22 of them apply only to a server that is a program rather than a URL, and
replace the ones that have no meaning over a pipe. A run reports every check it
did not make, by id and with the reason, rather than leaving it out.
130 of those are fixed, and 1 is a family whose id is built at run time —
one check per value the run encounters, marked * below.
This file is generated from the source: every check is created through
(*Session).check(id, title), and this table is those call sites. CI fails
when it drifts, so the figure passmcp publishes is the figure it implements.
A check may be reached from more than one branch — a handshake can fail in
several ways and report the same id. The count is of distinct ids, because
that is what a reader sees in a report.
These run only under passmcp a2a check, against an agent that speaks the Agent2Agent protocol rather than MCP. They are not a phase of an MCP run: they read the agent's Agent Card and make one unauthenticated read, and the id names the protocol because that is the first thing a reader needs to know about them.
These run only when the server is a program and --watch-egress was given. They belong to the resilience phase, at the end of the run, because where a server went is only fully answered once it has had the whole run to go there. The id names the observation rather than the phase, because that is what a reader is looking for.
These run only when the server is a program and --plant-canaries was given. They belong to the resilience phase: the decoys are planted before the process starts and read back after it ends, so the answer is only complete once the run is. The id names what was watched rather than the phase, because that is what a reader is looking for.
These run only when the server is a program rather than a URL. They belong to the connectivity and resilience phases, not to a phase of their own: a pipe has no name to resolve and no session to lose, so they take the place of the checks that do.
Check
What it looks for
stdio.alive
Server survived the run
stdio.bind_all
Server listens on no public interface
stdio.clean_exit
Server stopped when its input closed
stdio.environment
Environment handed to the server
stdio.launch_config
Launch commands carry no shell, download or secret
stdio.no_zombie
The server left nothing running
stdio.post_init_connections
No connection nobody asked for, after the handshake
stdio.post_init_processes
Processes started after the handshake
stdio.post_init_writes
No writes outside the working directory, after the handshake
These run only when the server is a program, and read the file rather than ask the server anything. They belong to the connectivity phase, which is where passmcp establishes what it is talking to; the id names what was read because that is what a reader is looking for.