
GRAFOMEM CGR Capture
com.grafomemv0.1.0更新於 Sep 29, 2026
Record agent judgments and their real outcomes on GRAFOMEM Cloud. Capture now, score later.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 GRAFOMEM CGR Capture,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
grafomem-cgr
An MCP server that lets a coding agent record its own judgments and how they turned out, against your GRAFOMEM Cloud tenant.
The model is capture now, score later. Every time your agent makes a call it could be
wrong about — "this deploy is safe", "this scan is clean", "this review finding is real" —
it records the judgment. Later, when reality settles, it records the outcome. The two are
joined by a work_item_id you choose. What accumulates is an append-only, attributable
record of judgments and their results.
This package is the capture half only. It writes to your tenant; it does not compute, serve, or display scores.
cgr.cosign.v1 verifier (optional extra)
Beside the capture client, this package also ships a reference verifier for the
cgr.cosign.v1 two-party co-signature envelope — grafomem_cgr.cosign_verify.verify(record, registry, ledger, trusted_issuers), implementing docs/cgr/cgr-cosign-v1-spec.md §8 (amended
by decisions 0010 and 0011). trusted_issuers is required (§8.2a issuer pinning): a
collection of issuer key ids with no default and no trust-everything path — omitting it or
passing an empty set rejects, rather than trusting the record's self-declared issuer. It is the
second, independent reference implementation (the first is @gns-foundation/cgr-verify,
JS); both pass the same 28-vector conformance corpus at conformance/cgr-cosign-v1/ with zero
verdict disagreements. Install its deps with the extra:
Capture does not depend on it; the extra is verifier-only.
What it is not
- It does not score anything at capture time, and it does not read scores back into your session.
- It does not make your agent safer or gate anything. Nothing is blocked, approved, or prevented.
- It is not a compliance, audit, or security product.
- Scoring on GRAFOMEM Cloud is single-dimension today: all judgment/certify decisions
score under one dimension regardless of
domain. Thedomainyou pass is stored durably per decision (see below), so it can be attributed later — but it is not scored separately yet.
Requirements
A GRAFOMEM Cloud account. The free tier is sufficient — expected volume is a handful of decisions per day. Note that governed decisions meter as real usage on your plan; the server prints your current usage on startup so this is never a surprise.
Install & configure
One command, plus environment variables — no repo checkout, no launcher script.
Claude Code:
Or any MCP client that reads a JSON config:
Environment
Role keys
A role handle (cc-builder@acme) is the identity a judgment is attributed to. Its
agent_key is a stable Ed25519 public key, 64 hex characters — the subject the record
binds to. Generate one per role:
Keep the private half. This version does not use it — it binds to the public key only — but per-decision proof-of-possession is planned hardening, and holding the private key is what will let you prove the identity is yours.
Tools
cgr_record_decision — record a judgment.
agent_confidence is accepted by the tool schema for forward compatibility but is not
currently written to the decision record. Don't rely on it being stored.
Only judgment + certify moves a score. A rule decision is deterministic and carries
no reputational weight — tag honestly.
cgr_record_outcome — record how it turned out.
An unrecognised result is a deliberate no-op. The decision stays pending rather than
being resolved on a guess — falsely resolving a decision corrupts the record permanently.
Mapped labels are: deploy_succeeded, deploy_healthy, ci_passed, migration_applied,
merge_landed, pr_merged, scan_clean, no_vuln_confirmed, review_confirmed,
finding_correct, bug_confirmed (success); deploy_failed, deploy_rolled_back,
migration_failed, ci_failed, merge_reverted, vuln_found, secret_found,
review_refuted, finding_wrong, bug_not_real (failure).
Safety properties
- Tenant pinning. You declare the tenant up front. The pin is enforced at startup and re-checked against the tenant the API actually resolved on every decision response — so a rotated or mistaken key cannot quietly write somewhere else.
- Denylist.
GRAFOMEM_CGR_FORBIDDEN_TENANTSrefuses named tenants outright. - Key custody. The caller picks a role handle; the server injects that role's key. A tool call can never supply an arbitrary key or target another tenant.
- Fail-open. If the server is misconfigured it exits non-zero and simply doesn't load. Your session continues unblocked, with no tools registered. A refused tool call returns an error as normal tool output rather than crashing the MCP server.
- Domain durability.
domainis sent as a dedicated field and stored server-side, per decision, in the never-encrypted CGR-readable decisionparametersascgr_domain— in the signed decision record, not in a client-side log.selftestincludes a durability guard that re-reads the decision it just wrote and aborts loudly ifcgr_domaindid not round-trip, rather than silently recording a domainless decision.
CLI
selftest closes the loop once — decision → durability guard → outcome → score read — and
prints the movement and the meter. Run it before wiring the server into a session.
Links
MIT licensed.
來源:packages/grafomem-cgr/README.md,提交 7c667c8
工具
0版本歷史
1- v0.1.0最新Sep 16, 2026


