AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

Astray Verify

mcp-theastraydev-astray-verify · by TheAstrayDev

Record and replay MCP server contracts in CI.

No reviews yet
0 installs
1 views
0.0% view→install

Install

$ agentstack add mcp-theastraydev-astray-verify

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
23d ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Astray Verify? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Astray Verify

> Record an MCP server's contract once. Catch breaking changes before your AI clients do.

[](https://github.com/TheAstrayDev/astray-verify/actions/workflows/ci.yml) [](LICENSE) [](https://modelcontextprotocol.io/)

An MCP server can still start successfully after a release while an AI client has quietly lost a tool, received a changed JSON schema, or begun seeing invalid data on stdout. Astray Verify turns the server interface that already works today into a committed regression test.

It is a tiny, local-first test runner for authors of MCP servers and teams that maintain them.

What it does

working MCP server
       │
       ├── astray-verify record
       │       saves the expected tools and schemas
       │
       └── astray-verify test
               fails when a later change breaks that contract

In the first release, Astray Verify launches a stdio MCP server, performs the standard handshake, snapshots tools/list, and replays it later. A fixture is plain JSON, designed to be reviewed and committed with the server source.

Install

Linux and macOS

curl -fsSL https://raw.githubusercontent.com/TheAstrayDev/astray-verify/main/install.sh | sh

Windows PowerShell

curl.exe -fsSL https://raw.githubusercontent.com/TheAstrayDev/astray-verify/main/install.ps1 | powershell -NoProfile -ExecutionPolicy Bypass -

The installers download the matching binary from the latest GitHub Release.

From source

git clone https://github.com/TheAstrayDev/astray-verify.git
cd astray-verify
cargo install --path .

Quick start

Run these commands inside the repository that contains your MCP server:

astray-verify init

# Everything after -- is the command that starts your MCP server.
astray-verify record --name filesystem -- \
  npx -y @modelcontextprotocol/server-filesystem ./demo

astray-verify test

You will get two files worth committing:

astray.verify.json
fixtures/
  filesystem.mcp.json

When an intentional interface change is made, record the fixture again and review the diff just like any other API change.

Example

The repository includes a minimal MCP demo server:

mkdir /tmp/astray-verify-demo && cd /tmp/astray-verify-demo
astray-verify init
astray-verify record --name echo -- \
  python3 /path/to/astray-verify/examples/echo_server.py
astray-verify test

Expected result:

PASS  echo

Why not only use the MCP Inspector?

The official MCP Inspector is excellent for exploring and debugging a server interactively. Astray Verify is for the next step: a small, repeatable check that runs after every change in local development or CI.

| Inspector | Astray Verify | | --- | --- | | Explore and debug now | Preserve what worked for later | | Interactive | Commit-friendly fixture | | Individual calls | Regression check in CI |

Current scope

  • Stdio transport
  • MCP initialize handshake
  • tools/list contract snapshots
  • Strict JSON-RPC stdout validation
  • Human-readable failure output

Roadmap

  • [ ] Record and replay tools/call fixtures
  • [ ] Stable, reviewable JSON diff output
  • [ ] GitHub Action
  • [ ] Streamable HTTP support
  • [ ] Compatibility profiles for major MCP clients

Contributing

Issues, fixtures from real servers, and focused pull requests are welcome. Please do not add new transport or client support without a reproducible test case. The project should stay small, predictable, and useful in CI.

License

MIT. See [LICENSE](LICENSE).

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.