VITNA – Containment for rogue AI agents
Local package path declaredNo credentials listedRepository declared by sourceUpdated 2026-10-07
xyz.costrinity/vitna-compliance-preflight · Registry status: active
At a glance
Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records.
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declaredMCP-Register · 2026-08-12
- Required secrets declared
- No credentials listedMCP-Register · 2026-08-12
- Declared version and change
0.5.4· Source-reported change date 2026-10-07MCP-Register · 2026-10-08- Repository as declared
- github.com/COSTRINITY/vitna-compliance-mcpMCP-Register · 2026-08-12
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers without declared required secrets36,126
- Locally executed MCP servers17,143
- MCP servers with a repository URL30,309
- Local MCP servers without declared required secrets13,303
- Local MCP servers with a repository URL16,232
- MCP servers as an npm package only10,232
6 of 10 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- No credentials listed
- Registry record changed
- 2026-10-07
- Setup
- Template available
- Registry name
xyz.costrinity/vitna-compliance-preflight- Package coordinate
npm:@costrinity/vitna-compliance-mcp- Declared version
0.5.4- Source-reported listing date
- 2026-10-07
- Source-reported change date
- 2026-10-07
- First seen by tracevero
- 2026-08-12
- Vendor's website
- https://vitna.costrinity.xyz
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | No credentials listed no Original data – Required secret variables (raw): confirmed absent Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-12 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio, streamable-http Source: MCP-Register · collected on 2026-08-12 · derived |
| Path argument present | no Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-08-12 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/COSTRINITY/vitna-compliance-mcp Source: MCP-Register · collected on 2026-08-12 · derived |
| Declared version | 0.5.4 Source: MCP-Register · collected on 2026-10-08 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Where this server connects to
- Address as stated in the raw record
https://vitna.costrinity.xyz/api/mcp- Host
vitna.costrinity.xyzEntries carrying exactly this value: 1
Taken verbatim from the raw record. The registry does not call this address and does not infer a shared operator from a shared host.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records. Source: MCP-Register · collected on 2026-10-08 · self-declared |
|---|---|
| Environment variables (raw) | VITNA_OWNER_ID, VITNA_API_KEY, VITNA_EMAIL, VITNA_BASE_URL, VITNA_OPEN_CLAIM Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Required secret variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-12 · self-declared |
| Transports (raw) | stdio, streamable-http Source: MCP-Register · collected on 2026-08-12 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-12 · self-declared |
| Repository (raw) | https://github.com/COSTRINITY/vitna-compliance-mcp Source: MCP-Register · collected on 2026-08-12 · self-declared |
| Package registries (raw) | npm Source: MCP-Register · collected on 2026-08-12 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | https://vitna.costrinity.xyz/api/mcp Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | vitna.costrinity.xyz Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-10-07 Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Last changed in the registry (raw) | 2026-10-07 Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | package and remote Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | @costrinity/vitna-compliance-mcp Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 0.5.4 Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Runtime hints (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | VITNA_API_KEY=Your VITNA API key (new keys vitna_..., legacy vigil_... keys remain valid). Optional: self-provisioned if unset. The old VIGIL_API_KEY name is still accepted. · VITNA_BASE_URL=VITNA base URL; override only for self-hosted. The old VIGIL_BASE_URL name is still accepted. · VITNA_EMAIL=Email to own the self-provisioned trial account. Optional: a throwaway is used if unset. It does not claim the account: claim it with GitHub or a passkey. The old VIGIL_EMAIL name is still accepted. · VITNA_OPEN_CLAIM=Set to 1 to have the trial's claim link opened in your default browser when a trial starts. Either way the link is printed in the MCP server log, and the agent is never sent it. · VITNA_OWNER_ID=Your VITNA operator UUID. Optional: if unset, the first tool call self-provisions a restricted trial key. The old VIGIL_OWNER_ID name is still accepted. Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"@costrinity/vitna-compliance-mcp","version":"0.5.4","transport":"stdio","environment":[{"name":"VITNA_OWNER_ID","description":"Your VITNA operator UUID. Optional: if unset, the first tool call self-provisions a restricted trial key. The old VIGIL_OWNER_ID name is still accepted.","required":false,"secret":false},{"name":"VITNA_API_KEY","description":"Your VITNA API key (new keys vitna_..., legacy vigil_... keys remain valid). Optional: self-provisioned if unset. The old VIGIL_API_KEY name is still accepted.","required":false,"secret":true},{"name":"VITNA_EMAIL","description":"Email to own the self-provisioned trial account. Optional: a throwaway is used if unset. It does not claim the account: claim it with GitHub or a passkey. The old VIGIL_EMAIL name is still accepted.","required":false,"secret":false},{"name":"VITNA_BASE_URL","description":"VITNA base URL; override only for self-hosted. The old VIGIL_BASE_URL name is still accepted.","required":false,"secret":false},{"name":"VITNA_OPEN_CLAIM","description":"Set to 1 to have the trial's claim link opened in your default browser when a trial starts. Either way the link is printed in the MCP server log, and the agent is never sent it.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[{"url":"https://vitna.costrinity.xyz/api/mcp","transport":"streamable-http","headers":[{"name":"Authorization","description":"Bearer <your VITNA API key>. Discovery (initialize, tools/list) and vitna_help work without it; every governed decision tool requires it. Get a key free at https://vitna.costrinity.xyz/dashboard. X-API-Key is also accepted.","required":false,"secret":true}]}]} Source: MCP-Register · collected on 2026-10-08 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/xyz-costrinity-vitna-compliance-preflight)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-10-08 | Declared version: 0.5.1 → 0.5.4 |
|---|---|
| 2026-10-08 | Description (raw): Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions. → Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records. |
| 2026-10-08 | Last changed in the registry (raw): 2026-10-04 → 2026-10-07 |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/xyz-costrinity-vitna-compliance-preflight