One endpoint. Connect the chatbot you already use — Claude, ChatGPT, Cursor, Codex — and it can survey any repository, repair what the survey finds, and harvest the whole tree into a sealed capability ledger. This server does the mechanical work and hands back the method, so the only model in the loop is the one you are already talking to.
Two minutes on what the SHPBL MCP server is, how it attaches to the chatbot you already use, and what a run hands back. Prefer to read? The user's manual covers all of it.
Presented by my AI Founder Twin · Written & approved by Kenneth E. Sweet Jr.
Connect in three steps
1 · Add the endpoint
https://shpbl.com/mcp
This door speaks OAuth. Your client registers itself, opens a sign-in page, and you approve it once — no key is ever typed into a client or a prompt.
2 · Sign in and bind your key once
Signing in proves who you are; it does not prove what you bought. Bind your subscription key to your account at your account and every agent you connect afterwards carries your tier automatically. Stage one needs none of this — the free tools answer any caller.
3 · Client cannot sign in? Use the key-only door
https://shpbl.com/api/public/mcp
Authentication None, transport Streamable HTTP, plus one request header: Authorization: Bearer shpbl_mcp_YOUR_KEY. Same 17 tools. If your client cannot send headers either, pass the key as the tool's optional key argument.
Is it working?
Paste your key once. This page checks it exactly as the tools do and answers in one line: tier, status, calls used this month, and whether pull requests are switched on.
What you can ask for
The free lane evaluates the repository and stops at the composition boundary: neither library is searched, so no candidates or architecture come back. It does not run the full gauntlet. Practitioner at $39 a month runs that governed sequence — both libraries read to your agent as cited rows, new capability composed and verified, and the report, diffs and harvested capabilities written into your own repository as a pull request.
What you keep, you can reuse. Every kept run leaves an index at .shpbl/README.md in your own repository. Tell your agent to read it and pass those lines back as own_library on the next run, and the audit checks your own capabilities before citing anything else — so you never harvest the same thing twice. Those entries are read for that one call and never stored by us.
Source rules are simple: harvest from public repositories that carry a proper open-source license, from your own repositories, or from private repositories you have access to. The server never reads a repo you have no right to read, and it never absorbs customer harvests into the public library.
Ten meta-capabilities
These are our engines, not yours to find. They live privately inside the SHPBL MCP tree and they govern how a run is conducted — what it attends to, what it carries between steps, how it recovers, what it may touch and what it may spend. Every run states the rules they impose and holds them for the whole run. They are never harvested, never cited as prior art, and never counted as a capability found in your code.
MENGINE-CREATIVE-FORGE
Creative Forge
generative synthesis and pattern evolution
MENGINE-WORLD-FIRST-COGNITIVE
World-First Cognitive
attention, memory, intent and DREAM-style evolution in one cognitive layer
MENGINE-DEEP-COGNITION-NEXUS
Deep Cognition Nexus
deep reasoning, dialogue understanding, observability and debt analysis
MENGINE-KNOWLEDGE-NEXUS
Knowledge Nexus
graph, context and retrieval-based knowledge management
MENGINE-MEMORY-INTELLIGENCE-FABRIC
Memory Intelligence Fabric
tiered memory, salience scoring and memory-aware reasoning
MENGINE-INTELLIGENCE-PIPELINE
Intelligence Pipeline
synthesis, insight and prediction into actionable intelligence
MENGINE-QUALITY-FABRIC
Quality Fabric
continuous quality, compliance, audit and traceability
MENGINE-RESILIENCE-SHIELD
Resilience Shield
rollback, policy access, prompt safety and operational resilience
MENGINE-SECURITY-FORTRESS
Security Fortress
zero-trust security, threat defense and compliance posture
MENGINE-RESOURCE-GOVERNOR
Resource Governor
budget, quota, entitlement and spend control
The procedure is law
A capable model handed a good method will improvise a faster-looking shortcut: run the whole thing in one turn, merge three steps into one, infer a finding it never read. Every one of those produces a report that looks complete and isn’t. So the server enforces the run rather than requesting it.
One step per turn
Your agent calls a step, does it, tells you one plain line, then calls the next. Never two at once, never the whole gauntlet in one go.
No inference
If the supplied material doesn't answer something, it writes “not present”. No finding without a path.
Order enforced, not asked
From step 2 on, the call is refused without the ledger from the step before it — a skipped step can't be hidden.
You approve every stretch
Every 3 harvest steps the run pauses until your agent has reported back and you've said keep going.
Moderate steps
Each step is sized to about 45,000 characters, so a run stays readable and the cost stays visible.
One legal deviation
Only a collision with a stated guideline — a hands-off path, a licence boundary. Then it stops, says which step and which rule, and waits for you.
One run, start to finish
1
Point at a repo
Tell the chatbot you already use to audit a GitHub repository — or POST the same tool from a script. Nothing to install.
All three deliveries
2
Read it blind
The repository is surveyed as it actually is before any suggestion is made — files, languages, spine files, risk signals.
All three deliveries
3
Audit
What exists, what works, what hurts, and what must be left exactly as it is.
All three deliveries
4
Repair and harvest
A ranked repair order with diffs and guards, plus the capabilities your repository already contains, named and classed into a sealed ledger.
All three deliveries
5
The composition boundary
A free run establishes that new capability could be composed here — then stops, before either library is searched. No candidates, no library rows, no architecture.
Free stops here
6
Compose, then keep it
Practitioner continues: both libraries searched, candidates evaluated, new capability composed and verified, then landed in your own repository as a pull request.
$39/mo, 7 free days
01
Point at a repo
Tell the chatbot you already use to audit a GitHub repository — or POST the same tool from a script. Nothing to install.
All three deliveries
→
02
Read it blind
The repository is surveyed as it actually is before any suggestion is made — files, languages, spine files, risk signals.
All three deliveries
→
03
Audit
What exists, what works, what hurts, and what must be left exactly as it is.
All three deliveries
→
04
Repair and harvest
A ranked repair order with diffs and guards, plus the capabilities your repository already contains, named and classed into a sealed ledger.
All three deliveries
→
05
The composition boundary
A free run establishes that new capability could be composed here — then stops, before either library is searched. No candidates, no library rows, no architecture.
Free stops here
→
06
Compose, then keep it
Practitioner continues: both libraries searched, candidates evaluated, new capability composed and verified, then landed in your own repository as a pull request.
$39/mo, 7 free days
The same run, as a ring
Nothing is written before the verdict, and nothing leaves the ring before the gate. A run that ends with “this already works” has still completed the circle.
Who owns which stage
Every colour on this site is one of the six lit facets of the mark, and each facet owns one concern of the run. Nothing is tinted for variety.
01 · harvestReading what is already thereIt reads what is already in your repository and lifts out the parts that solved something real, with provenance. Everything else is left exactly where it sits.
02 · evaluateVerdict before repairEvery finding is tagged and located — defect, missing dependency, performance risk — and nothing is written until the verdict is on paper.
03 · composeParts into wholesVerified parts are composed into higher-order capability instead of being rewritten from scratch, and composites are counted separately from candidates.
04 · libraryOn the shelf, not in a chat logEach kept capability lands on a shelf with a name, a citation and a licence, readable by the next agent that opens the repository. Chat logs are not a library.
05 · repairThe right part in the right placeApproved repairs fit verified components into the broken structure, then prove the result before anything is allowed to move.
06 · shipNothing moves unauthorisedWrite-back is authorised, single-use and expiring: a signed build intent or nothing moves, and what clears the gate arrives as a pull request you can read.
Stage One
Evaluate
Free · no key needed
evaluate_repo
The repository as it actually is: file and byte counts, language spread, spine files, tree-born risk signals, opening library matches and the ten meta-capability run rules that bind the run. Then the evaluation protocol your agent carries out. Works on public repositories with proper licensing, your own repos, and private repos you have access to.
Stage Two
Fix
Included in the free evaluation
fix_repo
A repair order for the files you name, ranked by what fails silently first, with own-library reuse, the meta-capability run rules, unified diffs, the guard that should catch each fault next time, and what was left alone and why. Your agent writes the repairs; you approve every change.
Stage Three
Harvest
Included in the free evaluation
harvest_repo
The shortcut straight to the capabilities: point it at a repository you hold a reuse licence to, and it reads what that repository can already do, fuses those affordances with the owned SHPBL capability library, then names ranked proposals a person can read. You decide on each one; only the ones you approve are emitted as seed modules into your own .shpbl library. It never writes to the target repository.
Stage All of it
Run the gauntlet
$39/mo Practitioner · first 7 days free
run_gauntlet
The full governed sequence: survey, own-library and catalog comparison, evaluation, repair, batched harvest, closing comparison, composition, verification, branded HTML report and pull-request delivery. One call to plan it, one call per step to walk it.
Replace OWNER/REPO with the repository, or ask your agent to call list_repos and pick from the list. Paid stages page their material: tell your agent to walk every part before it concludes.
What a run will never touch
A repository is not only source. It is also the wiring your own tools read — your Lovable project, your Cursor or Claude workspace, your package manager, your host’s build. A change that looks obviously right in a diff can take a running app down the moment it is merged, and the diff will not show it.
So the method draws a hard line rather than a preference. These are read, quoted and written about, and never edited, renamed or deleted by a run:
.env and any environment file
every lockfile — bun, npm, pnpm, yarn, Cargo, Go, Composer
backend wiring and migration history, and generated database clients
build, CI and deploy configuration — workflows, Vercel, Netlify, Wrangler, Docker
version-control internals, vendored output, and any credential or signing file
The write-back tool refuses those paths outright — every tier, no override. When a real finding lives behind one, your agent is instructed to hand it to you as advice instead: the file, the finding, the change it would make and what it would affect, for you or your own agent to decide.
Or let your agent read the manual
Every fact on this page is published in one machine-readable file. Paste this to your assistant and it connects itself:
Read https://shpbl.com/llms.txt and connect to the SHPBL MCP server
described in it, then explain in plain language what it can do for me.
Once it is connected, its first call is welcome — free, no key — which hands it the greeting, the whole tool menu and the sentences you can say. You can read the same thing yourself in the user's manual.
Full client reference — Claude, ChatGPT, Cursor, Codex
Claude.ai (web or mobile)
Settings → Connectors → Add custom connector
Sign-in door (recommended)
URL https://shpbl.com/mcp
Auth OAuth — Claude registers itself and asks you to sign in
Key-only door
URL https://shpbl.com/api/public/mcp
Auth None
Transport Streamable HTTP (under Advanced)
Under “Request headers” press Add header:
Header name Authorization
Value Bearer shpbl_mcp_YOUR_KEY
Claude Desktop / Claude Code
Settings → Connectors, or claude_desktop_config.json
Name SHPBL
Description Governed repository audit and capability harvest
MCP server https://shpbl.com/mcp
Auth OAuth
Then press Create and Connect — ChatGPT registers itself,
you sign in once, approve, and the seventeen tools appear.
Turn the connector on in the composer (+ → Apps) before you ask.
Client cannot sign in? Use the key-only door:
URL: https://shpbl.com/api/public/mcp
Auth: none (No authentication)
Header: Authorization: Bearer shpbl_mcp_YOUR_KEY
Cursor
.cursor/mcp.json in your project, or Settings → MCP
Add a remote server of transport type “streamable HTTP”
url = "https://shpbl.com/mcp" # OAuth
transport = "http"
# or the key-only door:
# url = "https://shpbl.com/api/public/mcp"
# headers = { Authorization = "Bearer shpbl_mcp_YOUR_KEY" }
The exact prompts to say, stage by stage
Evaluate · Free · no key needed
“Use the SHPBL MCP server to evaluate github.com/OWNER/REPO, then follow the protocol it returns. Hold the ten meta-capability run rules and use public repositories with proper licensing, my own repos, or private repos I have access to.”
Fix · Included in the free evaluation
“Use the SHPBL MCP server's fix_repo to repair the findings in github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Check my own .shpbl library first, keep holding the ten meta-capability run rules, walk every part, then give me the repair order, the diffs and the guards.”
Harvest · Included in the free evaluation
“Use the SHPBL MCP server's harvest_repo on github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Show me the ranked capability proposals with the host evidence each one mounts on, and wait for my decision before building anything.”
Run the gauntlet · $39/mo Practitioner · first 7 days free
“Use the SHPBL MCP server's run_gauntlet on github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Start with no step to get the run card, read my .shpbl library if present, state the ten meta-capability run rules, walk every step in order, then close the run and give me the HTML report.”
Tiers and what each one opens
Try · Try
Free
No key required
The diagnosis, run for real, free: audit, every capability found in your repository, the full benchmark, the ordered repair plan, and the harvest walked batch by batch into a sealed ledger. It stops at the composition boundary: neither library is searched, so no candidates, library rows, parents or proposed architecture are returned, and nothing is retained. No key, no card over MCP or the API.
·`evaluate_repo` — the complete audit: report, every capability with signature, file, line and stated contract, the full benchmark
·`fix_repo` — verbatim source of every file you name, with the ordered remediation protocol
·`harvest_repo` — the harvest shortcut for a repository you hold a reuse licence to: what it can already do, and how much owned capability is offerable against it. Ranked, named proposals and the seed modules they carry require Practitioner
·Reads a PRIVATE repository free, when a `github_token` is passed or the SHPBL GitHub App is connected to your key. Paced at 60 calls a minute rather than charged.
·Stops before composition: the run establishes that a composition opportunity exists, then ends — no library search, no candidates, no Build Intent, no foundry
·Nothing persists: no pull request, no export, no recorded run. Each run names what a subscription would have kept.
·`list_repos` — real repository names, and whether a pull request can be opened
·Seven volumes: titles, messages, epigraphs, seals, read and download links
·`selfcheck_mcp` — the server audited against its own seven axes, live, pass/fail
Practitioner · Borrow
$39/mo
100,000 calls / month
Borrow the library: the library read as cited rows, and every run kept — written back into your own repository as a pull request, exported, sealed. What a run produces is yours outright.
·`run_gauntlet` — the full governed sequence: audit, repair, harvest, both libraries searched, composition, verification and optional write-back
·`compose_capability` — the harvest lane: Capability Grants that fuse what your software already does with owned SHPBL primitive capabilities, each with its bound bodies, declared ports, seed module, wiring and limits
·`write_to_repo` — land repairs, ledgers and reports as a branch and a pull request, uncapped
·`library_search` — the engineered component ledger and the capability units, as cited rows: ID, name, capability, class, verification axes, matched-on
·`library_document` — any volume in full, the catalog outline, the report template, the standing order
·Run export and sealed run records, plus cross-repository comparison
·Your runs are yours: no licence back to us, no claim on your harvests or your repairs
·100,000 tool calls a month
·One key per subscription, rotatable on request
Write back to a repository
On a paid key, install the official SHPBL GitHub App on the repositories you choose and the tools can open pull requests instead of handing you text to copy. Nothing is ever pushed to your default branch.
Have a Practitioner key in the field above.
Click Connect on GitHub and pick the account and the repositories.
Authorize. You return here with “Connected.”
Ask your agent to use fix_repo or write_to_repo; it opens a pull request for you to merge.
Paste your key in the field above first.
What this grants, and what it does not
We never ask for a personal access token and store no credential of yours.
Access is scoped to the repositories you tick, with permission to write files and open pull requests. Nothing more.
Each run mints a one-hour token and drops it. You revoke the whole thing in your GitHub settings in one click.
Each key is separate: another subscriber installs the app on their own account with their own key, and never reaches your repositories.
Installed the app straight from GitHub? GitHub does not send us your key in that case — press Already installed — bind it once.
Prefer to install nothing? Your agent can pass a one-off github_token on the call instead — used once, never stored — or simply hand you the diffs.