Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

tc39-mcp

NPM · TC39-MCP · 2 COMPONENTS · SCANNED AUG 3

Independent MCP server for the TC39 specs (ECMA-262 + ECMA-402): clauses, search, diffs, history.

+28 this week 81 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security86
  • No malware found by supply-chain analysis.Pass
  • Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to xyzzylabs/tc39-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 26 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability85
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 7163 tokens (~51/item across 139 items; 19 tools + 120 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
  • Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 99% of tool parameters carry a description.Partial
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · tc39-mcp

# add to Claude Code
claude mcp add xyzzylabs-tc39-mcp -- npx -y tc39-mcp
# add to Codex CLI
codex mcp add xyzzylabs-tc39-mcp -- npx -y tc39-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "xyzzylabs-tc39-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "tc39-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add xyzzylabs-tc39-mcp --command npx --arg -y --arg tc39-mcp
# ~/.hermes/config.yaml
mcp_servers:
  xyzzylabs-tc39-mcp:
    command: "npx"
    args: ["-y", "tc39-mcp"]
// mcp.json
{
  "mcpServers": {
    "xyzzylabs-tc39-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "tc39-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 +49
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • Known CVEs: unverified → partial security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • The attested source repository moved: xyzzylabs/tc39-mcp security
    • Capabilities: pass → unverified functional
    • Stability: unverified → 0.20 functional
    • Schema quality: unverified → excellent functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Maintenance: unverified → pass functional
    • Licence: MIT functional
  • 1 Aug 26 +26
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Schema quality: unverified → 100 functional
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −30
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −18
    • Malware scan: pass → unverified security
  • 27 Jul 26 53

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
xyzzylabs/tc39-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/xyzzylabs/tc39-mcp/.github/workflows/release.yml@refs/tags/v0.6.1
Rekor log index:
2105131187
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:b8f5130c27d0c620cd317e55e92b5a2980623c72d3229a422823fbc0c6bd09f55bba5f1c50f33dd0824452d190e28f3bbb8b611772a59ec2274d23a5b
Discovery method:
attestation_endpoint
Dependencies 94 packages

94 packages in the resolved dependency tree · 94 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 19 exposed · ~3,852 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
clause.get ~195

Fetch a parsed TC39 clause as structured JSON: metadata, signature, algorithm steps, notes, cross-refs, and outward citations to external specs (Unicode, IETF, WHATWG). `spec` selects '262' (default) or '402'. `edition` defaults to `latest` (current stable release on both specs — es2026 today).

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
idstringyesSpec clause id, e.g. 'sec-tonumber' (262) or 'sec-intl.numberformat' (402).
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

clause.list ~265

List parsed spec clauses with optional filters (kind, section prefix, has_algorithm). Returns lightweight rows {id, aoid, title, number, kind, algorithms}; follow up with clause.get for detail. `spec` selects '262' or '402'.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
has_algorithmbooleanIf true, return only clauses with at least one `<emu-alg>`.
kindstringFilter by clause kind (e.g. 'op', 'sdo', 'built-in function', 'concrete method').
limitintegerMax clauses returned. The full spec has ~3000 clauses; the default is a safe slice.
sectionstringFilter to clauses whose section number starts with this prefix, e.g. '22.2' for RegExp or '15' for the Locale-aware operations in ECMA-402.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

clause.outline ~203

Return the section tree (table of contents) for a parsed (spec, edition). `depth` caps tree depth (1 = top-level only). `under` anchors at a specific clause id so you get just its descendants. Each node carries { id, number, title, kind, children }.

NameTypeReqDescription
depthintegerMax tree depth to return. 1 = top-level only; 2 = first two levels; omitted = full tree.
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).
understringOptional clause id. If set, return only descendants of this clause.

No output schema declared.

No examples provided.

proposal.get ~99

Fetch one TC39 proposal by slug (exact) or name (case-insensitive). Returns { slug, name, stage, authors, champions, url, test262_flag, source_file }. Slug is canonical — use what proposal.list returns directly.

NameTypeReqDescription
namestringyesMatch against either the proposal's slug (preferred, exact-match) or its name (case-insensitive). Slug is the canonical id — use what proposal.list returns directly.

No output schema declared.

No examples provided.

proposal.list ~254

List TC39 proposals from a parsed proposals index sourced via the loader chain (local cache → hosted Worker → bundled fallback); the index is fetched on first use and cached locally. Filter by `stage` ('0'|'1'|'2'|'2.7'|'3'|'finished'|'inactive'|'active'), `champion` (substring), or `contains` (name/slug substring). Returns lightweight rows; follow up with `proposal.get`. No auth, no subprocess.

NameTypeReqDescription
championstringCase-insensitive substring filter on the champion list.
containsstringCase-insensitive substring filter applied to the proposal name + slug.
limitintegerMax proposals returned from the filtered set.
specstringFilter to one spec's proposals: '262' (core language) or '402' (Intl). tc39/proposals tracks the two in parallel — omit to list both.
stagestringFilter to one stage: '0', '1', '2', '2.7', '3', 'finished', 'inactive', or 'active' (anything in the active README — stages 2/2.7/3).

No output schema declared.

No examples provided.

spec.about ~71

Return self-description of this MCP server: package name + version, per-snapshot pin metadata (sha, fetched_at, biblio_commit, clause_count) for every supported (spec, edition), plus test262 + proposals index headers when present. Lets callers verify freshness and reproducibility without loading the parses themselves.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

spec.crossrefs ~348

For a clause id, return its outgoing references (clauses it cites) and/or incoming references (clauses that cite it — the back-reference index the parse alone doesn't expose). Direction: 'in' | 'out' | 'both' (default). Outgoing also carries an `external` category: the clause's citations to external specs (Unicode, IETF, WHATWG) as resolvable URLs. Set `include_cross_spec: true` to also resolve outgoing references from ECMA-262 → ECMA-402 (or vice versa).

NameTypeReqDescription
directionstring'in' = clauses that reference this one (back-refs); 'out' = clauses this one references; 'both' = both.
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
idstringyesSpec clause id, e.g. 'sec-tonumber' (262) or 'sec-intl.numberformat' (402).
include_cross_specbooleanIf true, outgoing references also include AOIDs that resolve to the *other* TC39 spec (262 ↔ 402). Useful for queries like 'every 262 op that calls into Intl'. Off by default because it requires load…
limitintegerMax hits returned in each direction (incoming and outgoing are limited independently).
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.diff ~166

Clause-level diff across any two editions of one spec. Defaults: from='latest', to='main' (working draft). Reports status (identical / modified / added / removed / missing-from-both) plus a field-level diff: title, signature, step count, per-step reworded indices, notes, crossrefs. `spec` selects '262' or '402'.

NameTypeReqDescription
fromstringThe 'before' edition. Defaults to the latest stable release.
idstringyesSpec clause id.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).
tostringThe 'after' edition. Defaults to the working draft (main).

No output schema declared.

No examples provided.

spec.global_search ~146

Run spec.search across both ECMA-262 and ECMA-402 in one call and interleave results by score. Each hit is tagged with the spec it came from. Useful when you don't know which spec defines the symbol (e.g. `Canonicalize` is 262, `CanonicalizeLocaleList` is 402).

NameTypeReqDescription
limitintegerTotal hits across both specs combined.
querystringyesSearch text. Matched against clause id, aoid, and title across both specs (and step text when search_steps is true).
search_stepsbooleanAlso match against algorithm step text. Slower + noisier; off by default.

No output schema declared.

No examples provided.

spec.grammar ~284

Query standalone `<emu-grammar>` productions from the spec's lexical / syntactic grammar (§11-15 in 262). Three modes: { nonterminal: 'X' } returns every production for X; { contains: 'Y' } returns productions whose RHS or non-terminal name contains Y; neither returns a list of all non-terminals with their production counts. Set include_sdo:true to also surface SDO-attached grammar headers.

NameTypeReqDescription
containsstringFilter to productions whose RHS lines or non-terminal name contain this substring (case-insensitive).
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
include_sdobooleanIf true, also include productions captured as SDO algorithm headers. Off by default — most callers want the standalone lexical/syntactic grammar definitions.
limitintegerMax productions (or non-terminal groups in list mode) returned.
nonterminalstringFilter to productions defining this non-terminal (exact match). Example: 'BindingIdentifier'.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.history ~192

Recent commits in the vendored spec checkout that touched a clause's `id="..."` token. Uses git pickaxe (`-S`) so it catches clause creation, deletion, and edits to the opening tag reliably; interior-text-only edits won't show. Returns SHA, date, author, subject per commit. `spec` selects '262' or '402'.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
idstringyesSpec clause id.
limitintegerMax commits returned from the vendored spec checkout's git log.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.sdo_index ~250

Index Syntax-Directed Operations by the grammar production they handle. SDOs are abstract operations (Evaluation, BoundNames, etc.) with one `<emu-alg>` per production. Default by='production' returns { [production]: [{ sdo, id, title }] }; by='sdo' returns { [sdo title]: [productions] }. `filter` substring-narrows keys; `spec` selects '262' or '402'.

NameTypeReqDescription
bystringIndex direction. 'production' (default) groups SDO definitions by the production they handle. 'sdo' groups productions by which SDO defines them.
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
filterstring
limitintegerCap the number of groups returned. Each group can still hold many entries.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.search ~214

Search the parsed spec by clause id / aoid / title (and step text when search_steps is true). Returns lightweight hits ranked by match quality — the entry point when you don't know the exact clause id. `spec` selects '262' or '402'. Follow up with clause.get.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
limitintegerMax ranked hits returned.
querystringyesSearch text. Matched against clause id, aoid, and title (and step text when search_steps is true).
search_stepsbooleanAlso match against algorithm step text. Slower + noisier; off by default.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.snapshots ~109

List every (spec, edition, sha, fetched_at) snapshot this server has parsed. Use to discover what historical SHAs you can query via `at: "<sha>"`, or to verify reproducibility across server versions. Optional `spec` / `edition` filters.

NameTypeReqDescription
editionstringFilter to one edition (concrete name like 'main' or 'es2025'). Omit for all.
specstringFilter to one spec. Omit for both.

No output schema declared.

No examples provided.

spec.symbol_resolve ~216

Resolve spec notation like `[[Prototype]]` (internal slot), `%Object.prototype%` (well-known intrinsic), or `~number~` (sigil enum) to the clauses that mention or define it. Hits ranked by occurrence count + section-prefix bumps for the canonical definition location. `spec` selects '262' or '402'.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
limitintegerMax candidate clauses returned, ranked by relevance score.
notationstringyesSpec notation like `[[Prototype]]` (internal slot), `%Object.prototype%` (well-known intrinsic), or `~number~` (sigil enum).
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.tables ~249

List or fetch parsed `<emu-table>` content. Pass `id` to get one table with full columns + rows; omit `id` to list tables (lightweight summaries) optionally filtered by caption/id substring. Authoritative source for the well-known intrinsics table (id='table-well-known-intrinsic-objects'), well-known symbols, completion record fields, etc. `spec` selects '262' or '402'.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
filterstringCase-insensitive substring filter on the caption or id (list mode only).
idstringIf set, return exactly this table (full columns + rows). If omitted, list tables (lightweight rows).
limitintegerMax table summaries returned in list mode (ignored when 'id' is set).
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

spec.well_known_intrinsics ~209

Enumerate the well-known intrinsics (`%X%` notations) used in the spec, with each one's probable defining clause (chosen by a title-substring heuristic — see `matched_on` per hit). For the canonical 262 well-known intrinsics table, read `clause.get { id: 'sec-well-known-intrinsic-objects' }` directly.

NameTypeReqDescription
editionstringEdition within the chosen spec. ECMA-262: es2016 … es2026, main. ECMA-402: es2016 … es2026, main. Aliases: latest, draft, next.
filterstringCase-insensitive substring filter on the intrinsic name (bare, e.g. 'object.prototype').
limitintegerMax well-known intrinsics returned.
specstringWhich TC39 spec to read: '262' (core language, default) or '402' (Internationalization API).

No output schema declared.

No examples provided.

test262.get ~129

Fetch one test's source + parsed front-matter by path within the vendored tc39/test262 checkout. Pairs with test262.search — the paths it returns plug in here directly. Returns { source, front_matter, test262_sha, url } or { hint } if the path can't be resolved.

NameTypeReqDescription
pathstringyesPath within the test262 checkout, relative to the repo root. Example: 'test/built-ins/Number/prototype/toString/S15.7.4.2_A1_T01.js'. The values returned by test262.search go here directly.

No output schema declared.

No examples provided.

test262.search ~253

Search tc39/test262 for tests matching a free-text query and/or an esid (clause id, prefix-matched). test262 covers both ECMA-262 and ECMA-402. Served from a parsed test262 index sourced via the loader chain (local cache → hosted Worker → bundled fallback); the index is fetched on first use and cached locally. If no layer can produce the index the result is empty + a hint explaining the one-time local build. No auth, no subprocess.

NameTypeReqDescription
esidstringFilter to tests whose front-matter esid: starts with this prefix (case-insensitive). Prefix match catches the common case where test262 uses a more specific esid than the spec section id — e.g. `esid…
limitintegerMax ranked hits returned from the test262 index.
querystringFree-text query. Matched case-insensitively as whitespace-separated tokens (AND) across each test's description + path. Either `query` or `esid` (or both) must be supplied.

No output schema declared.

No examples provided.