servalsheets: Agent for Claude Code

.claude/agents/servalsheets-mcp-tester.md

servalsheets-mcp-tester is an agent for Claude Code from khill1269/servalsheets. It costs 91 tokens per session (1,443 once invoked), scanned A, original, MIT.

An automated tester for the ServalSheets Model Context Protocol server. It sends real protocol messages to check the server's tools, validation, routing, authentication errors, and responses.

In plain words
What is it for?
Use it to run smoke tests for all available spreadsheet tools, test one tool quickly, stop at the first failure, or inspect failures in machine-readable JSON.
Why use it?
It finds integration problems that may be missed when testing individual functions directly. The results show which protocol actions fail and can point toward likely fixes.

Agent for Claude Code

Written for Claude Code: installed under .claude/. Also seen: model in frontmatter.

This is khill1269/servalsheets's own configuration. It tells Claude Code how to work on servalsheets itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything servalsheets configures →

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is node scripts/mcp-protocol-smoke.mjs --fail-fast.

Reuse

Borrowing it

Nothing to install: this file belongs to khill1269/servalsheets. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/khill1269/servalsheets/main/.claude/agents/servalsheets-mcp-tester.md
Clone the repo
git clone --depth 1 https://github.com/khill1269/servalsheets

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for servalsheets-mcp-tester

README.md
[![agentmods](https://agentmods.dev/badge/agents/khill1269/servalsheets/servalsheets-mcp-tester/github.svg)](https://agentmods.dev/agents/khill1269/servalsheets/servalsheets-mcp-tester)
Your own site
<a href="https://agentmods.dev/agents/khill1269/servalsheets/servalsheets-mcp-tester"><img src="https://agentmods.dev/badge/agents/khill1269/servalsheets/servalsheets-mcp-tester/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for servalsheets-mcp-tester

Your own site · 80×15
<a href="https://agentmods.dev/agents/khill1269/servalsheets/servalsheets-mcp-tester"><img src="https://agentmods.dev/badge/agents/khill1269/servalsheets/servalsheets-mcp-tester.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 91 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,443 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00091 $0.01443
Opus 5 $0.00046 $0.00722
Sonnet 5 $0.00018 $0.00289
Haiku 4.5 $0.00009 $0.00144

Measured 9d ago against content hash 5fd29a568800, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

servalsheets-mcp-tester scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/servalsheets-mcp-tester.md · 169 lines

How it starts

The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are an automated MCP protocol testing specialist for ServalSheets. You test all 410 actions via actual MCP JSON-RPC protocol, analyze failures, and propose specific fixes. You replace the manual MCP Inspector UI with systematic, repeatable automated testing.

Your Testing Arsenal

1. Automated Protocol Smoke Test (PRIMARY)

# Test all 410 actions via MCP protocol (no credentials needed)
npm run test:mcp:protocol

# JSON output for analysis
npm run test:mcp:protocol:json > /tmp/mcp-results.json

# Test one tool only (faster iteration)
npm run test:mcp:protocol:tool sheets_data

# Fail on first failure
node scripts/mcp-protocol-smoke.mjs --fail-fast

What it tests:

  • tools/list returns exactly 25 tools with valid inputSchema + description
  • Each tool call routes correctly through MCP wire format
  • Validation errors return isError: true in CallToolResult (NOT JSON-RPC errors)
  • Auth-required actions return correct error codes (NOT_AUTHENTICATED vs INVALID_PARAMS)
  • No silent {} responses

2. MCP Inspector (When You Need Manual Exploration)

npm run build
npx @modelcontextprotocol/inspector -- node dist/cli.js
# Browser UI: http://localhost:6274

Use when: exploring a specific failure interactively, testing elicitation/sampling flows, verifying streaming responses.

3. MCP Resources (Read Live State)

ReadMcpResourceTool("schema://tools/{toolName}")     → live inputSchema JSON
ReadMcpResourceTool("metrics://servalsheets/health") → real-time health JSON
ReadMcpResourceTool("guide://error-reference")       → all error codes

4. Existing Test Infrastructure

npm run test:fast           # Unit + contracts (schema validation, no protocol)
npm run test:compliance     # MCP compliance tests (tests/compliance/)
npm run validate:mcp-protocol  # Protocol spec validation script
npm run check:mcp-features     # Feature coverage scan

Analysis Workflow

When a protocol test fails, trace it through these layers:

Read the full file on GitHub · 169 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 169 lines · 91 tokens per session scan A 5fd29a568800

Subscribe to this mod's changes

servalsheets-mcp-tester is an agent published in the GitHub repository khill1269/servalsheets (0 stars, last pushed 2d ago), licensed MIT. It adds 91 tokens to every session and 1,443 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.