{"name":"io.github.verax-ai/verax","slug":"verax-ai-verax","title":"VERAX","description":"The body an agent asks before it acts: decide, approve, and keep a signed record on your machine.","url":"https://mcp.market/server/verax-ai-verax","rating":null,"grade":"A","score":86,"certified":false,"status":"active","category":"ai","tags":["ai"],"presence":{"score":0,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":null},"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/verax-ai/verax","website":"https://verax-ai.com","version":"0.1.2","remotes":[],"packages":[{"registryType":"npm","identifier":"@verax-ai/body","version":"0.1.2","transport":{"type":"streamable-http","url":"http://{VERAX_BIND}/mcp"},"environmentVariables":[{"description":"Issuer the agent's token must carry. The body refuses to start without one; `verax doctor` names what is missing.","isRequired":true,"name":"VERAX_ISSUER"},{"description":"Where the body fetches the keys that verify that token.","isRequired":true,"name":"VERAX_JWKS_URL"},{"description":"Audience the token must name, so a token minted for something else is refused.","isRequired":true,"name":"VERAX_AUDIENCE"},{"description":"Directory the ledger, keys and approvals live in. It stays on this machine.","isRequired":true,"format":"filepath","name":"VERAX_STATE_DIR"},{"description":"Policy the gate applies. @verax-ai/proxy ships policy/default.json, which denies what it does not name.","isRequired":true,"format":"filepath","name":"VERAX_POLICY_FILE"},{"description":"host:port the body listens on. Anything but loopback needs VERAX_TLS_TERMINATED=1.","default":"127.0.0.1:8787","name":"VERAX_BIND"},{"description":"Roster document the body serves; the format is @verax-ai/inventory.","format":"filepath","name":"VERAX_INVENTORY_FILE"}]}],"tools":[],"scan":{"score":86,"grade":"A","scanned_at":"2026-09-18T00:14:09.140Z","report":{"scannerVersion":"0.1.2","scannedAt":"2026-09-18T00:14:09.085Z","components":{"code":{"score":20,"max":25,"notes":["67 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":15,"max":15,"notes":["only the listing description was available"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 0 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"net.raw-ip","severity":"medium","component":"code","title":"Network call to a raw IP address","evidence":"dist/doctor.js: …n checks; } const DEFAULT_REDIRECTS = [\"http://127.0.0.1:5173/\", \"http://127.0.0.1:4173/\"]; function s…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@verax-ai/body","version":"0.1.2","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":4,"publishedAt":"2026-09-17T23:37:49.840Z","repositoryUrl":"git+https://github.com/verax-ai/verax.git","weeklyDownloads":208}],"repo":{"found":true,"owner":"verax-ai","repo":"verax","archived":false,"pushedAt":"2026-09-17T23:30:28Z","stars":0,"openIssues":0,"ownerType":"Organization","ownerCreatedAt":"2026-09-03T21:29:14Z","license":"Apache-2.0"}}}},"grade_history":[],"reviews":[]}