MCP server
The tools, resources and safety model of rcas mcp, the Model Context Protocol server of Rule Cascade.
rcas mcp serves the Model Context Protocol over standard input
and output (JSON-RPC 2.0, one message per line, protocol revisions 2025-06-18, 2025-03-26 and
2024-11-05). An AI tool starts it; you rarely run it yourself. To register it, see
AI coding tools.
rcas mcp [--root <dir>] [--read-only] [--list-tools]| Flag | Meaning |
|---|---|
--root <dir> | The project. Default: the directory the tool starts it in; rcas.yaml is looked up from there |
--read-only | Leave out propose_ruleset. Also mcp.readOnly: true in rcas.yaml |
--list-tools | Print the tools and exit |
Logs go to standard error; standard output carries protocol messages only.
Tools
| Tool | Arguments (required in bold) | Returns |
|---|---|---|
list_rules | ruleset, entity, operation | The rules that apply to an operation on an entity: id, title, kind, severity, field, enforcement, who may accept the risk |
explain_rule | ruleset, rule_id | One rule in full, as in the server manifest |
evaluate_rules | ruleset, entity, operation, data_json, original_json, channel, actor_roles, resolutions_json | The result of a dry run: decision, findings, effects, commands |
check | paths, content | Lint, load and golden tests of rulesets, or of a draft passed as content (checked where it would live, written nowhere) |
test | paths, content | The same as check |
compile | path, include_bundle | Id, version, checksum and channels of the compiled bundle (and the bundle on request) |
manifest | path, channel | The client or server manifest |
derive | source, id, schema, pointer, entity, scope | The baseline ruleset YAML from an OpenAPI component schema or a JSON Schema, and what could not be derived |
analyze | path, include, exclude, max_files | The inventory of schemas and decisions in code, with file:line |
propose_ruleset | id, title, files (path, content), rationale, source_refs | The stored proposal and its status: pending, or invalid with the problems check found |
list_proposals | status | Proposals and their status |
get_proposal | id | One proposal with the content of its files |
get_spec_section | section | A section of the specification by number (4.4) or words; without one, the list of sections |
get_operator_reference | operator | The operator table, or the lines about one operator |
get_authoring_guide | topic (authoring, naming, enforcement, openapi, cookbook), section | A guide, or one section of it |
Every tool except propose_ruleset is marked read-only (readOnlyHint). A tool that fails returns
its error as text with isError, so the model can read it and correct its call.
Resources
| URI | Content |
|---|---|
rcas://docs/<topic> | The specification and the guides, as Markdown (specification, authoring, naming, enforcement, openapi, cookbook) |
rcas://rulesets/<id> | The source of each ruleset of the project |
The documents are embedded in the command, so they match its version and need no network.
Safety model
- Proposals only. The one tool that writes,
propose_ruleset, writes under the proposals directory (.rcas/proposals/by default). A proposal may contain only*.ruleset.yaml,*.ruleset.yml,*.ruleset.jsonand*.schema.jsonfiles under the rules directory, none of them hidden: never configuration, version control, CI or tool files. A path that leaves the project, by.., an absolute path or a symbolic link, is refused.acceptchecks the same again. - What was reviewed is what is accepted. An agent cannot replace a proposal that exists; it must propose under a new id.
- Reads stay in the project. Schemas and API documents a draft refers to are read only from inside the project.
- A person accepts.
rcas proposals accept <id>writes the files, and refuses when a target file changed after the proposal was made, or when the proposal does not passcheck(--forceoverrides both, deliberately). - Evaluation is a dry run on the source rulesets of the project. The actor of a dry run is a test value; in production the actor always comes from authentication, never from a model.
- No network, no shell. The server reads the project and writes proposals; it starts no processes and opens no connections.
Try it by hand
printf '%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18"}}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check","arguments":{}}}' \
| rcas mcpAI coding tools
Connect Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Windsurf and other AI coding tools to Rule Cascade, with agent instructions and the rcas MCP server.
Learn Rule Cascade
A short lesson for every feature of the rule language, then your language and the whole process. Every example runs in your browser.