GitHub repo, npm package, uvx command, or JSON config.
methodology
Every verdict comes from a run you can inspect.
Throne does not grade README claims. It starts the artifact, replays calibrated client behavior, records raw traces, scans risk, and seals the evidence.
Install and launch the server in a single-use sandbox.
Server behavior is replayed under Claude Code and Cursor identities, calibrated from recorded Claude Code 2.1.172 and Cursor 3.4.20 traffic, with serial vs pipelined dispatch and Cursor's 2 connections.
Connect, discover, schema, tools, errors, streaming, resources, parallel, reconnect.
Path, shell, prompt, secret, obfuscation, network, dependency, and install heuristics.
Publish scan id, raw trace, timestamp, verdict, and evidence hash.
client coverage
Truthful coverage beats false completeness.
Tested against Claude Code and Cursor client profiles with recorded behavior. Cross-client behavioral divergence testing in development. Planned clients are visible so buyers understand the roadmap, but they never produce false pass or fail results.
nine compatibility checks
nine compatibility checks
profile pending real-traffic capture
emulation profile not yet calibrated
emulation profile not yet calibrated
verdict model
Compatibility and security stay separate until the release call.
Ship
Live client checks pass and no release-blocking security finding is present.
Fix or approve
The server runs, but needs credentials, launch arguments, or security review before trust.
Do not release
A real client fails, the server never launches, or a high severity finding is present.