{"_id":"@assurly/mcp-server","_rev":"9-45ec129a0a0bdcdfbe0776f1f455525c","name":"@assurly/mcp-server","dist-tags":{"latest":"1.2.2"},"versions":{"1.0.0":{"name":"@assurly/mcp-server","version":"1.0.0","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.0.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://github.com/assurly/assurly/issues"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"1e0ec617af541c126875a6933e9c4d774f0837e0","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.0.0.tgz","fileCount":4,"integrity":"sha512-TsAq26e94/iWwaDRsOBpi7xlGLWBglhkL8K7mJ96ZLz1VnSQI64BWGrXvoyD7nwcQYpfEihvNiJv6+OLNxR/Hg==","signatures":[{"sig":"MEYCIQC3qX+9DJVlQI1yDgE4PaL4B5flrh2pLMm1FrSIgN4+tQIhAKylNuQ5dgUd0z2D7iwCuAbOthQ7ASkvRtIvIRp945Ay","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fmcp-server@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10824},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"0c9b239855921573b36f3f44af4ae23579837052","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.0.0","@assurly/scanner-core":"1.0.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.0_1783533529292_0.6571872638508711","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@assurly/mcp-server","version":"1.0.1","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.0.1","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://github.com/assurly/assurly/issues"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"830c60b318547b7dc1565b2993cae5a87595c50e","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.0.1.tgz","fileCount":4,"integrity":"sha512-q7W4NggcMUVISpDDMhNAW6cEyPGTBS8uyFNnimjPDE8Hkj/Bp83JSoEtbvtdE9m3Rv8MTxoEIFC1sjAi97f0fg==","signatures":[{"sig":"MEYCIQDVn3CsSE3PC7hFLSvjNR97Vuvqa8hwsMifV/X6KbKU6QIhAOyIrULdQHAMcNJcu2Z94M7BzJOzrOW68kg1aC8qbCVQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fmcp-server@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10824},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"8d26cfba60f1ac2479fc47771c3f4c4eb3e20aa2","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.0.1","@assurly/scanner-core":"1.0.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.1_1783535126067_0.6321795763625038","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@assurly/mcp-server","version":"1.0.2","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.0.2","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://github.com/assurly/assurly/issues"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"a75a4e85a51e6a9be530b1f90cf7376c5d7691ef","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.0.2.tgz","fileCount":4,"integrity":"sha512-a3eGo5DY2OvVaE4xfodHeNoDGQ905Xj+aHz+wVUifkR9qMXoBsG81N83VTtYGVsMOa7O66LW/SpdcVsO5m0nNw==","signatures":[{"sig":"MEUCIDNX8V6/zApwOtemT61zkVdeYyHwTGpGTTw88MNFpVq1AiEAyfmxZuArljBi6hH5ighu1vZhb2MBw1GBt5OVWqAUoNU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fmcp-server@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":11148},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"ac2021c0dc3907932e0a3aa7ce8eaf02c9a4e3d4","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.0.2","@assurly/scanner-core":"1.0.2","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.2_1783546110511_0.34603863758561393","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@assurly/mcp-server","version":"1.0.3","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","windsurf","vibe-coding","agent-tools","lovable"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.0.3","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"91fe3e6e1acd5936a8dcf573d9f690801de9768e","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.0.3.tgz","fileCount":5,"integrity":"sha512-Xz3rHMizy2Qq1KC2mtikkgsWyU46gCnPqiIQEkztM9VG4UMlqPLm055swfbwMzPcODzHAd3hE+BZktBXK/WTbg==","signatures":[{"sig":"MEUCIQD8pyMiiRx85FeveDSyAgwXsHKRuCcQ0S83hJSVYYhrEgIgb2+O744ndplF80gFp8Ng39A7H0WREyJnaDGJEPcyt08=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15771},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"4ed08c94dadc62eea014c42244b2e587ff8ee0c3","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.0.3","@assurly/scanner-core":"1.0.3","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.3_1784667048465_0.1814857315229541","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@assurly/mcp-server","version":"1.0.4","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","windsurf","vibe-coding","agent-tools","lovable"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.0.4","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"d7ddd0e9800444b0466c0f433ad4ca36dcd88e9b","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.0.4.tgz","fileCount":5,"integrity":"sha512-IW0k5rfjCF02raP+t/LvaWcnZws7uY4yIwU5OuXBq2zYYlqtkT+gkexmoZqaWdAiEosDEkpsM7DxXaRpPMbb8w==","signatures":[{"sig":"MEQCIGMEjYTMyRLSTNyZUVCcsV+D0eETuqg/BX1X48b4h748AiBboJH4XlV1n72KYLU09rnTwL2smOHkgaHz/HRaRCzn2w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16177},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"86ef4045166751457648e824d87ed904c97bbb5e","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.0.4","@assurly/scanner-core":"1.0.4","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.4_1784710754794_0.6878207084121277","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@assurly/mcp-server","version":"1.1.0","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","windsurf","vibe-coding","agent-tools","lovable"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.1.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"5b7d85d5ce690ff01be2453fad95cce7a4a53793","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.1.0.tgz","fileCount":5,"integrity":"sha512-S68NKZrqkM9n+JAOT05wquMfqhuKNgG9OUpCSEGEYu46oZa3Zt0cjn6vXSoGzpoKoL8zO8klKzBtzQxyEYQ75g==","signatures":[{"sig":"MEYCIQDSkdRNMFNK0ZBKFb8N4LwVP0DmGsoA1bknStEngTFxpQIhALMLecuqU1EFkShQAKkJ9/0N6+3mn/mU3O6KuMrWzexJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21267},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"2dafa4820f891f38ef25caa10fc8eb633ea6410f","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.1.0","@assurly/scanner-core":"1.1.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.0_1785092244572_0.580075752244231","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@assurly/mcp-server","version":"1.2.0","keywords":["mcp","model-context-protocol","mcp-server","cursor","claude-code","ai-agents","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","windsurf","vibe-coding","agent-tools","lovable"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.2.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"fd736ad68c95f40740479b8f9e42a3f13a75fd22","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.2.0.tgz","fileCount":5,"integrity":"sha512-ryZE/U7K8oki/7KZVpuJidKaZBjzIGbP8EhOTjyFCUROTwPN/8SGI+nXxlivlifJpl0uV2M71Sth+qv0O/5GwQ==","signatures":[{"sig":"MEUCIQCx24BD66Ks3nHJSmII5h7DcgKhbwYXJCWBZuSMgmXG0QIgNTquEf9QwLSGWpiMB2kUrcWcEFB6YlK5ekNdzb3DIv0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21757},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"7e7ac0b90c2100de2fefe1a60ddd3a79809f9c49","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server exposing Assurly Ship Gate scans to AI agents — a pre-deploy ship gate Cursor and Claude Code call before shipping","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.2.0","@assurly/scanner-core":"1.2.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.2.0_1785130900539_0.7072103172421982","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@assurly/mcp-server","version":"1.2.1","keywords":["mcp","model-context-protocol","mcp-server","mcp-security","agent-security","agent-tools","prompt-injection","cursor","claude-code","windsurf","vscode","ai-agents","allowscripts","install-scripts","npm12","supply-chain-security","slopsquat","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","vibe-coding"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/mcp-server@1.2.1","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev/mcp","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"bin":{"assurly-mcp":"dist/index.js"},"dist":{"shasum":"82832bbd270a0b42ba44f2470e8c16ee7700bdc8","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.2.1.tgz","fileCount":5,"integrity":"sha512-98yX8jln1xqPrnF1le3XvQk257sj8QhRhMENM2Fb2nMR+1VbpTNfzxevB0fGj/ygy2ffgr2xRbNBZ9KxrxT6Fg==","signatures":[{"sig":"MEUCIQC6jOJjfcYNCwpQNs/kT+xJD8pL2gZipeC5B+8e2AKWHAIgXLlidgt3M48W3Tzeru4S5TQyX/MDWy+q1ltaZkUsHGY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25153},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"f1cfd6916f4becbed2159eb3efb1043396ee1197","scripts":{"dev":"tsc -w","test":"vitest run src","build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"10.9.8","description":"MCP server that gives Cursor, Claude Code, VS Code and Windsurf a pre-deploy ship gate. Five tools: scan a path or files, explain a rule, read a hosted verdict, and audit the agent stack itself (MCP config and instruction files).","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.22.4","assurly":"1.2.1","@assurly/scanner-core":"1.2.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","esbuild":"^0.28.1","typescript":"^5.3.3","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.2.1_1785139719015_0.3485163706561998","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@assurly/mcp-server","version":"1.2.2","mcpName":"dev.assurly/mcp-server","description":"MCP server that gives Cursor, Claude Code, VS Code and Windsurf a pre-deploy ship gate. Five tools: scan a path or files, explain a rule, read a hosted verdict, and audit the agent stack itself (MCP config and instruction files).","keywords":["mcp","model-context-protocol","mcp-server","mcp-security","agent-security","agent-tools","prompt-injection","cursor","claude-code","windsurf","vscode","ai-agents","allowscripts","install-scripts","npm12","supply-chain-security","slopsquat","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","vibe-coding"],"homepage":"https://assurly.dev/mcp","main":"dist/index.js","types":"dist/index.d.ts","bin":{"assurly-mcp":"dist/index.js"},"engines":{"node":"^20.19.0 || >=22.12.0"},"scripts":{"build":"node -e \"require('fs').rmSync('dist',{recursive:true,force:true})\" && esbuild src/index.ts --bundle --platform=node --target=node22 --outfile=dist/index.js --packages=external","typecheck":"tsc --noEmit","dev":"tsc -w","test":"vitest run src"},"dependencies":{"@modelcontextprotocol/sdk":"1.29.0","assurly":"1.2.2","@assurly/scanner-core":"1.2.2","zod":"^3.22.4"},"devDependencies":{"@types/node":"^20.11.0","esbuild":"^0.28.1","typescript":"^5.3.3","vitest":"^4.1.8"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/assurly/assurly.git","directory":"packages/mcp-server"},"license":"MIT","author":{"name":"Assurly"},"bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"_id":"@assurly/mcp-server@1.2.2","gitHead":"24077ed38d474a7b516177500f4fd33c7b006b11","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-t3dvPFaENw/x6vJxsahh1ySZcF2vC6wpbewgkJJxoJwvuNB8rWyoHJgZxCxRkdZBbbN+9xG1cxyKCMX4aCzdBg==","shasum":"c6475a2f3cb391733ebd804c6b2a15177a39e1e9","tarball":"https://registry.npmjs.org/@assurly/mcp-server/-/mcp-server-1.2.2.tgz","fileCount":5,"unpackedSize":25529,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDr/UgF5y2qQUIJ0wkGUYignJnpNP1HV+epmL9W8c63xAIgOdQS0a9HDGTrqp6drY/+XHpismz8/I++rqde9QbNV9c="}]},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"directories":{},"maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_1.2.2_1785428172202_0.5145537383263883"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-08T17:58:49.129Z","modified":"2026-07-30T16:16:12.697Z","1.0.0":"2026-07-08T17:58:49.428Z","1.0.1":"2026-07-08T18:25:26.197Z","1.0.2":"2026-07-08T21:28:30.644Z","1.0.3":"2026-07-21T20:50:48.634Z","1.0.4":"2026-07-22T08:59:14.954Z","1.1.0":"2026-07-26T18:57:24.722Z","1.2.0":"2026-07-27T05:41:40.672Z","1.2.1":"2026-07-27T08:08:39.165Z","1.2.2":"2026-07-30T16:16:12.415Z"},"bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"author":{"name":"Assurly"},"license":"MIT","homepage":"https://assurly.dev/mcp","keywords":["mcp","model-context-protocol","mcp-server","mcp-security","agent-security","agent-tools","prompt-injection","cursor","claude-code","windsurf","vscode","ai-agents","allowscripts","install-scripts","npm12","supply-chain-security","slopsquat","security","ship-gate","static-analysis","pre-deploy","nextjs","supabase","vibe-coding"],"repository":{"type":"git","url":"git+https://github.com/assurly/assurly.git","directory":"packages/mcp-server"},"description":"MCP server that gives Cursor, Claude Code, VS Code and Windsurf a pre-deploy ship gate. Five tools: scan a path or files, explain a rule, read a hosted verdict, and audit the agent stack itself (MCP config and instruction files).","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"readme":"# @assurly/mcp-server\n\n**A pre-deploy ship gate your AI agent calls before shipping.** A local stdio [MCP](https://modelcontextprotocol.io) server that lets Cursor, Claude Code, and other MCP clients scan a Next.js + Supabase + Stripe + Vercel project and get one trusted verdict — blockers to fix, warnings to review — _before_ the agent ships to production.\n\nThe agent that wrote your app can now check it: **write code → `assurly_scan_path` → fix blockers → re-scan until READY TO SHIP.**\n\n**Your source code never leaves your machine.** The scanning tools run entirely locally over stdio and mirror the `assurly scan` pipeline exactly (`allRules` + detector + Ship Gate report), so an agent scan matches the CLI on the same project. The one tool that talks to the network, `assurly_verdict`, is opt-in and sends only the URL or repo name you ask about — never source.\n\n## In short\n\n`@assurly/mcp-server` is a local stdio MCP server that gives an AI coding agent a\npre-deploy ship gate. It exposes five tools: scan a project directory, scan in-memory\nfiles, explain a rule id, read a hosted verdict for a deployed URL or repository, and\naudit the agent's own stack. A blocked verdict is returned with `isError: true`, so the\nagent stops instead of shipping. Install it with `npx -y @assurly/mcp-server`; it works\nwith Cursor, Claude Code, VS Code and Windsurf.\n\n## Can a scanner check the agent's own setup?\n\n`assurly_scan_agent` does. It reads the MCP client configuration and the instruction files\nan agent is given — `.cursor/mcp.json`, `.vscode/mcp.json`, `README.md`, `CLAUDE.md`,\n`AGENTS.md`, `.cursorrules`, pull-request and issue templates — and reports eight classes\nof problem:\n\n> An MCP server configured to run `bash` or pipe a download into a shell can execute\n> arbitrary code from the agent session. A remote MCP endpoint on plain `http://` exposes\n> tool traffic and credentials in transit. A credential written directly into an MCP `env`\n> block is usually committed or synced. And an instruction file can carry directives that a\n> reader never sees but a model always does — hidden inside an HTML comment or zero-width\n> characters — including text that tries to override the agent's prior instructions or tell\n> it to send `.env` contents to a remote endpoint.\n\nThese are advisory: they audit the developer's tooling rather than the application being\ndeployed, so they never block a ship verdict.\n\n## Tools\n\n| Tool                   | Description                                                   | Network |\n| ---------------------- | ------------------------------------------------------------- | ------- |\n| `assurly_scan_path`    | Scan a local project directory                                | Local   |\n| `assurly_scan_files`   | Scan in-memory `{ path, content }[]` files                    | Local   |\n| `assurly_explain_rule` | Explain a rule id and how to fix it                           | Local   |\n| `assurly_verdict`      | Read the hosted ship verdict for a deployed URL or repository | Hosted  |\n| `assurly_scan_agent`   | Advisory audit of MCP configs and agent instruction files     | Local   |\n\n`assurly_verdict` returns the status, Ship Score, and top issue, and sets `isError: true` when the verdict is **blocked** — so the agent stops instead of shipping. It requires `ASSURLY_API_KEY` (see [Connect the hosted verdict](#connect-the-hosted-verdict)).\n\n## How do I stop my AI agent from deploying broken code?\n\nGive it a gate it must call, and make a failed gate an error rather than a suggestion.\n\n> [The MCP specification](https://modelcontextprotocol.io/specification) lets a tool return\n> `isError: true`, and agents treat that as a failed call rather than a result to interpret.\n> Assurly uses it deliberately: a **blocked** verdict comes back as an error, so the agent\n> stops and reports instead of deciding for itself whether the finding matters. Advisory\n> findings never set it — a gate that errors on everything is a gate the agent learns to\n> work around.\n\nPaste the rules from [assurly.dev/mcp](https://assurly.dev/mcp) into `.cursorrules`,\n`CLAUDE.md` or `AGENTS.md` so the agent calls the gate before every deploy without being\nasked.\n\n## Does my source code leave my machine?\n\nNo, for the four local tools. `assurly_scan_path` and `assurly_scan_files` run the rules in\nthis process over stdio, and `assurly_explain_rule` is a lookup. The fifth tool,\n`assurly_verdict`, is the only one that reaches the network, and it sends only the URL or\nrepository name you ask about — never file contents. It is opt-in: without\n`ASSURLY_API_KEY` it does nothing.\n\n## Which MCP clients does this work with?\n\nAny client that speaks stdio MCP. Configuration examples below cover Cursor, Claude Code,\nVS Code and Windsurf. Note that VS Code uses a `servers` key where Cursor and Windsurf use\n`mcpServers` — copying a config between them without renaming that key is the most common\nreason a server appears not to load.\n\n## Requirements\n\nNode `^20.19.0 || >=22.12.0`.\n\n## Install (npm)\n\nRun the server directly with npx — no global install needed:\n\n```bash\nnpx -y @assurly/mcp-server\n```\n\n## Cursor (`.cursor/mcp.json`)\n\nAdd this server next to your other MCP entries:\n\n```json\n{\n  \"mcpServers\": {\n    \"assurly\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@assurly/mcp-server\"]\n    }\n  }\n}\n```\n\nAfter saving, restart Cursor (or reload MCP) and confirm the five `assurly_*` tools appear.\n\n## Claude Code\n\nFrom your project directory:\n\n```bash\nclaude mcp add assurly -- npx -y @assurly/mcp-server\n```\n\n## VS Code (`.vscode/mcp.json`)\n\nVS Code uses the top-level key `servers`, not `mcpServers`:\n\n```json\n{\n  \"servers\": {\n    \"assurly\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@assurly/mcp-server\"]\n    }\n  }\n}\n```\n\n## Windsurf (`~/.codeium/windsurf/mcp_config.json`)\n\n```json\n{\n  \"mcpServers\": {\n    \"assurly\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@assurly/mcp-server\"]\n    }\n  }\n}\n```\n\n## Any other stdio client\n\nPoint the client at `npx` with these arguments:\n\n```json\n{\n  \"command\": \"npx\",\n  \"args\": [\"-y\", \"@assurly/mcp-server\"]\n}\n```\n\n## Connect the hosted verdict\n\n`assurly_verdict` reads the hosted Assurly API — it never scans locally and never triggers an active probe. Create an API key in the Assurly dashboard under **Settings → API keys** (it is shown once), then expose it to the server:\n\n```json\n{\n  \"mcpServers\": {\n    \"assurly\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@assurly/mcp-server\"],\n      \"env\": {\n        \"ASSURLY_API_KEY\": \"your-key-here\"\n      }\n    }\n  }\n}\n```\n\n`ASSURLY_API_URL` is optional and defaults to `https://assurly.dev`. Pass exactly one of `url` or `repo` (in `owner/name` form) when calling the tool.\n\n## Typical agent loop\n\n1. Agent writes or edits code.\n2. Call `assurly_scan_path` or `assurly_scan_files`.\n3. Read blockers from the Ship Gate summary.\n4. Call `assurly_explain_rule` for remediation hints.\n5. Fix issues and re-scan until the verdict is **READY TO SHIP**.\n6. Before deploying, call `assurly_verdict` — a blocked verdict comes back as an error, so the agent halts rather than shipping.\n\n## Troubleshooting\n\n| Symptom                           | Fix                                                                                                                |\n| --------------------------------- | ------------------------------------------------------------------------------------------------------------------ |\n| Tools do not appear               | Restart the client or reload MCP, then confirm the five `assurly_*` tools are listed.                              |\n| `ASSURLY_API_KEY is not set`      | Create a key in the Assurly dashboard (Settings → API keys) and expose it to this MCP server as `ASSURLY_API_KEY`. |\n| `invalid or revoked (401)`        | The key is no longer valid. Issue a new one.                                                                       |\n| `Provide exactly one of url/repo` | `assurly_verdict` takes one target, not both and not neither.                                                      |\n| Server fails to start             | Check your Node version against the requirement above.                                                             |\n\n## Build from source (contributors)\n\nIf you are working on this repository directly, build and point your MCP client at the local output:\n\nFrom the repo root:\n\n```bash\nnpm run build -w assurly\nnpm run build -w @assurly/mcp-server\n```\n\nRun (stdio):\n\n```bash\nnode packages/mcp-server/dist/index.js\n```\n\nCursor (`.cursor/mcp.json`) with an absolute path to your clone:\n\n```json\n{\n  \"mcpServers\": {\n    \"assurly\": {\n      \"command\": \"node\",\n      \"args\": [\"/absolute/path/to/assurly/packages/mcp-server/dist/index.js\"]\n    }\n  }\n}\n```\n\nClaude Code:\n\n```bash\nclaude mcp add assurly -- node /absolute/path/to/assurly/packages/mcp-server/dist/index.js\n```\n\nReplace `/absolute/path/to/assurly` with the path to this repository on your machine.\n","readmeFilename":"README.md"}