# io.github.NickLiapin/tdcv2 (npm · tdcv2-mcp)

Deterministic test data from a .tdc config, generated locally by the TDCv2 engine.

- Trust score: 79/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- npm · `tdcv2-mcp`: 79/100 (this document), [markdown](https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp.md), [page](https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp)

## Channel facts

- Registry: `npm`
- Package: `tdcv2-mcp`
- Version: `0.1.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 33 of 119 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to NickLiapin/tdcv2-agents).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 2 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 59/100
  - 25% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 956 tokens (~106/item across 9 items; 6 tools + 3 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the io.github.NickLiapin/tdcv2 MCP server?

io.github.NickLiapin/tdcv2 runs locally as an npm package, launched with npx -y tdcv2-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add nickliapin-tdcv2 -- npx -y tdcv2-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "nickliapin-tdcv2": {
      "command": "npx",
      "args": [
        "-y",
        "tdcv2-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "nickliapin-tdcv2": {
      "command": "npx",
      "args": [
        "-y",
        "tdcv2-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add nickliapin-tdcv2 -- npx -y tdcv2-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "nickliapin-tdcv2": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "tdcv2-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add nickliapin-tdcv2 --command npx --arg -y --arg tdcv2-mcp
```

### Hermes

```yaml
mcp_servers:
  nickliapin-tdcv2:
    command: "npx"
    args: ["-y", "tdcv2-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "nickliapin-tdcv2": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "tdcv2-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add nickliapin-tdcv2 -t stdio -c npx -a -y tdcv2-mcp
```

### Other

```json
{
  "mcpServers": {
    "nickliapin-tdcv2": {
      "command": "npx",
      "args": [
        "-y",
        "tdcv2-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-02 (score 79, +16)

- [security improvement] Malware scan: unverified → pass

### 2026-10-01 (score 63, −14)

- [security regression] Malware scan: pass → unverified
- [functional improvement] Stability: unverified → 0.07
- [functional] Package version: 0.1.1 → 0.1.2

### 2026-09-30 (score 77, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-09-29 (score 62)

First indexed and scored.

## MCP tools (6)

### `tdc_check` (~99 tokens)

Check a TDCv2 config

Validate a .tdc config without generating anything. Returns every diagnostic with its code, line, column, hint and "did you mean" suggestion, plus warnings and whether a seed is set. Run it until the config is clean.

Input parameters:

- `config` (string): The .tdc config text. Give this or `path`.
- `path` (string): A .tdc file, relative to the project folder. Give this or `config`.

### `tdc_generate` (~256 tokens)

Generate data from a TDCv2 config

Make test data — CSV, JSON, SQL, any text — from a .tdc config, instead of writing a generator script. Without `output`: renders in memory and returns the first `preview` lines (max 50) — nothing is written. With `output`: writes the whole file inside the project folder and returns its size, a per-column summary and the first lines. A failed <assert> comes back as row, message, condition and values, so the config can be fixed. Same config and seed give the same bytes every time.

Input parameters:

- `config` (string): The .tdc config text. Give this or `path`.
- `count` (integer): Override <env count> for this run. For the delivered file keep count in the config instead.
- `output` (string): File to write, relative to the project folder. Omit to preview only.
- `path` (string): A .tdc file, relative to the project folder. Give this or `config`.
- `preview` (integer): Lines to return (default 10, max 50).
- `seed` (string): Override <env seed> for this run. For the delivered file keep seed in the config instead.

### `tdc_find_packs` (~141 tokens)

Find TDCv2 data packs

Search the data packs installed on this machine by words ("last name", "iban", "city") — the paths to write in <gen type="template" value="…"/>. Never guess a path; ask this. Returns path, the locales that have it, and what it holds (never the values).

Input parameters:

- `limit` (integer): At most this many results (default 15).
- `locale` (string): Only packs for this locale, e.g. "fr". Says how to install it if missing.
- `query` (string, required): Words to look for, English works best: "last name", "email", "country".

### `tdc_peek` (~109 tokens)

Summarise a generated file

A short summary of a CSV, JSON or SQL file in the project: row count; per column the distinct values, the split, the range; INSERT rows per table. The proof that a file holds what was asked, without reading it all.

Input parameters:

- `column` (string): One column in full (up to 50 values with counts).
- `path` (string, required): The file, relative to the project folder.
- `rows` (integer): Sample rows to include (default 3).

### `tdc_read_docs` (~149 tokens)

Read the TDCv2 guide and reference

Start here when asked for test data, fixtures or seed data: the TDCv2 guide ("guide" — read it before the first config), traps check does not catch ("traps"), using the data from test code in five languages ("from-code"), the list of reference pages ("index"), or one reference page such as "generators/date". `query` searches the page list.

Input parameters:

- `offset` (integer): For long pages: continue from this character.
- `page` (string): guide | traps | from-code | index | a reference path like generators/date. Default: guide.
- `query` (string): Words to find in the page list instead of opening a page.

### `tdc_format` (~49 tokens)

Format a TDCv2 config

Pretty-print a .tdc config the way `tdcv2 format` does. Returns the text unchanged if it does not parse.

Input parameters:

- `config` (string, required): The .tdc config text.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp#diagnostics

## Score history

- 2026-10-03: 79
- 2026-10-02: 79
- 2026-10-01: 63
- 2026-09-30: 77
- 2026-09-29: 62

## Common questions

### What is the io.github.NickLiapin/tdcv2 MCP server?

io.github.NickLiapin/tdcv2 is an MCP server listed in the public MCP registry as io.github.NickLiapin/tdcv2. Deterministic test data from a .tdc config, generated locally by the TDCv2 engine. This page covers its npm package (tdcv2-mcp).

### Is the io.github.NickLiapin/tdcv2 MCP server safe to use?

io.github.NickLiapin/tdcv2 scores 79 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 3 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.NickLiapin/tdcv2 MCP server expose?

io.github.NickLiapin/tdcv2 exposes 6 tools: tdc_check, tdc_generate, tdc_find_packs, tdc_peek, tdc_read_docs, tdc_format. Their descriptions and schemas cost roughly 803 tokens of context every time the server is loaded.

### Is the io.github.NickLiapin/tdcv2 MCP server still maintained?

io.github.NickLiapin/tdcv2 is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the io.github.NickLiapin/tdcv2 MCP server under?

io.github.NickLiapin/tdcv2 declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/tdcv2-mcp
- Socket report: https://socket.dev/npm/package/tdcv2-mcp
- Repository: https://github.com/NickLiapin/tdcv2-agents
- Changelog RSS feed: https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp.json
- HTML version of this page: https://verifymcp.io/servers/nickliapin-tdcv2/tdcv2-mcp
