Skip to main content

Zero Harm AI MCP

Zero Harm AI MCP is a Model Context Protocol server that lets AI agents and runtime firewalls call Zero Harm AI safety checks for text, chat messages, prompts, tool inputs, and generated outputs.

The server is a thin adapter over zero-harm-ai-detectors. It should not duplicate detector logic from the detector package or from the Zero Harm AI GitHub Action.

Goals

  • Expose PII, secret, and harmful-content detection through MCP tools.
  • Return structured findings that agents and firewalls can enforce.
  • Support local/self-hosted operation for sensitive data.
  • Keep logs privacy-safe by default.
  • Provide stable tool contracts that can be used by coding agents, chat agents, and firewall.

Non-Goals

  • Reimplementing zero-harm-ai-detectors.
  • Acting as a hosted service by default.
  • Making policy enforcement decisions that belong to a firewall or calling agent.
  • Replacing the Zero Harm AI GitHub Action.

Relationship To Other Projects

zero-harm-ai-detectors
  Shared detector engine for PII, secrets, and harmful content.

zero-harm-ai-gh-action
  GitHub Action and CI-oriented scanner for pull requests.

zero-harm-ai-mcp
  MCP server adapter that exposes detector functionality to AI agents.

zero-harm-ai-firewall (future)
  Runtime enforcement layer. It can call zero-harm-ai-mcp or use
  zero-harm-ai-detectors directly.

Installation

Install from PyPI:

pip install zero-harm-ai-mcp

For local development:

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
pytest
ruff check .

MCP Client Configuration

{
  "mcpServers": {
    "zero-harm-ai": {
      "command": "zero-harm-ai-mcp",
      "args": []
    }
  }
}

MCP Tools

zero_harm.scan_text

Scan one text string for PII, secrets, and harmful content.

Use this for prompt inputs, generated outputs, tool arguments, logs, and arbitrary text.

zero_harm.scan_messages

Scan chat-style messages while preserving message roles and indexes.

Use this when an agent wants to inspect a conversation before sending it to a model or tool.

zero_harm.redact_text

Return a redacted version of text plus findings.

Use this when the caller wants to continue safely after removing sensitive spans.

zero_harm.evaluate_policy

Map detector findings to an action recommendation.

Use this when a caller wants a normalized decision such as allow, warn, redact, or block.

Working Examples

These examples are generated from the current local server implementation.

zero_harm.scan_text

Input:

{
  "text": "Contact alice@example.com before sharing the token.",
  "targets": ["pii", "secret", "harmful"],
  "redact": true
}

Output:

{
  "schema_version": "1.0.0",
  "risk_level": "medium",
  "recommended_action": "redact",
  "categories": [
    "pii"
  ],
  "summary": {
    "total_findings": 1,
    "pii": 1,
    "secret": 0,
    "harmful": 0
  },
  "findings": [
    {
      "type": "email",
      "category": "pii",
      "severity": "medium",
      "confidence": 0.99,
      "span": {
        "start": 8,
        "end": 25
      },
      "redacted": "[PII]",
      "message_index": null,
      "message_role": null,
      "evidence_available": false
    }
  ],
  "redacted_text": "Contact [PII] before sharing the token."
}

zero_harm.scan_messages

Input:

{
  "messages": [
    {
      "role": "system",
      "content": "You are a helpful assistant."
    },
    {
      "role": "user",
      "content": "My email is alice@example.com."
    }
  ],
  "targets": ["pii", "secret", "harmful"],
  "redact": true
}

Output:

{
  "schema_version": "1.0.0",
  "risk_level": "medium",
  "recommended_action": "redact",
  "categories": [
    "pii"
  ],
  "summary": {
    "total_findings": 1,
    "pii": 1,
    "secret": 0,
    "harmful": 0
  },
  "findings": [
    {
      "type": "email",
      "category": "pii",
      "severity": "medium",
      "confidence": 0.99,
      "span": {
        "start": 12,
        "end": 29
      },
      "redacted": "[PII]",
      "message_index": 1,
      "message_role": "user",
      "evidence_available": false
    }
  ],
  "redacted_text": "[{\"role\": \"system\", \"content\": \"You are a helpful assistant.\"}, {\"role\": \"user\", \"content\": \"My email is [PII].\"}]"
}

zero_harm.redact_text

Input:

{
  "text": "aws_access_key_id = AKIAIOSFODNN7EXAMPLE",
  "targets": ["pii", "secret", "harmful"]
}

Output:

{
  "schema_version": "1.0.0",
  "risk_level": "high",
  "recommended_action": "block",
  "categories": [
    "secret"
  ],
  "summary": {
    "total_findings": 1,
    "pii": 0,
    "secret": 1,
    "harmful": 0
  },
  "findings": [
    {
      "type": "api_key",
      "category": "secret",
      "severity": "high",
      "confidence": 0.95,
      "span": {
        "start": 20,
        "end": 40
      },
      "redacted": "[SECRET]",
      "message_index": null,
      "message_role": null,
      "evidence_available": false
    }
  ],
  "redacted_text": "aws_access_key_id = [SECRET]"
}

zero_harm.evaluate_policy

Input:

{
  "text": "Contact alice@example.com before sharing the token.",
  "targets": ["pii", "secret", "harmful"],
  "redact": false
}

Output:

{
  "schema_version": "1.0.0",
  "risk_level": "medium",
  "recommended_action": "warn",
  "categories": [
    "pii"
  ],
  "summary": {
    "total_findings": 1,
    "pii": 1,
    "secret": 0,
    "harmful": 0
  }
}

Privacy Requirements

  • Do not log raw input text by default.
  • Do not log detected secret values by default.
  • Include a config option for audit logs that stores only counts, categories, severities, and request metadata.
  • Avoid sending data to external services unless explicitly configured.
  • Keep the default transport local-first.

Development

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
pytest
ruff check .

Release

Build and validate distribution artifacts:

python -m build
twine check dist/*

See RELEASE.md for the full PyPI release flow.

Release files for zero-harm-ai-mcp 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for zero-harm-ai-mcp 0.1.1
File Size Uploaded
zero_harm_ai_mcp-0.1.1.tar.gz 15.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for zero-harm-ai-mcp 0.1.1
File Interpreter ABI Platform
zero_harm_ai_mcp-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 24.6 kB

Release files / zero_harm_ai_mcp-0.1.1.tar.gz

Download URL zero_harm_ai_mcp-0.1.1.tar.gz
Size 15.5 kB
Tags Source
SHA-256 checksum
How to use checksums
78af7d1ea0d5e2039b0db5d43546cf825127153464030e81c372e5badd78da6c
BLAKE2b-256 checksum
How to use checksums
90d9a4e3bac2ffd7dcdaf8b7961014e6b701e86858dc43d9136bcc80fe6a2ac3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / zero_harm_ai_mcp-0.1.1-py3-none-any.whl

Download URL zero_harm_ai_mcp-0.1.1-py3-none-any.whl
Size 9.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
931425cca423922bce97652251bb1addaf8e5129a1e2bdb24ec4fc4edd716bd3
BLAKE2b-256 checksum
How to use checksums
b6b24b7470dec1bb0a033e106eb897a834bc4163fb524a07be48868b44cfe15a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page