{"$schema":"https://json.schemastore.org/mcp.json","name":"safety-herbarium","version":"1.0.0","description":"A mounted reading catalogue for AI-safety and alignment literature. Read volumes, mount papers and open-access textbooks, run a deterministic coverage engine over ten AI-safety risk classes, and replay a SHA-384 audit chain.","repository":{"url":"https://github.com/aniruddhaadak80/safety-herbarium","source":"github"},"mcpServers":{"safetyHerbarium":{"type":"http","url":"https://safety-herbarium.vercel.app/api/mcp","headers":{"x-herbarium-scope":"replace-with-your-own-random-token"}}},"tools":[{"name":"list_volumes","effect":"read","description":"List the reading volumes owned by the calling session, newest first. Read-only.","inputSchema":{"type":"object","properties":{"includeRetired":{"type":"boolean","description":"Include volumes that were retired (tombstoned) instead of deleted."}},"additionalProperties":false}},{"name":"get_volume","effect":"read","description":"Read one volume with its mounted sheets, the audit chain head and its event count. Read-only.","inputSchema":{"type":"object","properties":{"volumeId":{"type":"string","description":"The volume uuid.","maxLength":64}},"required":["volumeId"],"additionalProperties":false}},{"name":"coverage_report","effect":"analysis","description":"Run the herbarium-grade/1.0.0 coverage engine over a volume: the score, itemised per-class factors, open gaps and a next-read recommendation. Analysis only; writes nothing.","inputSchema":{"type":"object","properties":{"volumeId":{"type":"string","description":"The volume uuid.","maxLength":64},"includeCandidates":{"type":"boolean","description":"Query the live arXiv index for next-read candidates."}},"required":["volumeId"],"additionalProperties":false}},{"name":"mount_sheet","effect":"mutating","description":"Mount an arXiv paper or an open-access bookshelf book into a volume. The server resolves the record from its source, so metadata cannot be spoofed. Idempotent per (volume, source).","inputSchema":{"type":"object","properties":{"volumeId":{"type":"string","description":"The volume uuid.","maxLength":64},"sourceKind":{"type":"string","enum":["arxiv","book"],"description":"Which catalogue."},"sourceId":{"type":"string","description":"An arXiv id such as 2411.01042, or a bookshelf key.","maxLength":64},"mountedClass":{"type":"string","enum":["deceptive_alignment","reward_misspecification","scalable_oversight","interpretability","value_uncertainty","corrigibility","power_seeking","robustness_fragility","evaluation_rigor","governance_assurance"],"description":"Which risk class this sheet is mounted on. Defaults to the strongest match."}},"required":["volumeId","sourceKind","sourceId"],"additionalProperties":false}},{"name":"record_decision","effect":"mutating","description":"Record a reading decision (admitted, deferred, rejected) with an optional note, and optionally set the reading status. Seals a new chain event.","inputSchema":{"type":"object","properties":{"sheetId":{"type":"string","description":"The sheet uuid.","maxLength":64},"decision":{"type":"string","enum":["admitted","deferred","rejected"]},"status":{"type":"string","enum":["queued","reading","read","parked","rejected"]},"note":{"type":"string","description":"Why. Recorded in the audit chain.","maxLength":1000}},"required":["sheetId","decision"],"additionalProperties":false}},{"name":"annotate_sheet","effect":"mutating","description":"Write marginalia onto a mounted sheet. The text is stored, never rendered as HTML.","inputSchema":{"type":"object","properties":{"sheetId":{"type":"string","description":"The sheet uuid.","maxLength":64},"marginalia":{"type":"string","description":"Your note on the paper.","maxLength":4000}},"required":["sheetId","marginalia"],"additionalProperties":false}},{"name":"remove_sheet","effect":"mutating","description":"Remove a mounted sheet. This writes a tombstone so the audit chain stays replayable; the volume keeps its seal.","inputSchema":{"type":"object","properties":{"sheetId":{"type":"string","description":"The sheet uuid.","maxLength":64}},"required":["sheetId"],"additionalProperties":false}},{"name":"verify_chain","effect":"analysis","description":"Replay a volume's audit chain and report the first broken link. Analysis only; writes nothing.","inputSchema":{"type":"object","properties":{"volumeId":{"type":"string","description":"The volume uuid.","maxLength":64}},"required":["volumeId"],"additionalProperties":false}}],"authentication":{"type":"session-header","header":"x-herbarium-scope","notes":"Every call is scoped to an anonymous session token. There are no accounts. Generate your own random token and send it in x-herbarium-scope; it will see only the volumes it creates. A browser session uses the hb_scope HTTP-only cookie instead."}}