Problem/Motivation

An operator or a governed agent that works with a site over MCP cannot ask whether the audit chain is healthy. The answer is on the status report and in Drush: is the chain keyed, when did scheduled verification last run and what did it find, how far is the seal, is the evidence export behind.

The module already computes all of this in bounded services: AuditChainMetrics::integrity(), keyedSplit(), windowCounts() and recoveryStatus(), AuditChainLogger::signingStatus() and getSeal(), and ScheduledVerifier::runNow().

Proposed resolution

Add an optional submodule, audit_chain_mcp, with Tool API plugins over those services. It depends on Tool API and MCP Sentinel. MCP Sentinel already depends on Audit Chain, so the tools have to live in a submodule to avoid a dependency cycle; the base module gains no dependency.

  • audit_chain_status (read): last scheduled verdict and when, whether appends are keyed, sealed-through position, recovery status. No seal MAC, no prefix digest, no key material.
  • audit_chain_window_counts (read): keyed and unkeyed entry counts for a fixed set of windows.
  • audit_chain_export_status (read): export checkpoint and how many entries are waiting. The destination is shown only through the existing redaction.
  • audit_chain_verify_now (trigger): run scheduled verification now and return the verdict. Rate-limited, because verification walks the whole table.

Not tools, by design: sealing, recovery prepare or activate, re-encryption and pruning (permanent, built around a human confirmation), export to a caller-supplied destination, writing log entries (an agent must not be able to forge evidence), and any reader of rows or metadata (IP addresses, user agents and decrypted metadata are personal data).

Remaining tasks

  • Kernel tests: discovery and direct execution, anonymous and wrong-permission refusal, governance not ready, no key material or row data in any output, verify-now verdict on an intact and on a broken chain.
  • CI step for the optional submodule.
  • README section and CHANGELOG entry.

API changes

None in the base module, apart from any small public accessor the export status needs.

Comments

jmcerda created an issue. See original summary.

  • jmcerda committed c03e36df on feature/3624446-mcp-tools
    docs: #3624446 say that a failed metrics query reads as zero
    
    The...

  • jmcerda committed 490f47fb on 1.x
    test: #3624446 prove the window is re-validated in code
    
    Follow-up to...

  • jmcerda committed c03e36df on 1.x
    docs: #3624446 say that a failed metrics query reads as zero
    
    The...

  • jmcerda committed 54cf53f6 on 1.x
    test: #3624446 prove stored free text never reaches a tool result
    
    Seeds...

  • jmcerda committed 91e60d9b on 1.x
    feat: #3624446 add optional audit_chain_mcp tools submodule
    
    Four Tool...
jmcerda’s picture

Status: Active » Fixed

Committed to 1.x. The optional audit_chain_mcp submodule ships in 1.9.0 with four tools: audit_chain_status, audit_chain_window_counts, audit_chain_export_status and audit_chain_verify_now. The base module gains no dependency. A findings review after the first commit added tests that stored free text never reaches a tool result and that the window input is re-validated in code.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.