Atlas / MCP servers / kronova-intelligent-systems / Kronova Asset Intelligence

Kronova Asset IntelligenceBLOCK

mcp/kronova-intelligent-systems/kronova-asset-intelligence

Open-source platform for multi-agent AI orchestration, real-world asset tokenization, workflow automation. Includes OAuth 2.1 MCP agent management, a 44-field RWA schema, Stripe, designed to integrate with AetherNet QUAS & KVS sovereign, post quantum, architecture agnostic omni-substrate, semantic m

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
74 65r · 9w · 0d
Transport
—
License
NOASSERTION
Stars
249
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Welcome to the official open-source frontend and intelligent orchestration layer for the Kronova Intelligent Systems ecosystem. Most of the codebase is functional, production worthy, and scalable with relatively minor tweaks.

This repository provides a production-ready Next.js application designed to orchestrate Real-World Asset (RWA) tokenization, run complex AI Agent workflows, and manage an OAuth 2.1 MCP server. It includes our comprehensive 44-field asset schema and a library of integrated AI tools out of the box.

Architecture: Open Orchestration, Secure Execution

We believe that AI orchestration and UI layers should be open, flexible, and community-driven. However, we also know that executing legally binding financial state changes and managing post-quantum secure cryptographic settlement requires a zero-trust environment.

To give developers complete freedom over their UI without compromising enterprise security, we utilize a Decoupled Settlement Architecture:

1. The Orchestrator (This Repository)

Everything you see here is open-source under the Apache 2.0 License. You have complete freedom to run this locally, deploy it to your own infrastructure, add new AI models, or fork the UI. It handles the "thinking" — the AI routing, the data ingestion, and the payload construction.

2. The Engine: AetherNet QUAS (The Settlement Layer)

When your AI agents need to stop "thinking" and start "executing" (e.g., finalizing an RWA tokenization, moving funds, or interacting with secure hardware enclaves), this repository relies on the AetherNet QUAS API.

AetherNet acts as a black-box secure gateway, utilizing Canton smart contracts to ensure MEV resistance and post-quantum security.

Getting Started

You can run the entire intelligence platform locally without an AetherNet subscription.

1. Clone and Install

git clone https://github.com/kronova/asset-intelligence-platform.git
cd 
Read from source at commit 7629dec21de8OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kronova-platform --env AETHER_API_KEY=${AETHER_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CANTON_ACCESS_TOKEN=${CANTON_ACCESS_TOKEN} --env CANTON_API_KEY=${CANTON_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kronova-platform": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AETHER_API_KEY": "${AETHER_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CANTON_ACCESS_TOKEN": "${CANTON_ACCESS_TOKEN}",
        "CANTON_API_KEY": "${CANTON_API_KEY}"
      }
    }
  }
}
03

Exposed tools (74)

65 read · 9 write · 0 destructive.

ToolRiskDescription
AetherNetreadP2P messaging network
AutonomousDroneFleetCoordinatorreadManages a fleet of delivery drones, optimizing routes and battery usage. Records delivery confirmations to AetherChain.
BitcoinreadBitcoin network integration
EthereumreadConnect to Ethereum mainnet and L2s
GrowthreadFor growing businesses ready to scale with advanced AI.
KronovareadThe world
OnyxreadOnyx SaaS PWA Template with validated CRUD ops, user authentication + RBAC, maximum header security, Rust API runtime, TanStack, and more.
ProductivityAssistantreadPersonal productivity agent that manages schedules, prioritizes tasks, and optimizes workflows.
ScalereadFor large enterprises needing the full, unlimited suite.
SolanareadHigh-performance blockchain
StarterreadFor small stores getting started with AI.
TaskAutomatorreadStreamline repetitive tasks and workflows with intelligent automation and decision-making capabilities.
accessibility_compliance_scannerreadScan and ensure WCAG 2.1 Level AA compliance across digital assets and interfaces (Problem #12: $250K annual compliance cost reduction)
aethernet_p2p_communicationwriteEnable secure peer-to-peer communication between AI agents via AetherNet protocol. Post-quantum secure with OAuth 2.1 (Problem #10)
ai_agent_deploymentwriteDeploy and manage autonomous AI agents for specialized asset management tasks. Enables enterprise to build agent teams without AI expertise (Problem #8)
ai_agent_executionsreadAgent execution history
ai_workflowsreadWorkflow definitions
analyze_datareadAnalyze data and generate insights
analyze_nftsreadAnalyze NFTs and provide insights
asset_insightsreadAI-generated asset insights
asset_lifecycle_eventsreadAsset lifecycle tracking
asset_relationshipsreadAsset connections and dependencies
asset_tokenization_enginereadTokenize assets on Sui blockchain with fractional ownership
asset_utilization_optimizerreadOptimize asset utilization and reduce idle time
assetsreadAsset inventory and metadata
autonomous_system_protocolwriteEnable autonomous decision-making protocols for robotic and automated systems. Reduces human intervention by 85% (Problem #14)
code-cushman-001readAlmost as capable as Davinci Codex, but slightly faster. This speed advantage may make it preferable for real-time applications.
code-davinci-002readMost capable Codex model. Particularly good at translating natural language to code. In addition to completing code, also supports inserting completions within code.
compliance_monitoring_systemreadAutomated compliance monitoring against OSHA, FDA, EPA regulations
compliance_trackingreadMonitor compliance requirements and regulations
crm_connectionsreadCRM connections and contacts
data_sovereignty_managerreadManage data sovereignty and jurisdiction compliance for international operations (Problem #16: Critical for EU/APAC enterprise)
edge_computing_coordinatorreadCoordinate edge computing nodes for low-latency AI inference at asset locations. Reduces latency by 90% (Problem #17)
estimate_shipping_costreadEstimate the cost of shipping
execute-agentwriteExecute AI agents with context injection
execute-workflowwriteRun multi-step automated workflows
financial_analysisreadConduct financial analysis and TCO calculations
financial_data_integration_enginereadIntegrate Plaid, Stripe, and financial data with real-time TCO calculations
generate_asset_insightsreadGenerate asset-specific insights and recommendations
generate_codereadGenerate code based on a description
generate_insightsreadGenerate analytical insights from data
hybrid_cloud_orchestratorreadOrchestrate hybrid cloud deployments across public, private, and edge infrastructure (Problem #18: Enterprise flexibility)
inventory_analyticsreadAnalyze inventory levels and optimization
iot_analyticsreadAnalyze IoT device data and sensor readings
iot_device_coordinationreadCoordinate and orchestrate IoT sensor networks for real-time asset monitoring. Integrates 1000+ sensors seamlessly (Problem #13)
oauth-introspectreadValidate OAuth tokens
on_premise_ai_deploymentwriteDeploy AI models and agents on-premise for data sovereignty and compliance. Supports air-gapped environments (Problem #15)
optimize_packagingreadOptimize packaging for a shipment
predictive_maintenance_analysisreadAI-powered predictive maintenance with failure probability modeling
process-database-embeddingsreadBatch process database records
process-embeddingsreadGenerate vector embeddings for content
profilesreadUser profile information
provenance_verification_systemreadVerify asset provenance using blockchain and AI anomaly detection
query_databasereadQuery the database for information
query_sui_blockchainreadQuery data from the Sui blockchain
real_time_monitoringreadMonitor assets in real-time with alerts
risk_modelingreadPerform risk analysis and modeling
search_embeddingsreadSearch for similar documents in the data embeddings
security_monitoringreadMonitor security aspects and threats
stablecoin-operationsreadMint/burn private stablecoins
sustainability_metricsreadTrack sustainability and ESG metrics
text-ada-001readCapable of very simple tasks, usually the fastest model in the GPT-3 series, and lowest cost.
text-babbage-001readCapable of straightforward tasks, very fast, and lower cost.
text-curie-001readVery capable, but faster and lower cost than Davinci.
text-davinci-003readMost capable GPT-3 model. Can do any task the other models can do, often with higher quality, longer output and better instruction-following. Also supports inserting completions within text.
tokenize-assetreadMint blockchain tokens for assets
voice-websocketreadReal-time voice processing
voice-websocket-aethernetreadVoice with AetherNet integration
voice_agent_interfacewriteMulti-modal voice-enabled AI agent interface with ElevenLabs integration. Enables hands-free operations (Problem #11)
voice_data_entry_processorreadProcess voice commands for hands-free asset management
web_searchreadSearch the web for information
workflow_automation_builderwriteBuild and execute complex multi-step asset workflows. Reduces workflow setup from 2 weeks to 2 hours (Problem #9)
workflow_executionswriteWorkflow run history
workflow_learning_datareadWorkflow execution learning data
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:75
This repository is provided as a free, open-source orchestration sandbox. While I am obsessed with shipping perfectly secure, highly advanced code, my active development time is strictly focused on bu
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:77
- Community Contributions: If you spot a vulnerability, responsible disclosures are highly appreciated (and will be patched). Community PRs to maintain and expand this codebase are always welcome.
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:79
- Enterprise Production: This repository provides the frontend orchestration and agent logic. However, if you require zero-trust, post-quantum secure transactions and true defense-in-depth, you must c
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
app/actions/ai-actions.ts:1185
console.log("Using Meta Llama model with API key:", apiKey ? "API key present" : "API key missing")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
lib/sui-client-hooks.ts:46
url: "http://127.0.0.1:9000",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
lib/sui-client.ts:28
return "http://127.0.0.1:9000"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
app/oauth/consent/oauth-consent-client.tsx:33
icon: "👨💼",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/dashboard/members/components/create/CreateForm.tsx:27
import { createMember, updateMemberById } from "../../actions";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
supabase/functions/process-ap2-mandate/index.ts:3
import { Database } from "../../../src/types/supabase-types"; // Path to your types
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/SUI_CONFIGURATION.md:45
localnet: { url: "http://127.0.0.1:9000", variables: { ... } }
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
app/api/v1/voice/process/route.ts:65
const audioBuffer = Uint8Array.from(atob(audioData), (c) => c.charCodeAt(0))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
supabase/functions/voice-websocket-aethernet/index.ts:176
const audioData = Uint8Array.from(atob(message.data.audio), (c) => c.charCodeAt(0))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
supabase/functions/voice-websocket/index.ts:129
const audioData = Uint8Array.from(atob(message.data.audio), (c) => c.charCodeAt(0))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
lib/sdk/package.json
typescript
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@elevenlabs/elevenlabs-js, @emotion/is-prop-valid, @hookform/resolvers, @mysten/bcs, @mysten/dapp-kit, @mysten/sui, @radix-ui/react-alert-dialog, @radix-ui/react-avatar
Why it matters. 76 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
docs/API_DOCUMENTATION.md:159
const response = await fetch('https://app.resend-it.com/api/v1/agents/agent-123/execute', {
Why it matters. remote text is to be obeyed as instructions
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
docs/API_INTEGRATION_GUIDE.md:148
const response = await fetch('https://api.resend-it.com/api/v1/agents/agent-123/execute', {
Why it matters. remote text is to be obeyed as instructions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/OAUTH_ARCHITECTURE.md:228
| `/api/v1/oauth/token` | POST | Token endpoint |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/OAUTH_ARCHITECTURE.md:373
curl -X POST https://your-domain.com/api/v1/oauth/token \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/OAUTH_ARCHITECTURE.md:394
curl -X POST https://YOUR_PROJECT_REF.supabase.co/auth/v1/oauth/token \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/OAUTH_CONFIGURATION.md:84
POST https://<project-ref>.supabase.co/auth/v1/oauth/token
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/oauth-integration-guide.md:56
POST https://app.resendit.com/oauth/token
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
public/avatar.png
public/avatar.png
Why it matters. 2008585 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
public/content-creation-writing.png
public/content-creation-writing.png
Why it matters. 1359878 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
public/professional-asian-female-headshot.png
public/professional-asian-female-headshot.png
Why it matters. 1108465 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 7629dec21de8full audit observations/trust-audit/mcp-server/kronova-intelligent-systems__kronova-asset-intelligence.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-067629dec21de8BLOCKD69first audit
06

Questions

What is the Kronova Asset Intelligence MCP server?

Open-source platform for multi-agent AI orchestration, real-world asset tokenization, workflow automation. Includes OAuth 2.1 MCP agent management, a 44-field RWA schema, Stripe, designed to integrate with AetherNet QUAS & KVS sovereign, post quantum, architecture agnostic omni-substrate, semantic m

What tools does Kronova Asset Intelligence expose?

74 in total: 65 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kronova Asset Intelligence safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Kronova Asset Intelligence need?

It reads AETHER_API_KEY, ANTHROPIC_API_KEY, CANTON_ACCESS_TOKEN, CANTON_API_KEY, CIRCLE_API_KEY, CRON_SECRET, ELEVENLABS_API_KEY, ENCRYPTION_KEY, GOOGLE_API_KEY, GOOGLE_AUTH_TOKEN, INFURA_IPFS_PROJECT_SECRET and KRONOVA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (7629dec21de8), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement