2. Registries to enforce minimum security requirements
  3. Consumers to make informed installation decisions
  4. Enterprises to set procurement policies

Compliance Levels

MTF defines four compliance levels, each building on the previous:

Level Name Target Controls
L1 Basic Personal projects, experimentation 6
L2 Standard Team tools, published packages 14
L3 Verified Production, enterprise use 22
L4 Attested Critical infrastructure, regulated industries 25

Security Domains

Controls are organized into five domains:

  • Supply Chain (SC): SBOM, vulnerability scanning, dependency pinning
  • Code Quality (CQ): Secret detection, malicious patterns, static analysis
  • Artifact Integrity (AI): Manifest validation, content hashes, signatures
  • Provenance (PR): Source repository, author identity, build attestation
  • Capability Declaration (CD): Tool declarations, permission scopes

Specification

See MTF-0.1.md for the full specification.

Schemas

JSON schemas for validation:

Implementations

Implementation Language Maintainer
mpak-scanner Python NimbleBrain (reference implementation)

Contributing

MTF is developed in the open. Contributions, feedback, and discussion are welcome.

License

This specification is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).

You are free to share and adapt this material for any purpose, including commercial use, as long as you provide appropriate attribution.

from github.com/NimbleBrainInc/mpak-trust-framework

Установка Mpak Trust Framework

У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.

▸ github.com/NimbleBrainInc/mpak-trust-framework

FAQ

Mpak Trust Framework MCP бесплатный?

Да, Mpak Trust Framework MCP бесплатный — установка в пару кликов через Unyly без оплаты.

Нужен ли API-ключ для Mpak Trust Framework?

Нет, Mpak Trust Framework работает без API-ключей и переменных окружения.

Mpak Trust Framework — hosted или self-hosted?

Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.

Как установить Mpak Trust Framework в Claude Desktop, Claude Code или Cursor?

Открой Mpak Trust Framework на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.

Похожие MCP

Compare Mpak Trust Framework with

Не уверен что выбрать?

Найди свой стек за 60 секунд

Автор?

Embed-бейдж для README

Похожее

Все в категории ai