Перейти к содержимому

MCP Server Supply Chain: Bundle, Sign, Attest, Verify, Tamper

Gorkem Ercan

0:00 / 0:00

MCP Server Supply Chain: Bundle, Sign, Attest, Verify, Tamper

15 просмотров · 9 дней назад
Gorkem Ercan
28 подписчиков
15 просмотров · 9 дней назад
An MCP server is arbitrary code with access to your credentials, your data and your local machine. This is one full run of packaging one so that it can be verified before an agent ever loads it. No narration. The terminal is the whole demo: about three minutes, unedited, running offline against a local registry. What happens, in order: mcpb init and mcpb pack build a real MCPB bundle from the upstream "everything" MCP server: 2,560 files, the server plus every production dependency. mcpb info reports "Not signed". npm sbom emits a CycloneDX bill of materials, 106 components with purls. That is npm doing it, not a script. SLSA v1 provenance is written for the build that just ran: source commit, manifest digest, tool versions. Only fields the build actually observed. kit init generates the Kitfile. It recognises the .mcpb and writes the mcpServers section itself. kit pack and kit push put it in a registry as a single layer. The sha256 of the local .mcpb and the OCI layer digest are printed next to each other. They are identical. The bundle is not transformed or re-wrapped. It gains an address and somewhere to hang claims about it, nothing more. cosign sign, then cosign attest twice, for the provenance and the SBOM. cosign tree shows all three hanging off one immutable digest as OCI referrers. None of them modified the artifact.