NOA — the Agent Action Receipt. Open governance layer for AI agents: gate risky actions before they run, emit a tamper-evident receipt anyone can verify offline. Early access · Apache-2.0.
NordenSoft/noa is an MCP server distributed on github, maintained by NordenSoft, tracked here since August 2026. It has shipped 4 releases and exposes 3 tools. Tools include echo, read_data, transfer_funds. Its composite risk grade is D — an inferred review prompt computed from observed signals, not a verdict. 1 known CVE on file.
1 advisory published against this server still applies to the version it ships, the most severe rated critical, most recently 2026-08-03.
Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.
full security breakdown →-
echo -
read_data -
transfer_funds
| version | date | src |
|---|---|---|
| v0.6.0 | 2026-08-04 | github |
| v0.5.0 | 2026-08-04 | github |
| v0.4.0 | 2026-07-10 | github |
| v0.3.0 | 2026-07-09 | github |