CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
rul1an avatar

Assay MCP Server

rul1an/assay
5STDIOregistry active
Summary

A policy enforcement layer that sits between Claude and any MCP server, logging tool calls and applying allow/deny rules before execution. You give it a policy YAML with path constraints, tool allowlists, and optional evidence requirements, then wrap your existing MCP server with `assay mcp wrap`. Every tool invocation gets audited into a tamper-evident bundle with cryptographic verification. The trust-basis compiler turns those bundles into claim artifacts (verified, self-reported, inferred, absent) for CI gates or SARIF output. Useful when you need runtime guardrails on filesystem access, exec boundaries, or sensitive tool usage without rewriting the upstream server. Ships as a Rust CLI with stdio transport, no hosted backend required.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →

Assay

The open, recomputable evidence profile for privileged MCP tool actions.
Assay records what a privileged tool call decided, what was observed, and what stays unproven, so a reviewer can replay the claim offline instead of trusting the agent's account of itself. In enforcement mode, the proxy gate for routed MCP tools/call requests is deterministic and fail-closed, and the enforcing proxy is the reference producer rather than the contract itself. Optional eBPF/LSM instrumentation on supported Linux hosts adds kernel-level observations. CI-native, no backend, bounded by design.

Crates.io CI License

Quickstart · How it works · See it work · MCP example · OWASP MCP Top 10 · Discussions


Agents got real tool access through MCP — and tool poisoning, rug pulls, and confused-deputy OAuth came with it. Assay sits at the tool-call boundary and does three things, in order.

One golden path: the release-pinned agent journey records the nine driven CLI/MCP steps and their exit/stdout contracts. Its protected-action fixture lives in examples/privileged-action-gate/.

Enforce, prove, stay honest

  • Enforce. In enforcement mode, the gate decides tools/call requests routed through it before forwarding, with the precise reason for each allow or deny. Separate controls on supported Linux hosts include cgroup eBPF IPv4/TCP connect filtering (whose hook error path allows connections) and Landlock TCP-connect port allowlisting. assay sandbox --enforce refuses an unavailable backend or conflicting filesystem policy unless --allow-audit-fallback is explicit. --enforce-net requires --enforce; active Landlock network enforcement rejects policies it cannot express as TCP-port allowlists, even with audit fallback enabled.
  • Prove. Configured producers can record decisions and bounded observations for export into offline-verifiable, tamper-evident evidence bundles. The privileged-action flow carries the verdict, pre-call establish journey, and declared-vs-observed conformance for CI review without a hosted backend. Basic assay mcp wrap does not automatically create a bundle; enable the required recording and export steps.
  • Stay honest. Trust Basis classifies supported claims as verified, self_reported, inferred, or absent; its gates check the declared claim boundaries. A tool returning "success" is the provider's assertion, never proof. Assay ships no single safety score; read each artifact’s source, coverage and non-claims before relying on it.

Quickstart

# Fast path: release installer for Linux and macOS.
curl -fsSL https://getassay.dev/install.sh | sh

# Confirm the command resolves; if setup fails, run `assay doctor`.
assay --version

# Source-build alternative (requires Rust):
cargo install assay-cli --version 6.9.0 --locked

python3 examples/mcp-quickstart/run.py

For v6.9.0, run the last command from a source checkout or an extracted published CLI archive. The installer is binary-only and does not carry the bounded quickstart assets. The live getassay.dev installer verifies the selected archive against its published SHA-256 sidecar before extraction. Set ASSAY_REQUIRE_PROVENANCE=1 to additionally require GitHub artifact provenance; the default reports provenance_not_requested and strict success reports provenance_verified. A checksum proves byte equality with the published sidecar, not producer identity. Provenance identifies the source and build, not runtime safety or semantic correctness.

Captured runner output (the bundled local mock performs no external action):

assay quickstart: PASS
mcp_requests=initialize,tools/list,tools/call
decision=allow tool=read_file
decision_artifact=.assay/quickstart/decisions.ndjson
non_claim=forwarded_to_local_mock_only

Assay decides each MCP tool call before it runs, fail-closed, with the reason

Released surfaces:

  • Static project manifests are shipped for Claude Code and Cursor; Codex uses the equivalent TOML entry documented in the editor MCP recipe. Manifest presence is not host-discovery proof. assay mcp config-path supports Claude Desktop and Cursor only.
  • Published v6.9.0 CLI archives cover Linux x86_64/arm64, macOS x86_64/arm64, and Windows x86_64. The Python wheels cover CPython 3.12, 3.13, and 3.14 on macOS x86_64/arm64 and Linux x86_64; other interpreters and platforms are not claimed.
  • Published assay-mcp-server archives cover Linux x86_64/arm64. MCPB and server.json package descriptors are also published; their presence is not host-discovery proof.
  • CI: GitHub Action. Core flows need no hosted backend or API key. New to the threat model? The OWASP MCP Top 10 mapping states, per risk, what Assay covers and deliberately does not.

What ships

OutputWhat it is
Policy gateassay mcp wrap — deterministic allow/deny before tools run, with the reason.
Evidence bundleOffline-verifiable, tamper-evident archive for audit and replay.
Trust Basis / Trust CardCanonical trust-basis.json (bounded claim classification) plus review-friendly trustcard.{json,md,html}.
External receiptsEval outcomes, runtime decisions, and model inventory as bounded receipts with JSON Schema contracts.
Tool-decision logsFor handled known-tool calls, the assay-mcp-server stdio server emits an info-level tool_decision event when enabled by its log filter; decision contains a JSON-encoded observed decision entry with projected target fields.
SARIF / CIGitHub Action, Security-tab integration, policy gates on PRs.
AttestationSign an evidence bundle as a DSSE-wrapped in-toto v1 Statement with the evidence-bundle/v1 predicate.
  Agent ──► Assay ──► MCP Server
              ├─ ✅ ALLOW / ❌ DENY  (policy, with reason)
              ├─► 📋 Evidence bundle (offline-verifiable)
              └─► 📊 Trust Basis → Trust Card → SARIF / CI

Current release: v6.9.0. CHANGELOG.md and release notes remain the authority for released behavior; merged changes after the tag are Unreleased, and crates.io publication is separate from merge state. Launch definition and support commitment: docs/LAUNCH.md.

Is this for me?

Yes if you already have eval output, runtime decisions, inventory artifacts, or MCP tool-call tests, and you want a small reviewable CI artifact instead of a dashboard — bounded auditability, not a scalar trust badge.

Not yet if you need Assay to judge model correctness for you, want a hosted dashboard as the product, or want a compliance claim rather than a bounded evidence boundary. Assay is not a trust-score engine, a generic eval dashboard, or a hosted observability product — see what it is and is not.

See it work

An agent tries a privileged action — github.add_deploy_key — through the enforcing proxy, decided per call before it forwards, offline against a local mock (no real credentials):

cd examples/privileged-action-gate && ./run.sh

privileged-action PR-gate demo

A deny is fail-closed caution, not a verdict on intent; an allow is the decision to forward, never proof the action happened. Declared-vs-observed conformance is recorded beside the verdict, never as a gate. Full walkthrough: privileged-action-gate.

Pick your path

You haveWhat you getStart here
Promptfoo JSONL from CI evalsEval outcome receipts + verified bundle + Trust Basis diffPromptfoo JSONL
OpenFeature EvaluationDetailsDecision receipt + verified bundleOpenFeature
CycloneDX ML-BOM model componentInventory receipt + verified bundleCycloneDX ML-BOM
MCP tool callsAllow/deny audit trail + observed-behavior evidenceMCP Quick Start
A GitHub PR gateTrust Basis diff, gate status, SARIF/JUnit-ready outputCI Guide
A Runner archive / coverage annotationCoverage descriptors + claim-class cells + a claimed-vs-observed checkCoverage-honesty walkthrough

The workflow stays small: import or record a bounded outcome, bundle and verify it, compile trust-basis.json, gate the Trust Basis diff. Assay doesn't make the upstream tool the source of truth; it makes the evidence boundary inspectable. For privileged tool actions, the MCP proxy records each tools/call as a structured tool-decision surface — keeping the asserted-versus-verified line honest.

Policy is simple

version: "2.0"
name: "my-policy"
tools:
  allow: ["read_file", "list_dir"]
  deny: ["exec", "shell", "write_file"]
schemas:
  read_file:
    type: object
    properties:
      path: { type: string, pattern: "^/app/.*" }
    required: ["path"]

assay init --from-trace trace.jsonl generates the runtime-observation policy used by the trace-generation flow (files, network, and processes); it is not an MCP authorization policy. Migrate a legacy MCP constraints: policy with assay policy migrate. See Policy Files.

Why Assay

Canonical evidenceAssay's evidence model is the stable contract; OpenTelemetry and protocol adapters (ACP / A2A projection profile / UCP) map into it.
DeterministicThe policy gate uses explicit rules; its decision depends on the request, policy and applicable session state. This does not make live evaluators or external effects deterministic.
Bounded claimsExplicit about verified vs visible vs absent — no score-first UX.
Offline-firstNo backend required for core enforcement and bundle verification.
Checkable provenanceWhich piece of the source-class and coverage model shipped when, as commits you can git log rather than claims you have to take — provenance, prior art credited first.

Learn more

  • MCP Quickstart · Editor MCP recipe — policy-enforcing MCP in Cursor / Claude Code / Codex
  • MCP 2025/2026 protocol-era parity — pinned resultType and interim-result compatibility corpus
  • Coding-agent governance · OpenTelemetry & Langfuse — observed runs → evidence
  • Evidence Receipts in Action — Promptfoo / OpenFeature / CycloneDX receipt families
  • CI Guide · Evidence Store (S3 / B2 / MinIO)
  • OWASP MCP Top 10 mapping · Security experiments
  • Positioning: ADR-033 · RFC-005
Evidence epistemology, latency, and the internal Runner

Trust claims use explicit epistemology, not a single safety score: verified (direct evidence or offline verification), self_reported (emitted without independent corroboration), inferred (bounded, documented rules), absent (no trustworthy evidence). Assay ships no aggregate trust score or safe/unsafe badge as the main output — see ADR-033.

The historical fragmented-IPI experiment results, dated 2026-03-02 and naming commit 289a43ecc144, report 0.771ms p50 / 1.913ms p95 for the deterministic set. The harness times complete local mock tools/call round trips, including JSON-RPC transport and the tool response. These reported timings do not isolate policy-decision overhead or establish current-release or end-to-end model performance.

Assay-Runner is an internal/experimental measured-run subsystem behind the delegated Linux/eBPF acceptance path. Its crates are included in the workspace publication process so dependent packages can resolve them; publication does not make Runner a standalone product or give its APIs a separate stability commitment.

Ecosystem

Related projects for evidence generation, verification, and reviewability; each has its own interface and scope:

  • assay-action — GitHub Action: verify bundles, PR summaries, SARIF (Marketplace).
  • Assay-Harness — recipe, gate, and report layer over canonical evidence artifacts.
  • observed-effect-v0 — worked examples of the bounded observed-effect evidence record and its neutral carriers (in-toto, SCITT, MCP evidenceRef).
  • gateway-evidence-replay — deterministic offline replay verifier for gateway-path evidence bundles.
  • RGE-Bench — a conformance kit for evidence reviewability, maintained separately under its own machine-checked neutrality guard. Reproduction there is digest-scoped and does not carry forward: the v1 71-vector digest sha256:e769822bc6c9e31085da7b1a17b163b9747fe0d04314fbb8685d4e612087c7cb and the historical v2 digest sha256:ba0e3795d75c788fa48313ab462493f22d78759851d1b3275d8117051bb22fd0 (95 vectors) each carry one reported independent implementation by a second author on a different stack. JM-Lab reported the v2 95/95 reproduction on 2026-08-24, from the contract text and author-supplied inputs without reading expected. Neither reproduction transfers to the current 104-vector v3 candidate digest sha256:93f8ae9654eb5a16dee28d882087669cae5183e02e116ba1e8071a30594cfb6a, which the record lists as unreproduced. See its REPRODUCTIONS.md.

Open profile: privileged-mcp-action/v0

privileged-mcp-action/v0 is a composition and verification contract over evidence records that already exist: what a privileged MCP tool call decided, what was observed of its effect, and what stays unproven. It adds no new envelope and no aggregate verdict.

It ships with a 14-vector conformance corpus (5 accept, 9 reject) whose digest is a candidate: it is not called reproduced until a non-author implementation derives the expected outcomes from the specification text alone.

That reproduction is open, and the invitation is real: #1840. Any language, any stack. The invitation names the exact commit the current digest describes. The clean-room protocol provides an opaque, attested inputs pack, a one-command scoring action, and an implementation-report template without supplying verifier logic or expected outcomes. The corpus README states the authorship boundary and the claim ceiling.

Contributing

cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings

See CONTRIBUTING.md and GitHub Discussions.

License

MIT

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
Registryactive
Packagehttps://github.com/Rul1an/assay/releases/download/v3.9.2/assay-mcp-server-v3.9.2-linux.mcpb
TransportSTDIO
UpdatedMay 6, 2026
View on GitHub