Owned product · Local Poppy MCP boundary
TentaClaw
A local-only stdio MCP exposing six bounded Poppy tools without placing the account-wide credential in the model or client configuration.
Ownership disclosure
SharetoBoard is an independent third-party product ecosystem. Poppy membership is separate and managed by Poppy. SharetoBoard is not affiliated with or endorsed by Poppy.
The project decision
Giving an AI client a provider-wide credential creates more authority and disclosure risk than the workflow requires.
Who it is for: Technical Poppy users and agent builders who need a local, inspectable MCP path with visible approval boundaries.
What works
Verified or explicitly documented behavior.
- Exactly six local stdio tools remain inside the release boundary.
- Credentials stay outside the model, skill, and ordinary client configuration.
- Credit-using and state-changing operations require visible approval and avoid unsafe retries.
- Reproducible packages, checksums, cross-platform checks, and dependency audits pass.
Known limitations
What this project is not allowed to claim yet.
- Live Poppy write approval and exact supported-client acceptance remain open.
- Publisher identity, signing, provenance, and public publication approval remain open.
- TentaClaw is local only and must not be described as ShriMCP or a cloud service.
- A verified artifact is not yet a published public package.
Current evidence
The public claim must stay inside this boundary.
- 01Source candidate 0.3.0rc10 is merged at 98c1b0cb5de2c8af0b59476fbd8c38ad16a0e412.
- 02Exact candidate SHA-256 is 20563472820d7c77e785c975a4f253414ab3d2a1d5f6a3d8f9b7636f7e9e0672.
- 03Python 3.10–3.14, Windows, macOS, Linux, Gemini, audit, checksum, and artifact gates pass.
Current blockerLive approved writes, exact client records, signing/provenance, and publication authorization remain open.
Next gateComplete the live approval/client matrix and publish only the exact verified bundle after explicit authorization.
Follow the next gate