Decionis execution authority, local MCP evaluator
217
A stdio Model Context Protocol server that
lets AI coding agents (Claude Code, Cursor, Codex, OpenHands, …) read a
repository's DECIONIS_POLICY.md and evaluate candidate actions before
they commit, deploy, or migrate anything.
This image wraps the published npm package
@decionis/mcp at an exact
pinned version — packaging only, no fork. The evaluator boots the real
Decionis protocol service in-process: the verdict an agent sees locally is the
verdict the platform would produce — with zero network, zero database, zero
credentials, and nothing recorded.
Mount your policy read-only; the evaluator needs no network and writes no state:
docker run -i --rm \
--network none --read-only \
-v "$PWD/DECIONIS_POLICY.md:/work/DECIONIS_POLICY.md:ro" \
decionis/mcp
Claude Code (.mcp.json at the repo root), Cursor, and other stdio MCP
clients use the same shape — replace the absolute path with your repo's:
{
"mcpServers": {
"decionis": {
"command": "docker",
"args": [
"run", "-i", "--rm", "--network", "none", "--read-only",
"-v", "/absolute/path/to/your/repo/DECIONIS_POLICY.md:/work/DECIONIS_POLICY.md:ro",
"decionis/mcp"
]
}
}
}
| Tool | Purpose |
|---|---|
decionis_read_policy | Path, sha256, and compiled rules (or compile errors) of the repo's DECIONIS_POLICY.md. |
decionis_evaluate | Evaluate a candidate action payload against the policy through the real evaluator; returns the verdict + matched rule. |
decionis_verdict_help | The verdict vocabulary, rules-block grammar, and how an agent should behave on each verdict. |
From the server's own decionis_verdict_help:
Verdicts (a rule's
action):allow(execute),block(never execute),restrain(hold for human review),escalate(require an authorized approver). The protocol reports outcomes as APPROVE / REJECT / REVIEW / ESCALATE; this server also returns the normalized verdict (allow / block / review / escalate). When no rule matches, the platform holds the decision for review (outcome REVIEW).
Agent behavior on each verdict: allow → proceed; block → do not proceed; review/escalate → stop and involve a human.
| Variable | Required | Secret | Purpose |
|---|---|---|---|
DECIONIS_POLICY_PATH | no | no | Policy file path. The image presets /work/DECIONIS_POLICY.md — mount your policy there. |
No credentials are required.
@decionis/mcp at an exact, lockfile-pinned version; the image
version tracks the wrapped package version.Content type
Image
Digest
sha256:494710a80…
Size
57.7 MB
Last updated
about 1 month ago
docker pull decionis/mcp