PluginBench
MCP Server
Maintained
Apache-2.0

io.github.TheBarmaEffect/glassbox-framework MCP Server

io.github.TheBarmaEffect/glassbox-framework

Runtime constitutional verification for AI answers with transparent reasoning chains and audit trails.

What is the io.github.TheBarmaEffect/glassbox-framework MCP server?

The Glassbox Framework MCP server provides runtime verification of AI-generated answers by decomposing them into atomic claims with reasoning chains, scoring epistemic confidence across five dimensions, and applying adversarial red-team probes. It produces deterministic, auditable Trust Cards that show exactly why an answer is trustworthy, questionable, or should be rejected.

Glassbox wraps any (question, answer) pair through a verification pipeline that extracts claims with reasoning, scores confidence transparently, runs seven adversarial probes (Glassbox Court), evaluates against your constitutional intents, and returns a structured Trust Card with a deterministic audit hash. Use it to verify AI outputs before shipping them, audit past decisions, or build trust into AI workflows.

How to install io.github.TheBarmaEffect/glassbox-framework

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • ANTHROPIC_API_KEY
    required
    secret

    Your Anthropic API key (sk-ant-...). Required for the claim extractor, red team, constitution engines, and ECS coherence checks. One v1 tool (generate_trust_card) works without an API key — it's pure assembly + deterministic audit hashing.

  • GLASSBOX_MODEL

    Override the Claude model used by the verification engines. Defaults to claude-sonnet-4-6.

  • GLASSBOX_MAX_TOKENS

    Per-engine-call max-tokens cap. Defaults to 2048; raise for verifying long-form content.

  • GLASSBOX_ECS_MODE

    ECS aggregation mode: arithmetic (weighted mean, default) or geometric (stricter — any zero dimension collapses the total).

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "glassbox-framework": {
      "command": "npx",
      "args": [
        "-y",
        "@glassbox-framework/mcp"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "<YOUR_ANTHROPIC_API_KEY>",
        "GLASSBOX_MODEL": "<YOUR_GLASSBOX_MODEL>",
        "GLASSBOX_MAX_TOKENS": "<YOUR_GLASSBOX_MAX_TOKENS>",
        "GLASSBOX_ECS_MODE": "<YOUR_GLASSBOX_ECS_MODE>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • glassbox_verify_answer — Full pipeline: takes a question and answer, returns a complete Trust Card with claims, ECS score, red-team verdicts, constitution evaluation, and audit log.
  • glassbox_extract_claims — Decomposes an answer into atomic claims, each paired with a reasoning chain explaining support and falsification conditions.
  • glassbox_score_ecs — Computes Epistemic Confidence Score (ECS) across five dimensions with full breakdown and published formula.
  • glassbox_red_team — Runs Glassbox Court: seven adversarial probes (fabrication, source manipulation, bias injection, context attack, overconfidence, underspecification, constitutional violation).
  • glassbox_generate_trust_card — Assembles a Trust Card from prebuilt parts (claims, ECS, red-team results, constitution) without making new LLM calls.
  • glassbox_export_audit_report — Runs the full pipeline and exports a deterministic SHA-256 audit log with log_id that reproduces identically across runs and languages.

Use cases

  • Verify medical, legal, or financial AI claims before deployment by checking reasoning chains and constitution compliance.
  • Audit past AI decisions with deterministic log_ids to prove what reasoning led to a verdict.
  • Red-team your own AI outputs using seven adversarial probes to catch fabrication, bias, and overconfidence before users see them.
  • Enforce custom constitutional rules (e.g., 'never make medical claims without peer-reviewed sources') at runtime.
  • Build transparent Trust Cards into customer-facing AI products to show users exactly why an answer is trustworthy or risky.

io.github.TheBarmaEffect/glassbox-framework MCP server FAQ

What does Glassbox do?

Glassbox takes an AI-generated answer and runs it through a verification pipeline: it extracts atomic claims with reasoning chains, scores epistemic confidence across five dimensions, runs seven adversarial red-team probes, evaluates your constitutional intents, and returns a structured Trust Card with a deterministic audit hash.

Is Glassbox free?

The framework is open-source under Apache 2.0. There is also a free Lite verifier (GlassBox Lite) available as a web app, PWA, GitHub App, Discord bot, and Telegram bot that performs deterministic structural checks without requiring a paid model API.

How do I install it in Claude or Cursor?

Install via npm (`npm install -g @glassbox-framework/mcp`) or Python (`pip install glassbox-framework`). In Claude Desktop, add it to `claude_desktop_config.json` with the command `npx -y @glassbox-framework/mcp` and set your `ANTHROPIC_API_KEY` environment variable.

Do I need an API key?

The full MCP server requires an `ANTHROPIC_API_KEY` to run the LLM-assisted verification pipeline. The free Lite verifier requires no API key and is available as a web app or public remote MCP.

What is the audit log_id?

The log_id is a deterministic SHA-256 hash of the canonicalised inputs, claims, ECS dimensions, red-team verdicts, and constitution evaluations. Identical inputs always produce the same log_id across runs, machines, and languages, making audits reproducible and verifiable.

Can I use custom constitutional rules?

Yes. You pass a list of natural-language deployer intents (e.g., 'Never make specific medical claims without citing peer-reviewed sources') and Glassbox evaluates the answer against them at runtime, reporting which intents were violated.

README (reference)

Source of truth, from the repository.

Glass Box Framework

Runtime constitutional verification for AI answers. Every claim carries a reasoning chain. Every score breaks down. Every verdict is traceable.

CI PyPI version npm version Homebrew MCP Registry PyPI downloads License GitHub stars

⭐️ Star this repo if you want runtime AI verification to become the default. Every star moves Glassbox up the search ranking on GitHub, the MCP Registry, and Smithery — which means more developers find this before they ship an AI feature without a Trust Card.

<p align="center"> <img src="mcp/assets/glassbox-walkthrough.gif" alt="Glassbox in 70 seconds — walkthrough of all 6 tools" width="100%"> </p>
pip install glassbox-framework         # Python
npm install -g @glassbox-framework/mcp # Node / MCP
brew install thebarmaeffect/glassbox/glassbox-mcp   # macOS

Zero-cost public GlassBox Lite

The repository also ships a separate deterministic Lite verifier and cross-platform gateway that require no paid model API:

Lite performs bounded structural checks and does not browse or establish factual truth. The original six-tool model-assisted MCP documented below remains a separate surface.

See PLATFORMS.md for the exact live, downloadable, pilot, and external-review status of every integration.

What it is

The Glass Box Framework hands an (question, answer) pair to a runtime verification pipeline and returns a structured Trust Card containing:

  • Claims — every atomic assertion in the answer, paired with a reasoning chain explaining why it's asserted, what would support it, and what would falsify it.
  • Epistemic Confidence Score (ECS) — a transparent, weighted aggregate over five dimensions with a published formula and an always-visible per-dimension breakdown.
  • Glassbox Court — seven adversarial probes (fabrication, source manipulation, bias injection, context attack, overconfidence, underspecification, constitutional violation).
  • Constitution — your natural-language deployer intents compiled into structured runtime rules and evaluated against the answer.
  • Verdict — trust / caution / reject, with the exact reasoning that derived it.
  • Audit reference — a deterministic SHA-256 log_id; identical inputs reproduce the same identifier across runs and languages.

It is intentionally not a wrapper around a single LLM call — the reasoning chain on every claim, the formula on the ECS, and the determinism of the audit hash together form the "Glass Box" principle: no opaque scores.

Quick start (Python)

from glassbox_framework import Glassbox

with Glassbox() as gb:
    card = gb.verify_answer(
        question="Can intermittent fasting cure type 2 diabetes?",
        answer="Yes ...",
        intents=[
            "Never make specific medical claims without citing peer-reviewed sources.",
            "Always recommend consultation with a licensed healthcare professional.",
        ],
    )

print(card["verdict"])              # "reject"
print(card["ecs"]["total"])         # 0.6032
print(card["audit"]["log_id"])      # glassbox-85cc09903bd4...  (deterministic)

The six tools

ToolPurpose
glassbox_verify_answerFull pipeline → Trust Card
glassbox_extract_claimsAtomic claims with reasoning chains
glassbox_score_ecsECS with full breakdown + formula
glassbox_red_teamGlassbox Court — 7 adversarial probes
glassbox_generate_trust_cardAssemble a Trust Card from prebuilt parts (no LLM call)
glassbox_export_audit_reportFull pipeline + deterministic SHA-256 audit log

Full schemas, examples, and configuration: mcp/README.md. Python pip-specific docs: mcp/python/README.md.

Architecture (two-layer)

┌──────────────────────────────────────────────────────────┐
│ glassbox-framework (PyPI)         Python client          │
│   thin JSON-RPC stdio wrapper                            │
│   spawns ↓                                               │
├──────────────────────────────────────────────────────────┤
│ @glassbox-framework/mcp (npm)     Node MCP server        │
│   6 tools, Zod-validated I/O                             │
│   ↳ verify_answer  ↳ extract_claims  ↳ score_ecs         │
│   ↳ red_team       ↳ generate_trust_card                 │
│   ↳ export_audit_report                                  │
└──────────────────────────────────────────────────────────┘

The Python client makes zero LLM calls itself; it forwards arguments to the MCP server over stdio and renders the returned JSON. Set ANTHROPIC_API_KEY once and both layers use it.

Use with Claude Desktop

{
  "mcpServers": {
    "glass-box": {
      "command": "npx",
      "args": ["-y", "@glassbox-framework/mcp"],
      "env": { "ANTHROPIC_API_KEY": "sk-ant-..." }
    }
  }
}

~/Library/Application Support/Claude/claude_desktop_config.json on macOS.

Determinism

Audit log_ids are SHA-256 over canonicalised JSON of (inputs_hash, claims, ECS dimensions, red-team probe verdicts, constitution evaluations). Timestamps are recorded but never enter the hash, so identical inputs and identical engine outputs always produce the same log_id — across runs, machines, and even languages (the Python client → Node server → JSON canonicalisation produces byte-identical hashes).

Verifiable example, no API key needed:

pip install glassbox-framework
python -c "
import json
from glassbox_framework import Glassbox
with open('mcp/demo/raw-inputs.json') as f: i = json.load(f)
with Glassbox() as gb:
    c = gb.generate_trust_card(
        question=i['question'], answer=i['answer'],
        claims=i['claims'], red_team=i['red_team'], ecs=i['ecs'],
        constitution=i['constitution'])
print(c['audit']['log_id'])   # glassbox-85cc09903bd4b3f8022a4087
"

Project layout

mcp/                       — the MCP server + Python client (this release)
  ├── src/                 — TypeScript MCP server (6 tools)
  ├── python/              — Python pip package (glassbox-framework)
  ├── homebrew/            — Homebrew formula
  ├── assets/              — Launch video + reveal + title cards
  ├── demo/                — Live terminal demo with prebuilt Trust Card
  ├── Dockerfile           — Container image
  ├── server.json          — MCP Registry manifest
  ├── smithery.yaml        — Smithery.ai manifest
  ├── LAUNCH.md            — Launch kit
  └── DISTRIBUTION.md      — Every channel's status + commands
LICENSE                    — Apache 2.0
ROADMAP.md                 — Phase 5 (governor) plans for the broader framework
CONTRIBUTING.md
CHANGELOG.md

Contributing

Glassbox is open source under Apache 2.0 and actively wants forks and PRs. A few specific places we'd love help:

  • More red-team probes — mcp/src/engines/redteam.ts has // v2: placeholders for alignment_faking, reasoning_trace_deception, eval_awareness_gaming, agentic_misalignment, and sustained_jailbreak. Each is a tractable PR — same shape as the existing 7 probes, just a different angle. See .github/ISSUE_TEMPLATE/good_first_issue.md.
  • More language clients — currently Python (glassbox-framework) and Node (@glassbox-framework/mcp). Go, Rust, Ruby, Swift, Kotlin would all be welcome as thin JSON-RPC clients that spawn the existing MCP server.
  • More integrations — Cursor / Cline / Continue / Roo Cline / Zed / Neovim — wherever MCP is read, Glassbox should be one paste away.
  • Real-world Trust Card examples — submit (Q, A) pairs from your own AI workflows so the test suite covers more terrain.

Process:

  1. Pick a good first issue or open one with your idea
  2. Fork, branch, work — the PR template walks you through verification
  3. CI must pass (.github/workflows/ci.yml) — TS strict mode, Python wheel build, cross-language determinism on the canonical audit hash
  4. Open the PR; we aim for review within 48 hours

Code of conduct: Contributor Covenant 2.1. Be kind, stay on substance, no harassment, contact thebarmaeffect@gmail.com for anything off-public-channel.

Star ⭐ this repo

The fastest way to help right now is to star the repo. Every star:

  • Surfaces Glassbox higher in GitHub's MCP topic listings
  • Pushes the project up on the MCP Registry and Smithery rankings
  • Tells the next developer evaluating AI-safety tooling that this is the one with eyes on it

⭐ Star Glassbox

Author

Karthik Barma · MS Artificial Intelligence · Northeastern University.

Powered by Aura.

Issues + PRs: https://github.com/TheBarmaEffect/glassbox/issues

Related MCP servers

Verified AI-tool prices and AI product margin math for agents.

0
TypeScript
MIT
View repository →

Will a local LLM run on your hardware? GGUF quant, buy-vs-rent-vs-API cost, used-GPU prices.

Delegate real-world actions from Claude Code, Codex, and other agents to Hermes Agent.

1
TypeScript
MIT
View repository →

Amazon Seller Central + Ads: settlement-accurate P&L, full PPC, every write staged for approval.

1
MIT
View repository →

Generate and edit images, remove backgrounds, upscale, and create sprite sheets through DreamLayer.

View repository →
DODoxa MCP logo

Doxa MCP

Active

Christian AI for any question, in any season. Bible (BSB), grace + truth. faith.tools 5/5.

1
TypeScript
MIT
View repository →