An agent with the plugin
The same tools, inside Claude Code: claude plugin install s2ar@starlab adds the hosted s2ar tools as MCP tools, and the plugin’s skills say when to use them. This page is one headless session, run by a script that reads the session’s event stream and checks what the agent actually did, not what it said. The session’s words vary; the chain does not.
Run 2026-10-10 19:38 UTC · Claude Code ? · model `claude-sonnet-5` · 3 tool calls · 4 turns · $0.08851460000000001 of model time · 22509 ms · the plugin's key is the operator's (the calls cost nothing) · every check re-derived from the stream by tools/mcp_walkthrough.py
1. The session
claude -p "<the prompt below>" --model claude-sonnet-5 --max-turns 8 --plugin-dir ./plugin-s2ar \
--mcp-config mcp.json --strict-mcp-config --allowedTools mcp__s2ar_api__sym_read_repo,mcp__s2ar_api__assert_output
The prompt:
Using the hosted s2ar tools only: read the symbol `Glob as Flag` from file `crates/core/flags/defs.rs` in the GitHub repository `BurntSushi/ripgrep` at ref `14.1.1` with the sym_read_repo tool. Then answer ONLY with a JSON object (no prose around it) of the shape {"summary": <one sentence>, "quote": <one verbatim sentence copied from the function's doc comment>, "source_url": "https://github.com/BurntSushi/ripgrep/blob/14.1.1/crates/core/flags/defs.rs"}. Before you answer, call the assert_output tool on that exact JSON with rubric "quotes-source" and the text you read as `source`, and include nothing else in your final message.
The init event: server s2ar_api connected; the s2ar tools in this session are mcp__s2ar_api__… (the plugin’s server, given to the session as an explicit MCP config with --strict-mcp-config, so no other server is present; installed from the marketplace the prefix is mcp__s2ar_api__).
2. What the agent did
1. ToolSearch
{
"query": "select:mcp__s2ar_api__sym_read_repo,mcp__s2ar_api__assert_output",
"max_results": 5
}
2. mcp__s2ar_api__sym_read_repo
{
"repo": "BurntSushi/ripgrep",
"file": "crates/core/flags/defs.rs",
"symbol": "Glob as Flag",
"ref": "14.1.1"
}
impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)
2459 impl Flag for Glob {
2460 fn is_switch(&self) -> bool {
2461 false
2462 }
2463 fn name_short(&self) -> Option<u8> {
2464 Some(b'g')
2465 }
2466 fn name_long(&self) -> &'static str {
2467 "glob"
… 45 more lines
3. mcp__s2ar_api__assert_output
{
"rubric": "quotes-source",
"source": "impl Flag for Glob {\n fn is_switch(&self) -> bool {\n false\n }\n fn name_short(&self) -> Option<u8> {\n Some(b'g')\n }\n fn name_long(&self) -> &'static str {\n \"glob\"\n }\n fn doc_variable(&self) -> Option<&'static str> {\n Some(\"GLOB\")\n }\n fn doc_category(&self) -> Category {\n Category::Filter\n }\n fn doc_short(&self) -> &'static str {\n r\"Include or exclude file paths.\"\n }\n fn doc_long(&self) -> &'static str {\n r#\"\nInclude or exclude files and directories for searching that match the given\nglob. This always overrides any other ignore logic. Multiple glob flags may\nbe used. Globbing rules match \\fB.gitignore\\fP globs. Precede a glob with a\n\\fB!\\fP to exclude it. If multiple globs match a file or directory, the glob\ngiven later in the command line takes precedence.\n.sp\nAs an extension, globs support specifying alternatives:\n.BI \"\\-g '\" ab{c,d}* '\nis equivalent to\n.BI \"\\-g \" \"abc \" \"\\-g \" abd.\nEmpty alternatives like\n.BI \"\\-g '\" ab{,c} '\nare not currently supported. Note that this syntax extension is also
pass: 1 of 1 checks passed
ok quotes_in_source {"quotes": 1, "missing": [], "path": "quote"}
record 045fbd7ed0c1308ed4054fc434a6684b7b4ad8082846eca57d304066401131ee · verify free at https://api.s2ar.dev/v1/verify/045fbd7ed0c1308ed4054fc434a6684b7b4ad8082846eca57d304066401131ee
3. The answer
{
"summary": "The Glob flag implementation defines the -g/--glob CLI option that lets users include or exclude files and directories from a ripgrep search using gitignore-style glob patterns.",
"quote": "Include or exclude file paths.",
"source_url": "https://github.com/BurntSushi/ripgrep/blob/14.1.1/crates/core/flags/defs.rs"
}
4. The checks
- the session read
Glob as Flagthroughmcp__s2ar_api__sym_read_repo(the result carriesimpl Flag for Glob) - the assertion’s record
045fbd7ed0c1308e…fetched back from/v1/verify: sealed, signed, pinned toassay-1 - the answer’s
quoteis found verbatim in the text the session read - the final JSON re-asserted by the generator on the house key:
pass, record394542155e5bedf1…
What varies, what cannot
The model’s sentence, its turn count and the cost vary run to run; the generator aborts and writes nothing when the read, the assertion, the record or the quote is missing. The record this run issued: 045fbd7ed0c1308ed4054fc434a6684b7b4ad8082846eca57d304066401131ee; the issuer’s key is the one at /.well-known/assay.json (assay-1). The plugin: mcp.html; the bench behind it: token economics.