diff --git a/CONNECTORS.md b/CONNECTORS.md index 35b6bb589e..a20f03f887 100644 --- a/CONNECTORS.md +++ b/CONNECTORS.md @@ -42,6 +42,7 @@ Connectors shipped in the default `.mcp.json` of each plugin: | **Linear** | product-legal | | **Atlassian (Jira)** | product-legal | | **Asana** | product-legal | +| **LawAI Gov Hub** | ai-governance-legal, regulatory-legal | See the `.mcp.json` in each plugin directory for the authoritative list. diff --git a/ai-governance-legal/.mcp.json b/ai-governance-legal/.mcp.json index 51f3e4e4a2..0a78e5547b 100644 --- a/ai-governance-legal/.mcp.json +++ b/ai-governance-legal/.mcp.json @@ -11,6 +11,12 @@ "url": "https://drivemcp.googleapis.com/mcp/v1", "title": "Google Drive", "description": "Search, read, and fetch documents from Google Drive." + }, + "LawAI Gov Hub": { + "type": "http", + "url": "https://mcp.lawaigovhub.com/mcp/", + "title": "LawAI Gov Hub", + "description": "Official AI regulation index — laws, executive orders, court cases, and regulatory guidance from 240+ jurisdictions, each result linked to its primary legal source with citation-ready identifiers and jurisdiction ISO codes." } }, "recommendedCategories": [ diff --git a/ai-governance-legal/CONNECTOR_HEALTH.md b/ai-governance-legal/CONNECTOR_HEALTH.md new file mode 100644 index 0000000000..418d10aa43 --- /dev/null +++ b/ai-governance-legal/CONNECTOR_HEALTH.md @@ -0,0 +1,105 @@ +# LawAI Gov Hub — Connector Health Check + +This file records the end-to-end health check performed against the LawAI Gov Hub MCP server before this connector entry was added to `.mcp.json`. **Two captures** are documented below: a local capture during development and a **live production capture against `https://mcp.lawaigovhub.com/mcp/`** — the URL the connector resolves to in the plugin's `.mcp.json`. + +To reproduce, clone the [lawaigovhub repo](https://github.com/Brokemountain/http-lawaigovhub.com-) and run `python -m mcp_server` plus `pytest mcp_server/tests/`, or hit the live endpoint with the official MCP Python client. + +## Result + +**PASS** — server identifies as `LawAI Gov Hub` over the streamable-HTTP transport, all five tools answer, primary-source policy enforced (0 aggregator URLs leaked under `official_only=true`), unknown-id errors return the contracted `isError=true` MCP error shape. + +## Production capture + +Captured at **2026-05-15T08:55:25Z** against `https://mcp.lawaigovhub.com/mcp/`. + +### Service identity + +| Field | Value | +| --- | --- | +| Service | `lawai-gov-hub-mcp` | +| Version | `1.0.0` | +| MCP protocol version | `2025-11-25` | +| Server name (from `initialize`) | `LawAI Gov Hub` | +| Transport | Streamable HTTP | +| TLS | Let's Encrypt (auto-renewed by certbot) | + +### `/healthz` response (live) + +```json +{ + "status": "ok", + "service": "lawai-gov-hub-mcp", + "version": "1.0.0", + "transport": "streamable-http", + "endpoint": "/mcp", + "regulations_indexed": 14275, + "jurisdictions_total": 265, + "active_jurisdictions": 240, + "hallucination_cases_indexed": 1275, + "site_stats": { + "total_profiles": 265, + "country_profiles": 252, + "regional_profiles": 13, + "active_profiles": 240, + "total_entries": 14394 + }, + "tools": [ + "search_regulations", + "fetch_regulation", + "list_jurisdictions", + "search_cases", + "fetch_case" + ] +} +``` + +### Probes (live) + +| # | Probe | Result | +| - | --- | --- | +| 1 | `search_regulations(query="EU AI Act", jurisdiction="EU", year_from=2024)` | `total=9`; first hit is the official EUR-Lex corrigendum `https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689R(01)`, `is_primary_source=true` | +| 2 | `fetch_regulation(id="eu:a60727cb8857")` | Round-trips the id; same `source_url` as probe 1; `retrieved_at=2026-05-15T08:53:28+00:00` | +| 3 | `list_jurisdictions(active_only=true)` | `total=240`; top three by entry count: US (4533), GB (957), CN (933) | +| 4 | `search_cases(query="sanction")` | `total=355`; first hit: `Staley v. City of Elba, et al.` | +| 5 | **Aggregator audit** (`search_regulations(limit=100, official_only=true)`) | **0** non-primary URLs in the sample of 100 — primary-source policy enforced | +| 6 | `fetch_regulation(id="NOPE:000000000000")` | `isError=true`, body begins `Error executing tool fetch_regulation: No regulation with id` — contracted MCP error shape, no transport-level exception | + +The aggregator audit is the contract enforcement: with `official_only=true`, every result is on a primary source (government register, court system, intergovernmental body). The blocklist covers `regulations.ai`, `incidentdatabase.ai`, `wp.oecd.ai`, `techieray.com`, `damiencharlotin.com`, and major social/blog hosts; the allowlist covers `.gov`, `.gov.`, `.europa.eu`, `.gob.*`, `.gouv.*`, `.int`, parliament/legislature domains, and similar. + +## Local capture (development) + +Captured at **2026-05-14T14:42:06Z** against `http://127.0.0.1:8767/mcp/` during development. Same five tools, same response shape, same audit result (0 non-primary URLs in 100). The local capture is what the 12-test pytest suite validates on every change. + +## Reproducing this check + +From a clone of the [lawaigovhub repo](https://github.com/Brokemountain/http-lawaigovhub.com-): + +```bash +python -m venv .venv && . .venv/bin/activate +pip install "mcp[cli]>=1.16" httpx pytest uvicorn starlette +python -m pytest mcp_server/tests/ -v # 12 tests, ~4s +``` + +To probe the live endpoint: + +```bash +curl -sS https://mcp.lawaigovhub.com/healthz +curl -sS -X POST https://mcp.lawaigovhub.com/mcp/ \ + -H "Content-Type: application/json" \ + -H "Accept: application/json, text/event-stream" \ + -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' +``` + +## What the connector cannot do + +For transparency: + +- It is **read-only**. There are no write tools, no auth flows, no PII exchange — the dataset is public AI regulation. +- Source coverage matches the public website at `lawaigovhub.com`. When a primary register has not yet been linked for an entry, the entry is still indexed but `is_primary_source` will be `false`; the default `official_only=true` filters those out. +- Citation strings are formatted for legal documents but **do not relieve the lawyer of verifying the cite against the linked primary source**. The plugin already flags this in its citation-tiering language; the connector enforces it by always linking the primary source so verification is one click away. + +## Operational notes + +- The MCP server runs as a `lawai-mcp` systemd unit on the same DigitalOcean droplet as `lawaigovhub.com`, on `127.0.0.1:8765`. nginx terminates TLS for `mcp.lawaigovhub.com` and proxies to the local service. +- TLS certificate auto-renews via certbot's scheduled task (Let's Encrypt cert). +- DNS-rebinding protection is enabled in the MCP transport: only `mcp.lawaigovhub.com` and loopback are accepted as Host headers. diff --git a/ai-governance-legal/README.md b/ai-governance-legal/README.md index 69239c8bac..ad8b70c77d 100644 --- a/ai-governance-legal/README.md +++ b/ai-governance-legal/README.md @@ -125,6 +125,14 @@ ai-governance-legal/ └── matter-workspace/ ``` +## Integrations + +Ships with the general bucket of connectors in `.mcp.json`: + +- **Slack** — search messages, read channels, find discussions +- **Google Drive** — search, read, and fetch documents +- **LawAI Gov Hub** — official AI regulation index across 240+ jurisdictions; every result links to its primary legal source (statute, executive order, court decision, regulatory guidance) with citation-ready identifiers and jurisdiction ISO codes. Powers `reg-gap-analysis` source resolution and supplies primary-source citations for impact assessments. + ## How it learns Your practice profile at `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` isn't static — it improves as you use the plugin. Skills tell you when an output used a default you should tune. The `policy-monitor` agent watches for drift between your AI governance policy and your practice and proposes updates. You can re-run setup, edit the file directly, or tell a skill to record a new position. diff --git a/regulatory-legal/.mcp.json b/regulatory-legal/.mcp.json index 92468b7b56..47e66b9fec 100644 --- a/regulatory-legal/.mcp.json +++ b/regulatory-legal/.mcp.json @@ -11,6 +11,12 @@ "url": "https://drivemcp.googleapis.com/mcp/v1", "title": "Google Drive", "description": "Search, read, and fetch documents from Google Drive." + }, + "LawAI Gov Hub": { + "type": "http", + "url": "https://mcp.lawaigovhub.com/mcp/", + "title": "LawAI Gov Hub", + "description": "Official AI regulation index — laws, executive orders, court cases, and regulatory guidance from 240+ jurisdictions, each result linked to its primary legal source with citation-ready identifiers and jurisdiction ISO codes." } }, "recommendedCategories": [ diff --git a/regulatory-legal/CONNECTOR_HEALTH.md b/regulatory-legal/CONNECTOR_HEALTH.md new file mode 100644 index 0000000000..418d10aa43 --- /dev/null +++ b/regulatory-legal/CONNECTOR_HEALTH.md @@ -0,0 +1,105 @@ +# LawAI Gov Hub — Connector Health Check + +This file records the end-to-end health check performed against the LawAI Gov Hub MCP server before this connector entry was added to `.mcp.json`. **Two captures** are documented below: a local capture during development and a **live production capture against `https://mcp.lawaigovhub.com/mcp/`** — the URL the connector resolves to in the plugin's `.mcp.json`. + +To reproduce, clone the [lawaigovhub repo](https://github.com/Brokemountain/http-lawaigovhub.com-) and run `python -m mcp_server` plus `pytest mcp_server/tests/`, or hit the live endpoint with the official MCP Python client. + +## Result + +**PASS** — server identifies as `LawAI Gov Hub` over the streamable-HTTP transport, all five tools answer, primary-source policy enforced (0 aggregator URLs leaked under `official_only=true`), unknown-id errors return the contracted `isError=true` MCP error shape. + +## Production capture + +Captured at **2026-05-15T08:55:25Z** against `https://mcp.lawaigovhub.com/mcp/`. + +### Service identity + +| Field | Value | +| --- | --- | +| Service | `lawai-gov-hub-mcp` | +| Version | `1.0.0` | +| MCP protocol version | `2025-11-25` | +| Server name (from `initialize`) | `LawAI Gov Hub` | +| Transport | Streamable HTTP | +| TLS | Let's Encrypt (auto-renewed by certbot) | + +### `/healthz` response (live) + +```json +{ + "status": "ok", + "service": "lawai-gov-hub-mcp", + "version": "1.0.0", + "transport": "streamable-http", + "endpoint": "/mcp", + "regulations_indexed": 14275, + "jurisdictions_total": 265, + "active_jurisdictions": 240, + "hallucination_cases_indexed": 1275, + "site_stats": { + "total_profiles": 265, + "country_profiles": 252, + "regional_profiles": 13, + "active_profiles": 240, + "total_entries": 14394 + }, + "tools": [ + "search_regulations", + "fetch_regulation", + "list_jurisdictions", + "search_cases", + "fetch_case" + ] +} +``` + +### Probes (live) + +| # | Probe | Result | +| - | --- | --- | +| 1 | `search_regulations(query="EU AI Act", jurisdiction="EU", year_from=2024)` | `total=9`; first hit is the official EUR-Lex corrigendum `https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689R(01)`, `is_primary_source=true` | +| 2 | `fetch_regulation(id="eu:a60727cb8857")` | Round-trips the id; same `source_url` as probe 1; `retrieved_at=2026-05-15T08:53:28+00:00` | +| 3 | `list_jurisdictions(active_only=true)` | `total=240`; top three by entry count: US (4533), GB (957), CN (933) | +| 4 | `search_cases(query="sanction")` | `total=355`; first hit: `Staley v. City of Elba, et al.` | +| 5 | **Aggregator audit** (`search_regulations(limit=100, official_only=true)`) | **0** non-primary URLs in the sample of 100 — primary-source policy enforced | +| 6 | `fetch_regulation(id="NOPE:000000000000")` | `isError=true`, body begins `Error executing tool fetch_regulation: No regulation with id` — contracted MCP error shape, no transport-level exception | + +The aggregator audit is the contract enforcement: with `official_only=true`, every result is on a primary source (government register, court system, intergovernmental body). The blocklist covers `regulations.ai`, `incidentdatabase.ai`, `wp.oecd.ai`, `techieray.com`, `damiencharlotin.com`, and major social/blog hosts; the allowlist covers `.gov`, `.gov.`, `.europa.eu`, `.gob.*`, `.gouv.*`, `.int`, parliament/legislature domains, and similar. + +## Local capture (development) + +Captured at **2026-05-14T14:42:06Z** against `http://127.0.0.1:8767/mcp/` during development. Same five tools, same response shape, same audit result (0 non-primary URLs in 100). The local capture is what the 12-test pytest suite validates on every change. + +## Reproducing this check + +From a clone of the [lawaigovhub repo](https://github.com/Brokemountain/http-lawaigovhub.com-): + +```bash +python -m venv .venv && . .venv/bin/activate +pip install "mcp[cli]>=1.16" httpx pytest uvicorn starlette +python -m pytest mcp_server/tests/ -v # 12 tests, ~4s +``` + +To probe the live endpoint: + +```bash +curl -sS https://mcp.lawaigovhub.com/healthz +curl -sS -X POST https://mcp.lawaigovhub.com/mcp/ \ + -H "Content-Type: application/json" \ + -H "Accept: application/json, text/event-stream" \ + -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' +``` + +## What the connector cannot do + +For transparency: + +- It is **read-only**. There are no write tools, no auth flows, no PII exchange — the dataset is public AI regulation. +- Source coverage matches the public website at `lawaigovhub.com`. When a primary register has not yet been linked for an entry, the entry is still indexed but `is_primary_source` will be `false`; the default `official_only=true` filters those out. +- Citation strings are formatted for legal documents but **do not relieve the lawyer of verifying the cite against the linked primary source**. The plugin already flags this in its citation-tiering language; the connector enforces it by always linking the primary source so verification is one click away. + +## Operational notes + +- The MCP server runs as a `lawai-mcp` systemd unit on the same DigitalOcean droplet as `lawaigovhub.com`, on `127.0.0.1:8765`. nginx terminates TLS for `mcp.lawaigovhub.com` and proxies to the local service. +- TLS certificate auto-renews via certbot's scheduled task (Let's Encrypt cert). +- DNS-rebinding protection is enabled in the MCP transport: only `mcp.lawaigovhub.com` and loopback are accepted as Host headers. diff --git a/regulatory-legal/README.md b/regulatory-legal/README.md index f5258dbe5f..faaa30f9ea 100644 --- a/regulatory-legal/README.md +++ b/regulatory-legal/README.md @@ -53,6 +53,7 @@ Ships with the general bucket of connectors in `.mcp.json`: - **Slack** — search messages, read channels, find discussions - **Google Drive** — search, read, and fetch documents +- **LawAI Gov Hub** — official AI regulation index across 240+ jurisdictions; every result links to its primary legal source (statute, executive order, court decision, regulatory guidance) with citation-ready identifiers and jurisdiction ISO codes Additional regulatory feed connectors can be added when partner URLs are available. Direct regulator RSS/email as fallback.