io.github.Looted/kibi-mcp
NPM · KIBI-MCP · SCANNED OCT 2
MCP server for Kibi's requirements, traceability, and proof workflows in coding agents.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 55 of 149 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to Looted/kibi). View diagnostics → Pass
- Clear OSI-approved license (AGPL-3.0-or-later).Pass
- Actively maintained (last published 0 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability78
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4804 tokens (~177/item across 27 items; 23 tools + 4 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management7
- Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage95
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 81% of tool parameters carry a description.Partial
- Structured output schemas are declared (96% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.Looted/kibi-mcp server?
io.github.Looted/kibi-mcp runs locally as an npm package, launched with npx -y kibi-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · kibi-mcp
claude mcp add looted-kibi-mcp -- npx -y kibi-mcp
{
"mcpServers": {
"looted-kibi-mcp": {
"command": "npx",
"args": [
"-y",
"kibi-mcp"
]
}
}
} {
"servers": {
"looted-kibi-mcp": {
"command": "npx",
"args": [
"-y",
"kibi-mcp"
]
}
}
} codex mcp add looted-kibi-mcp -- npx -y kibi-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"looted-kibi-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"kibi-mcp"
],
"enabled": true
}
}
} openclaw mcp add looted-kibi-mcp --command npx --arg -y --arg kibi-mcp
mcp_servers:
looted-kibi-mcp:
command: "npx"
args: ["-y", "kibi-mcp"] {
"McpServers": {
"looted-kibi-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"kibi-mcp"
]
}
}
} assistant mcp add looted-kibi-mcp -t stdio -c npx -a -y kibi-mcp
{
"mcpServers": {
"looted-kibi-mcp": {
"command": "npx",
"args": [
"-y",
"kibi-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Oct 26 +15
- Malware scan: unverified → pass ▲ security
- 1 Oct 26 +1
- Malware scan: unverified → pass ▲ security
- Stability: unverified → 0.03 ▲ functional
- Package version: 2.2.0 → 2.3.0 functional
- 30 Sept 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Analysed npm/kibi-mcp@2.3.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | Looted/kibi |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/Looted/kibi/.github/workflows/publish.yml@refs/heads/master |
| Rekor log index | 3038573666 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:0e723319b2e14e3a920b183fc2347430905e7decaf9a8fecf6ac34ef08b90b395888021a16e0df754a6e7dd31bcdf7aa097230a083aeddc275d689d77 |
Background: How many MCP packages publish verified provenance →
Dependencies 149 packages
| Packages resolved | 149 |
|---|---|
| Deprecated | 1 |
| Stale | 53 |
| No linked repository | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
kb_apply_plan ~222
Apply an explicitly approved kibi.bootstrap-plan.v1, kibi.compile-plan.v1, kibi.migration-plan.v2, or entity-deletion plan after revalidating its canonical hash and live snapshots. Bootstrap actions are dependency-ordered, sequential, source-first, and recoverable from a typed journal.
| Name | Type | Req | Description |
|---|---|---|---|
| approvedActionIds | array | – | Required for migration-plan.v2. Exact automatic action IDs explicitly approved for this application. |
| approvedPlanHash | string | – | Exact SHA-256 planHash returned by kb_plan_bootstrap, kb_compile_intent, or another approved plan after human review. |
| plan | object | – | The complete kibi.bootstrap-plan.v1, kibi.compile-plan.v1, kibi.migration-plan.v2, or hash-bound kibi.entity-deletion-plan.v1 object. Migration plans require approvedActionIds and reject blocked/non-… |
| recoveryJournalId | string | – | Typed recovery journal identifier returned by a committed_with_repairs result. Recovery replays only the immutable journal and never the original plan request. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_check ~501
Run KB validation rules and return violations, quality diagnostics, and typed kibi.migration-plan.v2 actions. Use before or after mutations and after source edits; checks remain read-only and never infer or apply actions from prose suggestions.
| Name | Type | Req | Description |
|---|---|---|---|
| async | boolean | – | When true, start the check as a background job and return a kibi.job.v1 receipt immediately instead of holding the request until the tool timeout. Poll kb_job_status with the returned jobId. Use for… |
| includeImpactDiagnostics | boolean | – | When true, include changed-file impact diagnostics such as symbol_granularity_violation and symbol_semantic_review_needed in structured output. |
| includeWorkingTreeDiff | boolean | – | When true, inspect current unstaged working-tree diffs for impact diagnostics. Pair with sourceFiles to scope the analysis. |
| maxDiagnostics | integer | – | Optional maximum number of impact diagnostics to return. Graph validation violations are not capped by this value. |
| rules | array | – | Optional rule subset. Allowed: must-priority-coverage, symbol-coverage, symbol-traceability, no-dangling-refs, source-relationship-parity, no-cycles, required-fields, deprecated-adr-no-successor, dom… |
| sourceFiles | array | – | Optional repo-relative source files to inspect for early impact diagnostics. Use with includeImpactDiagnostics after meaningful source edits. |
| staged | boolean | – | When true, inspect staged source changes for impact diagnostics using the shared CLI impact analyzer without shelling out to kibi check. |
| workspaceRoot | string | – | Optional workspace root for impact diagnostics. Defaults to the MCP server workspace. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Synchronous check payload, or a kibi.job.v1 receipt when async:true detached the check into a background job (poll kb_job_status with the jobId). |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_compile_intent ~328
Compile complete change intent into a deterministic, snapshot-bound read-only plan. Reuses intent-aware discovery and semantic modeling, accounts for every proposition, reports contradiction witnesses, proposes traceability links, and emits dependency-ordered kb_upsert-style steps only for resolved typed claims. No mutation side effects.
| Name | Type | Req | Description |
|---|---|---|---|
| clauses | array | – | Optional complete atomic clause decomposition. Each assertive clause receives independent proposition accounting. |
| intent | string | yes | Complete post-change normative intent. Send the desired behavior, not a patch fragment. |
| interpretations | array | – | Optional host-supplied typed kibi.logic.v1 interpretations; Kibi validates them before including rule steps. |
| mode | – | yes | Create a new requirement or update an existing one. Update auto-selection is allowed only with a high-confidence, well-separated candidate. |
| proposalDecisions | array | – | Explicit decisions for deterministic traceability proposals. Pending proposals never enter steps. |
| requirementId | string | – | Optional exact requirement ID. Required for an update when automatic selection is below the confidence and margin gates. |
| scenarioDrafts | array | – | Optional scenario drafts. Each is linked requirement -> scenario with specified_by. |
| semanticFacets | object | – | Host-agent facets forwarded to deterministic intent-v1 discovery. |
| sourceLocations | array | – | Workspace-relative source coordinates used for discovery and before-hash binding. |
| testDrafts | array | – | Optional test drafts. Tests are attached to scenarios with verified_by; direct req -> test proof links are not emitted. |
| title | string | – | Optional requirement title; existing title is preserved for updates when omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_coverage ~278
Generate curated structural coverage and conservative end-to-end requirement proof reports for requirements, symbols, or grouped types. Reports include the compatible repair plan plus typed kibi.migration-plan.v2 actions; semantic and E2E actions remain review/execution work. Paginated plans identify incomplete scope and no mutation occurs.
| Name | Type | Req | Description |
|---|---|---|---|
| by | – | – | – |
| includeMigrationPreview | boolean | – | Opt in to a deterministic, read-only kibi.legacy-migration-plan.v1 preview for ready semantic-inventory repair batches. |
| includePassing | boolean | – | – |
| includeTransitive | boolean | – | – |
| limit | integer | – | – |
| migrationLimit | integer | – | Maximum requirement migration batches to preview. Defaults to one review batch. |
| migrationOffset | integer | – | Zero-based offset into ready semantic-inventory batches. |
| migrationPredicateLimit | integer | – | Maximum exact predicate-schema candidates retained per assertive proposition. |
| migrationPredicateMinScore | number | – | Minimum deterministic predicate-schema rank score retained in migration previews. |
| offset | integer | – | – |
| statuses | array | – | Requirement proof-status filter (req mode): include only rows whose proofStatus is listed. Selecting statuses implies include-passing; not_applicable rows carry their typed applicability reason in pr… |
| tags | array | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_delete ~98
Delete entities by ID. Use only for intentional removals after dependency checks. Do not use as a bulk cleanup shortcut. Side effects: mutates and saves KB; skips entities with dependents.
| Name | Type | Req | Description |
|---|---|---|---|
| approvedPlanHash | string | – | Exact hash returned by a prior authored-entity deletion plan. |
| ids | array | – | Entity IDs to delete after dependency checks. |
| relationships | array | – | Exact relationship triples to retract, including legacy shard records. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_find_gaps ~87
Run bulk missing/present relationship analysis over KB entities. Use for questions like which requirements lack scenarios or tests. No mutation side effects.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| missingRelationships | array | – | – |
| offset | integer | – | – |
| presentRelationships | array | – | – |
| sourceFile | string | – | – |
| tags | array | – | – |
| type | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_graph ~79
Run bounded graph traversal from one or more seed IDs across curated relationship types. No mutation side effects.
| Name | Type | Req | Description |
|---|---|---|---|
| depth | integer | – | – |
| direction | – | – | – |
| entityTypes | array | – | – |
| maxEdges | integer | – | – |
| maxNodes | integer | – | – |
| relationships | array | – | – |
| seedIds | array | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_ingest_proof ~219
Ingest a producer-emitted kibi.proof-run.v1 artifact and evaluate it against each selected test's kibi.proof-contract.v1 proof obligations. Revalidates the live workspace snapshot, integration command binding, run-level outcome, attempt history, success policy, and append-only proof-receipt history before deriving and appending idempotent kibi.proof-receipt.v1 receipts. Producers report what happened; Kibi evaluates proof. Prefer `kibi prove` so the configured producer runs automatically; direct ingestion is an integration path for custom producers and agents.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | object | yes | Producer-emitted kibi.proof-run.v1 proof artifact. Producers report what happened; Kibi evaluates proof obligations and policies. Produce it via `kibi prove` or direct kb_ingest_proof calls. |
| snapshot | string | yes | Workspace snapshot captured immediately before the run. |
| testIds | array | – | Existing test entities with proof_contract.v1. Omit to evaluate every test contracted to the artifact's integration. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_job_status ~70
Poll a background job started with async:true (e.g. kb_check async jobs). Returns the kibi.job.v1 state: running, succeeded (with the full result), or failed (with the error).
| Name | Type | Req | Description |
|---|---|---|---|
| jobId | string | yes | The jobId from the kibi.job.v1 receipt. |
No output schema declared.
No examples provided.
kb_model_requirement ~418
Convert a prose requirement plus optional extracted claim fields into a deterministic strict-lane write set. Read-only modeling returns a sequential applyPlan for later kb_upsert calls. High-confidence claims emit req+fact strict output; lower-confidence claims emit an observation review artifact. Includes migration warnings when legacy schemaVersion metadata is detected.
| Name | Type | Req | Description |
|---|---|---|---|
| claimKey | string | – | Optional advisor-issued claim key for the exact proposition represented by logic. |
| claimText | string | – | Optional exact proposition text represented by logic; defaults to text. |
| confidence | number | – | Confidence score for the extracted claim. >= 0.70 yields strict-lane output; lower confidence yields observation-only review output. |
| existingLogicClaims | array | – | Existing requirement logic_claims values. The returned requirement update merges the new atomic claim key into this manifest instead of replacing prior claims. |
| logic | object | – | Optional typed kibi.logic.v1 IR. Kibi validates and canonicalizes it into a rule fact; raw Prolog is rejected. |
| operator | – | – | Optional extracted semantic claim operator. Example: 'eq'. |
| propertyKey | string | – | Optional extracted semantic claim propertyKey. Example: 'Retention Years'. |
| provenance | string | – | Optional extracted text reference. Falls back to source when omitted. Example: '.kb/requirements/customer-retention.md#L1'. |
| requirementId | string | – | Optional existing requirement ID to receive the requires_rule relationship. |
| source | string | – | Optional primary source path or provenance root used for stable IDs and text refs. Example: '.kb/requirements/customer-retention.md'. |
| sourceFiles | array | – | Optional related source files. The first value is used as the source fallback when source is omitted. |
| subjectKey | string | – | Optional extracted semantic claim subjectKey. Example: 'Customer.Data'. |
| text | string | yes | Required prose requirement text to model. Example: 'Customer data must be retained for 7 years.' |
| value | – | – | Optional extracted semantic claim value. Accepts string, number, or boolean. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_plan_bootstrap ~178
Generate a deterministic, snapshot-bound kibi.bootstrap-plan.v1 for repository onboarding. Read-only analysis returns evidence, bounded context questions, exact dependency-ordered actions, a canonical plan hash, and no mutation side effects.
| Name | Type | Req | Description |
|---|---|---|---|
| bootstrapContext | object | – | Optional declared bootstrap context supplied by the agent to ground the read-only synthesis output. |
| entityTypes | array | – | Optional filter to limit candidate generation to specific entity types. |
| includeGenericMarkdown | boolean | – | Whether to include generic markdown file content as candidate facts. Default: true. |
| maxCandidates | integer | – | Maximum number of candidates to return. Clamped to [1, 200]. Default: 50. |
| minConfidence | number | – | Minimum confidence threshold for candidates. Clamped to [0.60, 0.95]. Default: 0.80. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_prepare_impact_review ~64
Prepare complete content-bound impact-review authoring inputs from the current staged snapshot or explicitly selected immutable Git commits. Returns strict reviewer schemas and an unauthored template; it does not decide, approve, sign, stage, or prove the review.
| Name | Type | Req | Description |
|---|---|---|---|
| scope | – | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_query ~218
Read entities from the KB with filters. Use for discovery and lookup before edits. Do not use for writes. No mutation side effects. Tags filter by metadata tags only, not entity IDs.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Optional exact entity ID. Example: 'REQ-cli-gc'. If omitted, returns matching entities by other filters. |
| limit | number | – | Optional max rows to return after filtering. Default: 100 when omitted. Example: 25. |
| offset | number | – | Optional zero-based pagination offset. Default: 0. Example: 50 to skip first 50 rows. |
| sourceFile | string | – | Optional source-file substring filter. Example: 'src/auth/login.ts'. Uses KB source linkage, not file-system scanning. |
| tags | array | – | Optional tag filter. Matches entities that contain any provided tag. Example: ['security','billing']. |
| type | – | – | Optional entity type filter. Allowed: req, scenario, test, adr, flag, event, symbol, fact. Example: 'req'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_search ~308
Search KB entities for discovery using legacy lexical ranking or deterministic intent-v1 ranking. Intent mode accepts host-agent semantic facets and source locations, returns evidence and abstains below its confidence threshold. Use for exploratory lookup before exact follow-up with kb_query. No mutation side effects.
| Name | Type | Req | Description |
|---|---|---|---|
| fields | – | – | Optional result detail. 'summary' returns identifying metadata plus the match snippet for discovery. Use 'full' to include complete entity bodies, or follow up with kb_query for the exact entities yo… |
| limit | integer | – | Optional max rows to return after ranking. Default: 20. |
| minScore | number | – | Intent-v1 acceptance threshold between 0 and 1. Low-confidence queries abstain instead of returning misleading matches. |
| offset | integer | – | Optional zero-based pagination offset. Default: 0. |
| query | string | yes | Free-text query for metadata and markdown body discovery. Example: 'OAuth login flow'. |
| rankingMode | – | – | Optional deterministic ranking mode. Omit for backward-compatible lexical search; use intent-v1 for semantic facets, source-aware evidence, graph boosts, and abstention. |
| semanticFacets | object | – | Optional host-agent semantic interpretation. Kibi uses these strings as deterministic aliases/facets; it does not call a model itself. |
| sourceLocations | array | – | Optional changed-code locations. Results are matched to source-linked symbols/entities and include source evidence. |
| type | – | – | Optional entity type filter to narrow discovery. Example: 'req'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_semantic_advisor ~246
Analyze requirement prose without mutating the KB and return semantic advisor receipts with modeling suggestions. Use before constructing kb_upsert payloads when prose may contain machine-checkable logic. Suggestions can include strict-property facts, predicate facts, ambiguity observations, or ontology-gap observations; all suggestions are advisory and reviewable.
| Name | Type | Req | Description |
|---|---|---|---|
| clauses | array | – | Optional complete list of atomic requirement clauses supplied by the caller. Use this for compound prose so every normative clause receives a stable claim key and independent grounding review. |
| id | string | – | Optional requirement ID used for deterministic draft relationship guidance. |
| interpretations | array | – | Optional host-LLM typed kibi.logic.v1 interpretations. Kibi validates and canonicalizes them; raw Prolog is not accepted. |
| source | string | – | Optional provenance for draft suggestions. |
| status | string | – | Optional requirement status for draft suggestions. |
| text | string | yes | Requirement prose to inspect for machine-checkable modeling suggestions. |
| title | string | – | Optional requirement title for draft apply plans. |
| type | – | – | Entity type context for analysis. Requirement, domain-fact, and supporting prose all receive a proposition ledger; only requirements receive deterministic modeling suggestions. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_skills_list ~34
List bundled Kibi agent skills available for progressive disclosure. Read-only; does not mutate the KB or require Prolog.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_skills_load ~71
Load a bundled Kibi agent skill by ID, returning its manifest metadata, Markdown body, declared resources, content hash, and source type. Read-only; does not execute scripts or require Prolog.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundled skill ID to load. Example: 'kibi-usage'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_skills_read ~88
Read a declared resource from a bundled Kibi agent skill. Resource paths are restricted to the skill manifest; arbitrary file paths are not exposed. Read-only; does not require Prolog.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundled skill ID. Example: 'kibi-usage'. |
| resource | string | yes | Manifest-declared resource path to read. Example: 'resources/workflows.md'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_sparql_remote ~106
Opt-in remote SPARQL query tool for external HTTP(S) RDF endpoints. This does not query Kibi's local RDF store directly, stores no credentials, and depends on network availability.
| Name | Type | Req | Description |
|---|---|---|---|
| endpoint | string | yes | Remote SPARQL endpoint URL. Must start with http:// or https://. |
| query | string | yes | SPARQL SELECT query to send to the remote endpoint. |
| timeoutMs | number | – | Optional positive timeout in milliseconds for the remote query. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_status ~53
Report current branch, KB snapshot, freshness metadata, schema status, and a typed kibi.migration-plan.v2 action graph. Read-only status inspection with no mutation side effects; damaged stores are diagnosed without starting the engine.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_suggest_predicates ~426
Suggest ontology predicate schemas for prose requirements before agents write facts. Retrieval/ranking is followed by a semantic applicability gate and conservative binding review; complete-looking generic placeholders never trigger application. Read-only guidance returns additive candidate diagnostics, an applicable predicate-fact plan only for a semantically eligible candidate with reviewed bindings, or an explicit ontology-gap observation plus a deterministic review-only predicate schema draft when no schema fits.
| Name | Type | Req | Description |
|---|---|---|---|
| argumentBindings | object | – | Optional exact predicate argument values keyed by a candidate schema's argument_names. Required before applying a candidate whose binding_status is incomplete; Kibi never substitutes guessed values f… |
| existingLogicClaims | array | – | Existing requirement logic_claims values. Returned relationship guidance includes a merged manifest so repeated clause modeling does not discard earlier claims. |
| includeExistingSchemas | boolean | – | Whether to include existing KB fact_kind=predicate_schema facts alongside Kibi's built-in predicate catalog. Default: true. |
| maxCandidates | integer | – | Maximum ranked predicate candidates to return. Default: 5. |
| minScore | number | – | Minimum candidate score. Higher values make ontology-gap fallback more likely. Default: 0.35. |
| polarityHint | – | – | Optional reviewed polarity override for claims whose surface negation does not express predicate denial. Use only after reviewing the selected schema and full claim scope. |
| requirementId | string | – | Optional existing requirement ID. When provided, the response includes a relationshipPlan describing the req -> fact requires_predicate link to attach after preserving existing requirement metadata. |
| schemaId | string | – | Optional exact reviewed predicate schema ID. When supplied, Kibi selects that schema instead of lexical rank order and fails closed if it is unavailable. |
| source | string | – | Optional provenance or text reference for generated predicate facts or ontology-gap observations. |
| subjectHint | string | – | Optional canonical subject key to use as the first predicate argument. Example: 'editor.annotation'. |
| text | string | yes | Required prose requirement or claim to classify into ontology predicates. Example: 'When users navigate away, draft edits must auto-save.'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_upsert ~434
Create or update one entity and optional relationships. Use for KB mutations after validating intent; prefer kb_validate_upsert first because it returns semantic advisor receipts for prose-heavy requirements. Use kb_model_requirement before hand-writing strict property facts from prose, and kb_suggest_predicates before hand-writing ontology predicate facts. Use the `relationships` array for batch creation of multiple links in a single call (e.g., linking a requirement to multiple tests or facts). Prefer modeling requirements as reusable fact links (`constrains`, `requires_property`, or `requires_predicate`) so consistency and contradiction checks remain queryable. Relationship endpoints must already exist in KB. For requirements, the write will be rejected if it contradicts existing current requirements that constrain the same subject with incompatible properties. To replace a conflicting requirement, include a `supersedes` relationship from the new requirement to the old one in the same request. Successful writes may return non-blocking semantic advisor warnings; inspect and repair those warnings before treating prose as contradiction-checkable. Do not use for read-only inspection. Side effects: writes KB, may refresh symbol coordinates.
| Name | Type | Req | Description |
|---|---|---|---|
| document | object | – | Optional source-first document write. Paths are workspace-relative; omit body when updating to preserve the existing body bytes. |
| id | string | yes | Unique entity ID (string). Example: 'REQ-cli-gc'. Name entities by the behavior they govern (<TYPE>-<area>-<behavior>), never by the next free number. Existing ID updates the entity; new ID creates i… |
| properties | object | yes | Entity fields to persist. Must include title and status. If created_at, updated_at, or source are omitted, server fills defaults. |
| relationships | array | – | Optional relationship rows to create in the same call. For requirement encoding, prefer `constrains` + `requires_property` for strict property facts or `requires_predicate` for ontology predicate fac… |
| type | – | yes | Entity type to create/update. Allowed: req, scenario, test, adr, flag, event, symbol, fact. Example: 'req'. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
kb_validate_upsert ~114
Validate a kb_upsert payload without mutating the KB. Use this read-only preflight before kb_upsert, especially for requirements, because it returns schema/modeling errors plus semantic advisor receipts that identify prose likely needing kb_model_requirement, kb_suggest_predicates, ambiguity review, or an ontology-gap observation.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| properties | object | yes | Entity properties to validate using the same snake_case field names accepted by kb_upsert. |
| relationships | array | – | – |
| type | – | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
| diagnostics | array | yes | – |
| effects | array | yes | – |
| error | object | – | – |
| kibiProtocol | number | yes | – |
| nextActions | array | yes | – |
| operation | string | yes | – |
| resultVersion | string | yes | – |
| status | – | yes | – |
No examples provided.
What is the io.github.Looted/kibi-mcp server?
io.github.Looted/kibi-mcp is listed in the public MCP registry as io.github.Looted/kibi-mcp. MCP server for Kibi's requirements, traceability, and proof workflows in coding agents. This page covers its npm package (kibi-mcp).
Is the io.github.Looted/kibi-mcp server safe to use?
io.github.Looted/kibi-mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 2 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.Looted/kibi-mcp server expose?
io.github.Looted/kibi-mcp exposes 23 tools: kb_query, kb_search, kb_status, kb_skills_list, kb_skills_load, and 18 more. Their descriptions and schemas cost roughly 4,640 tokens of context every time the server is loaded.
Is the io.github.Looted/kibi-mcp server still maintained?
io.github.Looted/kibi-mcp is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.Looted/kibi-mcp server under?
io.github.Looted/kibi-mcp declares the AGPL-3.0-or-later licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.