A cryptographically verifiable static MCP. Latin-named defensive spells — each a
SKILL.md an LLM subagent casts against a target, SHA-256 verified against an
ECDSA P-256-signed manifest before it reaches a model.
Add to any MCP client (Claude Code, Cursor, …):
{ "mcpServers": { "datamancy": { "command": "npx", "args": ["-y", "datamancy"] } } }
Content integrity, not access control: the manifest is signed by a key held
non-exportably in AWS KMS; the public key (fingerprint 09db7668…) is pinned in the
npm package and cross-published at
datamancer.dev. Tampered content is refused, never delivered.