RowAttest
Runs an eight-stage isolation test against your staging Supabase and issues a signed attestation.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"rowattest": {
"url": "https://app.rowattest.com/mcp"
}
}
}远程端点
https://app.rowattest.com/mcpstreamable-http它能做什么
工具清单
工具(6)
🟢list_projects
Lists the Supabase projects connected to this account with id, name, connection state and whether each is ready to run. Call this first to get a project_id.
输入模式
{
"type": "object",
"properties": {},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢run_review(project_id)
Starts an authorization test run on a connected project and returns the run_id and status. If the project already has a run waiting to start, returns that run instead of starting another. Runs that do not fail count against the monthly allowance.
输入模式
{
"type": "object",
"properties": {
"project_id": {
"type": "string"
}
},
"required": [
"project_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_run_status(run_id)
Returns a run's status (queued, running, complete or failed), its current stage, timestamps and, when a signed report exists, its verify_url.
输入模式
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢wait_for_run(run_id, timeout_seconds)
Waits up to timeout_seconds (1 to 60) for a run to finish, then returns the same information as get_run_status. Call it again while the status is still queued or running.
输入模式
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
},
"timeout_seconds": {
"type": "number"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_findings(run_id)
Returns the cells that did not pass in a complete run that has a signed report — verdict, surface, operation, boundary, identity, layer outcomes and notes — plus tenancy flags and blocking findings. For a complete run with no signed report, while one can still be bought on the run page, it returns the run's unverified result instead: the verdict, surface, operation and principal of each cell that did not pass, the run page's finding lines, the counts, the coverage lines and the access model summary. The list of cells is empty when every tested cell passed. Contains no fix suggestions: the engine records only what it observed.
输入模式
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_report(run_id)
Returns the full signed report of a complete run as the exact stored JSON, with its verify_url and report_sha256 (sha256 of the canonical signed bytes, the fingerprint shown on the verify page). Use get_findings for the compact view.
输入模式
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}社区
证据