Covenant

by studiomeyer-io

187 downloads Not rated yet MIT

About

Contract & breaking-change detector for MCP servers — semver for your interface. Snapshot tools/resources/prompts into a lockfile, diff in CI, fail on breaking changes. Single Rust binary, SARIF, GitHub Action.

Details

License
MIT

Explore

- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: studiomeyer-io/[email protected]

cargo install mcp-covenant

Or build from source:

git clone https://github.com/studiomeyer-io/mcp-covenant
cd mcp-covenant && cargo build --release

mcp-covenant snapshot -o mcp-covenant.lock --http https://my-server.example/mcp

2. Check in CI — non-zero exit on a breaking change:

mcp-covenant check --fail-on breaking -- node dist/server.js

3. Lint the interface for schema hygiene (the things that quietly hurt tool selection):

$ mcp-covenant lint -- node dist/server.js
mcp-covenant lint: 2 finding(s) (0 error, 1 warning, 1 info)

WARNING (1)
tool:newtool — tool has no description; the model cannot tell when to call it [tool.missing_description]
INFO (1)
tool:search → limit — parameter has no description [tool.param.missing_description]

Everything also runs fully offline against two lockfiles — no server needed:

mcp-covenant check --baseline v1.lock --against v2.lock
mcp-covenant lint   --from v1.lock

---

mcp-covenant

crates.io
CI
OpenSSF Scorecard
License: MIT

Contract & breaking-change detection for Model Context Protocol servers — semver for your MCP interface.

When you ship a typed library you have a public API and tooling that screams when you break
it. MCP servers have neither: they just serve whatever tools/list returns today. Rename a
tool, add a required argument, narrow an enum — every agent built on your server breaks, and
nothing in your pipeline noticed.

mcp-covenant is one static binary that snapshots your server's interface into a committed
lockfile and fails CI when a change would break existing clients — classified the way a
human would: breaking / minor / patch.

```text
$ mcp-covenant check --baseline mcp-covenant.lock -- node dist/server.js
mcp-covenant: 3 change(s) — required version bump: MAJOR

BREAKING (2)
x tool:legacy — tool was removed [tool.removed]
x tool:search → inputSchema.properties.limit — new required property [schema.property.required.added]
MINOR (1)
+ tool:newtool — new tool [tool.added]

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.