Skip to main content

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check NSA-ANT-class persistence indicators (BIOS/SMM/HPA/boot-ROM), HMAC-signed firmware attestation, gate AI inference on verified hardware trust.

Project description

MCP Scorecard: 88/100

Firmware Attestation MCP

Hardware trust layer for sovereign AI. Persistence implants live below the OS (BIOS/UEFI, SMM, network boot ROMs, HDD HPA) and survive OS reinstalls and disk wipes. This MCP attests a host's firmware trust state and gates inference on a verified result.

Tools

Tool What
scan_firmware read-only host evidence (Secure Boot, TPM, SIP, BIOS, HPA)
check_ant_signatures match to NSA-ANT-class persistence preconditions + defenses
attest_firmware HMAC-signed attestation, verifiable at proofof.ai/api/verify
gate_inference ALLOW/BLOCK AI on this host (strict by default)
list_threat_model the attack surface this defends against

Honest by design

Reports indicators (preconditions implants rely on), never "clean". A BLOCK means "lacks confirmed trust anchors," not "hacked." Harden per the listed defenses, then re-gate.

pip install firmware-attestation-mcp

© CSOAI LTD (trading as MEOK AI Labs) · MIT

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "firmware-attestation-mcp": {
      "command": "uvx",
      "args": ["firmware-attestation-mcp"]
    }
  }
}

Or: pip install firmware-attestation-mcp then run the firmware-attestation-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use scan_firmware to …"
  • "Use check_ant_signatures to …"
  • "Use attest_firmware to …"

Part of the MEOK constellation

This MCP is one node in a connected ecosystem built by MEOK AI LABS around a single sovereign AI core — governed agents with a hash-chained audit trail, mapped to the CSOAI compliance charter.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

firmware_attestation_mcp-1.0.3.tar.gz (10.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

firmware_attestation_mcp-1.0.3-py3-none-any.whl (7.5 kB view details)

Uploaded Python 3

File details

Details for the file firmware_attestation_mcp-1.0.3.tar.gz.

File metadata

  • Download URL: firmware_attestation_mcp-1.0.3.tar.gz
  • Upload date:
  • Size: 10.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.5

File hashes

Hashes for firmware_attestation_mcp-1.0.3.tar.gz
Algorithm Hash digest
SHA256 f4d4c26a236cbeceecf5ea98a0f9a6bb0459fecdc6c03c138732a8e4ffb98801
MD5 98501a2a052050a284c12cf4d0278592
BLAKE2b-256 4a5fd66282cef9c060d548cb1d69c479ecd5b6c63b564c3c8465c401a47f21ef

See more details on using hashes here.

File details

Details for the file firmware_attestation_mcp-1.0.3-py3-none-any.whl.

File metadata

File hashes

Hashes for firmware_attestation_mcp-1.0.3-py3-none-any.whl
Algorithm Hash digest
SHA256 f3e7daaf571e4a0f8ec5ae2644a2e7824ab3b798293735ec2d95cdbe6ee96f97
MD5 ea7d22c16ffb5f4505bc7972c2828c05
BLAKE2b-256 922ab8f366da7bd90d7478ad417165a3b09b826ece2610e07f3a52fa5ce9f54c

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page