{"_id":"@asobacloud/sdlc-integrity-mcp","_rev":"3-5bf81961b6d7631c1e368a37f93819d6","name":"@asobacloud/sdlc-integrity-mcp","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@asobacloud/sdlc-integrity-mcp","version":"1.0.0","keywords":["mcp","sdlc","code-integrity","devops","safety-checker","audit","model-context-protocol"],"author":{"name":"AsobaCloud","email":"engineering@asoba.co"},"license":"MIT","_id":"@asobacloud/sdlc-integrity-mcp@1.0.0","maintainers":[{"name":"asoba","email":"shingai@asoba.co"}],"homepage":"https://github.com/AsobaCloud/sdlc-integrity-mcp","bugs":{"url":"https://github.com/AsobaCloud/sdlc-integrity-mcp/issues"},"bin":{"sdlc-integrity-mcp":"bin/cli.js"},"dist":{"shasum":"802e70ee541b5c9359eb1512abaa0bdb84040576","tarball":"https://registry.npmjs.org/@asobacloud/sdlc-integrity-mcp/-/sdlc-integrity-mcp-1.0.0.tgz","fileCount":28,"integrity":"sha512-LwzXeYgx2mwY9Bx2/UNicd7lhuoj+HKn6wPE+a6kab938d9jc1jJk6bK/880gpFFSvMoRiTpC7Z1GRG/xhmAgw==","signatures":[{"sig":"MEUCIQCitltOu1GOw3IKa99no22gn6EE2mMzfVIprqH/z43WEwIgU6e8vnT56CM7dtW+OV6KgV1380I6rMKlW6PiG9oZaX8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88684},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"7de9aeb5124e9eac35f6939a50321197d5b29e9c","scripts":{"dev":"node --watch dist/index.js","test":"node tests/mcp-server.test.mjs","build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"asoba","email":"shingai@asoba.co"},"repository":{"url":"git+https://github.com/AsobaCloud/sdlc-integrity-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"MCP Server for enterprise SDLC code integrity: lifecycle teardown parity, mock theater detection, DRY violations, and safety checks for shell, JS, and Python.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"esprima":"^4.0.1","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-integrity-mcp_1.0.0_1786139202791_0.7716279506753589","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@asobacloud/sdlc-integrity-mcp","version":"1.0.1","keywords":["mcp","sdlc","code-integrity","devops","safety-checker","audit","model-context-protocol"],"author":{"name":"Asoba","email":"support@asoba.co"},"license":"MIT","_id":"@asobacloud/sdlc-integrity-mcp@1.0.1","maintainers":[{"name":"asoba","email":"shingai@asoba.co"}],"homepage":"https://github.com/AsobaCloud/sdlc-integrity-mcp","bugs":{"url":"https://github.com/AsobaCloud/sdlc-integrity-mcp/issues"},"bin":{"sdlc-integrity-mcp":"bin/cli.js"},"dist":{"shasum":"473b36e1ae0a7d43bde2fc3172fcdedde15f1789","tarball":"https://registry.npmjs.org/@asobacloud/sdlc-integrity-mcp/-/sdlc-integrity-mcp-1.0.1.tgz","fileCount":28,"integrity":"sha512-8c6gyb6ZIk+dasrpSjvgz4arVbIkGTrLxyfi+ptUPkNNDvyCvMkXRx0HGsRTBCGmdrhnWTakD5X/5T1GFc6TOw==","signatures":[{"sig":"MEUCID8xdQioG+5WkFLhWDgWw5ogVMf2fjvZ+WfD80bjExj7AiEAuERxyFrSaviVdDwDXCysiUWKCL+8IFEpIqRLkU8vtkk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88827},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"dc59637e33afa39645b96a4f11474820fc0ad3f7","scripts":{"dev":"node --watch dist/index.js","test":"node tests/mcp-server.test.mjs","build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"asoba","email":"shingai@asoba.co"},"repository":{"url":"git+https://github.com/AsobaCloud/sdlc-integrity-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"MCP Server for enterprise SDLC code integrity: lifecycle teardown parity, mock theater detection, DRY violations, and safety checks for shell, JS, and Python.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"esprima":"^4.0.1","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-integrity-mcp_1.0.1_1786148230262_0.785798154970583","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@asobacloud/sdlc-integrity-mcp","version":"1.0.2","description":"MCP Server for enterprise SDLC code integrity: lifecycle teardown parity, mock theater detection, DRY violations, and safety checks for shell, JS, and Python.","keywords":["mcp","sdlc","code-integrity","devops","safety-checker","audit","model-context-protocol"],"author":{"name":"Asoba","email":"support@asoba.co"},"license":"MIT","homepage":"https://github.com/AsobaCloud/sdlc-integrity-mcp","repository":{"type":"git","url":"git+https://github.com/AsobaCloud/sdlc-integrity-mcp.git"},"type":"module","main":"dist/index.js","bin":{"sdlc-integrity-mcp":"bin/cli.js"},"scripts":{"build":"tsc","start":"node dist/index.js","dev":"node --watch dist/index.js","test":"node tests/mcp-server.test.mjs","prepublishOnly":"npm run build && npm test"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","esprima":"^4.0.1"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.4.0"},"engines":{"node":">=22.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"gitHead":"e51a4b33b44b83e124782f0b4d03f73b9a9a25dc","types":"./dist/index.d.ts","_id":"@asobacloud/sdlc-integrity-mcp@1.0.2","bugs":{"url":"https://github.com/AsobaCloud/sdlc-integrity-mcp/issues"},"_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-+M5hpSrVoJelfeNYPjOIjIMRY9rprexNZMpR/JgKtHQ/lVx/W51rvI4lV6QUdEuR99sAsG/EPaZt9VafbyTLEQ==","shasum":"b8fd1352c87c8d4afe8f6209c92ae067db945df7","tarball":"https://registry.npmjs.org/@asobacloud/sdlc-integrity-mcp/-/sdlc-integrity-mcp-1.0.2.tgz","fileCount":28,"unpackedSize":88971,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFmSTiQBGsAYVNLHpdZ3uEekKnum1RHGhooRxjNgy4v6AiBV7skMGogqiMkquFQt9HWeSFwauRw5A9Kif2ANv+Irag=="}]},"_npmUser":{"name":"asoba","email":"shingai@asoba.co"},"directories":{},"maintainers":[{"name":"asoba","email":"shingai@asoba.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdlc-integrity-mcp_1.0.2_1786171606096_0.493678845026966"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-07T21:46:42.639Z","modified":"2026-08-08T06:46:46.380Z","1.0.0":"2026-08-07T21:46:42.928Z","1.0.1":"2026-08-08T00:17:10.467Z","1.0.2":"2026-08-08T06:46:46.240Z"},"bugs":{"url":"https://github.com/AsobaCloud/sdlc-integrity-mcp/issues"},"author":{"name":"Asoba","email":"support@asoba.co"},"license":"MIT","homepage":"https://github.com/AsobaCloud/sdlc-integrity-mcp","keywords":["mcp","sdlc","code-integrity","devops","safety-checker","audit","model-context-protocol"],"repository":{"type":"git","url":"git+https://github.com/AsobaCloud/sdlc-integrity-mcp.git"},"description":"MCP Server for enterprise SDLC code integrity: lifecycle teardown parity, mock theater detection, DRY violations, and safety checks for shell, JS, and Python.","maintainers":[{"name":"asoba","email":"shingai@asoba.co"}],"readme":"# <img src=\"https://raw.githubusercontent.com/AsobaCloud/sdlc-integrity-mcp/master/docs/asoba-logo.svg\" alt=\"Asoba\" width=\"36\" height=\"36\" align=\"bottom\" /> SDLC Code Integrity\n\nMCP server for enterprise SDLC code integrity. AI coding agents call its tools over the [Model Context Protocol](https://modelcontextprotocol.io/) to scan a workspace for lifecycle teardown gaps, mock-theater tests, DRY violations, and language-specific safety issues in shell, JavaScript/HTML, and Python.\n\n[![npm](https://img.shields.io/npm/v/@asobacloud/sdlc-integrity-mcp.svg)](https://www.npmjs.com/package/@asobacloud/sdlc-integrity-mcp)\n[![CI](https://github.com/AsobaCloud/sdlc-integrity-mcp/actions/workflows/ci.yml/badge.svg)](https://github.com/AsobaCloud/sdlc-integrity-mcp/actions/workflows/ci.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n\n## Quick start\n\nSet `SDLC_WORKSPACE` to the absolute path of the repo to audit. If omitted, the server uses its process working directory. The server speaks MCP over **stdio** (no HTTP port).\n\n### Cursor\n\nAdd to `~/.cursor/mcp.json` or the project `.cursor/mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"sdlc-integrity\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@asobacloud/sdlc-integrity-mcp\"],\n      \"env\": {\n        \"SDLC_WORKSPACE\": \"/absolute/path/to/your/repo\"\n      }\n    }\n  }\n}\n```\n\nRestart Cursor (or reload MCP servers), then ask the agent to run the integrity tools.\n\n### Claude Code\n\nCLI (user scope):\n\n```bash\nclaude mcp add --transport stdio --scope user \\\n  --env SDLC_WORKSPACE=/absolute/path/to/your/repo \\\n  sdlc-integrity -- npx -y @asobacloud/sdlc-integrity-mcp\n```\n\nOr put the same JSON under `mcpServers` in project `.mcp.json` (team-shared) or `~/.claude.json` (user-wide):\n\n```json\n{\n  \"mcpServers\": {\n    \"sdlc-integrity\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@asobacloud/sdlc-integrity-mcp\"],\n      \"env\": {\n        \"SDLC_WORKSPACE\": \"/absolute/path/to/your/repo\"\n      }\n    }\n  }\n}\n```\n\nVerify with `claude mcp list`. Project `.mcp.json` servers need approval the first time you open the repo in Claude Code.\n\n### Codex\n\nCLI:\n\n```bash\ncodex mcp add sdlc-integrity --env SDLC_WORKSPACE=/absolute/path/to/your/repo -- npx -y @asobacloud/sdlc-integrity-mcp\n```\n\nOr edit `~/.codex/config.toml` (or project `.codex/config.toml` in a trusted project):\n\n```toml\n[mcp_servers.sdlc-integrity]\ncommand = \"npx\"\nargs = [\"-y\", \"@asobacloud/sdlc-integrity-mcp\"]\n\n[mcp_servers.sdlc-integrity.env]\nSDLC_WORKSPACE = \"/absolute/path/to/your/repo\"\n```\n\nCodex CLI, the IDE extension, and the ChatGPT desktop Codex host share this config.\n\n### Run directly\n\n```bash\nnpx -y @asobacloud/sdlc-integrity-mcp\n```\n\n## Tools\n\n| Tool | Runtime | What it checks |\n|------|---------|----------------|\n| `AuditCodeIntegrity` | `python3` | Lifecycle teardown parity, mock-theater test detection, naming invariants, swallowed exceptions, DRY / duplicative functions. Returns structured JSON. |\n| `ShellSafetyChecker` | `bash` | Missing `set -euo pipefail`, shebang issues, hardcoded credentials, background-job silent-failure risk; optionally [shellcheck](https://www.shellcheck.net/) errors. |\n| `JsSafetyChecker` | `node` | JS/HTML syntax errors, duplicate function definitions, duplicate HTML element IDs (AST-based via [esprima](https://www.npmjs.com/package/esprima)). |\n| `PythonSafetyChecker` | `python3` | [bandit](https://bandit.readthedocs.io/) (High/Critical), [ruff](https://docs.astral.sh/ruff/), AST checks for `eval`/`exec`, pickle loads, hardcoded credentials, mutable default args. |\n\nEach tool accepts:\n\n- `target` — file or directory to scan (relative paths resolve against `SDLC_WORKSPACE`)\n- `timeout` — optional timeout in ms (default `120000`, max `600000`)\n\nChecker exit code `1` (findings) becomes `isError: true` on the MCP result. Unexpected crashes are reported as errors.\n\n## Requirements\n\n| Runtime | Required for |\n|---------|----------------|\n| Node.js ≥ 22 | MCP server + `JsSafetyChecker` |\n| Python 3 | `AuditCodeIntegrity`, `PythonSafetyChecker` |\n| bash | `ShellSafetyChecker` |\n\nOptional (skipped with a warning if missing):\n\n| Tool | Improves |\n|------|----------|\n| [shellcheck](https://www.shellcheck.net/) | `ShellSafetyChecker` |\n| [bandit](https://bandit.readthedocs.io/) | `PythonSafetyChecker` |\n| [ruff](https://docs.astral.sh/ruff/) | `PythonSafetyChecker` |\n\n## Custom rules\n\nDrop JSON tool configs into `<workspace>/.sdlc-rules/`. Local rules **override** bundled tools with the same `name`, or add new ones. Script paths resolve relative to `.sdlc-rules/`.\n\n```json\n{\n  \"name\": \"MyCustomAudit\",\n  \"description\": \"Project-specific integrity check\",\n  \"input_schema\": {\n    \"type\": \"object\",\n    \"properties\": {\n      \"target\": { \"type\": \"string\", \"description\": \"File or directory to scan\" },\n      \"timeout\": { \"type\": \"integer\", \"description\": \"Timeout in ms (max 600000)\" }\n    }\n  },\n  \"execution\": {\n    \"runtime\": \"python3\",\n    \"script\": \"./my-audit.py\",\n    \"args\": [\"--target\", \"{{target}}\"],\n    \"default_timeout\": 120000,\n    \"max_timeout\": 600000\n  }\n}\n```\n\n`{{placeholder}}` values are filled from the tool call. If a value is omitted, that flag and its placeholder are skipped.\n\n## Architecture\n\n```\nrules/*.json   → tool schemas + execution specs\nscripts/*      → checker subprocesses\nsrc/loader.ts  → bundled rules + .sdlc-rules/ overlay\nsrc/runner.ts  → spawn, timeouts, exit-code → isError\nsrc/index.ts   → MCP stdio server\nbin/cli.js     → npx / bin entrypoint\n```\n\n## Development\n\n```bash\ngit clone https://github.com/AsobaCloud/sdlc-integrity-mcp.git\ncd sdlc-integrity-mcp\nnpm install\nnpm run build\nnpm test\n```\n\n| Script | Purpose |\n|--------|---------|\n| `npm run build` | Compile TypeScript → `dist/` |\n| `npm test` | E2E via real MCP `Client` + fixture assertions for all tools |\n| `npm start` | Run the server on stdio |\n| `npm run dev` | `node --watch` on `dist/` |\n\nLocal MCP config (instead of npx):\n\n```json\n{\n  \"mcpServers\": {\n    \"sdlc-integrity\": {\n      \"command\": \"node\",\n      \"args\": [\"/absolute/path/to/sdlc-integrity-mcp/dist/index.js\"],\n      \"env\": {\n        \"SDLC_WORKSPACE\": \"/absolute/path/to/your/repo\"\n      }\n    }\n  }\n}\n```\n\n## Releasing\n\nCI runs build + E2E on every push/PR. To publish a new version:\n\n1. Bump `version` in `package.json`\n2. Commit, push, and create a GitHub Release (`gh release create vX.Y.Z --generate-notes`)\n3. `.github/workflows/publish.yml` publishes to npm (Trusted Publisher / OIDC, or `NPM_TOKEN` if configured)\n\n## License\n\nMIT © [Asoba](https://asoba.co)\n","readmeFilename":"README.md"}