Skip to content

Repository audit & repair · MCP

Evaluate. Fix. Harvest.

One endpoint. Connect the chatbot you already use — Claude, ChatGPT, Cursor, Codex — and it can survey any repository, repair what the survey finds, and harvest the whole tree into a sealed capability ledger. This server does the mechanical work and hands back the method, so the only model in the loop is the one you are already talking to.

Two minutes on what the SHPBL MCP server is, how it attaches to the chatbot you already use, and what a run hands back. Prefer to read? The user's manual covers all of it.

Presented by my AI Founder Twin · Written & approved by Kenneth E. Sweet Jr.

Connect in three steps

  1. 1 · Add the endpoint

    https://shpbl.com/mcp

    This door speaks OAuth. Your client registers itself, opens a sign-in page, and you approve it once — no key is ever typed into a client or a prompt.

  2. 2 · Sign in and bind your key once

    Signing in proves who you are; it does not prove what you bought. Bind your subscription key to your account at your account and every agent you connect afterwards carries your tier automatically. Stage one needs none of this — the free tools answer any caller.

  3. 3 · Client cannot sign in? Use the key-only door

    https://shpbl.com/api/public/mcp

    Authentication None, transport Streamable HTTP, plus one request header: Authorization: Bearer shpbl_mcp_YOUR_KEY. Same 17 tools. If your client cannot send headers either, pass the key as the tool's optional key argument.

Is it working?

Paste your key once. This page checks it exactly as the tools do and answers in one line: tier, status, calls used this month, and whether pull requests are switched on.

What you can ask for

The free lane evaluates the repository and stops at the composition boundary: neither library is searched, so no candidates or architecture come back. It does not run the full gauntlet. Practitioner at $39 a month runs that governed sequence — both libraries read to your agent as cited rows, new capability composed and verified, and the report, diffs and harvested capabilities written into your own repository as a pull request.

What you keep, you can reuse. Every kept run leaves an index at .shpbl/README.md in your own repository. Tell your agent to read it and pass those lines back as own_library on the next run, and the audit checks your own capabilities before citing anything else — so you never harvest the same thing twice. Those entries are read for that one call and never stored by us.

Source rules are simple: harvest from public repositories that carry a proper open-source license, from your own repositories, or from private repositories you have access to. The server never reads a repo you have no right to read, and it never absorbs customer harvests into the public library.

Ten meta-capabilities

These are our engines, not yours to find. They live privately inside the SHPBL MCP tree and they govern how a run is conducted — what it attends to, what it carries between steps, how it recovers, what it may touch and what it may spend. Every run states the rules they impose and holds them for the whole run. They are never harvested, never cited as prior art, and never counted as a capability found in your code.

  • MENGINE-CREATIVE-FORGE

    Creative Forge

    generative synthesis and pattern evolution

  • MENGINE-WORLD-FIRST-COGNITIVE

    World-First Cognitive

    attention, memory, intent and DREAM-style evolution in one cognitive layer

  • MENGINE-DEEP-COGNITION-NEXUS

    Deep Cognition Nexus

    deep reasoning, dialogue understanding, observability and debt analysis

  • MENGINE-KNOWLEDGE-NEXUS

    Knowledge Nexus

    graph, context and retrieval-based knowledge management

  • MENGINE-MEMORY-INTELLIGENCE-FABRIC

    Memory Intelligence Fabric

    tiered memory, salience scoring and memory-aware reasoning

  • MENGINE-INTELLIGENCE-PIPELINE

    Intelligence Pipeline

    synthesis, insight and prediction into actionable intelligence

  • MENGINE-QUALITY-FABRIC

    Quality Fabric

    continuous quality, compliance, audit and traceability

  • MENGINE-RESILIENCE-SHIELD

    Resilience Shield

    rollback, policy access, prompt safety and operational resilience

  • MENGINE-SECURITY-FORTRESS

    Security Fortress

    zero-trust security, threat defense and compliance posture

  • MENGINE-RESOURCE-GOVERNOR

    Resource Governor

    budget, quota, entitlement and spend control

The procedure is law

A capable model handed a good method will improvise a faster-looking shortcut: run the whole thing in one turn, merge three steps into one, infer a finding it never read. Every one of those produces a report that looks complete and isn’t. So the server enforces the run rather than requesting it.

  • One step per turn

    Your agent calls a step, does it, tells you one plain line, then calls the next. Never two at once, never the whole gauntlet in one go.

  • No inference

    If the supplied material doesn't answer something, it writes “not present”. No finding without a path.

  • Order enforced, not asked

    From step 2 on, the call is refused without the ledger from the step before it — a skipped step can't be hidden.

  • You approve every stretch

    Every 3 harvest steps the run pauses until your agent has reported back and you've said keep going.

  • Moderate steps

    Each step is sized to about 45,000 characters, so a run stays readable and the cost stays visible.

  • One legal deviation

    Only a collision with a stated guideline — a hands-off path, a licence boundary. Then it stops, says which step and which rule, and waits for you.

One run, start to finish

  1. 1

    Point at a repo

    Tell the chatbot you already use to audit a GitHub repository — or POST the same tool from a script. Nothing to install.

    All three deliveries

  2. 2

    Read it blind

    The repository is surveyed as it actually is before any suggestion is made — files, languages, spine files, risk signals.

    All three deliveries

  3. 3

    Audit

    What exists, what works, what hurts, and what must be left exactly as it is.

    All three deliveries

  4. 4

    Repair and harvest

    A ranked repair order with diffs and guards, plus the capabilities your repository already contains, named and classed into a sealed ledger.

    All three deliveries

  5. 5

    The composition boundary

    A free run establishes that new capability could be composed here — then stops, before either library is searched. No candidates, no library rows, no architecture.

    Free stops here

  6. 6

    Compose, then keep it

    Practitioner continues: both libraries searched, candidates evaluated, new capability composed and verified, then landed in your own repository as a pull request.

    $39/mo, 7 free days

The same run, as a ring
One rungovernedHarvestunit 01Evaluateunit 02Composeunit 03Libraryunit 04Repairunit 05Shipunit 06

Nothing is written before the verdict, and nothing leaves the ring before the gate. A run that ends with “this already works” has still completed the circle.

Who owns which stage

Every colour on this site is one of the six lit facets of the mark, and each facet owns one concern of the run. Nothing is tinted for variety.

  • 01 · harvestReading what is already thereIt reads what is already in your repository and lifts out the parts that solved something real, with provenance. Everything else is left exactly where it sits.
  • 02 · evaluateVerdict before repairEvery finding is tagged and located — defect, missing dependency, performance risk — and nothing is written until the verdict is on paper.
  • 03 · composeParts into wholesVerified parts are composed into higher-order capability instead of being rewritten from scratch, and composites are counted separately from candidates.
  • 04 · libraryOn the shelf, not in a chat logEach kept capability lands on a shelf with a name, a citation and a licence, readable by the next agent that opens the repository. Chat logs are not a library.
  • 05 · repairThe right part in the right placeApproved repairs fit verified components into the broken structure, then prove the result before anything is allowed to move.
  • 06 · shipNothing moves unauthorisedWrite-back is authorised, single-use and expiring: a signed build intent or nothing moves, and what clears the gate arrives as a pull request you can read.
  1. Stage One

    Evaluate

    Free · no key needed

    evaluate_repo

    The repository as it actually is: file and byte counts, language spread, spine files, tree-born risk signals, opening library matches and the ten meta-capability run rules that bind the run. Then the evaluation protocol your agent carries out. Works on public repositories with proper licensing, your own repos, and private repos you have access to.

  2. Stage Two

    Fix

    Included in the free evaluation

    fix_repo

    A repair order for the files you name, ranked by what fails silently first, with own-library reuse, the meta-capability run rules, unified diffs, the guard that should catch each fault next time, and what was left alone and why. Your agent writes the repairs; you approve every change.

  3. Stage Three

    Harvest

    Included in the free evaluation

    harvest_repo

    The shortcut straight to the capabilities: point it at a repository you hold a reuse licence to, and it reads what that repository can already do, fuses those affordances with the owned SHPBL capability library, then names ranked proposals a person can read. You decide on each one; only the ones you approve are emitted as seed modules into your own .shpbl library. It never writes to the target repository.

  4. Stage All of it

    Run the gauntlet

    $39/mo Practitioner · first 7 days free

    run_gauntlet

    The full governed sequence: survey, own-library and catalog comparison, evaluation, repair, batched harvest, closing comparison, composition, verification, branded HTML report and pull-request delivery. One call to plan it, one call per step to walk it.

Replace OWNER/REPO with the repository, or ask your agent to call list_repos and pick from the list. Paid stages page their material: tell your agent to walk every part before it concludes.

What a run will never touch

A repository is not only source. It is also the wiring your own tools read — your Lovable project, your Cursor or Claude workspace, your package manager, your host’s build. A change that looks obviously right in a diff can take a running app down the moment it is merged, and the diff will not show it.

So the method draws a hard line rather than a preference. These are read, quoted and written about, and never edited, renamed or deleted by a run:

  • .env and any environment file
  • every lockfile — bun, npm, pnpm, yarn, Cargo, Go, Composer
  • generated code — *.gen.ts, route trees, schema types, __generated__/
  • agent instruction files — AGENTS.md, CLAUDE.md, .cursor*, .lovable/
  • backend wiring and migration history, and generated database clients
  • build, CI and deploy configuration — workflows, Vercel, Netlify, Wrangler, Docker
  • version-control internals, vendored output, and any credential or signing file

The write-back tool refuses those paths outright — every tier, no override. When a real finding lives behind one, your agent is instructed to hand it to you as advice instead: the file, the finding, the change it would make and what it would affect, for you or your own agent to decide.

Or let your agent read the manual

Every fact on this page is published in one machine-readable file. Paste this to your assistant and it connects itself:

Read https://shpbl.com/llms.txt and connect to the SHPBL MCP server
described in it, then explain in plain language what it can do for me.

Once it is connected, its first call is welcome — free, no key — which hands it the greeting, the whole tool menu and the sentences you can say. You can read the same thing yourself in the user's manual.

Read llms.txt yourself.

Full client reference — Claude, ChatGPT, Cursor, Codex

Claude.ai (web or mobile)

Settings → Connectors → Add custom connector

Sign-in door (recommended)
  URL          https://shpbl.com/mcp
  Auth         OAuth  — Claude registers itself and asks you to sign in

Key-only door
  URL          https://shpbl.com/api/public/mcp
  Auth         None
  Transport    Streamable HTTP   (under Advanced)
  Under “Request headers” press Add header:
    Header name   Authorization
    Value         Bearer shpbl_mcp_YOUR_KEY

Claude Desktop / Claude Code

Settings → Connectors, or claude_desktop_config.json

{
  "mcpServers": {
    "shpbl": {
      "url": "https://shpbl.com/api/public/mcp",
      "headers": { "Authorization": "Bearer shpbl_mcp_YOUR_KEY" }
    }
  }
}

ChatGPT

Settings → Apps & Connectors → Advanced → Developer mode (on), then Create connector

Name         SHPBL
Description  Governed repository audit and capability harvest
MCP server   https://shpbl.com/mcp
Auth         OAuth
Then press Create and Connect — ChatGPT registers itself,
you sign in once, approve, and the seventeen tools appear.
Turn the connector on in the composer (+ → Apps) before you ask.

Client cannot sign in? Use the key-only door:
URL:   https://shpbl.com/api/public/mcp
Auth:  none  (No authentication)
Header: Authorization: Bearer shpbl_mcp_YOUR_KEY

Cursor

.cursor/mcp.json in your project, or Settings → MCP

{
  "mcpServers": {
    "shpbl": {
      "url": "https://shpbl.com/api/public/mcp",
      "headers": { "Authorization": "Bearer shpbl_mcp_YOUR_KEY" }
    }
  }
}

Codex / any MCP client

Add a remote server of transport type “streamable HTTP”

url = "https://shpbl.com/mcp"          # OAuth
transport = "http"

# or the key-only door:
# url = "https://shpbl.com/api/public/mcp"
# headers = { Authorization = "Bearer shpbl_mcp_YOUR_KEY" }
The exact prompts to say, stage by stage

Evaluate · Free · no key needed

“Use the SHPBL MCP server to evaluate github.com/OWNER/REPO, then follow the protocol it returns. Hold the ten meta-capability run rules and use public repositories with proper licensing, my own repos, or private repos I have access to.”

Fix · Included in the free evaluation

“Use the SHPBL MCP server's fix_repo to repair the findings in github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Check my own .shpbl library first, keep holding the ten meta-capability run rules, walk every part, then give me the repair order, the diffs and the guards.”

Harvest · Included in the free evaluation

“Use the SHPBL MCP server's harvest_repo on github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Show me the ranked capability proposals with the host evidence each one mounts on, and wait for my decision before building anything.”

Run the gauntlet · $39/mo Practitioner · first 7 days free

“Use the SHPBL MCP server's run_gauntlet on github.com/OWNER/REPO. My key is set as a request header, so call it without a key argument. Start with no step to get the run card, read my .shpbl library if present, state the ten meta-capability run rules, walk every step in order, then close the run and give me the HTML report.”

Tiers and what each one opens

Try · Try

Free

No key required

The diagnosis, run for real, free: audit, every capability found in your repository, the full benchmark, the ordered repair plan, and the harvest walked batch by batch into a sealed ledger. It stops at the composition boundary: neither library is searched, so no candidates, library rows, parents or proposed architecture are returned, and nothing is retained. No key, no card over MCP or the API.

  • `evaluate_repo` — the complete audit: report, every capability with signature, file, line and stated contract, the full benchmark
  • `fix_repo` — verbatim source of every file you name, with the ordered remediation protocol
  • `harvest_repo` — the harvest shortcut for a repository you hold a reuse licence to: what it can already do, and how much owned capability is offerable against it. Ranked, named proposals and the seed modules they carry require Practitioner
  • Reads a PRIVATE repository free, when a `github_token` is passed or the SHPBL GitHub App is connected to your key. Paced at 60 calls a minute rather than charged.
  • Stops before composition: the run establishes that a composition opportunity exists, then ends — no library search, no candidates, no Build Intent, no foundry
  • Nothing persists: no pull request, no export, no recorded run. Each run names what a subscription would have kept.
  • `list_repos` — real repository names, and whether a pull request can be opened
  • Seven volumes: titles, messages, epigraphs, seals, read and download links
  • `selfcheck_mcp` — the server audited against its own seven axes, live, pass/fail

Practitioner · Borrow

$39/mo

100,000 calls / month

Borrow the library: the library read as cited rows, and every run kept — written back into your own repository as a pull request, exported, sealed. What a run produces is yours outright.

  • `run_gauntlet` — the full governed sequence: audit, repair, harvest, both libraries searched, composition, verification and optional write-back
  • `compose_capability` — the harvest lane: Capability Grants that fuse what your software already does with owned SHPBL primitive capabilities, each with its bound bodies, declared ports, seed module, wiring and limits
  • `write_to_repo` — land repairs, ledgers and reports as a branch and a pull request, uncapped
  • `library_search` — the engineered component ledger and the capability units, as cited rows: ID, name, capability, class, verification axes, matched-on
  • `library_document` — any volume in full, the catalog outline, the report template, the standing order
  • Run export and sealed run records, plus cross-repository comparison
  • Your runs are yours: no licence back to us, no claim on your harvests or your repairs
  • 100,000 tool calls a month
  • One key per subscription, rotatable on request

Write back to a repository

On a paid key, install the official SHPBL GitHub App on the repositories you choose and the tools can open pull requests instead of handing you text to copy. Nothing is ever pushed to your default branch.

  1. Have a Practitioner key in the field above.
  2. Click Connect on GitHub and pick the account and the repositories.
  3. Authorize. You return here with “Connected.”
  4. Ask your agent to use fix_repo or write_to_repo; it opens a pull request for you to merge.

Paste your key in the field above first.

What this grants, and what it does not
  • We never ask for a personal access token and store no credential of yours.
  • Access is scoped to the repositories you tick, with permission to write files and open pull requests. Nothing more.
  • Each run mints a one-hour token and drops it. You revoke the whole thing in your GitHub settings in one click.
  • Each key is separate: another subscriber installs the app on their own account with their own key, and never reaches your repositories.
  • Installed the app straight from GitHub? GitHub does not send us your key in that case — press Already installed — bind it once.
  • Prefer to install nothing? Your agent can pass a one-off github_token on the call instead — used once, never stored — or simply hand you the diffs.

Take a key

Tier

The first 7 days are free and the key works from the first minute. Stripe holds your card and makes the first $39/mo charge on day 7; cancel before then and you are never charged. Monthly after that, cancel any time. The key is shown once, on the page you land on after checkout — the register keeps only its hash, so it cannot be read back. Lost keys are reissued by hand at dev@KESJr.com.

Cancelling

One link. Put the email on your receipt in the field above and open Stripe — cancel there, in a click, with no form to fill in and nobody to ask. Cancel inside the first 7 days and nothing is charged. Cancel later and the key keeps working until the month you have paid for runs out.