Skip to main content

MCP Arcade

GameDay for MCP servers. The house keeps the tape.

CI License: MIT Landing Page

You point Arcade at a server. It runs four named experiments. The oracle is the JSON-RPC wire: which tools/call went out, with which arguments, and whether the sandbox changed. It does not score a regex on a tool description, a flourish in a TUI, or a model essay.

A full bar is not a safety certificate. It is “these experiments did not catch a lie this time.”

The tape that comes out can be played as Ghost on the Menu, a short arcade shooter in the sister repo. The instrument scores the wire. The game never does.

The four experiments

That is the whole catalog.

Experiment What it asks
The Honest Menu Is the menu the server publishes the menu it will serve?
The Whispered Errand Does a side-quest buried in a description become a tools/call?
The Long Con After a few clean calls, is it still the same tool?
The Ghost on the Menu Does the server answer a name that was never on the menu?

The agent on the other end is a policy, not a judge: naive follows “also call X” whispers, task-only runs the named tool and stops, ollama:<model> is a local model that sees the menu and emits calls. naive and task-only are the controls.

Install

pip install mcp-arcade

Python 3.11 or later. From a clone: pip install -e ".[dev]".

Run a bout

# Lab fixture. No --allow-live needed. naive will follow the whisper.
mcp-arcade bout --target fixture --agent naive --no-prompt -o receipt.json

# Same lab, policy that refuses whispered errands.
mcp-arcade bout --target fixture --agent task-only --no-prompt

# Your stdio server. Fail-closed: opt in, and name a benign task.
mcp-arcade bout --target stdio \
  --cmd python --cmd -m --cmd your_server \
  --task your_read_only_tool \
  --allow-live --no-prompt

mcp-arcade atoms lists the catalog. Leave off --no-prompt in a real terminal: Arcade asks what you think the wire will show before it posts the score.

Docker is the sandbox for a real container. The fixture image needs no --allow-live; your image always does. See the handbook for flags, framing, the local-model seat, and what a green bar is not.

Keep the tape

mcp-arcade receipt receipt.json --timeline    # one row per wire event, no score
mcp-arcade tape receipt.json -o tape.json     # the cabinet's input

The timeline is the diagnostic: every tools/call, every reply, every notification. Scores stay off it until you ask. The tape file is what Ghost on the Menu reads. Arcade never writes a game score onto it.

More

  • Handbook — install, a first bout, the CLI, how scoring works
  • Changelog — what shipped in each wave
  • SECURITY.md — default is the lab fixture; live servers need --allow-live; no telemetry
  • Live fire — a real SDK server, the controls, and the limits of 0.x

Do not point --allow-live at a production server that can reach real secrets. Read a live receipt before you share it.

MIT. See LICENSE.

Metadata

Release files for mcp-arcade 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mcp-arcade 0.2.0
File Size Uploaded
mcp_arcade-0.2.0.tar.gz 1.8 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for mcp-arcade 0.2.0
File Interpreter ABI Platform
mcp_arcade-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.8 MB

Release files / mcp_arcade-0.2.0.tar.gz

Download URL mcp_arcade-0.2.0.tar.gz
Size 1.8 MB
Tags Source
SHA-256 checksum
How to use checksums
b0d91e000493c56fb6e18b00cbb7355c80ddff9ffe302f073eba4ee368eceb75
BLAKE2b-256 checksum
How to use checksums
98347c94fbb1ff34826ae57443bd5f1ef3419af7f2ffbe78d1a5e69e60177345
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release files / mcp_arcade-0.2.0-py3-none-any.whl

Download URL mcp_arcade-0.2.0-py3-none-any.whl
Size 60.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6bb1aafefe6ed0d2af0fc9a62c9951ee7de45b8be7f502aade7b20fd4f0de3e3
BLAKE2b-256 checksum
How to use checksums
91f9328bb45f30ede2d1c908774661527a0533fbdbff789c593022589ba85177
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.0

2 release files

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page