{"name":"io.github.vikasny30/aletheia-mcp","slug":"vikasny30-aletheia-mcp","title":"Aletheia Runtime Safety & Scope Creep Filter","description":"Deterministic pre-execution filter that blocks known scope-creep and prompt-injection tool calls","url":"https://mcp.market/server/vikasny30-aletheia-mcp","rating":null,"grade":"B","score":83,"certified":false,"status":"active","category":"ai","tags":["ai"],"presence":{"score":33,"stars":1,"forks":0,"downloads_week":235,"last_push_at":"2026-09-13T14:04:08.000Z","license":"NOASSERTION"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/vikasny30/aletheia-mcp","website":"https://github.com/vikasny30/aletheia-mcp","version":"0.3.1","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"aletheia-mcp","version":"0.3.1","transport":{"type":"stdio"},"packageArguments":[{"description":"Authorize filesystem writes and mutations (default: read-only).","type":"named","name":"--allow-write"},{"description":"Authorize outbound network requests (default: local-only).","type":"named","name":"--allow-network"},{"description":"Authorize requests to localhost / 127.0.0.1 dev servers (default: blocked).","type":"named","name":"--allow-loopback"},{"description":"Comma-separated list of directories writes are confined to (default: current working directory).","format":"filepath","type":"named","name":"--allowed-paths"}],"environmentVariables":[{"description":"Set to \"true\" to authorize filesystem writes (equivalent to --allow-write).","name":"ALETHEIA_ALLOW_WRITE"},{"description":"Set to \"true\" to authorize outbound network requests (equivalent to --allow-network).","name":"ALETHEIA_ALLOW_NETWORK"},{"description":"Set to \"true\" to authorize requests to localhost / 127.0.0.1 (equivalent to --allow-loopback).","name":"ALETHEIA_ALLOW_LOOPBACK"},{"description":"Operator token required to loosen an already-running session's mandate at runtime.","isSecret":true,"name":"ALETHEIA_OPERATOR_SECRET"}]}],"tools":[{"name":"aletheia_get_mandate","description":"Retrieve the current operational safety mandate, permissions, and active boundary constraints.","write_action":false,"price_micros":0,"input_schema":null},{"name":"aletheia_get_telemetry","description":"Retrieve runtime safety telemetry: total tool calls evaluated, block rate %, latency percentiles (p50, p95, p99 < 1ms), and violation counts broken down by signature.","write_action":false,"price_micros":0,"input_schema":null},{"name":"aletheia_intercept","description":"Universal sub-millisecond safety gatekeeper. Evaluates any proposed tool invocation against Signature S3 (Scope Creep) and S2b (Prompt Injection) to block destructive, out-of-boundary, or compromised actions before execution.","write_action":false,"price_micros":0,"input_schema":null},{"name":"aletheia_safe_bash","description":"Execute a shell/bash command with inline sub-millisecond Signature S3 scope creep protection. Blocks destructive deletes (rm -rf), disk formatting, fork bombs, credential harvesting, privilege escalation, and unauthorized network egress.","write_action":true,"price_micros":0,"input_schema":null},{"name":"aletheia_safe_sql","description":"Audit or execute a database query with Signature S3 safety filters. Detects destructive DDL (DROP, TRUNCATE), unbounded DML (DELETE/UPDATE without WHERE), and privilege tampering.","write_action":false,"price_micros":0,"input_schema":null},{"name":"aletheia_set_mandate","description":"Establish or update the active operational safety mandate for this agent session. Declares permissible boundaries, allowed tools, filesystem directories, write permissions, and risk tolerance. Loosening restrictions requires operatorSecret.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":83,"grade":"B","scanned_at":"2026-09-19T20:05:15.155Z","report":{"scannerVersion":"0.1.5","scannedAt":"2026-09-19T20:05:15.133Z","components":{"code":{"score":25,"max":25,"notes":["27 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 6 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"aletheia-mcp","version":"0.3.1","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":2,"publishedAt":"2026-09-12T16:17:21.347Z","repositoryUrl":"git+https://github.com/vikasny30/aletheia-mcp.git","weeklyDownloads":235}],"repo":{"found":true,"owner":"vikasny30","repo":"aletheia-mcp","archived":false,"pushedAt":"2026-09-13T14:04:08Z","stars":1,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/16021817?v=4","ownerCreatedAt":"2015-11-25T18:44:40Z","license":"NOASSERTION"},"icon":{"url":"https://avatars.githubusercontent.com/u/16021817?v=4&s=128","source":"registry","width":128,"height":128},"presence":{"stars":1,"forks":0,"downloadsWeek":235,"license":"NOASSERTION","lastPushAt":"2026-09-13T14:04:08.000Z","score":33}}}},"grade_history":[],"reviews":[]}