PluginBench
MCP Server
Active
AGPL-3.0

BLACKPROOF Local MCP MCP Server

io.github.l0gfr/blackproof

Local-first cyber evidence integrity checks and dossier comparison for audits and reviews.

What is the BLACKPROOF Local MCP MCP server?

BLACKPROOF Local MCP is a read-only MCP server that enables verification and comparison of cyber evidence dossiers on your device. It provides tools to check ProofPacks before transmission, compare review snapshots, and retrieve preparation checklists—without exposing answers, evidence files, or sensitive data to remote agents.

BLACKPROOF Local MCP lets you integrate cyber evidence verification into AI agent workflows while maintaining strict local-first privacy. It's designed for enterprise audits, internal reviews, and supplier questionnaires, allowing you to verify dossier integrity and compare snapshots through aggregate changes without uploading data or exposing sensitive details.

How to install BLACKPROOF Local MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "blackproof": {
      "command": "https://github.com/l0gfr/BLACKPROOF-AGPL/releases/download/mcp-v0.1.0/blackproof-local-mcp-0.1.0.mcpb",
      "args": []
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • ProofPack verification — Check a selected ProofPack before transmission to verify integrity and structure.
  • Snapshot comparison — Compare two review snapshots and obtain aggregate changes between them.
  • Preparation checklists — Retrieve public preparation checklists for cyber reviews, internal audits, and questionnaires.

Use cases

  • Verify cyber evidence dossier integrity before sharing with stakeholders
  • Compare two audit snapshots to identify changes and gaps in compliance preparation
  • Generate and retrieve audit preparation checklists for internal reviews
  • Integrate evidence verification into AI-assisted audit workflows while keeping sensitive data local
  • Validate ProofPack structure and completeness in enterprise security assessments

BLACKPROOF Local MCP MCP server FAQ

What is BLACKPROOF Local MCP?

It's a read-only MCP server that runs locally on your device to verify cyber evidence dossiers, compare audit snapshots, and retrieve preparation checklists—without exposing answers, evidence files, or sensitive data to remote agents.

Is BLACKPROOF free?

Yes, BLACKPROOF is free and open-source under AGPL-3.0-only. No account, activation key, or application server is required.

How do I install it in Cursor or Claude?

Use the mcpb binary from the releases: https://github.com/l0gfr/BLACKPROOF-AGPL/releases/download/mcp-v0.1.0/blackproof-local-mcp-0.1.0.mcpb. It runs over stdio on your device.

Does it require authentication?

No authentication is required. BLACKPROOF is local-first; dossiers are processed and encrypted on your device, and no server upload is permitted.

What data does it expose to the agent?

The MCP server is read-only and does not expose answers, evidence references, or files to the agent. It only provides verification results, aggregate comparisons, and public preparation checklists.

Is my data private?

Yes. All dossiers are processed locally in your browser or device, encrypted in IndexedDB, and never uploaded. The MCP server runs over stdio on your device, not on a public server.

README (reference)

Source of truth, from the repository.

BLACKPROOF

BLACKPROOF is a free, open-source, local-first cyber evidence app under AGPL-3.0-only. Create, import, encrypt, export and verify dossiers directly in your browser. No account, activation key or application server is required. Use it to prepare cyber reviews, internal audits and supplier questionnaires. Bring your own review checklist, document answers, evidence references and reservations, then track the remaining preparation work. Source documents and audit conclusions still require human assessment; this is not a system scanner or an automated certification service.

Core flow:

questionnaire ou grille d'audit → réponses et références → preuves attendues → points à corriger → dossier interne → export relu facultatif.

Project structure

  • apps/web — public website and local-first app
  • apps/web/src/content/analyses (sourced Markdown analyses and publication drafts)
  • packages/core — ProofGraph, ProofDebt, ProofPack logic
  • packages/verifier — standalone Delivery verifier CLI/SDK
  • packages/mcp — local, read-only MCP server for minimized verification and comparison
  • tests/e2e — Chromium tests for the local-first editor and verification flows
  • scripts — schema generation, security checks and deployment tooling
  • docs — project context and technical documentation

Development

Requirements: Node.js 22.23.2 (see .nvmrc) and pnpm 10.34.5.

pnpm install --frozen-lockfile
pnpm dev

The authoritative local gate is:

pnpm verify:all

pnpm verify:all runs schema drift checks, TypeScript/Astro/Svelte validation, unit tests, the static build, CSP generation, local-only artifact checks, the dependency and repository security audits, and the Chromium end-to-end tests.

Local-first boundary

Questionnaires, ProofPacks and Delivery snapshots are processed on the user's device; saved dossiers are encrypted in browser IndexedDB. No server upload is implemented or permitted for import, creation, editing, backup or verification. Downloading an export saves a local file; users transmit it separately, outside BLACKPROOF. See docs/LOCAL_FIRST_STORAGE.md and docs/SECURITY_MODEL.md before changing a storage, export or destructive operation.

Local MCP for enterprise agents

Use the local MCP server to check a selected ProofPack before transmission, compare two review snapshots through aggregate changes, and obtain public preparation checklists for cyber reviews, internal audits and questionnaires. It does not expose answers, evidence references or files to the agent. It runs over stdio on the user's device, not on the public website.

See installation, tools, fictional walkthrough and security limits. Private mode requires an end-to-end local client/model. A local transport alone cannot stop a host from forwarding results to a remote model.

Editorial analyses

The /analyses section is generated from a validated Astro content collection. Drafts are excluded from public routes, RSS and the sitemap. The complete authoring and verification workflow is documented in docs/EDITORIAL_ANALYSES.md.

Licence and contributions

The original software, documentation, schemas and standalone verifier are licensed under GNU AGPL version 3 only. See LICENSE and NOTICE. Third-party dependencies retain their own licences in THIRD_PARTY_NOTICES.md. Contributions are welcome: see CONTRIBUTING.md. Project names and logos are covered separately by TRADEMARKS.md.

Source: https://github.com/l0gfr/BLACKPROOF-AGPL

Self-hosting

pnpm build produces the static site in apps/web/dist/. Serve it over HTTPS (or localhost for development), with the CSP and security headers described in docs/DEPLOY_APACHE.md. Publish the corresponding source of your version and keep the licence/source link visible.

The application stores dossiers locally in browser IndexedDB. Back up encrypted dossiers before changing hostname or browser profile: browser storage is scoped to an origin and is not synchronized by the host.

The hosted public status registry is retired. Local verification and detached signatures remain available. A historical or unavailable registry must never be interpreted as proof that a Delivery is currently active.

Related MCP servers

MCP Server that turns your AI agent into a localization expert with token-efficient i18n translation

3
TypeScript
MIT
View repository →

Persistent, consensus-validated institutional memory for AI agents with Byzantine-resilient infrastructure.

244
Go
Apache-2.0
View repository →

Persistent, governed local memory for MCP-compatible AI clients.

0
C#
Apache-2.0
View repository →

Audit an MCP config, price a model, size a GPU, explain network config drift. Key-free.

0
JavaScript
MIT
View repository →

Subnet math, port and MAC lookups, DNS, DNSBL, TLS cert inspection, public IP. No account.

0
JavaScript
MIT
View repository →

Config drift, CIS/PCI checks, 802.1X diagnosis, certs inside configs, topology, change pre-flight.

0
Python
MIT
View repository →