{"_id":"@ahmedshaikh/attest-mcp","name":"@ahmedshaikh/attest-mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@ahmedshaikh/attest-mcp","version":"0.1.0","type":"module","description":"Evidence attribution for code changes as an MCP server — which test failures did MY change cause (vs pre-existing), did any test actually execute my changed lines, and is the artifact I'm testing built from my sources.","bin":{"attest":"dist/server.js"},"engines":{"node":">=22"},"scripts":{"serve":"tsx src/server.ts","build":"tsc","test":"node --import tsx --test --test-force-exit test/*.test.ts","prepublishOnly":"npm run build"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","c8":"^10.1.0","zod":"^3.23.8"},"devDependencies":{"@types/node":"^24.0.0","tsx":"^4.7.0","typescript":"^5.4.0"},"license":"MIT","author":{"name":"ahmedshaikh"},"keywords":["mcp","model-context-protocol","claude","agent","ai","test-attribution","coverage","baseline","flaky","verification"],"repository":{"type":"git","url":"git+https://github.com/RaziStuff/attest-mcp.git"},"homepage":"https://github.com/RaziStuff/attest-mcp#readme","bugs":{"url":"https://github.com/RaziStuff/attest-mcp/issues"},"publishConfig":{"access":"public"},"gitHead":"93d0fca58bbf2d6ac9d707ac42f91028ed5e12f9","_id":"@ahmedshaikh/attest-mcp@0.1.0","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-NdfnyXkqr8tcs6JeUmMM/dW7ovVwg6ohqDMoyDpzvRcM8/j935sK/QvW12KsUo0YsHJZaMfCBZVbBxQjTOY30g==","shasum":"7b41fa97237675723346ab870c257061a069b6f0","tarball":"https://registry.npmjs.org/@ahmedshaikh/attest-mcp/-/attest-mcp-0.1.0.tgz","fileCount":12,"unpackedSize":43572,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDf+B5kNMrXOwB+0bubX8ml8gg8ozRVLosvr3SscCVA8wIhAIgwZ7G1OJOJDflJ59B1C7B/cWDNDFOYcOtx+r7jAmpB"}]},"_npmUser":{"name":"ahmedshaikh","email":"ahmed@shaikh1.com"},"directories":{},"maintainers":[{"name":"ahmedshaikh","email":"ahmed@shaikh1.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/attest-mcp_0.1.0_1783370144999_0.8353472578289778"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-06T20:35:44.814Z","0.1.0":"2026-07-06T20:35:45.137Z","modified":"2026-07-06T20:35:45.294Z"},"maintainers":[{"name":"ahmedshaikh","email":"ahmed@shaikh1.com"}],"description":"Evidence attribution for code changes as an MCP server — which test failures did MY change cause (vs pre-existing), did any test actually execute my changed lines, and is the artifact I'm testing built from my sources.","homepage":"https://github.com/RaziStuff/attest-mcp#readme","keywords":["mcp","model-context-protocol","claude","agent","ai","test-attribution","coverage","baseline","flaky","verification"],"repository":{"type":"git","url":"git+https://github.com/RaziStuff/attest-mcp.git"},"author":{"name":"ahmedshaikh"},"bugs":{"url":"https://github.com/RaziStuff/attest-mcp/issues"},"license":"MIT","readme":"# attest-mcp\n\n**Evidence attribution for code changes, as an MCP server.**\n\nAgents (and humans) waste their worst debugging hours on *misattributed evidence*:\n\n- a suite shows 7 failures after an edit — and all 7 were already failing before it\n  (cue 30 turns of \"fixing\" other people's bugs, or reverting a correct change)\n- tests are green, so the change ships — but no test ever *executed* the changed\n  lines; green was about everything else\n- the fix \"has no effect\" — because `src/` was edited and stale `dist/` is running\n  (cue 10 turns of debug prints that also never run)\n\n`verify`-style tools answer *whether checks pass*. attest answers **whether that\npass/fail is actually evidence about your change**.\n\n## Tools\n\n### `attribute` — which failures did *my* change cause?\n\nRuns the checks in your working tree and compares against a baseline run at a\nknown ref (default: merge-base with main). The baseline executes in a throwaway\ngit worktree — your tree is never touched — and is cached by tree hash, so\nrepeat calls are instant.\n\n```\nattribute\n→ summary: 1 new · 0 fixed · 7 pre-existing (ignore)\n  NEW failures (caused by your change):\n    pytest:tests/test_pricing.py::test_discount — AssertionError: 10.8 == 12\n  pre-existing (already failing at baseline — not yours): …\n```\n\nCall it the moment you see red output, *before* debugging anything.\n\n### `diff_coverage` — did any test actually run my changed lines?\n\nDiffs the working tree against a base ref, runs the tests under coverage\n(Node via c8/V8 — no source instrumentation; Python via coverage.py), and\nintersects executed lines with the diff.\n\n```\ndiff_coverage\n→ verdict: UNTOUCHED\n  src/recover.js: 0/18 changed lines executed — NOT executed: 41-58\n  → changed lines that no test executes are unverified — add a test that reaches them\n```\n\n`UNTOUCHED` on a green suite is the classic false-victory tell.\n\n### `freshness` — is the artifact built from my sources?\n\nCall it the moment an edit \"has no effect\", before adding debug prints.\nPrefers sourcemap content comparison (exact — immune to mtime churn from\nbranch switches); falls back to mtime chains, clearly labeled as heuristic.\n\n```\nfreshness target=dist/cli.js\n→ STALE: dist/cli.js does NOT reflect current sources\n  src/parser.ts: on-disk content differs from the sourcemap's embedded copy\n  → rebuild first: npm run build\n```\n\n### `baseline` — pre-warm or refresh the comparison point\n\n`attribute` builds baselines lazily; call `baseline` explicitly to pre-warm one\nbefore starting an edit, or `force=true` to refresh a suspect cache entry.\n\n## How failures are identified\n\nRunner-native identities where possible — pytest node ids, unittest\n`module.Class.test`, node:test / vitest / jest test names — with a normalized\nfingerprint fallback (paths debased, numbers stripped) for unknown runners, so\neven a `make check` diff usefully.\n\n## Install\n\n```jsonc\n// .mcp.json\n{\n  \"mcpServers\": {\n    \"attest\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@ahmedshaikh/attest-mcp\"]\n    }\n  }\n}\n```\n\nBaselines cache in `~/.attest/attest.db` (override with `ATTEST_DB`). Project\nroot defaults to the server cwd (`ATTEST_ROOT` or per-call `cwd` override).\n\n## Limits\n\n- requires a git repository (baselines are git-ref-addressed)\n- baseline worktrees symlink `node_modules`/`.venv` from the main checkout;\n  repos whose checks need per-tree generated state may need `cmd` scoping\n- test-command detection covers `package.json` test scripts and python\n  test layouts; pass `cmd` explicitly for anything else\n- Python coverage needs `coverage.py` installed in the interpreter under test\n- per-test attribution (\"which test touches line N\") and flaky detection via\n  baseline double-runs are v2\n\n## Development\n\n```\nnpm install\nnpm test        # node:test; python tests need python3 (+ coverage.py for one test)\nnpm run build\n```\n\nMIT\n","readmeFilename":"README.md","_rev":"1-08ac96133c5dfbbb975550d776d3e073"}