VITNA — Agent Compliance Preflight
REMOTE · VITNA.COSTRINITY.XYZ · 2 COMPONENTS · SCANNED OCT 4
Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 23 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2436 tokens (~105/item across 23 items; 23 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage74
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 22% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 23 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
How do I install the VITNA — Agent Compliance Preflight MCP server?
VITNA — Agent Compliance Preflight is a hosted endpoint at https://vitna.costrinity.xyz/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · vitna.costrinity.xyz
claude mcp add --transport http xyz-costrinity-vitna-compliance-preflight 'https://vitna.costrinity.xyz/api/mcp'
{
"mcpServers": {
"xyz-costrinity-vitna-compliance-preflight": {
"url": "https://vitna.costrinity.xyz/api/mcp"
}
}
} {
"servers": {
"xyz-costrinity-vitna-compliance-preflight": {
"type": "http",
"url": "https://vitna.costrinity.xyz/api/mcp"
}
}
} [mcp_servers.xyz-costrinity-vitna-compliance-preflight] url = "https://vitna.costrinity.xyz/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xyz-costrinity-vitna-compliance-preflight": {
"type": "remote",
"url": "https://vitna.costrinity.xyz/api/mcp",
"enabled": true
}
}
} openclaw mcp add xyz-costrinity-vitna-compliance-preflight --url 'https://vitna.costrinity.xyz/api/mcp' --transport streamable-http
mcp_servers:
xyz-costrinity-vitna-compliance-preflight:
url: "https://vitna.costrinity.xyz/api/mcp" {
"McpServers": {
"xyz-costrinity-vitna-compliance-preflight": {
"Transport": "http",
"Url": "https://vitna.costrinity.xyz/api/mcp"
}
}
} assistant mcp add xyz-costrinity-vitna-compliance-preflight -t streamable-http -u 'https://vitna.costrinity.xyz/api/mcp'
{
"mcpServers": {
"xyz-costrinity-vitna-compliance-preflight": {
"type": "http",
"url": "https://vitna.costrinity.xyz/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Oct 26 0
- Server version: 0.5.0 → 0.5.1 functional
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 0
- Server version: 0.3.7 → 0.5.0 functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 10 Sept 26 +1
- Stability: 0.97 → pass security
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Sept 26 74
- Tool “consent_check” rewrote its description, which is the text the model reads security
- Tool “vitna_preflight” rewrote its description, which is the text the model reads security
- Schema quality: pass → fail ▼ functional
- Schema quality: good → excellent functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Probed https://vitna.costrinity.xyz/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=vitna.costrinity.xyz | CN=YR1,O=Let's Encrypt,C=US | 24 Sept 2026 | 23 Dec 2026 | RSA 2048 | SHA256-RSA | 592a3767b74a23064bbccc2474751edc4c5 |
| SANs: vitna.costrinity.xyz | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of vitna.costrinity.xyz. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| xyz. | present | 3599, 18130 | 8, 8 | Verified |
| costrinity.xyz. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'none'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | accelerometer=(), autoplay=(), battery=(), bluetooth=(), camera=(), clipboard-read=(self), clipboard-write=(self), cross-origin-isolated=(self), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(), gyroscope=(), hid=(), idle-detection=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-create=(self), publickey-credentials-get=(self), screen-wake-lock=(), serial=(), speaker-selection=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://vitna.costrinity.xyz/api/mcp | Verified | 200 | |
| http (plaintext) | http://vitna.costrinity.xyz/api/mcp | HTTPS enforced | 308 | https://vitna.costrinity.xyz/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
aadhaar_mask ~63
Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| aadhaar | string | yes | – |
No output schema declared.
No examples provided.
ai_act_classify ~187
Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identification / automated-decision / social-scoring / GPAI flags) and VITNA returns the risk tier (prohibited / high-risk / limited-risk / minimal-risk), GPAI obligations, and the per-tier obligations you would have to meet. A classification for you to act on: VITNA evaluates and records, it does not gate the build.
| Name | Type | Req | Description |
|---|---|---|---|
| automated_decisions | boolean | – | – |
| biometric | boolean | – | – |
| data_categories | array | – | – |
| general_purpose_ai | boolean | – | – |
| remote_identification | boolean | – | – |
| sectors | array | – | – |
| social_scoring | boolean | – | – |
| use_case | string | yes | – |
No output schema declared.
No examples provided.
breach_classify ~197
After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, sensitivity, recovery state) and VITNA returns reportability + reasoning + the notification deadline + who to notify, across DPDP §8, GDPR Art 33, CPRA §1798.82, LGPD Art 48, PDPA §26B, and US-FED sectoral. This makes the full incident decision from the facts; for a quick per-US-state deadline/recipient/threshold table without incident facts, use us_state_breach_deadline. VITNA evaluates and records; acting on the result is up to you.
| Name | Type | Req | Description |
|---|---|---|---|
| affected_count | integer | yes | – |
| data_categories | array | yes | – |
| jurisdiction | string | – | – |
| processing_purpose | string | – | – |
| recovery_state | string | yes | – |
| sensitivity | string | yes | – |
No output schema declared.
No examples provided.
consent_check ~167
Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and optional category); returns { allowed, reason, matching_consent_id, principal_id }, a determination you must honour yourself since VITNA evaluates and records but does not enforce. Use this for personal-data processing legality; for a dangerous technical action (shell / file / DB / network) use vitna_preflight instead.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional permitted-category check. |
| principal_id | string | – | UUID of the data principal (if known). |
| principal_ref | string | – | Operator-side identifier; will be SHA-256-hashed. |
| purpose | string | yes | Purpose code (e.g. 'operational_observability'). |
No output schema declared.
No examples provided.
cpf_validate ~44
Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| cpf | string | yes | – |
No output schema declared.
No examples provided.
dpia_threshold_check ~166
Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categories (and scale / systematic-monitoring / automated-decision / cross-border / vulnerable-subjects flags); returns dpia_required + the 9-criterion WP29 analysis + jurisdiction guidance, so you know whether to pause and assess before proceeding.
| Name | Type | Req | Description |
|---|---|---|---|
| automated_decision | boolean | – | – |
| cross_border | boolean | – | – |
| data_categories | array | yes | – |
| jurisdiction | string | – | – |
| processing_purpose | string | yes | – |
| scale | string | – | – |
| systematic_monitoring | boolean | – | – |
| vulnerable_subjects | boolean | – | – |
No output schema declared.
No examples provided.
global_compliance_map ~48
Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision and leaves no dashboard timeline trace.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
gstin_validate ~47
Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| gstin | string | yes | – |
No output schema declared.
No examples provided.
iban_validate ~49
Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| iban | string | yes | – |
No output schema declared.
No examples provided.
india_cross_border_status ~101
Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SEBI / IRDAI caveats. Pass the ISO-3166 alpha-2 country code (e.g. US). Stateless lookup: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | ISO-3166 alpha-2 (e.g. US). |
No output schema declared.
No examples provided.
india_regulators_directory ~103
Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup of who exists and what they cover. To instead work out which of them apply to a specific processing activity, use india_sectoral_check. Stateless lookup: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| sector | string | – | – |
No output schema declared.
No examples provided.
india_sectoral_check ~128
Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PFRDA) from its processing profile, so you know whose rules apply before you act. This analyses your processing to say what applies; for a plain directory of every Indian regulator regardless of your activity, use india_regulators_directory.
| Name | Type | Req | Description |
|---|---|---|---|
| counterparty_types | array | – | – |
| data_categories | array | yes | – |
| processing_purpose | string | yes | – |
| sector_hint | string | – | – |
No output schema declared.
No examples provided.
japan_cross_border_status ~78
Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-3166 alpha-2 country code. Stateless lookup: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | ISO-3166 alpha-2. |
No output schema declared.
No examples provided.
pan_classify ~61
Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| pan | string | yes | – |
No output schema declared.
No examples provided.
pii_test ~102
Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether severity would escalate. Nothing is persisted and nothing is filtered: a safe rehearsal you act on, not an enforced gate — it records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| jurisdiction | string | – | – |
| sample_event | object | yes | event_type / message / payload fields. |
No output schema declared.
No examples provided.
privacy_notice_get ~71
Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Called with an API key, the operator's name and contact details appear as placeholders; the signed-in owner gets the real values. Stateless generator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | – |
No output schema declared.
No examples provided.
sin_validate ~44
Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| sin | string | yes | – |
No output schema declared.
No examples provided.
sub_processors_register ~42
Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
us_sectoral_check ~124
Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing profile, so you can factor them in before you act. US-scoped; for Indian sectoral regulators use india_sectoral_check.
| Name | Type | Req | Description |
|---|---|---|---|
| ai_decisions | boolean | – | – |
| counterparty_types | array | – | – |
| data_categories | array | yes | – |
| has_revenue_threshold | boolean | – | – |
| processing_purpose | string | yes | – |
No output schema declared.
No examples provided.
us_state_breach_deadline ~120
Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unreasonable delay). This is a static table, not an incident ruling. When you have the actual incident facts and need a reportable / not-reportable decision with reasoning, use breach_classify instead. Stateless lookup: records no decision and leaves no dashboard timeline trace.
| Name | Type | Req | Description |
|---|---|---|---|
| state | string | yes | US 2-letter state code (CA, NY, TX, ...). |
No output schema declared.
No examples provided.
vitna_claim ~145
Ask whether this VITNA account has been claimed by a real person yet. Call this when the user asks about their VITNA account or when you are told evidence is not being kept. Returns { claimed, claim_url: null, claim_note, what_claiming_gets_you }. You are never given the claim link, and you must not look for it: only a person may claim the account that oversees you. If claimed is false, tell the user that the account's evidence is NOT being durably recorded and that they can claim it with the claim link VITNA showed them when the trial started (the stdio server prints it in its MCP server log).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
vitna_help ~91
What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check risky actions BEFORE running them, what a deny / hold decision means, trial vs claimed mode, and how the user can monitor and audit what you do. Runs entirely locally: no account, no API call, and no dashboard timeline trace.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
vitna_preflight ~282
SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the action BEFORE you run it: it flags dangerous shell / SQL / secret-exfil / prompt-injection / suspicious-network patterns and returns { decision: allowed|blocked|flagged }. RESPONSE SHAPE DEPENDS ON THE KEY: an unclaimed trial key gets the decision label only, because the pattern detail is what makes the classifier worth stealing. A claimed key additionally gets threat_category, severity, reason (the rule names that matched, never the matched text), a threats[] array and a redacted echo of what was scanned, plus a signed audit record the user can review. VITNA evaluates and records; it does NOT enforce, so treat blocked / flagged as a stop and get human approval. This is how a user keeps you in check. Heuristic pattern match, not a sandbox: novel or obfuscated payloads can pass.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | The proposed action / command text, e.g. "rm -rf /" or "DROP TABLE users". |
| action_type | string | – | Optional short label for the action kind (shell, file_delete, db_query, network). |
| payload | object | – | Optional structured payload to scan alongside the action text. |
No output schema declared.
No examples provided.
What is the VITNA — Agent Compliance Preflight MCP server?
VITNA — Agent Compliance Preflight is an MCP server listed in the public MCP registry as xyz.costrinity/vitna-compliance-preflight. Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions. This page covers its hosted endpoint (https://vitna.costrinity.xyz/api/mcp).
Is the VITNA — Agent Compliance Preflight MCP server safe to use?
VITNA — Agent Compliance Preflight scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the VITNA — Agent Compliance Preflight MCP server expose?
VITNA — Agent Compliance Preflight exposes 23 tools: vitna_help, vitna_claim, consent_check, breach_classify, ai_act_classify, and 18 more. Their descriptions and schemas cost roughly 2,460 tokens of context every time the server is loaded.
Does the VITNA — Agent Compliance Preflight MCP server require authentication?
No. We connected to VITNA — Agent Compliance Preflight without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the VITNA — Agent Compliance Preflight MCP server still maintained?
VITNA — Agent Compliance Preflight is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.