{"name":"io.github.zapsoblige-hash/policyvault","slug":"zapsoblige-hash-policyvault","title":null,"description":"Non-custodial Kaspa policy enforcement for AI agents; signers retain custody.","url":"https://mcp.market/server/zapsoblige-hash-policyvault","rating":null,"grade":"B","score":80,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":28,"stars":1,"forks":0,"downloads_week":97,"last_push_at":"2026-09-16T04:02:35.000Z","license":"Apache-2.0"},"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/zapsoblige-hash/PolicyVault","website":null,"version":"1.6.2","remotes":[],"packages":[{"registryType":"npm","identifier":"policyvault-mcp","version":"1.6.2","transport":{"type":"stdio"},"environmentVariables":[{"description":"Bare origin of the PolicyVault server (e.g. https://app.policy-vault.org, or your self-hosted origin). Refused if it embeds credentials or a path.","isRequired":true,"format":"string","name":"POLICYVAULT_MCP_SERVER_URL"},{"description":"Machine-identity bearer credential (pvmk_...), minted by the vault operator in the PolicyVault app with exactly the scopes the agent should hold. Never logged; deleted from the process environment after being read.","isRequired":true,"format":"string","isSecret":true,"name":"POLICYVAULT_MCP_TOKEN"},{"description":"Optional comma-separated scope list to narrow which tools are advertised (display-side only; enforcement is always server-side).","format":"string","name":"POLICYVAULT_MCP_SCOPES"}]}],"tools":[],"scan":{"score":80,"grade":"B","scanned_at":"2026-09-19T10:17:18.478Z","report":{"scannerVersion":"0.1.3","scannedAt":"2026-09-19T10:17:18.447Z","components":{"code":{"score":25,"max":25,"notes":["11 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 3 days ago"]},"identity":{"score":6,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"policyvault-mcp","version":"1.6.2","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":0,"publishedAt":"2026-09-15T02:26:05.818Z","repositoryUrl":"git+https://github.com/zapsoblige-hash/PolicyVault.git","weeklyDownloads":97}],"repo":{"found":true,"owner":"zapsoblige-hash","repo":"PolicyVault","archived":false,"pushedAt":"2026-09-16T04:02:35Z","stars":1,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/315660735?v=4","ownerCreatedAt":"2026-08-11T05:39:06Z","license":"Apache-2.0"},"icon":{"url":null,"source":"none"},"presence":{"stars":1,"forks":0,"downloadsWeek":97,"license":"Apache-2.0","lastPushAt":"2026-09-16T04:02:35.000Z","score":28}}}},"grade_history":[],"reviews":[]}