Inspiration
Ambient agents are moving into our living rooms, but they bring new risks. Without first-class identity and consent, a voice assistant might order groceries because of a TV ad or a child's request. Today’s MCP tools often execute irreversible actions in one shot. I realized household commerce needs a "consent kernel"—a reliable, deterministic layer that separates proposing an action from committing it.
What it does
Chaperone is a consent kernel for household commerce: the model may only propose; deterministic policy and hash-locked commit decide.
- Streamable HTTP MCP server (
propose_order/commit_order) + MCP App confirm UI. - Deterministic policy that handles child, guest, budget, and unidentified speaker scenarios without relying on the LLM to make security decisions.
- Hash-locked propose/commit (I1) ensuring exactly what the user approves is what executes.
- Append-only signed ledger (I3) for cryptographic audit trails.
- Simulated Alexa+ host allowing judges to experience the voice-to-screen flow (propose → confirm MCP App → commit) with no physical device required.
How I built it
I built a pnpm TypeScript monorepo consisting of @chaperone/policy, mcp-kernel, ledger, grocery-mock, eval-harness, apps/mcp-server, and apps/sim-host. It strictly implements the MCP Streamable HTTP spec (2025-11-25) and MCP Apps spec (2026-01-26).
AWS Builder Mini: I integrated DynamoDB to dual-write proposals and persist my ledger (CHAPERONE_AWS=1). I utilized live AWS KMS (RSASSA_PSS_SHA_256) to cryptographically sign every ledger row, proving the viability of immutable household audit trails.
Open Source Mini: I published the entire kernel under the MIT license to provide a foundational consent layer for the community, ensuring safe ambient AI development.
Challenges I ran into
- Simulating the Target Hardware: Since I didn't have Alexa+ preview access, I had to build
sim-hostfrom scratch—a Next.js app simulating an Echo Show client so judges could experience the exact workflow. - MCP Apps UI Constraints: Handling duplicate iframe CTAs and ensuring only the host's active commit buttons appeared required careful injection of host controls (
__CHAPERONE_HOST_CONTROLS__) into the confirm API routes. - Proving Security Determinism: Ensuring the LLM couldn't bypass the policy required building a strict offline evaluation harness (AmbientBench) rather than relying on manual testing.
Accomplishments that I'm proud of
- AmbientBench Validation: My offline evaluation (100 scenarios, 20 held-out sealed) proved 0 treatment consent bypasses. I demonstrated that ablating the hash-lock caused 10 bypasses, proving the architectural necessity of my pattern.
- Cryptographic Audit Trail: Successfully wiring up live AWS KMS RSA signatures for the DynamoDB ledger, bridging modern ambient AI with enterprise-grade security.
What I learned
I deeply learned the intricacies of the MCP Streamable HTTP and MCP Apps UI specifications. More importantly, I proved that LLMs should never be the final decider for authorization—they are excellent at eliciting intent, but deterministic code must handle the policy and consent.
What's next for Chaperone — household consent kernel for ambient MCP
- Expanding the policy engine to support multi-party threshold signatures (e.g., both parents must approve a large purchase).
- Awaiting first-class ambient identity (speaker recognition) on the MCP host level to pass identity natively.
- Extending the kernel beyond commerce to physical household controls (smart locks, security systems).
Built With
- aws-(dynamodb
- kms)
- mcp
- next.js
- node.js
- typescript
Log in or sign up for Devpost to join the conversation.