Required
- Local MCP stdio only
- Six policy-enforced Poppy tools
- Protected local credential
- Exact approved board/chat pairs
- Fixed outbound Poppy origin
TentaClaw runs as a local child process over MCP stdio and exposes exactly six focused Poppy tools without placing the Poppy key in the client or model.
| Version | 0.3.0rc13 |
|---|---|
| Draft source PR | savage-content/tentaclaw-mcp#21 |
| Reviewed head | c78d0cbecd999f027059ba93864a45899666d5ea |
| Candidate ZIP SHA-256 | 9651fab6e10272fb5a6d766bcd04ff12fb76929dcf2162fe000da993b1f1fd8e |
| Seven-subject digest | fd711b43ab9ddf9bc63ca218a34e9a9df3ece37e3cb5edc5e3736f523194d303 |
| Gate | Result |
|---|---|
| Tests | 501 passed; 38 skipped |
| Dependency audits | No known Python or npm vulnerabilities reported |
| Reproducibility | Four builds reproduced all seven artifacts byte for byte |
| Source review | Draft PR exact-head CI passed |
| Repository boundary | Private repository; no tag or public release created |
tentaclaw_mcp-0.3.0rc13-py3-none-any.whltentaclaw_mcp-0.3.0rc13.tar.gzSHA256SUMStentaclaw-mcp-0.3.0rc13-release.zip and companion digestThe artifact is private candidate evidence. It is not a public download authorization.
Approved testers may receive the checksum-bound RC13 candidate privately. No public tag, package publication, or public release is authorized.