Test CoverageSAFE
Context engineering: Make your agents aware of how they affect 🧪 test coverage🧪 during a coding session
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/test-coverage-mcp) [](https://opensource.org/licenses/MIT)
Make your agents coverage-aware as they code for you
“Hey, I’m a coding agent. I just created flashy nifty feature... but oops, I downgraded the coverage 🤓. How could I know that?”
“Hey, I’m a testing agent. I was tasked to cover some code with testing, but how can I find which areas are not covered?😳”
Give your coding and testing agent eyes: MCP server that provides instant, reliable, token-efficient test coverage data for any programming language (LCOV based)
__
🚀 Just launched (November 2025) ! I spend great time these days on polishing this library. If you find this valuable, a ⭐ star helps signal to other developers that this project is worth their attention
The Problem
When AI coding agents work on your code without proper coverage tooling, they face three critical issues:
- Coverage Blindness - They can't see if their changes improved or regressed test coverage
- Token Waste - They burn thousands of tokens trying to parse massive LCOV files (some exceed 10 MB)
- Unreliable Scripts - They improvise custom parsing scripts that often fail or produce incorrect results
The Solution
This MCP server solves all three problems by providing:
- Coverage Awareness - Agents can check coverage anytime with a simple tool call
- Token Efficiency - Get coverage summaries in <100 tokens instead of thousands
- Accuracy - Production-grade LCOV parsing that handles all format variations
- Baseline Tracking - Measure coverage progress wi
667eaece68d9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add test-coverage-mcp -- npx -y [email protected]
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
(cd "$script_dir/../../.." && pwd)
import { createServer } from '../../src/mcp/server.js';} from '../../src/schemas/tool-schemas.js';
zod-to-json-schema, @faker-js/faker, @vitest/coverage-v8
Gates applied: no_behavioural_pass, no_license.
667eaece68d9full audit observations/trust-audit/mcp-server/goldbergyoni__test-coverage.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 667eaece68d9 | SAFE | B | 89 | first audit |
Questions
What is the Test Coverage MCP server?
Context engineering: Make your agents aware of how they affect 🧪 test coverage🧪 during a coding session
Is Test Coverage safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Test Coverage need?
No credential environment variables were found in its source, so it appears to need none.
How does Test Coverage run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as coverage-mcp-playground at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (667eaece68d9), read on 2026-10-08. The repository is watched and re-audited when it changes.