Problem/Motivation
An operator or a governed agent that works with a site over MCP cannot ask whether the audit chain is healthy. The answer is on the status report and in Drush: is the chain keyed, when did scheduled verification last run and what did it find, how far is the seal, is the evidence export behind.
The module already computes all of this in bounded services: AuditChainMetrics::integrity(), keyedSplit(), windowCounts() and recoveryStatus(), AuditChainLogger::signingStatus() and getSeal(), and ScheduledVerifier::runNow().
Proposed resolution
Add an optional submodule, audit_chain_mcp, with Tool API plugins over those services. It depends on Tool API and MCP Sentinel. MCP Sentinel already depends on Audit Chain, so the tools have to live in a submodule to avoid a dependency cycle; the base module gains no dependency.
audit_chain_status(read): last scheduled verdict and when, whether appends are keyed, sealed-through position, recovery status. No seal MAC, no prefix digest, no key material.audit_chain_window_counts(read): keyed and unkeyed entry counts for a fixed set of windows.audit_chain_export_status(read): export checkpoint and how many entries are waiting. The destination is shown only through the existing redaction.audit_chain_verify_now(trigger): run scheduled verification now and return the verdict. Rate-limited, because verification walks the whole table.
Not tools, by design: sealing, recovery prepare or activate, re-encryption and pruning (permanent, built around a human confirmation), export to a caller-supplied destination, writing log entries (an agent must not be able to forge evidence), and any reader of rows or metadata (IP addresses, user agents and decrypted metadata are personal data).
Remaining tasks
- Kernel tests: discovery and direct execution, anonymous and wrong-permission refusal, governance not ready, no key material or row data in any output, verify-now verdict on an intact and on a broken chain.
- CI step for the optional submodule.
- README section and CHANGELOG entry.
API changes
None in the base module, apart from any small public accessor the export status needs.
Comments
Comment #7
jmcerdaCommitted to 1.x. The optional
audit_chain_mcpsubmodule ships in 1.9.0 with four tools:audit_chain_status,audit_chain_window_counts,audit_chain_export_statusandaudit_chain_verify_now. The base module gains no dependency. A findings review after the first commit added tests that stored free text never reaches a tool result and that the window input is re-validated in code.