tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. MCP Trust Monitor
Rayhan Basheer Patelabout 2 hours agoContributorJudging locked: Event build

MCP Trust Monitor

For developers connecting AI agents to third-party MCP servers: blocks calls when an approved tool's definition changes, reviews the change against the operator's policy, quarantines it on a hard-deny match or validated AI recommendation, and proves the blocked call never reached the server.

Tools used
  • ClickHouse logoClickHouse
  • SSenso.ai
  • SSemgrep

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo videoProject gallery
Demo video
Watch demo video
Project description
Problem: an MCP server can rewrite a tool's description after an operator approved it (a "rug pull"). Pinning tools can flag the change; we enforce it in the call path and prove the block. How it works: a managed MCP client binds trust to the SHA-256 revision of each tool's name, description and input schema. When a changed revision is observed, approval is invalidated and calls are refused before dispatch. Then: - Semgrep: deterministic hard-deny rules; a match quarantines and no model can override it. - Senso: the operator policy is retrieved scoped to its content ID, verified, and its digest is bound to each assessment. - OpenAI (gpt-6-astra, strict Structured Outputs, no tools): recommends review or quarantine only; it cannot approve. - Validation: accepted only if evidence spans appear verbatim and policy IDs, sources, revision and generation match. - Verification: the retried call is refused before dispatch and the server's own received-call count stays 1 -> 1; an unaffected control server keeps working. - ClickHouse: every transition is delivered as an append-only audit history and read back. Live result: Semgrep found no match, the model recommended quarantine under POL-001 quoting the exact sentence, it was validated and applied, and the block was verified. 6/6 fixed evaluation cases match (one run); 142 tests pass. Limits: synthetic demo servers; protects calls through our client only; scripted walkthrough, no polling or UI yet.
Project links
  • GitHub repository
  • Demo video
Tools used
  • ClickHouse logoClickHouse
  • SSenso.ai
  • SSemgrep