MCP server for AI agent safety — cost guards, injection scanning, decision tracing, agent identity (KYA), and signed receipts