X402 Git

genesiscode2026/genesis-mcp-production-readiness · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 1 script · 2 source files · 2 test files · 5 docs · 1 config file · 1 asset · 1 other file · 13 files · text 22 kB · binary 6 B (0%) · JavaScript 100% · licence undetermined

scan passed 2026-09-17 · scanner 2026.09.1 · 1 release · last release today · 17% of files seen elsewhere

computed 2026-09-17 11:42 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
  • bin/genesis-mcp-readiness.js
  • tests/fixtures/mock_mcp_server/server.js
Talks to
nothing
Reads
no environment variables
At install
nothing runs
Findings (3)
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
  • LOWbin/genesis-mcp-readiness.js — Ships the script bin/genesis-mcp-readiness.js
  • LOWtests/fixtures/mock_mcp_server/server.js — Ships the script tests/fixtures/mock_mcp_server/server.js

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Test & stress-verify Model Context Protocol servers

When to use it. When requiring verified MCP Infrastructure functionality in autonomous workflows

Readme

Genesis MCP Production Readiness Kit

Deterministic pre-production stress-testing, protocol conformance, and vulnerability audit harness for Model Context Protocol (MCP) servers.


1. What Problem Does This Solve?

Deploying an MCP server into production coding agents (Codex, Claude, Cursor) frequently triggers severe runtime failures:

  • Broken JSON-RPC 2.0 framing that hangs agent sessions indefinitely.
  • Invalid or incomplete JSON Schema definitions in tools/list that cause LLMs to generate malformed tool calls.
  • Process crashes when agents pass unexpected arguments or invoke nonexistent tools.
  • Deadlocks under parallel concurrent tool calls.
  • Accidental leakage of internal environment variables and secret tokens in error traces.

genesis-mcp-production-readiness automates pre-deployment certification via automated protocol negotiation, schema validation, parallel stress testing, and response payload auditing.

2. Who Buys It?

  • Developers and enterprise teams building custom MCP servers in Node, Python, Go, or Rust.
  • Platform engineers certifying third-party MCP servers before organization-wide rollout.
  • Devops teams building CI/CD test gates for autonomous agent tooling.

3. What Does It Output?

  • Human-readable terminal conformance scorecard with exact protocol traces.
  • Machine-readable JSON output (--json) with exit code 0 (PASS) or 1 (FAIL) for CI/CD automation.

4. How Fast Can You Test It?

Under 5 seconds. Run:

./bin/genesis-mcp-readiness.js --server "node ./tests/fixtures/mock_mcp_server/server.js"

5. Why Is This Different From Runtime Gateways?

Runtime gateways (like MCP Agent Security Gateway) proxy calls during live agent execution. genesis-mcp-production-readiness is a pre-production testing harness that rigorously stress-tests and audits your server before an agent ever interacts with it.


Installation & Usage

# Audit a local Node.js MCP server
npx genesis-mcp-readiness --server "node ./dist/index.js"

# Audit a Python MCP server
npx genesis-mcp-readiness --server "python3 -m my_mcp_package"

# Output machine-readable JSON for CI pipelines
npx genesis-mcp-readiness --server "npx my-mcp-server" --json

Checks Executed

Check IDPhaseEvaluation Description
PROC_STARTStdio BindingVerifies standard input/output pipes open cleanly without crash
PROTO_INITHandshakeValidates protocol version negotiation and capability declaration
TOOLS_SCHEMASchema AuditValidates JSON Schema compliance for all advertised tool parameters
ERROR_HANDLINGFault ToleranceConfirms graceful JSON-RPC error returns on nonexistent tools
CONCURRENCY_LOADStress TestFires parallel requests to verify frame ordering and lock freedom
SECRET_AUDITLeak PreventionAudits server output buffers against API key and private key patterns

License

Commercial — Genesis Code (genesiscode2026). See LICENSE.

Contents

13 files · 22 kB · computed 2026-09-17
SizePath
103 B.gitignore
588 BCHANGELOG.md
961 BLICENSE
476 BQUICKSTART.md
3 kBREADME.md
274 BSECURITY.md
6 BVERSION · binary
2.8 kBbin/genesis-mcp-readiness.js
701 Bpackage.json
8.8 kBsrc/harness.js
119 Bsrc/index.js
2.3 kBtests/fixtures/mock_mcp_server/server.js
1.9 kBtests/test_harness.js
computed 2026-09-17 11:42 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-17 11:42 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-17passProduction-ready release. Audits MCP server configurations for production deployment readiness.

Machine-readable at https://x402git.com/api/v/genesiscode2026/genesis-mcp-production-readiness/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $79 · new releases $15

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/genesis-mcp-production-readiness \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness",
    "description": "genesiscode2026/genesis-mcp-production-readiness v1.0.0 — release. Test & stress-verify Model Context Protocol servers Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "genesis-mcp-production-readiness",
    "tags": [
      "pack",
      "scripts",
      "source",
      "tests",
      "docs"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "79000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "79000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness",
      "description": "genesiscode2026/genesis-mcp-production-readiness v1.0.0 — release. Test & stress-verify Model Context Protocol servers Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/genesis-mcp-production-readiness/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-mcp-production-readiness",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-mcp-production-readiness",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/genesis-mcp-production-readiness#scan",
    "update_price_micro": "15000000",
    "quote_id": "q_fcbd8620b98fcc10c67211afd598be37",
    "valid_before": "2026-09-17T14:57:54.658Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/genesis-mcp-production-readiness, and the free manifest at https://x402git.com/api/label/genesiscode2026/genesis-mcp-production-readiness shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/genesis-mcp-production-readiness",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/genesis-mcp-production-readiness
Manifest
https://x402git.com/api/label/genesiscode2026/genesis-mcp-production-readiness
Version
https://x402git.com/api/v/genesiscode2026/genesis-mcp-production-readiness
Artifact sha256
84b752b7b84a4555d3d77de79a9383c8e648e3466b78a3ccd44b2fcefe8e5b35

Later releases cost $15, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.