Webcrypt MCP
putervision/state-memory-mcp
Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.
$ npx skills add wshobson/agents --skill protect-mcp-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents protect-mcp-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .claude/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .claude/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill protect-mcp-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents protect-mcp-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .agents/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .agents/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill protect-mcp-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents protect-mcp-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .cursor/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .cursor/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/protect-mcp/skills/protect-mcp-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill protect-mcp-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents protect-mcp-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .gemini/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .gemini/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents protect-mcp-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill protect-mcp-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .github/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .github/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill protect-mcp-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents protect-mcp-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .opencode/skills/protect-mcp-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "protect-mcp-setup" agent skill from https://github.com/wshobson/agents/tree/main/plugins/protect-mcp/skills/protect-mcp-setup into .opencode/skills/protect-mcp-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protect-mcp-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
protect-mcp-setupConfigure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.
Protect MCP Setup is an agent skill from wshobson/agents. Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool execution, or compliance-ready evidence of agent actions.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/receipt-format.md`).
It sits in Agent Workflows, covering Cryptography and MCP servers. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxclaudenodeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
npmjs.comdatatracker.ietf.orggithub.comveritasacta.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PROTECT_MCP_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Protect MCP Setup loads about 2.1k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 579 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 579 words, ~2,107 tokens.
.claude/skills/protect-mcp-setup/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Cryptographic governance for every Claude Code tool call. Each invocation is evaluated against a Cedar policy and produces an Ed25519-signed receipt that anyone can verify offline.
Claude Code runs powerful tools: Bash, Edit, Write, WebFetch. By default
there is no audit trail, no policy enforcement, and no way to prove what was
decided after the fact. protect-mcp closes all three gaps:
npx @veritasacta/verify. No server, no account,
no trust in the operator.AI agents make decisions that affect money, safety, and rights. The Claude Code session log records what happened, but the log is:
For compliance contexts (finance, healthcare, regulated research), this is not sufficient. You need tamper-evident evidence that can be verified by third parties without trusting you.
Add protect-mcp to your Claude Code project:
# 1. Install the plugin (adds hooks + skill to your project)
claude plugin install wshobson/agents/protect-mcp
# 2. Create ./protect.cedar (see below). The plugin installs the hooks.
# 3. Create the signing key once (protect-mcp 0.7.4 sign does not create it).
# An existing key is never replaced. See references/receipt-format.md to rotate.
if [ ! -e ./protect-mcp.key ]; then
d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./protect-mcp.key
fi
echo "/protect-mcp.key" >> .gitignore
# 4. Use Claude Code normally. Every tool call is now policy-evaluated
# and produces a signed receipt in ./receipts/Installing the plugin adds both hooks from hooks/hooks.json. Each hook runs a
script bundled with the plugin:
{
"hooks": {
"PreToolUse": [
{
"matcher": ".*",
"hooks": [
{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }
]
}
],
"PostToolUse": [
{
"matcher": ".*",
"hooks": [
{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/sign.sh" }
]
}
]
}
}Claude Code passes the hook event to the command as JSON on stdin and does not
set TOOL_NAME or TOOL_INPUT variables. evaluate.sh reads tool_name and
tool_input from that payload and passes them to protect-mcp as flags; sign.sh reads
tool_name only, because the 0.7.4 signer records nothing else. Set
PROTECT_MCP_POLICY, PROTECT_MCP_RECEIPTS, and PROTECT_MCP_KEY to change the
default paths. When the policy file is missing, the PreToolUse hook prints a
warning to stderr and allows the call.
PreToolUse — Runs BEFORE the tool executes. Evaluates the tool call against
your Cedar policy file. If Cedar returns deny, the hook exits with code 2 and
Claude Code blocks the tool call entirely.
PostToolUse runs AFTER the tool completes. It signs a receipt that names
the tool and appends it to ./receipts/receipts.jsonl. protect-mcp 0.7.4 does
not record the tool input or output.
Create ./protect.cedar at the project root:
// Read-only tools: one rule can name several tools in `when`. Add WebFetch
// with your own URL rule.
permit (principal, action == Action::"MCP::Tool::call", resource) when {
resource == Tool::"Read" || resource == Tool::"Glob" || resource == Tool::"Grep"
};
// Safe commands only; git limited to read subcommands
permit (principal, action == Action::"MCP::Tool::call", resource == Tool::"Bash") when {
context has input && context.input has command &&
(context.input.command like "git status*" || context.input.command like "git diff*" ||
context.input.command like "git log*" || context.input.command like "git show*" ||
context.input.command like "npm*" || context.input.command like "ls*" ||
context.input.command like "cat*" || context.input.command like "echo*" ||
context.input.command like "pwd*" || context.input.command like "test*")
};
// No chaining (`&` also denies `2>&1`), `$` expansion, redirection (`>` or
// `<`, which covers `<(`), file output (`git diff --output`), or rm -rf
forbid (principal, action == Action::"MCP::Tool::call", resource == Tool::"Bash") when {
context has input && context.input has command &&
(context.input.command like "*;*" || context.input.command like "*&*" ||
context.input.command like "*|*" || context.input.command like "*$*" ||
context.input.command like "*`*" || context.input.command like "*>*" ||
context.input.command like "*<*" || context.input.command like "*\n*" ||
context.input.command like "*--output*" || context.input.command like "*rm -rf*")
};
// Writes only inside the project (paths are absolute), never via `..`
permit (principal, action == Action::"MCP::Tool::call", resource) when {
(resource == Tool::"Write" || resource == Tool::"Edit") &&
context has input && context.input has file_path &&
context.input.file_path like "/path/to/project/*"
};
forbid (principal, action == Action::"MCP::Tool::call", resource) when {
(resource == Tool::"Write" || resource == Tool::"Edit") &&
context has input && context.input has file_path &&
(context.input.file_path like "*/../*" || context.input.file_path like "*/..")
};String matching is best-effort: like checks the raw string, not a
resolved path, and an npm* permit runs arbitrary code, so it is only as
safe as the project's scripts.
Verify every receipt against the public key in ./protect-mcp.key:
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./protect-mcp.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"
# Exit 0 = every receipt verified
# Exit 1 = a receipt failed (tampered, wrong key, or malformed line)
# Exit 2 = the file could not be readThe plugin's slash commands do the same inside Claude Code. /verify-receipt
takes one receipt in its own file, e.g., from
tail -n 1 ./receipts/receipts.jsonl > receipt.json.
/verify-receipt receipt.json
/audit-chain --last 20Each receipt is one line of ./receipts/receipts.jsonl. See
references/receipt-format.md for a sample.
signature--key| Before | After |
|---|---|
| "Trust me, the agent only read files" | Cryptographically provable: every Read logged and signed |
| "The log shows it happened" | The receipt proves it happened, and no one can edit it |
| "You'd have to audit our system" | Anyone can verify every receipt offline |
| "Logs might be different by now" | Ed25519 signatures lock the record at signing time |
© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/protect-mcp/skills/protect-mcp-setup of wshobson/agents.
Open the folder on GitHubat commit 46891e7
Protect MCP Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Protect MCP Setup this skillwshobson/agents | 40k | — | ~2.1k | Automated safety check: Pass | MIT | |
| Webcrypt MCPputervision/state-memory-mcp | 50 | — | ~847 | Automated safety check: Pass | MIT | |
| X Use Setupihuzaifashoukat/x-use | 171 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bind MCPLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Agentic Tool Integrationsamugit83/redamon | 3k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Sap Dependency Securitysecondsky/sap-skills | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 |
putervision/state-memory-mcp
Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.
ihuzaifashoukat/x-use
Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona).
LeoYeAI/openclaw-master-skills
Bind Protocol MCP server for credential verification, policy authoring, and zero-knowledge proof generation.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
secondsky/sap-skills
SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.
affaan-m/ECC
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
wshobson/agents
Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.
wshobson/agents
Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.
Works with
Categories
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Protect MCP Setup is an agent skill from wshobson/agents. Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.
Protect MCP Setup fits situations like: setting up projects that need cryptographic audit trails; policy-gated tool execution; compliance-ready evidence of agent actions.
Run `npx skills add wshobson/agents --skill protect-mcp-setup -a claude-code`. Or copy the skill folder (plugins/protect-mcp/skills/protect-mcp-setup in wshobson/agents) into .claude/skills/protect-mcp-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill protect-mcp-setup -a codex`. Or copy the skill folder (plugins/protect-mcp/skills/protect-mcp-setup in wshobson/agents) into .agents/skills/protect-mcp-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill protect-mcp-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protect-mcp-setup, .gemini/skills/protect-mcp-setup, .github/skills/protect-mcp-setup and .opencode/skills/protect-mcp-setup in your project.
Going by SKILL.md and its folder, Protect MCP Setup needs the command-line tools its instructions call (npx, claude and node) and credentials named PROTECT_MCP_KEY. Our summary lists: Node.js; A credential in PROTECT_MCP_KEY.
SKILL.md names 4 domains. As links in the text: npmjs.com, datatracker.ietf.org, github.com and veritasacta.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Protect MCP Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 415 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Protect MCP Setup: Webcrypt MCP (putervision/state-memory-mcp, 50 stars), X Use Setup (ihuzaifashoukat/x-use, 171 stars), Bind MCP (LeoYeAI/openclaw-master-skills, 2.2k stars) and Agentic Tool Integration (samugit83/redamon, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.