Agent Covenant is answering right now. Last checked 1 min ago. It exposes 7 tools. Last commit 18 Sep 2026.
Deny-by-default authority leases for agents wielding real power.
We read the source, 22 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
state = pickle.loads(row[0])
r = subprocess.run([sys.executable, "-c", code], capture_output=True, text=True)
$("kpis").innerHTML = cells.map(([l,v,d]) =>
self.environ = dict(os.environ if environ is None else environ)
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 1 min ago.
claude mcp add agent-covenant --transport http https://mcp.viridisconservation.com/covenant/mcp
{
"mcpServers": {
"agent-covenant": {
"url": "https://mcp.viridisconservation.com/covenant/mcp"
}
}
}
[mcp_servers.agent-covenant]
url = "https://mcp.viridisconservation.com/covenant/mcp"
{
"mcpServers": {
"agent-covenant": {
"url": "https://mcp.viridisconservation.com/covenant/mcp"
}
}
}
{
"mcpServers": {
"agent-covenant": {
"url": "https://mcp.viridisconservation.com/covenant/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_act
covenant_status
list_covenants
describe_agent
grant_covenant
revoke_covenant
verify_audit
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp.viridisconservation.com/covenant/mcp | streamable-http | answering | 344 ms | 1 min ago |
Local Power BI authoring for AI agents: edit .pbix, semantic model, report, and Power Query.
Safety-railed database access for agents: Postgres, MySQL, Redis. Read-only by default.
Shared memory MCP server for AI coding agents — local by default, team-shared via threadctx.dev.
Real-time semantic security for AI coding agents and MCP tools
Default trust layer for agentic payments: authorize agent spend, evidence, receipts, settlement.
Let coding agents query any SQL database safely. Read-only by default and scoped by your policies.
Minimal MCP server for downloading Gmail attachments to disk. Read-only OAuth by default.
x402 MCP for agents: crypto prices, funding, DeFi yields, Polymarket, Base RPC + MCP security.
Answers built from our own checks of this server.