Odel
firmware attestation mcp

firmware attestation mcp

Local
@csoai-orgPythonMITUpdated 2mo ago

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check

MCP Scorecard: 88/100

Firmware Attestation MCP

Hardware trust layer for sovereign AI. Persistence implants live below the OS (BIOS/UEFI, SMM, network boot ROMs, HDD HPA) and survive OS reinstalls and disk wipes. This MCP attests a host's firmware trust state and gates inference on a verified result.

Tools

ToolWhat
scan_firmwareread-only host evidence (Secure Boot, TPM, SIP, BIOS, HPA)
check_ant_signaturesmatch to NSA-ANT-class persistence preconditions + defenses
attest_firmwareHMAC-signed attestation, verifiable at proofof.ai/api/verify
gate_inferenceALLOW/BLOCK AI on this host (strict by default)
list_threat_modelthe attack surface this defends against

Honest by design

Reports indicators (preconditions implants rely on), never "clean". A BLOCK means "lacks confirmed trust anchors," not "hacked." Harden per the listed defenses, then re-gate.

pip install firmware-attestation-mcp

© CSOAI LTD (trading as MEOK AI Labs) · MIT

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "firmware-attestation-mcp": {
      "command": "uvx",
      "args": ["firmware-attestation-mcp"]
    }
  }
}

Or: pip install firmware-attestation-mcp then run the firmware-attestation-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use scan_firmware to …"
  • "Use check_ant_signatures to …"
  • "Use attest_firmware to …"

Part of the MEOK constellation

This MCP is one node in a connected ecosystem built by MEOK AI LABS around a single sovereign AI core — governed agents with a hash-chained audit trail, mapped to the CSOAI compliance charter.