
Security News
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
@veridocs/mcp
Advanced tools
Proof Layer (VeriDOCS) — official MCP server. Cryptographic AI governance receipts for Claude, Cursor, Cline, and any MCP-aware host.
@veridocs/mcp)Cryptographic AI governance for any MCP-aware host. Drop signed, hash-chained, independently verifiable receipts into Claude Desktop, Cursor, Cline, or any other Model Context Protocol client with a single config entry.
Built by WORLD999_LABS. Also known as VeriDOCS (legacy scope name on npm).
npx -y @veridocs/mcp@1.1.0
@veridocs/mcp is the official MCP server for Proof Layer — the cryptographic governance layer for AI agents. Once installed, it gives any MCP-aware AI assistant the ability to:
EXECUTE / BLOCK / REVIEW / SHADOW verdictsEvery receipt is Ed25519-signed, hash-chained, and independently verifiable offline using only the published public key at /v1/public-key.
Add this block to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"veridocs": {
"command": "npx",
"args": ["-y", "@veridocs/mcp@1.1.0"],
"env": {
"VERIDOCS_API_KEY": "vd_live_...",
"VERIDOCS_API_URL": "https://prooflayer.world999labs.com"
}
}
}
}
Restart Claude Desktop. Ask: "List my recent VeriDOCS receipts." — Claude will call vd_list_receipts and return your audit chain.
Get an API key at prooflayer.world999labs.com.
The same command / args / env block works in any MCP-aware host. Place it in the host's MCP server configuration file under whatever key the host uses (e.g. mcpServers in Cursor).
| Variable | Required | Description |
|---|---|---|
VERIDOCS_API_KEY | yes | Your vd_live_... key. Get one at prooflayer.world999labs.com. |
VERIDOCS_API_URL | no | Defaults to https://prooflayer.world999labs.com. Override for self-hosted or staging environments. |
VERIDOCS_TELEMETRY | no | Set to off to disable the anonymous install/heartbeat ping. See Telemetry & privacy below. |
This package sends one anonymous install ping on startup, plus periodic anonymous heartbeats while running. The ping contains:
1.0.2)claude-desktop, cursor, cline)darwin, linux, win32)US, DE)We do not collect: your IP address (only the derived country, then discarded), your name, your email, your prompts, your receipts, your API key, your file paths, your machine name, or any other environment variables.
To disable, add "VERIDOCS_TELEMETRY": "off" to the env block in your MCP host config. The flag is checked on every startup.
Raw pings are retained for 90 days then aggregated and deleted. Full policy: PRIVACY.md.
The @veridocs/verify package sends nothing — it runs entirely offline.
The server registers eight tools:
| Tool | What it does |
|---|---|
vd_evaluate | Submit an action proposal — returns a signed receipt with verdict EXECUTE / BLOCK / REVIEW / SHADOW. |
vd_get_receipt | Fetch a single receipt by its UUID. |
vd_verify_receipt | Cryptographically verify a receipt's Ed25519 signature and key status. |
vd_list_receipts | List recent receipts; filter by agent_id and verdict. |
vd_usage | Current quota usage, credit balance, billing cycle, and plan tier. |
vd_list_policy_packs | List all governance policy packs with the active one flagged. |
vd_create_plan | Human approves a scoped, time-bounded plan covering future agent actions. |
vd_delegate | Agent requests authorization to perform a specific action under a plan. |
Full schema for each tool is exposed via ListToolsRequestSchema — your MCP host will discover them automatically.
Your AI assistant (Claude Desktop / Cursor / Cline)
↓ MCP (stdio)
@veridocs/mcp ← this package
↓ HTTPS
Proof Layer kernel
↓
Signed receipt → hash chain → verifiable offline
Before any consequential action — sending email, modifying data, executing payment, deleting records — the assistant calls vd_evaluate. Proof Layer evaluates against your active policy pack and returns a verdict plus a signed receipt. The assistant proceeds only when the verdict is EXECUTE.
Receipts are independently verifiable using only Ed25519 standard library calls and the public key at https://prooflayer.world999labs.com/v1/public-key. No SDK or account required. See the main Proof Layer repo for the full verification protocol and offline tooling.
MIT — © WORLD999_LABS
Built by Proof Layer.
FAQs
Proof Layer (VeriDOCS) — official MCP server. Cryptographic AI governance receipts for Claude, Cursor, Cline, and any MCP-aware host.
We found that @veridocs/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.

Research
/Security News
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.