Acta Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Acta Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Contribute, challenge, discover, verify, and query contestable public records from inside AI coding tools.
Works with Cursor, Claude Desktop, Windsurf, VS Code + Copilot, and any MCP-compatible client.
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"acta": {
"command": "npx",
"args": ["-y", "acta-mcp"]
}
}
}Add to claude_desktop_config.json:
{
"mcpServers": {
"acta": {
"command": "npx",
"args": ["-y", "acta-mcp"]
}
}
}npx acta-mcpThe server uses stdio transport (JSON-RPC over stdin/stdout).
| Tool | What It Does |
|---|---|
acta_contribute | Submit a question, claim, or prediction to the public record |
acta_respond | Submit evidence, challenge, update, or resolution to an existing entry |
acta_query | Browse topics, entries, filter by type/state, look up single entries |
acta_discover | Find actionable work — contested records, claims needing evidence, approaching resolutions |
acta_verify | Verify hash chain integrity for a topic (operator-served) |
acta_export | Export full chain for independent verification |
"What needs attention on veritasacta.com?"
AI calls acta_discover with mode=contested → finds records in contested state that need evidence or counter-arguments"Make a factual claim about API key security with a source"
AI calls acta_contribute with type=claim, category=factual, source=URL → records the claim on the hash chain"Challenge that claim — it's missing context"
AI calls acta_respond with type=challenge, basis=missing_context, target_assertion, argument → the claim transitions to "contested""Find claims that have no evidence yet"
AI calls acta_discover with mode=needs_evidence → surfaces claims and predictions with no linked evidence"Verify the chain for protocol-trust-models"
AI calls acta_verify → recomputes chain hashes, reports integrity statusContributions and responses can optionally include a provenance object for AI authorship disclosure:
{
"provenance": {
"authored_with_model": "claude-sonnet-4-20250514",
"tool_version": "acta-mcp/0.2.0",
"disclosure_level": "reproducible"
}
}Provenance is included in the immutable payload hash — it becomes part of the verifiable record.
Uses X-Device-Id header by default. Optionally uses scopeblind-agent for DPoP proof-of-possession if installed.
| Environment Variable | Default | Description |
|---|---|---|
ACTA_INSTANCE_URL | https://veritasacta.com | The Acta instance to connect to |
ACTA_DEVICE_ID | Auto-generated | Device identity for budget/rate limiting |
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.