Metadata-Version: 2.4
Name: adversary-gate-mcp
Version: 2.10.0
Summary: AdversaryGate as an MCP server: a fail-closed merge gate an agent calls before saying done
Author-email: AdversaryGate Authors <sanflow086@gmail.com>
License-Expression: MIT
Project-URL: Homepage, https://sanflow10.github.io/adversary-gate/
Project-URL: Source, https://github.com/Sanflow10/adversary-gate
Requires-Python: >=3.10
Description-Content-Type: text/markdown
Requires-Dist: adversary-gate[mcp]==2.10.0

# adversary-gate-mcp

<!-- mcp-name: io.github.Sanflow10/adversary-gate -->

The MCP server of [AdversaryGate](https://github.com/Sanflow10/adversary-gate),
packaged so it runs with one command:

```bash
uvx adversary-gate-mcp
```

It is the same server as `pip install "adversary-gate[mcp]"` followed by
`adversary-gate-mcp`; this package ships no code of its own and pins
`adversary-gate[mcp]` at its own version.

AdversaryGate runs your tests on the baseline and on the patch and answers
MERGE, BLOCK or INCONCLUSIVE. The server gives a coding agent two tools,
`verify_repo` and `gate_policy`, so it can check its change before saying it
is done. The agent only names evidence; the operator sets the rest through the
environment:

| Variable | What it sets |
|---|---|
| `ADVERSARY_GATE_BASE_REF` | the baseline (e.g. `origin/main`). Unset, the agent may pick it, and whoever picks the baseline picks the oracle |
| `ADVERSARY_GATE_PYTHON` | the interpreter that runs the tests; one the agent cannot write to |
| `ADVERSARY_GATE_POLICY` | extra gate flags; evidence flags are refused |

Measurement covers Python/pytest today; other languages get INCONCLUSIVE, not
a false MERGE. Documentation, limits and the bug ledger:
<https://github.com/Sanflow10/adversary-gate>.
