Skip to content

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 14:40
· 198 commits to main since this release

Sonde 1.3 lets AI agents work with your request files. sonde mcp is a
Model Context Protocol server for Claude Code, Cursor, VS Code and other
MCP clients: it lists and checks .hurl and .sonde files, and, only
when you allow it, runs them against the hosts you name.

Highlights

  • sonde mcp. Two read-only tools are always available:
    sonde_list finds request files and sonde.yaml environments, and
    sonde_check returns syntax errors or a summary of each entry. With
    --allow-run, sonde_run runs one file and returns its --json
    result, plus the response body of each failing entry.
    docs/guides/mcp.md

    claude mcp add sonde -- sonde mcp --allow-run --allow-host localhost:8080
  • Runs are fenced in.

    • --allow-run requires at least one --allow-host, and there is no
      default host.
    • The allowlist is checked on every request, redirect and connection,
      proxies included.
    • Entries that would reroute a connection or write a file fail before
      anything is sent: proxy, connect-to, resolve, unix-socket,
      the netrc options and output. They still run with sonde --test.
    • Tools read only files under --root.
    • Secrets come only from sonde.yaml, SONDE_SECRET_* and the server's
      own flags, and are redacted from everything a tool returns.
    • Each tool call writes one line to an audit log on standard error.

The design is recorded in
decision 0006.
The server uses the official MCP Go SDK, which adds 2 MB to the binary and
no measurable start-up time.

Good to know

  • Host names in --allow-host are matched as written, never resolved:
    localhost does not match 127.0.0.1. Only ASCII names match; write
    internationalized names in punycode.
  • The allowlist trusts names. A wildcard such as *.example.com trusts
    every subdomain, and an allowed gateway reaches whatever it fronts.
  • Response bodies returned to the agent are data from the server under
    test, not instructions.

Compatibility

Every change to the CLI, the JSON report and the engine and exchange
Go packages is additive, as
docs/stability.md
promises for 1.x. The MCP tools are now part of that contract.

Install

brew install nhtera/tap/sonde                                   # macOS, Linux
scoop bucket add nhtera https://github.com/nhtera/scoop-bucket  # Windows
scoop install sonde
go install github.com/nhtera/sonde/cmd/sonde@v1.3.0

Changelog

Features

  • 46e8127 feat(mcp): serve request files to AI agents with sonde mcp