Roots Integrity Checker Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Roots Integrity Checker Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for the CMS File Integrity Checker.
Exposes integrity check operations as tools for AI agents (Archi) so users can submit and query file integrity jobs through natural language.
| Tool | Description |
|---|---|
submit_integrity_request | Submit up to N LFNs for integrity checking (async job) |
get_integrity_request | Poll status and results for a request by ID |
list_integrity_requests | List requests, optionally filtered by status or user |
get_integrity_files | Per-file results for a completed request |
get_integrity_replicas | Per-replica results for a completed request |
get_queue_status | Current queue depth (submitted + in-progress counts) |
| Variable | Required | Default | Must match |
|---|---|---|---|
INTEGRITY_CHECKER_URL | yes | — | — |
INTEGRITY_CHECKER_TOKEN | no | — | — |
INTEGRITY_CHECKER_TIMEOUT | no | 60 | — |
INTEGRITY_CHECKER_MAX_LFNS_PER_REQUEST | no | 20 | FIC_MAX_LFNS_PER_REQUEST on server |
INTEGRITY_CHECKER_MAX_CONCURRENT_JOBS | no | 3 | FIC_MAX_CONCURRENT_JOBS on server |
INTEGRITY_CHECKER_MCP_TRANSPORT | no | stdio | — |
INTEGRITY_CHECKER_MCP_HOST | no | 0.0.0.0 | — |
INTEGRITY_CHECKER_MCP_PORT | no | 8000 | — |
INTEGRITY_CHECKER_MAX_LFNS_PER_REQUEST and INTEGRITY_CHECKER_MAX_CONCURRENT_JOBS must be kept in sync with the corresponding env vars on the integrity checker server.
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"In stdio mode (the default) the server is launched as a subprocess by your MCP client (Claude Desktop, Archi, etc.) — configure it there rather than running it directly.
For manual testing with a network-accessible endpoint, use SSE transport:
INTEGRITY_CHECKER_URL=https://your-server \
INTEGRITY_CHECKER_MCP_TRANSPORT=sse \
integrity-checker-mcpdocker build -t integrity-checker-mcp .
docker run \
-e INTEGRITY_CHECKER_URL=https://your-server \
-e INTEGRITY_CHECKER_TOKEN=your-token \
-p 8000:8000 \
integrity-checker-mcppytest tests/Tests use a MockClient — no live server required.
Integrity checks are asynchronous. The typical flow is:
request_idget_queue_status (cron runs every minute)get_integrity_request until status is COMPLETEDget_integrity_files or get_integrity_replicasImportant: ERROR replica status means the file was inaccessible (e.g. on tape), not that it is corrupted. Never report ERROR replicas as corrupted.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.