Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
VAIBot governance circuit-breaker as an MCP server.
Exposes 4 tools to any MCP-compatible AI agent (Claude Code, Codex, ChatGPT, OpenClaw):
| Tool | Description |
|---|---|
vaibot_decide | Pre-execution risk + policy decision. Call before any risky action. |
vaibot_finalize | Report actual outcome after execution. Closes the governance receipt. |
vaibot_receipts | List recent governance receipts with optional filters. |
vaibot_approve | Approve or deny a pending action from the dashboard or agent. |
VAIBOT_API_KEY=vb_live_xxx \
VAIBOT_API_BASE_URL=https://api.vaibot.io \
npx @vaibot/mcp-serverAdd to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"vaibot": {
"command": "npx",
"args": ["-y", "@vaibot/mcp-server"],
"env": {
"VAIBOT_API_KEY": "vb_live_xxx",
"VAIBOT_API_BASE_URL": "https://api.vaibot.io"
}
}
}
}# .mcp.json in your project root
{
"mcpServers": {
"vaibot": {
"command": "npx",
"args": ["-y", "@vaibot/mcp-server"],
"env": {
"VAIBOT_API_KEY": "vb_live_xxx"
}
}
}
}The vaibot-guard-bridge plugin will point guardBaseUrl at the MCP server endpoint instead of localhost:39111. Config change only — no plugin code changes needed.
If your agent supports MCP over HTTP (Remote URL mode), connect directly to the VAIBot API without installing anything:
URL: https://api.vaibot.io/v2/mcp
Token: Bearer <your-api-key>The HTTP endpoint speaks JSON-RPC 2.0 and supports all 4 tools. Auth is the same API key as the stdio transport.
| Variable | Required | Default | Description |
|---|---|---|---|
VAIBOT_API_KEY | ✅ | — | VAIBot API key (vb_stg_xxx or vb_live_xxx) |
VAIBOT_API_BASE_URL | — | https://api.vaibot.io | API base URL |
Agent wants to run: curl -X POST https://deploy.example.com/release
1. Agent calls vaibot_decide:
→ VAIBot: APPROVAL_REQUIRED (high risk — outbound network call)
→ Returns: run_id, content_hash
2. Human reviews in dashboard, clicks Approve
3. Agent calls vaibot_approve (or dashboard fires callback):
→ VAIBot: ✅ APPROVED
4. Agent executes the action
5. Agent calls vaibot_finalize:
→ VAIBot: receipt updated, outcome=allowed~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.