Wyro for coding agents

Agents write most new backend code, and nobody has time to read all of it. Give the agent the check as a tool and it reads what its own change did to your backend (which routes reach which tables, and whether they authenticate) before it tells you it is done.

Add it in one line

Claude Code:

claude mcp add wyro -- npx -y wyro-check --mcp

Cursor reads .cursor/mcp.json in your project:

{
  "mcpServers": {
    "wyro": { "command": "npx", "args": ["-y", "wyro-check", "--mcp"] }
  }
}

Codex, Windsurf, Zed and any other MCP client take the same command, npx -y wyro-check --mcp, over stdio. It needs Node 18 or newer and makes no network calls of its own.

Without npm, download the self-contained build and point your agent at it instead:

curl -fsSL https://wyro.in/wyro-check.js -o ~/.wyro-check.js
claude mcp add wyro -- node ~/.wyro-check.js --mcp

What the agent gets

  • check_backend: the new findings in a directory, most dangerous first, each with its risk, the file and line, what is missing, and a suggested patch. Findings already recorded in the repository's baseline are counted as existing debt, not reported as new. It also says whether CI would pass.
  • describe_backend: every route, whether it authenticates, and the tables it reads or writes. Useful before a change (to understand the system) and after it (to see what the change did to its shape).
  • list_rules: every rule the check applies and what it protects against.

The server also tells the agent when to call it: after changing routes, handlers, middleware or schema, and before reporting a task as done. Ask for it directly too: “add a refunds endpoint, then check the backend.”

Tip:No tool can write the baseline or the config. An agent that could record a finding as accepted debt could make any check pass by silencing it, and a gate the gated thing can switch off is not a gate. Accepting debt stays your decision, made with --update-baseline on the CLI.

Why a deterministic check

Wyro is rule-based, not a model. The same code always gets the same answer, so “fix it and check again” converges, and a passing result means the same thing every time. When it cannot read your backend it says so instead of reporting a clean result for code it did not understand.

Then make it a gate

The agent loop catches problems as they are written. The GitHub Action catches the ones that get through anyway, on the pull request, failing only on findings that are new.