Mcp State Sidecar — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp State Sidecar (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.askadvaith/mcp-state-sidecar -->
An MCP-native state sidecar that externalises workflow state for distributed agent deployments.
Quite a simple idea really; instead of storing state inside agents (which breaks when processes crash, scale horizontally, or span multiple frameworks), agents write to and read from this sidecar over the Model Context Protocol (MCP). The sidecar is itself an MCP server; agents call its tools exactly the same way they call any other tool!
The server itself is built with distributed environments in mind, and natively handles concurrency, crash resilience and atomic claims in addition to being a common interface for state management between agents.
Install the package via pip or your favorite Python package manager:
pip install mcp-state-sidecarIf you want to use the Redis backend:
pip install mcp-state-sidecar[redis]To build and install the package from source:
git clone https://github.com/askadvaith/MCP-State-Sidecar.git
cd MCP-State-Sidecar pip install --upgrade build python -m build pip install dist/mcp_state_sidecar-*.whlOr install the package in editable mode for active development:
pip install -e .In a multi-agent distributed environment, you would typically run the state sidecar as an HTTP SSE service so multiple remote agents and clients can connect to it concurrently.
#### HTTP SSE Mode (Primary for Distributed Environments) Start the SSE server to listen on a network port:
mcp-state-sidecar-httpBy default, the server binds to 0.0.0.0 and listens on port 8000. The MCP endpoint is available at http://localhost:8000/mcp.
#### Stdio Mode (For Subprocess / Local Agent Execution) Launch the server via standard input/output:
mcp-state-sidecarThe server is configured entirely using environment variables:
| Environment Variable | Default | Description |
|---|---|---|
STATE_BACKEND | sqlite | Storage backend: sqlite or redis |
DB_PATH | state_sidecar.db | Path to the SQLite database file |
REDIS_URL | redis://localhost:6379 | Redis connection URL |
SIDECAR_HOST | 0.0.0.0 | IP host to bind the HTTP SSE server |
SIDECAR_PORT | 8000 | Port for the HTTP SSE server |
state_set(key, value, ttl_seconds?, agent_id?): Upsert a JSON-serialisable value with optional TTL.state_get(key): Retrieve a value (returns found=False if missing or expired).state_delete(key): Delete a key.state_list(prefix?): List all live keys, optionally filtered by prefix.workflow_create(name, tags?): Register a workflow; returns a unique run_id.workflow_discover(tags?, status?): Find workflows filtered by tags or status.workflow_claim(run_id, agent_id): Atomically claim a created workflow.workflow_checkpoint(run_id, step, output): Persist step output and advance the step counter.workflow_resume(run_id): Get full resume context including last step and all step outputs.workflow_status(run_id): Get lightweight status (status, last step, and timestamps).workflow_list(): List all registered workflows.lease_acquire(resource_id, holder_id, ttl_seconds): Attempt to acquire an exclusive lock.lease_release(resource_id, holder_id): Voluntarily release a held lease.lease_renew(resource_id, holder_id, ttl_seconds): Extend lease duration without releasing.session_save(session_id, context): Save a snapshot of workflow context.session_restore(session_id): Retrieve saved context after crash or handoff.history_log(key?, n?): Retrieve the last N state-transition records with timestamps and writer IDs.sidecar_health(): Liveness, backend type, uptime, and database metrics.sidecar_reset(): Irreversibly wipe all data.This project is licensed under the MIT License. See LICENSE for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.