MCP proxy and CLI for the Action Receipts protocol. Built on @attest-protocol/attest-ts. See attest-protocol/spec for the full spec.
- Language: TypeScript (ESM)
- Package manager: pnpm (via corepack)
- Linting & formatting: Biome (tabs, double quotes)
- Testing: vitest
- Git hooks: lefthook (pre-commit: lint + typecheck)
pnpm run build # tsc
pnpm run typecheck # tsc --noEmit
pnpm run lint # biome check .
pnpm run lint:fix # biome check --write .
pnpm run check # typecheck + lint
pnpm run test # vitest run
pnpm run test:watch # vitestsrc/
proxy/ # MCP proxy emitter + interceptor
cli/ # list, inspect, export, verify, stats commands
test-utils/ # shared test factories
Core SDK (receipt, store, taxonomy) lives in @attest-protocol/attest-ts — import from there, not local paths.
- All changes go through pull requests — never push directly to main
- Always request review from
Copilotwhen creating a PR (use the API:gh api repos/{owner}/{repo}/pulls/{number}/requested_reviewers -X POST --input -with{"reviewers":["Copilot"]}; the--reviewerflag ongh pr createdoesn't support bot reviewers)
Re-read every changed file with fresh eyes before committing. Check for:
- Input validation: empty strings, missing fields, unexpected types, duplicates
- Resource cleanup: streams, readers, DB connections, event listeners, timers
- Unbounded growth: maps/arrays that grow per-request without cleanup or caps
- Security: string interpolation in SQL/commands, unsanitized user input
- Guard rails: double-init, double-attach, use-after-close
- Test gaps: is there a test for the error/edge path, not just the happy path?
Fix issues and amend the commit — don't push a separate "fix review feedback" commit.
- Use
import typefor type-only imports (enforced byverbatimModuleSyntax) - All files use
.tsextension, output todist/ - Test files:
*.test.tsalongside source files insrc/ - Run
pnpm run lint:fixbefore committing to match Biome formatting