Skip to content
MCP ThesaurusMCP Thesaurus

glassbox framework

CommunityIncomplete39/100Claim

npm @glassbox-framework/mcpstdioApache-2.0updated 19d ago

Runtime constitutional verification for AI answers. Every claim carries a reasoning chain. Every score breaks down. Every verdict is traceable.

SourceWebsite11

What can you do with glassbox framework?

Glass Box Framework

Runtime constitutional verification for AI answers. Every claim carries a reasoning chain. Every score breaks down. Every verdict is traceable.

CI PyPI version npm version Homebrew MCP Registry PyPI downloads License GitHub stars

โญ๏ธ Star this repo if you want runtime AI verification to become the default. Every star moves Glassbox up the search ranking on GitHub, the MCP Registry, and Smithery โ€” which means more developers find this before they ship an AI feature without a Trust Card.

pip install glassbox-framework         # Python
npm install -g @glassbox-framework/mcp # Node / MCP
brew install thebarmaeffect/glassbox/glassbox-mcp   # macOS

Zero-cost public GlassBox Lite

The repository also ships a separate deterministic Lite verifier and cross-platform gateway that require no paid model API:

Lite performs bounded structural checks and does not browse or establish factual truth. The original six-tool model-assisted MCP documented below remains a separate surface.

See PLATFORMS.md for the exact live, downloadable, pilot, and external-review status of every integration.

What it is

The Glass Box Framework hands an (question, answer) pair to a runtime verification pipeline and returns a structured Trust Card containing:

  • Claims โ€” every atomic assertion in the answer, paired with a reasoning chain explaining why it's asserted, what would support it, and what would falsify it.
  • Epistemic Confidence Score (ECS) โ€” a transparent, weighted aggregate over five dimensions with a published formula and an always-visible per-dimension breakdown.
  • Glassbox Court โ€” seven adversarial probes (fabrication, source manipulation, bias injection, context attack, overconfidence, underspecification, constitutional violation).
  • Constitution โ€” your natural-language deployer intents compiled into structured runtime rules and evaluated against the answer.
  • Verdict โ€” trust / caution / reject, with the exact reasoning that derived it.
  • Audit reference โ€” a deterministic SHA-256 log_id; identical inputs reproduce the same identifier across runs and languages.

It is intentionally not a wrapper around a single LLM call โ€” the reasoning chain on every claim, the formula on the ECS, and the determinism of the audit hash together form the "Glass Box" principle: no opaque scores.

Quick start (Python)

from glassbox_framework import Glassbox

with Glassbox() as gb:
    card = gb.verify_answer(
        question="Can intermittent fasting cure type 2 diabetes?",
        answer="Yes ...",
        intents=[
            "Never make specific medical claims without citing peer-reviewed sources.",
            "Always recommend consultation with a licensed healthcare professional.",
        ],
    )

print(card["verdict"])              # "reject"
print(card["ecs"]["total"])         # 0.6032
print(card["audit"]["log_id"])      # glassbox-85cc09903bd4...  (deterministic)

The six tools

Tool Purpose
glassbox_verify_answer Full pipeline โ†’ Trust Card
glassbox_extract_claims Atomic claims with reasoning chains
glassbox_score_ecs ECS with full breakdown + formula
glassbox_red_team Glassbox Court โ€” 7 adversarial probes
glassbox_generate_trust_card Assemble a Trust Card from prebuilt parts (no LLM call)
glassbox_export_audit_report Full pipeline + deterministic SHA-256 audit log

Full schemas, examples, and configuration: mcp/README.md. Python pip-specific docs: mcp/python/README.md.

Architecture (two-layer)

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ glassbox-framework (PyPI)         Python client          โ”‚
โ”‚   thin JSON-RPC stdio wrapper                            โ”‚
โ”‚   spawns โ†“                                               โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ @glassbox-framework/mcp (npm)     Node MCP server        โ”‚
โ”‚   6 tools, Zod-validated I/O                             โ”‚
โ”‚   โ†ณ verify_answer  โ†ณ extract_claims  โ†ณ score_ecs         โ”‚
โ”‚   โ†ณ red_team       โ†ณ generate_trust_card                 โ”‚
โ”‚   โ†ณ export_audit_report                                  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Python client makes zero LLM calls itself; it forwards arguments to the MCP server over stdio and renders the returned JSON. Set ANTHROPIC_API_KEY once and both layers use it.

Use with Claude Desktop

{
  "mcpServers": {
    "glass-box": {
      "command": "npx",
      "args": ["-y", "@glassbox-framework/mcp"],
      "env": { "ANTHROPIC_API_KEY": "sk-ant-..." }
    }
  }
}

~/Library/Application Support/Claude/claude_desktop_config.json on macOS.

Determinism

Audit log_ids are SHA-256 over canonicalised JSON of (inputs_hash, claims, ECS dimensions, red-team probe verdicts, constitution evaluations). Timestamps are recorded but never enter the hash, so identical inputs and identical engine outputs always produce the same log_id โ€” across runs, machines, and even languages (the Python client โ†’ Node server โ†’ JSON canonicalisation produces byte-identical hashes).

Verifiable example, no API key needed:

pip install glassbox-framework
python -c "
import json
from glassbox_framework import Glassbox
with open('mcp/demo/raw-inputs.json') as f: i = json.load(f)
with Glassbox() as gb:
    c = gb.generate_trust_card(
        question=i['question'], answer=i['answer'],
        claims=i['claims'], red_team=i['red_team'], ecs=i['ecs'],
        constitution=i['constitution'])
print(c['audit']['log_id'])   # glassbox-85cc09903bd4b3f8022a4087
"

Project layout

mcp/                       โ€” the MCP server + Python client (this release)
  โ”œโ”€โ”€ src/                 โ€” TypeScript MCP server (6 tools)
  โ”œโ”€โ”€ python/              โ€” Python pip package (glassbox-framework)
  โ”œโ”€โ”€ homebrew/            โ€” Homebrew formula
  โ”œโ”€โ”€ assets/              โ€” Launch video + reveal + title cards
  โ”œโ”€โ”€ demo/                โ€” Live terminal demo with prebuilt Trust Card
  โ”œโ”€โ”€ Dockerfile           โ€” Container image
  โ”œโ”€โ”€ server.json          โ€” MCP Registry manifest
  โ”œโ”€โ”€ smithery.yaml        โ€” Smithery.ai manifest
  โ”œโ”€โ”€ LAUNCH.md            โ€” Launch kit
  โ””โ”€โ”€ DISTRIBUTION.md      โ€” Every channel's status + commands
LICENSE                    โ€” Apache 2.0
ROADMAP.md                 โ€” Phase 5 (governor) plans for the broader framework
CONTRIBUTING.md
CHANGELOG.md

Contributing

Glassbox is open source under Apache 2.0 and actively wants forks and PRs. A few specific places we'd love help:

  • More red-team probes โ€” mcp/src/engines/redteam.ts has // v2: placeholders for alignment_faking, reasoning_trace_deception, eval_awareness_gaming, agentic_misalignment, and sustained_jailbreak. Each is a tractable PR โ€” same shape as the existing 7 probes, just a different angle. See .github/ISSUE_TEMPLATE/good_first_issue.md.
  • More language clients โ€” currently Python (glassbox-framework) and Node (@glassbox-framework/mcp). Go, Rust, Ruby, Swift, Kotlin would all be welcome as thin JSON-RPC clients that spawn the existing MCP server.
  • More integrations โ€” Cursor / Cline / Continue / Roo Cline / Zed / Neovim โ€” wherever MCP is read, Glassbox should be one paste away.
  • Real-world Trust Card examples โ€” submit (Q, A) pairs from your own AI workflows so the test suite covers more terrain.

Process:

  1. Pick a good first issue or open one with your idea
  2. Fork, branch, work โ€” the PR template walks you through verification
  3. CI must pass (.github/workflows/ci.yml) โ€” TS strict mode, Python wheel build, cross-language determinism on the canonical audit hash
  4. Open the PR; we aim for review within 48 hours

Code of conduct: Contributor Covenant 2.1. Be kind, stay on substance, no harassment, contact thebarmaeffect@gmail.com for anything off-public-channel.

Star โญ this repo

The fastest way to help right now is to star the repo. Every star:

  • Surfaces Glassbox higher in GitHub's MCP topic listings
  • Pushes the project up on the MCP Registry and Smithery rankings
  • Tells the next developer evaluating AI-safety tooling that this is the one with eyes on it

โญ Star Glassbox

Author

Karthik Barma ยท MS Artificial Intelligence ยท Northeastern University.

Powered by Aura.

Issues + PRs: https://github.com/TheBarmaEffect/glassbox/issues