Humanmcp Go — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Humanmcp Go (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A personal content server speaking Model Context Protocol (MCP/JSON-RPC 2.0).
Live: https://kapoost.humanmcp.net Landing page: https://humanmcp.net Marketplace: https://marketplace.humanmcp.net Network explorer: https://humanmcp.net/humannetwork.html Author: kapoost (Łukasz Kapuśniak) — poet, builder, sailor. Warsaw / Malta.
humanMCP lets any human publish content and services with cryptographic proof of authorship, explicit license terms, and full control over access. Writers, artists, consultants, craftspeople, galleries, freelancers — anyone who creates valuable work. AI agents connect via MCP and interact with your content natively.
Every human can run their own instance. One server, one person, their rules.
Content & Discovery
| Tool | Description |
|---|---|
get_author_profile | Who is kapoost — bio, content overview, how to browse |
list_content | Browse all pieces with metadata, filter by type or tag |
read_content | Read a piece — respects all access gates |
search_content | Full-text search across all pieces |
request_access | Get gate details for locked content |
submit_answer | Unlock challenge-gated content |
list_blobs | Browse typed data artifacts |
read_blob | Read image, contact, dataset, vector (respects audience) |
IP & Verification
| Tool | Description |
|---|---|
verify_content | Verify Ed25519 signature |
get_certificate | Full IP certificate: license, price, originality index, hash, signature |
upgrade_timestamp | Upgrade OTS proof to Bitcoin-anchored |
Interaction
| Tool | Description |
|---|---|
request_license | Declare intended use, get terms, logged for audit |
leave_comment | Leave a reaction — visible in author dashboard |
leave_message | Send a direct note (max 2000 chars, URLs welcome) |
ask_human | Ask the author a question (private, async — returns question_id) |
get_answer | Check if the author answered your question (by question_id) |
Session & Context
| Tool | Description |
|---|---|
bootstrap_session | Unlock private context with session code |
recall | Retrieve saved memories |
remember | Save observations |
query_vault | Search personal knowledge vault |
list_vault | List vault documents |
Skills
| Tool | Description |
|---|---|
list_skills / get_skill | Agent instruction catalog |
upsert_skill / delete_skill | Manage skills (agent token) |
Personas
| Tool | Description |
|---|---|
list_personas / get_persona | Your expert team (requires session code or VAULT_URL) |
upsert_persona / delete_persona | Manage personas (agent token) |
humanmcp-go is a framework. Persona prompts and skill bodies are yours — they don't ship in this repo. Two ways to supply them:
upsert_persona / upsert_skill with the EDIT_TOKEN, or drop JSON files into ${CONTENT_DIR}/personas/ and ${CONTENT_DIR}/skills/ on the host volume.VAULT_URL env to a server you control (e.g. a private FastAPI on your tailnet). SkillStore fetches GET ${VAULT_URL}/persona/{id} and GET ${VAULT_URL}/skill/{slug} on demand with a 5min in-memory cache. Lets your sensitive prompts stay on your machine while the public framework serves them.Persona JSON shape (vault response):
{"id":"hermes","name":"Hermes","role":"Process Optimizer","prompt":"<full system prompt>"}Skill JSON shape (vault response):
{"slug":"system-diagram","title":"...","description":"...","persona_id":"mira","tags":[...],"instructions":"<full playbook>"}When VAULT_URL is unreachable, bootstrap_session loudly reports the downgrade (won't silently fall back). See internal/content/skill.go for the fetch/cache implementation.
Listings
| Tool | Description |
|---|---|
list_listings / read_listing | Browse classified ads |
respond_to_listing | Send response to listing |
subscribe_listings / unsubscribe_listings | Webhook subscriptions |
Federation
| Tool | Description |
|---|---|
list_peers | List known humanMCP servers in the network |
announce_peer | Announce your server to join the network |
Meta
| Tool | Description |
|---|---|
about_humanmcp | Open-source project info |
{
"mcpServers": {
"kapoost": {
"type": "http",
"url": "https://kapoost.humanmcp.net/mcp"
}
}
}Pieces (Markdown files):
poem, essay, note, artwork, image, contactpublic / members / lockedchallenge (Q&A), time, manual, tradefree, cc-by, cc-by-nc, commercial, exclusive, all-rightsBlobs (typed data artifacts):
image, contact, vector, document, dataset, capsule, provenance[agent:claude, human:alice, agent:*]Public links: read_blob slug:"kapoost-contact" — name, handle, github, instagram, facebook, landing page.
Private email: read_content slug:"kapoost-contact-private" — gated. Answer the challenge to access.
Every piece is signed with Ed25519. get_certificate returns:
Agent discovery:
/.well-known/agent.json — agent profile card/.well-known/mcp-server.json — MCP server discovery/openapi.json — OpenAPI 3.1 spec (ChatGPT, Gemini)/llms.txt — LLM preferences (signed)/for-agents — agent onboarding page/connect — connection methods pageREST API (for agents without MCP):
GET /api/content — list all piecesGET /api/content/{slug} — read pieceGET /api/search?q=... — full-text searchGET /api/profile — author name, bio, tagsGET /api/blobs — list data artifactsGET /listings/feed.json — listings feedGET /content/stream.json — unified content stream (pieces + listings, for humanNetwork)SEO:
robots.txt, sitemap.xml, humans.txt| Field | Limit |
|---|---|
| Message / comment text | 2000 chars |
| Blob inline text | 512 KB |
| File upload | 50 MB |
| Slug | 64 chars |
| Title | 256 chars |
list_peers / announce_peer MCP tools and /api/peers REST/data/new pagegit clone https://github.com/kapoost/humanmcp-go.git
cd humanmcp-go
bash setup.shThe script asks for your name and bio, then:
Done in ~2 minutes. You get:
https://yourname.humanmcp.net — your serverhttps://yourname.humanmcp.net/connect — share with friendshttps://humanmcp.net/humannetwork.html?add=https://yourname.humanmcp.net — 1-click followgo build ./cmd/server/
EDIT_TOKEN=secret AUTHOR_NAME=yourname ./serverfly launch --name yourname-humanmcp
fly secrets set EDIT_TOKEN=secret AUTHOR_NAME=yourname
fly deploygo run ./cmd/keygen/
fly secrets set SIGNING_PRIVATE_KEY="..." SIGNING_PUBLIC_KEY="..."136 tests across content, MCP, and upload/signature/license suites.
go test ./...~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.