Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .mockery.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
all: false
dir: '{{.InterfaceDir}}/mocks'
filename: authorizer.go
filename: '{{.InterfaceName | snakecase}}.go'
formatter: goimports
generate: true
include-auto-generated: false
Expand All @@ -14,3 +14,7 @@ packages:
github.com/meigma/codemode/authz:
interfaces:
Authorizer:
github.com/meigma/codemode/mcpserver:
interfaces:
Service:
InvocationResolver:
34 changes: 25 additions & 9 deletions docs/docs/index.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,32 @@
---
title: template-go Docs
title: CodeMode
slug: /
description: Starting point for Meigma Go projects.
description: Build MCP servers that expose bounded Go capabilities through Starlark.
---

# template-go Docs
# CodeMode

This repository is the starting point for Meigma Go projects.
CodeMode is a Go library for building code-native Model Context Protocol (MCP) servers. An application registers typed Go capabilities, selects the capabilities enabled for one deployment, and exposes them through a restricted Starlark runtime.

Generated projects should replace this page with project-specific documentation after bootstrapping:
## MCP boundary

- project summary
- quick start
- operating notes
- support and security paths
The `mcpserver` package exposes exactly three tools:

| Tool | Input | Output |
| --- | --- | --- |
| `search_api` | A bounded query string | Enabled capability names, signatures, and summaries |
| `describe_api` | One exact capability name | Its signature, description, and supported input and output fields |
| `execute` | One bounded Starlark program | `{"result": <main return value>}` |

Each tool call resolves an authenticated subject from trusted Go context before it reaches the CodeMode service. Tool arguments and MCP `_meta` cannot provide or replace identity, credentials, execution budgets, modules, or capability allow-lists.

`execute` creates a fresh interpreter for each call. The program must define a zero-argument `main()` function. Only the value returned by `main()` crosses the MCP boundary; printed text and intermediate values do not.

## Integration outline

1. Build an immutable `codemode.Server` from typed capabilities and deployment options.
2. Implement `authz.Authorizer` for each native capability call.
3. Implement `mcpserver.InvocationResolver` to read the authenticated subject from host-owned typed context.
4. Call `mcpserver.New` and connect the returned official MCP SDK server to the transport owned by the host application.

Disabled capabilities are absent from search, description, and execution. Authorization denial stops the native handler from running. Public tool errors use coarse classifications and do not include source text, arguments, credentials, policy details, stack traces, or handler results.
10 changes: 5 additions & 5 deletions docs/mkdocs.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
site_name: template-go
site_description: Meigma Go repository template
site_url: https://meigma.github.io/template-go/
repo_name: meigma/template-go
repo_url: https://github.com/meigma/template-go
site_name: CodeMode
site_description: Code-native MCP servers with bounded Go capabilities
site_url: https://meigma.github.io/codemode/
repo_name: meigma/codemode
repo_url: https://github.com/meigma/codemode
edit_uri: edit/master/docs/docs/
docs_dir: docs
site_dir: build
Expand Down
4 changes: 2 additions & 2 deletions docs/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@ tags:
- 'uv'

project:
title: 'template-go docs'
description: 'MkDocs documentation site for the Meigma Go repository template.'
title: 'CodeMode docs'
description: 'MkDocs documentation for the CodeMode Go library.'
owner: 'meigma'
maintainers:
- 'meigma'
Expand Down
8 changes: 8 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,20 @@ module github.com/meigma/codemode
go 1.26.6

require (
github.com/modelcontextprotocol/go-sdk v1.7.0
github.com/stretchr/testify v1.12.1
go.starlark.net v0.0.0-20260708150628-5395d018f003
)

require (
github.com/google/jsonschema-go v0.4.3 // indirect
github.com/segmentio/asm v1.1.3 // indirect
github.com/segmentio/encoding v0.5.4 // indirect
github.com/stretchr/objx v0.5.3 // indirect
github.com/yosida95/uritemplate/v3 v3.0.2 // indirect
go.yaml.in/yaml/v3 v3.0.5 // indirect
golang.org/x/oauth2 v0.35.0 // indirect
golang.org/x/sync v0.20.0 // indirect
golang.org/x/sys v0.42.0 // indirect
golang.org/x/time v0.15.0 // indirect
)
20 changes: 20 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
@@ -1,14 +1,34 @@
github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY=
github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE=
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
github.com/google/jsonschema-go v0.4.3 h1:/DBOLZTfDow7pe2GmaJNhltueGTtDKICi8V8p+DQPd0=
github.com/google/jsonschema-go v0.4.3/go.mod h1:r5quNTdLOYEz95Ru18zA0ydNbBuYoo9tgaYcxEYhJVE=
github.com/modelcontextprotocol/go-sdk v1.7.0 h1:yqjY2dsbKAC0LSuWZVBMrHgiG8ukXv6NRo0JiALay44=
github.com/modelcontextprotocol/go-sdk v1.7.0/go.mod h1:dL7u98E/zjJTGzEq+j30jQ8K2k1mb6LeAH4inEcSGts=
github.com/segmentio/asm v1.1.3 h1:WM03sfUOENvvKexOLp+pCqgb/WDjsi7EK8gIsICtzhc=
github.com/segmentio/asm v1.1.3/go.mod h1:Ld3L4ZXGNcSLRg4JBsZ3//1+f/TjYl0Mzen/DQy1EJg=
github.com/segmentio/encoding v0.5.4 h1:OW1VRern8Nw6ITAtwSZ7Idrl3MXCFwXHPgqESYfvNt0=
github.com/segmentio/encoding v0.5.4/go.mod h1:HS1ZKa3kSN32ZHVZ7ZLPLXWvOVIiZtyJnO1gPH1sKt0=
github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4=
github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0=
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
github.com/yosida95/uritemplate/v3 v3.0.2 h1:Ed3Oyj9yrmi9087+NczuL5BwkIc4wvTb5zIM+UJPGz4=
github.com/yosida95/uritemplate/v3 v3.0.2/go.mod h1:ILOh0sOhIJR3+L/8afwt/kE++YT040gmv5BQTMR2HP4=
go.starlark.net v0.0.0-20260708150628-5395d018f003 h1:cAxcqHgW8fnmT0cEBU3TzvVYHIFt8IIGDMWUF6rImk4=
go.starlark.net v0.0.0-20260708150628-5395d018f003/go.mod h1:Iue6g6iirlfLoVi/DYCi5/x0h/bAOuWF3dULTKpt2Vo=
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
golang.org/x/oauth2 v0.35.0 h1:Mv2mzuHuZuY2+bkyWXIHMfhNdJAdwW3FuWeCPYN5GVQ=
golang.org/x/oauth2 v0.35.0/go.mod h1:lzm5WQJQwKZ3nwavOZ3IS5Aulzxi68dUSgRHujetwEA=
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo=
golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
golang.org/x/tools v0.42.0 h1:uNgphsn75Tdz5Ji2q36v/nsFSfR/9BRFvqhGBaJGd5k=
golang.org/x/tools v0.42.0/go.mod h1:Ma6lCIwGZvHK6XtgbswSoWroEkhugApmsXyrUmBhfr0=
google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE=
google.golang.org/protobuf v1.36.11/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
6 changes: 6 additions & 0 deletions mcpserver/doc.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
// Package mcpserver exposes CodeMode as exactly three official MCP tools.
//
// The adapter resolves a trusted subject from host-owned Go context before every
// operation, ignores untrusted client metadata, and projects failures to stable
// coarse tool text. It does not proxy arbitrary downstream MCP tools.
package mcpserver
Loading