Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"fss-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# fss-mcp [](https://pypi.org/project/fss-mcp/) [](https://pypi.org/project/fss-mcp/) [](https://opensource.org/licenses/MIT) [](https://securityscorecards.dev/viewer/?uri=github.com/3soos3/fss-chassis) FSS-compliant MCP server chassis. Build forensic-grade MCP servers that satisfy the [Forensic Software Standards (FSS)](https://fss.3soos3.online) conformance levels L1–L5. ## What it provides - Security middleware pipeline: I/O limits → Auth → Rate limit → Sanitise → Validate - `_provenance` block on every tool response (FSS-0004) - Ed25519 signing of tool results (FSS-0005, L2+) - FIT JWT verification (FSS-0006, L5) - `/.well-known/fss-deployment.json` endpoint (FSS-0009, L4) - HTTP and stdio transports - OpenTelemetry integration ## Install ```bash pip install fss-mcp # with HTTP transport: pip install "fss-mcp[http]" # with auth middleware: pip install "fss-mcp[auth]" # with OpenTelemetry: pip install "fss-mcp[otel]" # everything: pip install "fss-mcp[http,auth,otel]" ``` ## Links - Repository: <https://github.com/3soos3/fss-chassis> - FSS standard: <https://fss.3soos3.online> - OpenSSF Scorecard: <https://securityscorecards.dev/viewer/?uri=github.com/3soos3/fss-chassis> - Security advisories: <https://github.com/3soos3/fss-chassis/security/advisories>
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.