Skip to main content

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check NSA-ANT-class persistence indicators (BIOS/SMM/HPA/boot-ROM), HMAC-signed firmware attestation, gate AI inference on verified hardware trust.

Project description

MCP Scorecard: 88/100

Firmware Attestation MCP

Hardware trust layer for sovereign AI. Persistence implants live below the OS (BIOS/UEFI, SMM, network boot ROMs, HDD HPA) and survive OS reinstalls and disk wipes. This MCP attests a host's firmware trust state and gates inference on a verified result.

Tools

Tool What
scan_firmware read-only host evidence (Secure Boot, TPM, SIP, BIOS, HPA)
check_ant_signatures match to NSA-ANT-class persistence preconditions + defenses
attest_firmware HMAC-signed attestation, verifiable at proofof.ai/api/verify
gate_inference ALLOW/BLOCK AI on this host (strict by default)
list_threat_model the attack surface this defends against

Honest by design

Reports indicators (preconditions implants rely on), never "clean". A BLOCK means "lacks confirmed trust anchors," not "hacked." Harden per the listed defenses, then re-gate.

pip install firmware-attestation-mcp

© CSOAI LTD (trading as MEOK AI Labs) · MIT

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "firmware-attestation-mcp": {
      "command": "uvx",
      "args": ["firmware-attestation-mcp"]
    }
  }
}

Or: pip install firmware-attestation-mcp then run the firmware-attestation-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use scan_firmware to …"
  • "Use check_ant_signatures to …"
  • "Use attest_firmware to …"

Part of the MEOK constellation

This MCP is one node in a connected ecosystem built by MEOK AI LABS around a single sovereign AI core — governed agents with a hash-chained audit trail, mapped to the CSOAI compliance charter.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

firmware_attestation_mcp-1.0.0.tar.gz (8.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

firmware_attestation_mcp-1.0.0-py3-none-any.whl (7.0 kB view details)

Uploaded Python 3

File details

Details for the file firmware_attestation_mcp-1.0.0.tar.gz.

File metadata

  • Download URL: firmware_attestation_mcp-1.0.0.tar.gz
  • Upload date:
  • Size: 8.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.15

File hashes

Hashes for firmware_attestation_mcp-1.0.0.tar.gz
Algorithm Hash digest
SHA256 90fec4d61f63426c651326758f1531028d31986d7dbe7558accdbaa3424e9a0c
MD5 359dd576dc03dabd90962de13b60e879
BLAKE2b-256 2312b449668d2118479f5e21b2d380538cd2a3df1a675831b23aee1ea6e79e3e

See more details on using hashes here.

File details

Details for the file firmware_attestation_mcp-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for firmware_attestation_mcp-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8d3e17d5d858b71ea82beb9691cb4ac1b52bb3df2c9357a9135b048eded70cd7
MD5 3a4590dd884605453de4b70a22a3343b
BLAKE2b-256 ac6e0c986aa0ce2839f479cab5a8404c62488748f22cb950ee77fc70db5dc286

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page