MCP server for compliance auditing using the darnit framework
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"darnit-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Darnit > *"Darnit patches holes in your software - like darning a sock, but for code."* **Darnit** is a pluggable compliance audit framework that helps projects conform to software engineering best practices. It provides infrastructure for running compliance audits, generating cryptographic attestations, and automating remediation workflows. While security is a key focus, Darnit covers the full spectrum of software quality: - **Security posture** - vulnerability management, access controls, threat modeling - **Testing practices** - code review requirements, CI/CD quality gates, test coverage - **Build reproducibility** - artifact signing, dependency pinning, release processes - **Project governance** - maintainer documentation, contribution guidelines, response times - **Documentation standards** - READMEs, changelogs, support information This repository includes an MCP (Model Context Protocol) server for AI assistant integration, plus the OpenSSF Baseline implementation as the first supported standard. ## Features - **Plugin Architecture**: Implement any compliance standard as a darnit plugin - **Composition**: Assemble your organization's posture as a TOML-only mix of slices from other installed implementations — no forking, no Python ([quickstart](specs/013-plugin-composition/quickstart.md)) - **MCP Server**: Integrates with AI assistants (Claude, etc.) for interactive auditing - **Automated Remediation**: Generate fixes for compliance gaps with dry-run support - **Project Configuration**: Canonical `.project.yaml` for project metadata and documentation locations - **Attestation Generation**: Create cryptographically signed in-toto attestations - **STRIDE Threat Modeling**: (Alpha) Built-in security threat analysis — works best on Python web services (Flask, FastAPI, Django, MCP servers); Go/JavaScript and CLI tools have limited coverage today. See [Coverage scope](#threat-model-coverage-scope) below. To be used for basic drafting only. - **CEL Expressio…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.