SWT3 AI Witness
Cryptographic AI governance + audit. 33 tools, 36 frameworks. EU AI Act, NIST, OWASP, CMMC, SR 11-7
The record the registry holds
There is no address to call. This one is a package you install and run yourself, wherever your assistant runs.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.tenova/swt3-witness",
"description": "Cryptographic AI governance + audit. 33 tools, 36 frameworks. EU AI Act, NIST, OWASP, CMMC, SR 11-7",
"title": "SWT3 AI Witness",
"repository": {
"url": "https://github.com/tenova-labs/swt3-ai",
"source": "github"
},
"version": "0.6.4",
"websiteUrl": "https://tenova.io",
"packages": [
{
"registryType": "npm",
"identifier": "@tenova/swt3-mcp",
"version": "0.6.4",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "SWT3 API key (starts with axm_). Omit for zero-config demo mode.",
"format": "string",
"isSecret": true,
"name": "SWT3_API_KEY"
},
{
"description": "Your tenant identifier",
"format": "string",
"name": "SWT3_TENANT_ID"
},
{
"description": "Path to swt3.yaml config file for policy-as-code",
"format": "string",
"name": "SWT3_CONFIG_FILE"
},
{
"description": "Data clearing level: 0=analytics, 1=standard, 2=sensitive, 3=classified",
"format": "string",
"name": "SWT3_CLEARING_LEVEL"
},
{
"description": "Agent identity for AI-ID.1 witnessing",
"format": "string",
"name": "SWT3_AGENT_ID"
},
{
"description": "HMAC-SHA256 signing key for non-repudiation",
"format": "string",
"isSecret": true,
"name": "SWT3_SIGNING_KEY"
}
]
}
],
"_meta": {
"io.modelcontextprotocol.registry/publisher-provided": {
"categories": [
"audit",
"governance",
"compliance",
"observability"
],
"frameworks": [
"EU AI Act",
"NIST AI RMF",
"OWASP Agentic Top 10",
"CMMC",
"NIST 800-53",
"NIST 800-171",
"SR 11-7",
"ISO 42001",
"FedRAMP",
"NIS 2 Directive",
"CA SB 942"
],
"keywords": [
"eu-ai-act",
"nist-ai-rmf",
"owasp-agentic-top10",
"cmmc",
"nist-800-53",
"sr-11-7",
"iso-42001",
"gdpr",
"ai-governance",
"ai-compliance",
"ai-audit",
"ai-safety",
"ai-accountability",
"cryptographic-attestation",
"audit-trail",
"non-repudiation",
"trust-mesh",
"policy-as-code",
"tool-policy-gate",
"inference-witnessing",
"agent-accountability",
"clearing-levels"
]
}
}
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-08-11T11:44:55.823381Z",
"publishedAt": "2026-08-11T11:44:55.823381Z",
"updatedAt": "2026-08-11T11:44:55.823381Z",
"isLatest": true
}
}
}
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
MCP server
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.
Somebody else's record
This listing was indexed rather than published here, so nobody has signed anything and this catalog cannot sign on their behalf. Treat it as a pointer to the publisher, not as terms.
The publisher's own address
The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.