GitPin
GitPin is a read-only, index-free MCP server that helps you prove and verify claims against local Git repositories by providing evidence packs with full SHA, line, and path. Its main capabilities include:
Discover repositories (
pin.catalog): List registered Git roots, HEAD SHAs, doc counts, and stale status.Search for candidates (
pin.search_docs/pin.search_code): Find documentation and code snippets (usinggit grepat HEAD) as candidates, not final claims.Prove claims (
pin.prove/pin.prove_set): Generate evidence packs for one or multiple file paths (up to 8) with line slices, full SHA, content hash, and a citable handle;pin.prove_setreturns an evidence set ID for multi-repo answers.Read pinned content (
pin.get_doc/pin.read): Retrieve committed documentation or specific source file slices with full SHA; sensitive paths are blocked.Verify claims (
pin.verify/pin.verify_set): Re-check path@SHA pairs usinggit show, optionally validating required text; reports HEAD match and verdict;pin.verify_sethandles batch verification for up to 8 citations.Analyze evidence (
pin.analyze): Produce an EvidenceBrief summarizing known facts, gaps, and an evidence set ID for decision-making.Inspect repository state (
pin.inspect): Examine HEAD-pinned status, recent commits, manifests, tests, or changes; dirty (uncommitted) work is excluded from evidence.Compare revisions (
pin.compare): Diff changed paths between two commits for change review.
Provides tools for proving and verifying agent claims against Git repositories, pinning answers to HEAD commits, full SHAs, and specific files and lines, with read-only access and support for local Git roots.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@GitPinProve the claim that the API key is loaded in src/config.ts:42 and verify the SHA."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
GitPin
Make agent-authored changes show exact evidence before merge.
GitPin is an agent-delivery assurance gate with a local evidence MCP. It makes material PR claims cover the actual diff and point to exact committed line slices. The local MCP supplies index-free, read-only, multi-repo evidence that humans and CI can re-check with git show.
Agent claim
→ pin.search_* (candidates only)
→ pin.prove (evidence pack: path + line + full SHA + content hash)
→ pin.verify (git show re-check; HEAD match report)
→ you run: git show <sha>:<path>Crowded category | GitPin product |
Vector / SQLite “repo context” servers | No embeddings, no DB, no reindex |
Filesystem MCP (writes) | Never writes indexed repos |
One-shot repo dumps | Live prove → verify MCP loop |
Grep hits as “the answer” | Candidates → evidence pack → verification report |
GitHub platform MCP | Local Git roots (private/offline) |
Formerly RepoContext 0.3.x. See migration.
Required PR evidence gate
gitpin gate --base <full-base-sha> --head <full-head-sha>The gate reads policy only from the trusted base commit, reads the submitted manifest only from the head commit, compares the merge-base diff, and verifies exact line-slice hashes. It never executes PR code and never labels a locator match as proof of semantic correctness. Use the GitPin GitHub Action setup to make it a required check. That guide also documents an optional, separate CrewScore check for teams that want written-control coverage alongside GitPin evidence verification.
Release candidate: GitPin 0.6.3 is prepared for npm, the MCP Registry, GitHub Releases, and Pages. After publication, install with
npx -y gitpin@0.6.3. Node 20+.
GitPin is maintained by Sarosh Hussain, who leads the project's technical direction. Pendoah is his company and operating context; GitPin remains the product and repository.
Related MCP server: repo-context
Five-minute path
# From a committed Git repository
npx -y gitpin@0.6.3 init --client codexinit creates ~/.gitpin/repositories.yaml outside the repo, runs doctor, prints a first evidence line with full SHA, and paste-ready MCP config. It never edits the indexed repository.
# Independently verify any claim (same contract as pin.verify)
npx -y gitpin@0.6.3 verify \
--repository my-service \
--path docs/architecture.md \
--line 42 \
--sha <full-or-short-hex>Product job
When agents invent file contents, mix dirty worktrees, or cite the wrong branch
You want every fact re-checkable with git show <sha>:<path>
GitPin registers local Git roots, serves HEAD-only docs/code, flags stale tracked docs, returns path / line / SHA, and closes the loop with pin.verify.
Agent tool surface (pin.*) — 12 read-only tools
Job | Tools |
Discover |
|
Find candidates |
|
Prove |
|
Verify |
|
Decide |
|
Inspect / diff |
|
Resource: gitpin://catalog. Prompt: prove-with-git-head (forces the product loop).
Cite formats: docs/cite-spec.md. Agent skill template: templates/gitpin-skill.md.
Functionality that is the pivot (not a rename)
Evidence pack (
pin.prove): claim binding, line slice, full SHA,contentSha256,citation.cite/handle, next-step verify.Multi-cite sets (
pin.prove_set/pin.verify_set): stableevidenceSetIdfor multi-repo answers and CI.Verification report (
pin.verify/ CLI): independentgit show; optionalmustContainclaim-text; status includescontradicted.Candidates, not claims: search returns
kind: evidence-candidateswith forcednext: pin.prove.EvidenceBrief: multi-repo knownFacts / gaps / stable
evidenceSetId(schema v2).Dirty exclusion: uncommitted work is never cited as HEAD evidence.
Explicit non-goals
Semantic / embedding search
Writing, committing, or pushing
Replacing GitHub Issues/PRs automation
Indexing non-Git umbrella folders as one “repo”
Configuration
Variable | Purpose |
| Registry YAML path (legacy compatibility alias: |
| HTTP bearer token (legacy compatibility alias: |
| HTTP host allowlist (legacy compatibility alias: |
Default registry: ~/.gitpin/repositories.yaml (legacy compatibility fallback: ~/.repocontext/... if present).
Docs
Tools · Compare · FAQ · Migration · Clients · Architecture · Competitive landscape
Site: shmindmaster.github.io/gitpin. GitPin is the canonical product and repository name; legacy repocontext references exist only for migration compatibility.
Development
corepack enable
pnpm install --frozen-lockfile
pnpm validate
pnpm build
pnpm verify:package
pnpm site:testLicense
Maintenance
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceProvides local codebase intelligence as an MCP server, enabling AI agents to query dependencies, assess change impact, and produce tamper-evident change evidence packets.509Apache 2.0
- AlicenseDqualityBmaintenanceRead-only repository context explorer for coding agents. Provides repository exploration tools via CLI or MCP adapter.1GPL 3.0
- AlicenseAqualityBmaintenanceA local-first, model-neutral MCP server for collecting and normalizing change-scoped release evidence. It provides deterministic Git change summaries, evidence collection, and review bundles for agent review.718Apache 2.0
- AlicenseNot gradedqualityBmaintenanceExposes code graphs across multi-program repositories via MCP, enabling humans and agents to query the fleet with evidence.MIT
Related MCP Connectors
Read-only Remote MCP for externally grounded AI agent trust receipts.
Independent static verification for exact immutable public GitHub commits.
Agent-native MCP server over the public saagarpatel.dev corpus. Read-only, stateless.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/shmindmaster/gitpin'
If you have feedback or need assistance with the MCP directory API, please join our Discord server