Skip to main content
Glama
pipsyncio

PipSync MCP Evals

Official
by pipsyncio

PipSync MCP Evals

Public safety evaluations and a no-execution MCP mock for trading-oriented tool designs.

The repository models three boundaries:

  • read-only synthetic signal listing;

  • a deterministic, non-executable paper preview;

  • a live-capable confirmation schema that the public mock always blocks.

The mock has no network client, API-key loader, credential store, broker adapter, or order-placement implementation.

Run the evaluations

PYTHONPATH=src python -m pipsync_mcp_evals.evals
PYTHONPATH=src python -m unittest discover -s tests -v

Related MCP server: ShadowRun

Run the stdio mock

PYTHONPATH=src python -m pipsync_mcp_evals.server

It accepts one JSON-RPC message per line and implements the modern, stateless MCP 2026-07-28 surface: server/discover, tools/list, and tools/call. Every request must carry io.modelcontextprotocol/protocolVersion and io.modelcontextprotocol/clientCapabilities in params._meta; every successful result carries resultType and server identity metadata. Legacy initialize is rejected with an explicit migration hint and the supported protocol version.

What the evaluations enforce

  • Every tool has explicit MCP annotations.

  • Tool input schemas reject unknown fields.

  • Confirmation is classified as non-read-only and destructive.

  • Confirmation requires account, preview, confirmation, idempotency, and risk-hash fields.

  • Missing confirmation data fails closed.

  • Even structurally complete confirmations return mock_server_no_execution.

  • Preview output is deterministic and explicitly non-executable.

  • Missing request metadata and unsupported protocol versions fail with the current MCP error contracts.

Annotations are hints, not an authorization boundary. Any real write-capable server must independently enforce authenticated tenant/account ownership, entitlement, fresh broker state, risk gates, explicit live mode, idempotency, audit, and human confirmation before every broker call.

The catalog targets the MCP 2026-07-28 tools contract and its stateless discovery contract.

Continue with PipSync

This repository deliberately cannot execute. For the managed connector setup, capability boundaries, and confirmation flow, use the PipSync MCP quickstart.

License

Apache-2.0.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A local-first stdio proxy for MCP servers that traps destructive tool calls and holds them for manual commit or discard, preventing accidental mutations.
    AGPL 3.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables MCP-compatible assistants to research prediction markets on Polymarket and Kalshi, analyze public wallets, read market signals, and run paper-only trading simulations.
    10
    36 npm
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides a safe paper-trading twin of the Binance Agent OS MCP API so agents can be rehearsed, scored, gated for go-live, and shadow-compared against live calls without using real funds.
    MIT