Aaa MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 18 Sep 2026.
Constitutional AI Governance with 13 enforced floors (F1-F13) and tri-witness consensus for LLMs.
We read the source, 21 min ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
result = subprocess.run(
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
"rm -rf on root filesystem",
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
__import__("os").path.exists("/.dockerenv"),
"/etc/cron.d", "/etc/crontab", "/etc/cron.daily",
result = subprocess.run(
path = os.path.join(OUT_DIR, f"{component}.md")
mod = __import__(cfg["health_module"], fromlist=[cfg["health_fn"]])
shell=True,
Path("/root/.ssh/operator_did_ed25519.pub"),
for d in Path(APPROVED_VENV_SITE_PACKAGES).iterdir():
grid.innerHTML = tools.map(tool => {
full_env = dict(os.environ)
TELEGRAM_API_BASE = "https://api.telegram.org"
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
TOKEN=$(curl -s -H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" \
- /var/run/docker.sock:/var/run/docker.sock:ro
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
Constitutional AI governance server with 5-organ Trinity and enforced floors F1-F13.
AI governance MCP server — policy enforcement, skills, memory, multi-LLM consensus
Constitutional guardrails and loop detection for AI agents
Governance runtime for AI-generated code. Enforce compliance and security standards.
AI agent governance for MCP: PII detection, policy enforcement, compliance, and kill switch.
AI governance MCP server for policy enforcement, cost control, and observability.
Institutional financial data with SEC filing citations, for every AI agent. OAuth 2.1.
Agent-native CLI: provenance, cost governance, and execution contracts for AI agents.
Answers built from our own checks of this server.