{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_pqt9fcc9cfbc","handle":"darnit-mcp","url":"https://wellknown.network/agents/darnit-mcp","links":{"self":"https://wellknown.network/agents/darnit-mcp/record.json","html":"https://wellknown.network/agents/darnit-mcp","markdown":"https://wellknown.network/agents/darnit-mcp/record.md","api":"https://wellknown.network/api/v1/agents/darnit-mcp","status":"https://wellknown.network/api/v1/agents/darnit-mcp/status","claim":"https://wellknown.network/agents/darnit-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/darnit-mcp/claim.json","badge":"https://wellknown.network/agents/darnit-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/darnit-mcp/history","tools":"https://wellknown.network/api/v1/agents/darnit-mcp/tools"},"ard":{"identifier":"urn:air::server:darnit-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"darnit-mcp","summary":"MCP server for compliance auditing using the darnit framework","description":"# Darnit\n\n> *\"Darnit patches holes in your software - like darning a sock, but for code.\"*\n\n**Darnit** is a pluggable compliance audit framework that helps projects conform to software engineering best practices. It provides infrastructure for running compliance audits, generating cryptographic attestations, and automating remediation workflows.\n\nWhile security is a key focus, Darnit covers the full spectrum of software quality:\n- **Security posture** - vulnerability management, access controls, threat modeling\n- **Testing practices** - code review requirements, CI/CD quality gates, test coverage\n- **Build reproducibility** - artifact signing, dependency pinning, release processes\n- **Project governance** - maintainer documentation, contribution guidelines, response times\n- **Documentation standards** - READMEs, changelogs, support information\n\nThis repository includes an MCP (Model Context Protocol) server for AI assistant integration, plus the OpenSSF Baseline implementation as the first supported standard.\n\n## Features\n\n- **Plugin Architecture**: Implement any compliance standard as a darnit plugin\n- **Composition**: Assemble your organization's posture as a TOML-only mix of slices from other installed implementations — no forking, no Python ([quickstart](specs/013-plugin-composition/quickstart.md))\n- **MCP Server**: Integrates with AI assistants (Claude, etc.) for interactive auditing\n- **Automated Remediation**: Generate fixes for compliance gaps with dry-run support\n- **Project Configuration**: Canonical `.project.yaml` for project metadata and documentation locations\n- **Attestation Generation**: Create cryptographically signed in-toto attestations\n- **STRIDE Threat Modeling**: (Alpha) Built-in security threat analysis — works best on Python web services (Flask, FastAPI, Django, MCP servers); Go/JavaScript and CLI tools have limited coverage today. See [Coverage scope](#threat-model-coverage-scope) below. To be used for basic drafting only.\n- **CEL Expressio…","publisher":{"name":"Michael Lieberman","url":null},"homepage":"https://github.com/kusari-oss/darnit","repository":"https://github.com/kusari-oss/darnit","version":"0.1.0","license":"Apache-2.0","protocols":["mcp"],"tags":["baseline","compliance","mcp","openssf","osps","security"],"pricing":null,"endpoints":[{"url":"pypi:darnit-mcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":1,"provenance":"derived"},{"slug":"code.documentation","name":"Code Documentation","confidence":0.848,"provenance":"derived"},{"slug":"code.review","name":"Code Review","confidence":0.836,"provenance":"derived"}],"categories":["code","dev"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"darnit-mcp","registry":"pypi","observedAt":"2026-09-15T12:25:40.076Z","publishedAt":"2026-07-31T16:06:21.106160Z","latestVersion":"0.1.0"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"darnit-mcp","url":"https://pypi.org/project/darnit-mcp/","firstSeenAt":"2026-09-09T13:21:19.953Z","fetchedAt":"2026-09-15T12:24:41.649Z","normalizedAt":"2026-09-15T12:24:41.649Z"}]},"firstSeenAt":"2026-09-09T13:21:19.953Z","updatedAt":"2026-09-15T12:25:40.076Z"}