
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
jidoseal-mcp
Advanced tools
Local check of a folder of markdown against OKF v0.2 frontmatter tiers — an MCP server for Claude, Cursor, GitHub Copilot, Codex, Gemini CLI, Zed and local models. The scan sends nothing (vendor claim, see README).
Check a folder of markdown notes against Open Knowledge Format (OKF) v0.2 — from inside Claude Code, Claude Desktop, Cursor, GitHub Copilot, OpenAI Codex, Gemini CLI, Zed, Cline, Continue, JetBrains AI Assistant or a local model, on your own machine.
Pick a folder, scan it. jidoseal-mcp is a local Model Context Protocol server that reads the YAML frontmatter of every *.md file under a folder, reports which tier the knowledge base reaches (Bronze / Silver / Gold), and lists — per file — the exact frontmatter fields missing for the next tier. The scan sends nothing over the network: no file, no file name, no file content. That is JidoSeal's own claim about its engine; below is how to check it.
pip install jidoseal-mcp
claude mcp add jidoseal -- jidoseal-mcp # Claude Code; every other tool is below
Then ask your assistant: "Scan ~/notes with JidoSeal and tell me what's missing for Silver."
Independent. OKF is an open specification from Google Cloud. JidoSeal is not affiliated with, sponsored by, or endorsed by Google or ISO. ISO names no fields: the Bronze/Silver/Gold tiers and their fields are defined by JidoSeal, as one way of evidencing selected ISO clauses. A JidoSeal tier or certificate is not an ISO certification.
*.md files under the folder you give it (hidden files and folders are skipped), plus <folder>/.jidoseal/config.yaml if present. The server refuses a folder that contains a symlink to a directory or to a file outside the folder.<folder>/.jidoseal/manifest.json (replaced on each scan) and <folder>/.jidoseal/progress.ndjson (appended to). Nothing else; your notes are not modified.jidoseal_start_checkout runs only with confirm: true. It sends eight fields to jidoseal.com: company, name and email as typed, the tier, a 0–100 score, the corpus's Merkle root, the local scan's id, and one flag saying which Bronze price applies. jidoseal.com copies them into the Stripe Checkout session it creates (the email as the session's customer email, all eight as session metadata), when the session is created, before any payment. No file contents, file names, per-file hashes or paths. No card data passes through this server.jidoseal package, under a proprietary licence. It ships as plain Python source and is pinned here to one version (0.1.4), with its sha256 in ENGINE-SHA256SUMS and an SBOM in sbom.cdx.json. So "nothing leaves your machine" is JidoSeal's own claim: you can check it with the commands under What leaves your machine and the tests in tests/, but it has not been independently audited.The scan is deterministic — presence of populated frontmatter fields, no model calls, no scoring by opinion. A field counts only if it has real content (title: with nothing after it earns nothing).
| Tier | A file must have (populated) | What it evidences |
|---|---|---|
| Bronze | type | OKF v0.2 as written — type is its one required field |
| Silver | Bronze + title, description, timestamp, owner | ISO 9001 §7.5.2, which asks for appropriate identification and description of a document and gives examples ("a title, date, author, or reference number"). These four fields are one reasonable way to evidence it. |
| Gold | Silver + status, review_policy, reviewed_at, next_review_at | ISO 30401's kept-current knowledge governance. The standard sets no review interval; a stated review policy with real review dates is how you evidence it, and the cadence is yours to choose. |
A corpus's tier is the tier of its weakest file. Coverage is the share of files that reach each tier. The full field reference — accepted aliases, what counts as "populated", what is excluded — is in docs/tiers.md.
A minimal Gold-tier file:
---
type: policy
title: Leave policy
description: How leave accrues and how to request it.
timestamp: 2026-09-01
owner: dept:people-ops
status: stable
review_policy: yearly
reviewed_at: 2026-09-01
next_review_at: 2027-09-01
---
Worked examples for each tier, and a mixed folder, are in examples/tiers/.
| Tool | What it does | Network |
|---|---|---|
jidoseal_scan | The free Self-Check over a folder on this machine: corpus tier, per-file missing fields for the next tier (each marked AUTO — a value JidoSeal can propose — or NEEDS-CLIENT — only the owner can answer), coverage per tier, a 0–100 score, and a Merkle root of the corpus. | none (JidoSeal's claim; see below) |
jidoseal_certification_offer | What optional certification would cost for this corpus, why, what it includes, and exactly which facts a purchase would send. Computes locally; starts nothing. | none (same claim) |
jidoseal_start_checkout | Only on your explicit go-ahead, passed as confirm: true (without it, nothing is sent): asks jidoseal.com to create a Stripe Checkout session and returns the link for you to open. Takes no payment. | jidoseal.com, which passes the fields to Stripe |
Example jidoseal_scan result for examples/tiers/mixed (three files, one Gold, one Bronze, one with no frontmatter):
{
"corpus": { "file_count": 3, "tier": "none",
"coverage": { "bronze": 66.7, "silver": 33.3, "gold": 33.3 } },
"score": 44,
"certified_eligible": false,
"files": [
{ "name": "expenses.md", "tier": "bronze",
"missing": { "silver": [ { "field": "description", "fix": "AUTO" },
{ "field": "timestamp", "fix": "AUTO" },
{ "field": "owner", "fix": "NEEDS-CLIENT" } ] } }
// …
]
}
frontmatter_ok: false on a file means its frontmatter block exists but does not parse; no field write can close its gaps until it is fixed by hand.
Requires Python 3.9+. pip install jidoseal-mcp also installs jidoseal (the scan engine and CLI, pinned to the tested version) and puts a jidoseal-mcp command on your PATH. No account and no API key. The scan itself needs no network — it runs the same offline.
Every tool below launches the same local command, jidoseal-mcp, over stdio. Only the place you write it down differs.
claude mcp add jidoseal -- jidoseal-mcp
or commit a project-scoped .mcp.json:
{ "mcpServers": { "jidoseal": { "command": "jidoseal-mcp" } } }
Settings → Developer → Edit Config opens claude_desktop_config.json. Add:
{ "mcpServers": { "jidoseal": { "command": "jidoseal-mcp", "args": [] } } }
Restart Claude Desktop afterwards.
~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{ "mcpServers": { "jidoseal": { "type": "stdio", "command": "jidoseal-mcp", "args": [] } } }
Copilot Chat uses MCP tools in Agent mode. In VS Code, add .vscode/mcp.json to the project (or run MCP: Open User Configuration for every project):
{ "servers": { "jidoseal": { "type": "stdio", "command": "jidoseal-mcp" } } }
Copilot in Visual Studio, JetBrains IDEs, Eclipse and Xcode takes the same servers entry in its own MCP settings. On a Copilot Business or Enterprise seat, your organization must have the "MCP servers in Copilot" policy turned on; it is off by default.
codex mcp add jidoseal -- jidoseal-mcp
or in ~/.codex/config.toml:
[mcp_servers.jidoseal]
command = "jidoseal-mcp"
gemini mcp add -s user jidoseal jidoseal-mcp
or in ~/.gemini/settings.json (or .gemini/settings.json in a project):
{ "mcpServers": { "jidoseal": { "command": "jidoseal-mcp" } } }
In Zed's settings.json (or Settings → AI → MCP Servers → Add Local Server):
{ "context_servers": { "jidoseal": { "command": "jidoseal-mcp", "args": [], "env": {} } } }
MCP Servers → Configure → Configure MCP Servers, then add:
{ "mcpServers": { "jidoseal": { "type": "stdio", "command": "jidoseal-mcp", "args": [], "disabled": false } } }
.continue/mcpServers/jidoseal.yaml in your workspace (MCP tools run in Continue's agent mode):
name: JidoSeal
version: 0.0.1
schema: v1
mcpServers:
- name: jidoseal
type: stdio
command: jidoseal-mcp
Settings → Tools → AI Assistant → Model Context Protocol (MCP) → Add → STDIO, and paste:
{ "mcpServers": { "jidoseal": { "command": "jidoseal-mcp", "args": [] } } }
Any MCP client that can launch a stdio server and sits in front of a local model takes the same two facts — a name and a command:
{ "mcpServers": { "jidoseal": { "command": "jidoseal-mcp", "args": [], "env": {} } } }
pipx install jidoseal && jidoseal --root ~/notes
Same scan, same verdict, from a terminal. See the jidoseal CLI on PyPI.
If your host uses a different Python than the one you installed into, point it at the module: "command": "/path/to/python", "args": ["-m", "jidoseal_mcp"].
Check the wiring by hand, without any host:
printf '%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"x","version":"0"}}}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list"}' \
| jidoseal-mcp
You should see an initialize result naming jidoseal, then the three tools.
The CLI writes .jidoseal/manifest.json; a few lines turn it into a gate. See docs/ci.md for a GitHub Actions workflow that fails the build when any file falls below Silver.
A scan: JidoSeal's claim is that it sends nothing: not the files, not their names, not their contents. The engine that does the scan is proprietary, and nobody independent has audited this claim. It is built to be checkable: jidoseal_mcp.py, scan_result.py and offer.py import no socket, no urllib, no HTTP client, and neither does anything they pull in, including the ten engine modules the pinned jidoseal wheel contains. checkout_client.py is the one module that can reach the network, and it is imported only inside the checkout handler.
A purchase, only if you choose one and the call carries confirm: true: the company, name and email you typed, the tier, a 0–100 score, the corpus's Merkle root, the local scan's id, and which Bronze price applies, sent to jidoseal.com. jidoseal.com copies them into the Stripe Checkout session it creates: the email as the session's customer email, and all eight as session metadata. That happens when the session is created, before any payment. No file contents, no file names, no per-file hashes, no paths, and no card data through this server (Stripe hosts the payment page). The Merkle root is a one-way digest.
Verify it yourself:
strace -f -o /tmp/trace.txt -e trace=network jidoseal-mcp < your-jsonrpc-input # no network syscalls during a scan
bwrap --unshare-net --dev-bind / / jidoseal-mcp < your-jsonrpc-input # the scan works with no network at all
The scan writes its own records — manifest.json and an appended progress.ndjson — under <folder>/.jidoseal/ and nowhere else. It never modifies your notes.
The test suite checks the same things on every change, against the pinned engine wheel after verifying its sha256 (see .github/workflows/tests.yml):
| File | What it holds |
|---|---|
tests/test_scan_isolation.py | The scan opens and lists nothing outside the folder; folders with symlinks that lead out of it, or to directories, or that redirect .jidoseal/, are refused before the engine runs; and the installed jidoseal CLI (engine 0.1.4) refuses links out on its own, writing nothing. |
tests/test_write_boundary.py | The only files created or changed are the two under <folder>/.jidoseal/; notes are byte-for-byte unchanged. |
tests/test_network_boundary.py | No socket, DNS lookup or child process during a scan — in-process with sockets blocked, and end to end over stdio in a process that exits on any socket event. |
tests/test_checkout_confirmation.py | Checkout makes no request without confirm: true, and with it sends exactly the eight fields above (HTTP mocked). |
tests/test_import_graph.py | Static check of every module on the scan path, the engine's included. |
tests/test_packaging.py | The engine pin, ENGINE-SHA256SUMS, the SBOM and the installed engine files all agree. No tool text or result shows the engine's unqualified no-egress line, and the checkout text names the Stripe step. |
The jidoseal command-line tool refuses such folders too, from engine 0.1.4 (the version pinned here): a symlink to a file or directory outside the folder, or a symlinked .jidoseal/, stops the run before anything is read or written, and the command exits with status 2. It does not follow a symlinked directory inside the folder either, so each file is read once. This server is a little stricter: it refuses a symlinked directory even when it stays inside. The CLI's own no-network line is worded as JidoSeal's claim, like this server's. Engine 0.1.3 and earlier followed symlinks and printed an unqualified line, so use 0.1.4 or later.
Scanning is free and unlimited, and so are the fixes. If you want a dated certificate for the grade your folder reached, bound to the Merkle root of your corpus, with a public verification page and a listing in the public registry, that is a paid step on jidoseal.com; current prices are published there, one flat price per grade however many files. A person at JidoSeal signs it off from the grade, the score and that fingerprint only, never from your file contents.
jidoseal-mcp · jidosealcom.jidoseal/jidoseal-mcpThis repository holds the source of the jidoseal-mcp package: an MCP server implemented on the Python standard library alone (no MCP SDK), speaking JSON-RPC 2.0 over stdio. It depends on the separately published jidoseal package for the scan engine, which is not part of this repository and is pinned to one tested version. Run the tests with pip install -e ".[test]" && pytest. Issues are welcome; please include the jidoseal-mcp and jidoseal versions and the smallest folder that reproduces a problem.
Apache-2.0 for the code in this repository — see LICENSE. The jidoseal engine it depends on is distributed separately under its own terms.
FAQs
Local check of a folder of markdown against OKF v0.2 frontmatter tiers — an MCP server for Claude, Cursor, GitHub Copilot, Codex, Gemini CLI, Zed and local models. The scan sends nothing (vendor claim, see README).
We found that jidoseal-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.