PQC Khepra MCP Server: Agentic Security Attestation Framework
About
KHEPRA MCP Server smithery badge MCP Registry License Container PQC Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings. Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact. The only MCP compliance server that runs on your metal — with the…
Details
- Transport
- SSE
Explore
- 36,195 offline STIG/CCI/NIST/CMMC mappings
- Post-quantum cryptographic attestation (ML-DSA-65 / FIPS 204)
- World's First DoD PQC STIG (17 controls)
- Godfather Report with dollar-denominated business impact (FAIR model)
- Air-gap and SCIF compatible (sovereign/ironbank modes)
- Flat annual licensing – no per-token charges
- Runs on your metal – on-prem, classified environments
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
PQC Khepra MCP Server: Agentic Security Attestation FrameworkCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
There are two delivery methods: Docker (recommended, no build required) and compiled binary (fastest startup, required for air-gap). Both support the same environment variables and all MCP clients.
Choose your path:
| Method | Best For | Startup |
|--------|----------|---------|
| Docker | Most users, easiest setup | ~2s |
| Compiled Binary | Air-gap, SCIF, performance | ~300ms |
---
npm install -g mcp-remote
Run this from your terminal to verify the server responds correctly:
| Mode | Air-Gap | Egress | Telemetry | Use Case |
|------|---------|--------|-----------|----------|
| sovereign | ✅ Yes | Zero | Zero | On-prem, SCIF, classified (DEFAULT) |
| ironbank | ✅ Yes | Zero | Zero | DoD/IC production, FIPS-only |
| hybrid | ❌ No | LAN | Zero | Edge + cloud coordination |
| edge | ❌ No | Unrestricted | Zero | Fully stateless SaaS |
Set via KHEPRA_MODE environment variable. Unknown values are rejected at startup and fall back to sovereign (fail-closed).
---
| Variable | Required | Default | Description |
|----------|----------|---------|-------------|
| KHEPRA_LICENSE_KEY | Sovereign/Pharaoh only | — | License key. Community tier runs without one. Get at nouchix.com |
| KHEPRA_MODE | No | sovereign | Deployment mode: sovereign, ironbank, hybrid, edge |
| KHEPRA_MANIFEST_PATH | No | manifest.json | Path to signed tool manifest file |
| KHEPRA_HOME | No | /var/lib/khepra | Data and compliance DB directory |
| KHEPRA_LOG_DIR | No | /var/log/khepra | Log directory |
| KHEPRA_DAG_PATH | No | ~/.khepra/dag | DAG audit chain storage path |
| KHEPRA_AUDIT_LOG_PATH | No | ~/.khepra/audit.ndjson | Signed audit log path |
| KHEPRA_MAX_CONCURRENT | No | 5 | Max concurrent tool calls per agent |
| KHEPRA_NETWORK_POLICY | No | lan | Network scope: lan, none, unrestricted |
| MCP_PQC_ENABLED | No | true | Enable ML-DSA-65 PQC attestation on all responses |
---
KHEPRA makes zero external network calls in sovereign and ironbank modes:
- License validated offline via ML-DSA-65 signed license.adinkhepra file
- Compliance databases (36,195 mappings) bundled in container — no external downloads
- No telemetry, no heartbeat, no egress — verified at the transport layer
bash
Running continuously on constrained edge hardware since May 12, 2026 to prove efficiency in sovereign environments:
- Hardware: Raspberry Pi 2 · 1 GB RAM · 900 MHz ARM · Live Spectrum Router
- SCADA Pod: STM32U585 / QRB2210 · Modbus TCP · MQTT · Zephyr RTOS 3.4+ · Live Dilithium Signature Verification
- Controls active: 3 open ports secured · 12 STIG violations detected · 100% file integrity monitoring (AIDE) · 24/7 continuous operation
threat_model
Generate a STRIDE threat model with NIST 800-53 + MITRE ATT&CK mappings. 100% offline.
packet_analyze
Analyze a PCAP capture file. Extracts: protocol distribution, suspicious connections, DNS queries, HTTP methods, potential C2 patterns.
khepra_export_attestation
Export PQC-signed attestation package covering all active compliance frameworks. C3PAO-ready evidence artifact — ML-DSA-65 signed, DAG-anchored.
vuln_scan
Scan project for known vulnerabilities in dependencies (Go, NPM, Python). Returns CVE IDs, CVSS scores, affected packages, and fix versions.
container_scan
Analyze Dockerfile and container manifests for security misconfigurations and base image vulnerabilities.
khepra_query_threat_intel
Query embedded CISA KEV + CVE threat intelligence from offline database. Returns relevant CVEs, EPSS scores, MITRE ATT&CK mappings.
godfather_approve
Deliver a staged Godfather Report. Requires the staged_token returned by godfather_report. Single-use — token is consumed on delivery.
kasa_status
Check current status of the KASA autonomous agent: uptime, active tasks, threat score, and EA kernel generation.
flight_record
Record an agent tool call to the SouHimBou AI Flight Recorder with cryptographic attestation. Creates a cryptographically verifiable audit trail.
drbc_restore
Restore the KHEPRA project from a DRBC genesis backup. Requires the same password used during backup.
nhi_revoke
Revoke a non-human identity credential
ert_scan
Run ERT security scan (SBOM, CVE, secrets, STIG, PQC inventory) in Docker sandbox
ert_godfather
Package D: EA KernelRouter causal risk attestation. Runs STIG, PQC, SBOM, Network agents in parallel, produces board-level causal chain with CVSS-band dollar impact and DAG-signed evidence node.
enumerate_host
Enumerate host information: OS, kernel, network interfaces, running services, users, installed packages. MITRE ATT&CK T1082.
compliance_scan
Run built-in compliance checks against CIS, STIG, and NIST baselines. Returns pass/fail per control with remediation guidance.
identity_epiphany
Decode a Nkyinkyim-shrouded strand back to plaintext. Reveals the original identity.
godfather_report
Generate a complete CMMC/STIG/NIST compliance report. When approval_required=true, returns a staged token — the full report is held until a human calls godfather_approve (30-min TTL).
khepra_get_compliance_score
Fast compliance score without full scan. Returns current CMMC/NIST/STIG satisfaction percentages from cached DAG state.
ouroboros_stig_eye
Ouroboros STIG Eye — continuous STIG compliance monitoring status. Returns current compliance posture and drift alerts.
fingerprint_device
Fingerprint a network device: OS detection, service banners, protocol analysis. MITRE ATT&CK T1046.
phantom_stealth
Engage Phantom Network stealth mode. GPS spoofing, thermal camouflage, ephemeral IMSI, spread spectrum pattern. Symbol: Eban (fortress).
identity_shroud
Encode a strand (identity token, API key, agent fingerprint) using Nkyinkyim mystery encoding for OPSEC identity protection.
acp_status
List active ACP credentials and their expiry status
nhi_excessive
Identify NHIs with overly broad permissions
stig_check
Check a system path or configuration against STIG controls. Default: RHEL-09-STIG-V1R3. Returns CAT I/II/III findings with remediation guidance and compliance score.
owasp_agent_assess
Assess this MCP server deployment against OWASP Agentic Top 10 (ASI01-ASI10). Returns scored findings, active controls, gaps, and ML-DSA-65 signed evidence.
ouroboros_fim_eye
Ouroboros FIM Eye — file integrity monitoring status. Returns hash baseline comparison and drift alerts.
forensic_snapshot
Collect a DFIR-grade forensic snapshot: processes, network connections, loaded modules, environment variables. ML-DSA-65 signed, DAG-attested.
pqc_verify
Verify an ML-DSA-65 signature against data. Returns verification result and signer metadata.
acp_issue
Issue a new PQC credential via the Agent Control Plane
pqc_stig
World's First DoD PQC STIG (PQC-01-STIG-V1R1). CNSA 2.0 / FIPS 203/204/205 compliance assessment. Returns per-control findings, compliance score, and ML-DSA-65 signed evidence.
khepra_get_dag_chain
Export the PQC-signed DAG chain for the current session. Returns all DAG nodes with ML-DSA-65 signatures and Adinkra symbol provenance.
sbom_generate
Generate a CycloneDX / SPDX SBOM with PQC readiness annotations.
ir_add_ioc
Add an Indicator of Compromise to an existing incident. The IOC is ML-DSA-65 signed and DAG-recorded.
ouroboros_waf_eye
Ouroboros WAF Eye — real-time web application firewall status from the Mitochondrial API Server. Returns blocked requests, threat patterns, and active rules.
audit_dag_integrity
Full integrity audit of the KASA DAG. Verifies: node count, parent linkage, PQC metadata completeness, and signature chain.
acp_revoke
Revoke an active ACP credential
nhi_orphans
Identify orphaned non-human identities with no active owner
ert_architect
Package B: Live supply chain risk — Syft SBOM + Grype CVE + CISA KEV/EPSS/MITRE enrichment. Returns findings with NIST 800-171 control mapping.
dark_crypto_contribute
Privacy-preserving contribution of anonymized crypto inventory to the Dark Crypto Intelligence Network. Returns global quantum exposure rank.
Cloud-based AI tools cannot directly spawn local subprocesses — they need an HTTP/SSE bridge to reach your local KHEPRA server. There are two approaches:
agent_record, dag_attestation, flight_export, khepra_get_dag_chain, nhi_inventory, acp_status, owasp_agent_assess, khepra_export_attestation, khepra_export_poam, khepra_get_compliance_score, ert_crypto, ert_readiness, stig_benchmark, ir_analysis, vuln_hunter, sbom_generate, threat_model, khepra_query_threat_intel, discover_assets, and more.
---
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"pqc khepra mcp server: agentic security attestation framework": {
"khepra": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"KHEPRA_MODE=sovereign",
"-v",
"/var/lib/khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}
}
McpServers
{
"khepra": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"KHEPRA_MODE=sovereign",
"-v",
"/var/lib/khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
KHEPRA MCP Server
Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings.
Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact.
The only MCP compliance server that runs on your metal — with the World's First DoD PQC STIG built in.
> PQC-01-STIG-V1R1 — Full Whitepaper →
> 17 controls covering CNSA 2.0, FIPS 203/204/205, and the NSA's May 2026 MCP security advisory.
> The world's first DoD-style Post-Quantum Cryptography STIG, including the first PQC controls for agentic AI and MCP deployments.
---
Tiers
| Tier | License Key | Tools | Telemetry | Egress |
|------|-------------|-------|-----------|--------|
| Community | ❌ Not required | pqc_stig + 12 core tools | Opt-in Dark Crypto Intel | Zero (sovereign mode) |
| Sovereign | ✅ Required | All 34 tools | Zero | Zero |
| Pharaoh | ✅ Required | All 34 tools + priority support | Zero | Zero |
> Community tier is free. Run pqc_stig to assess your project's quantum readiness against
> PQC-01-STIG-V1R1 — the World's First DoD-style Post-Quantum Cryptography STIG — no license key needed.
---
What It Does
KHEPRA MCP connects your AI assistant directly to a hardened compliance engine. Ask Claude or any MCP client to scan a system, map findings to STIG/NIST/CMMC controls, and generate an executive-ready risk report — all without sending data to external APIs.
Key capabilities:
- 36,195 STIG/CCI/NIST 800-53/800-171/CMMC mappings (offline, bundled)
- Post-quantum cryptographic attestation on every tool call (ML-DSA-65 / FIPS 204)
- World's First DoD PQC STIG — 17 controls covering CNSA 2.0 / FIPS 203/204/205 + agentic AI / MCP (PQC-01-STIG-V1R1)
- Godfather Report: dollar-denominated business impact per finding (FAIR model)
- Air-gap and SCIF compatible — sovereign/ironbank modes make zero egress calls
- Flat annual licensing — no per-token or per-query charges
- Runs on your metal: on-prem, DoD, IC, classified environments
---
Installation
There are two delivery methods: Docker (recommended, no build required) and compiled binary (fastest startup, required for air-gap). Both support the same environment variables and all MCP clients.
Choose your path:
| Method | Best For | Startup |
|--------|----------|---------|
| Docker | Most users, easiest setup | ~2s |
| Compiled Binary | Air-gap, SCIF, performance | ~300ms |
---
Option A: Docker (Recommended)
Requires Docker Desktop or Docker Engine. The image is pre-built and ships the full compliance database — no additional downloads in sovereign mode.
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



