Skip to main content

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check NSA-ANT-class persistence indicators (BIOS/SMM/HPA/boot-ROM), HMAC-signed firmware attestation, gate AI inference on verified hardware trust.

Project description

MCP Scorecard: 88/100

Firmware Attestation MCP

Hardware trust layer for sovereign AI. Persistence implants live below the OS (BIOS/UEFI, SMM, network boot ROMs, HDD HPA) and survive OS reinstalls and disk wipes. This MCP attests a host's firmware trust state and gates inference on a verified result.

Tools

Tool What
scan_firmware read-only host evidence (Secure Boot, TPM, SIP, BIOS, HPA)
check_ant_signatures match to NSA-ANT-class persistence preconditions + defenses
attest_firmware HMAC-signed attestation, verifiable at proofof.ai/api/verify
gate_inference ALLOW/BLOCK AI on this host (strict by default)
list_threat_model the attack surface this defends against

Honest by design

Reports indicators (preconditions implants rely on), never "clean". A BLOCK means "lacks confirmed trust anchors," not "hacked." Harden per the listed defenses, then re-gate.

pip install firmware-attestation-mcp

© CSOAI LTD (trading as MEOK AI Labs) · MIT

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "firmware-attestation-mcp": {
      "command": "uvx",
      "args": ["firmware-attestation-mcp"]
    }
  }
}

Or: pip install firmware-attestation-mcp then run the firmware-attestation-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use scan_firmware to …"
  • "Use check_ant_signatures to …"
  • "Use attest_firmware to …"

Part of the MEOK constellation

This MCP is one node in a connected ecosystem built by MEOK AI LABS around a single sovereign AI core — governed agents with a hash-chained audit trail, mapped to the CSOAI compliance charter.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

firmware_attestation_mcp-1.0.2.tar.gz (8.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

firmware_attestation_mcp-1.0.2-py3-none-any.whl (7.4 kB view details)

Uploaded Python 3

File details

Details for the file firmware_attestation_mcp-1.0.2.tar.gz.

File metadata

  • Download URL: firmware_attestation_mcp-1.0.2.tar.gz
  • Upload date:
  • Size: 8.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.15

File hashes

Hashes for firmware_attestation_mcp-1.0.2.tar.gz
Algorithm Hash digest
SHA256 b51dd0739371658a31b9a706fcc0aa66dc6e0886cc3bce84ad7dfa8f56b3be45
MD5 f079080e0dad5741cb23d6df2536f7cc
BLAKE2b-256 c536e4fae6f49a4b1139d89616676fec021cf0777ebfc9ea6717b6c04f031b72

See more details on using hashes here.

File details

Details for the file firmware_attestation_mcp-1.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for firmware_attestation_mcp-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 e216cab2193ab1266634a48d844a20945365032e4781506661318075f6d200ac
MD5 80f391afba5b03867b5d3165dd3dd27d
BLAKE2b-256 35d6aa33b7b13998613edb2851815495214f5ca0c235567610cc0de9d78d8ace

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page