Glintbase Documentation
The definitive technical guide to auditing, simulating, and hardening software for autonomous AI coding agents. Covers the 119-check ARS 3.0 standard, the multi-agent Flight Simulator, the 17-tool MCP server, and machine-first API endpoints.
01 / Command Interface
CLI Suite (`@glintbase/cli`)
Install globally via npm i -g @glintbase/cli or execute instantly via npx @glintbase/cli. Requires Node.js ≥ 20.
glintbase audit [target] [options]
Core AuditorExecutes the 119-check ARS 3.0 standard across 4 layers with dynamic denominator scaling, archetype classification, and AST static analysis.
Available Options & Flags
| Flag | Function |
|---|---|
| --simulate | Spawns embedded Flight Simulator alongside audit to empirically test mission completion |
| --report <file> | Exports complete executive Markdown audit report with remediation code diffs |
| --fail-under <score> | Exits with code 1 if ARS score drops below threshold (e.g. --fail-under 80) |
| --json | Outputs raw structured JSON telemetry for programmatic pipeline consumption |
Usage Example
# Audit any public web API or documentation site
npx @glintbase/cli audit https://api.stripe.com
# Audit local codebase offline via AST inspection with strict threshold & simulation
glintbase audit . --simulate --fail-under 85 --report audit-report.md02 / Empirical Verification
Autonomous Agent Flight Simulator
Instead of relying solely on static HTML regex checks, Glintbase spawns empirical multi-turn agent journeys. The simulator measures how real coding agents navigate your docs, understand your API parameters, and execute tools without burning token budgets.
Deep schema traversal, multi-step dependency chaining, strict JSON Schema type checking. Evaluates whether nested parameter definitions cause tool-use stalls.
Fast semantic indexing, tight token budgeting, IDE code-completion emulator. Measures context burn and checks for concise inline examples.
Zero-JavaScript SSR crawler, strict markdown parser, anti-SPA canary detector. Tests whether client-side hydration shells blind autonomous search agents.
Unoptimized documentation loaded into agent context windows burns thousands of tokens per turn. At scale across a 50-engineer engineering team, documentation token tax averages $433,200 / year.
Measures the probability of tool execution failure before runtime. A friction index > 0.25 triggers agent hallucinations and infinite retry loops.
In-Chat Multi-Modal Experience & Visual Replay
When executed via MCP in Claude, Cursor, or Windsurf, the Flight Simulator delivers an interactive visual experience:
Rendered inline directly in the chat using MCP image blocks (image/svg+xml).
Zlib-deflated base64url hash (#data=...) linking to the full visual cockpit.
Interactive SVG/HTML side-panels generated on-the-fly for inspection without leaving the conversation.
03 / Evaluation Science
Mathematical Scoring Engine (Dynamic Denominator)
Unlike legacy static audits that penalize sites for capabilities they don't need, ARS 3.0 uses a mathematically grounded Dynamic Denominator with archetype-based baselines and unpenalized bonus upside.
Bonus specifications (e.g. WorkOS auth.md, WebMCP, Google AP2) add 0 to the denominator when missing, preventing unfair score degradation.
Supporting any verified protocol (x402, UCP, ACP) awards full payment cluster credit; unused payment protocols are marked N/A, never failed.
| Archetype | Applicable Services | Eligible Layers | Base Denominator |
|---|---|---|---|
| api_devtool | APIs, SDKs, CLI tools, SaaS backend | Layer 1, 2, 3 | 85 pts |
| docs_kb | Documentation hubs, Knowledge bases | Layer 1, 2, 3 (Docs-kind) | 85 pts |
| ecommerce | Commerce APIs, checkout surfaces | Layer 1, 2, 3, 4 | 100 pts |
| content_media | Publishers, corporate blogs, portals | Layer 1, 2 | 50 pts |
04 / Protocol Standard
The 119-Check Taxonomy Across 4 Layers
Every check in ARS 3.0 evaluates a discrete failure surface that causes AI agents (Claude Code, Cursor, Perplexity) to stall, burn context tokens, or hallucinate.
Layer 1: Discovery & Entrypoints
Evaluates whether autonomous agents can find, index, and recognize your product surfaces across internet directories and AI crawlers.
Explicit Allow policies for ClaudeBot, PerplexityBot, and GPTBot without deceptive wildcard Disallow.
Valid /.well-known/ard.json manifest pointing to machine endpoints.
Deterministic resolution of docs root without infinite redirects or domain aliasing.
Verified Wikidata Q-identifier providing authoritative grounding.
src/core/checks/registry.ts.05 / Agent Tooling
Official MCP Server (17 Tools & 9 Skills)
Connect Glintbase to AI coding agents (Claude Code, Cursor, Windsurf, ChatGPT) to enable real-time readiness auditing, automated flight simulation, and self-healing code remediation inside your IDE.
Single endpoint with sliding-window rate limiting (60 req/min):
https://scan.glintbase.dev/api/mcpZero network overhead, direct stdin/stdout IPC for Claude Code & Cursor:
npx @glintbase/cli mcpEphemeral secure Cloudflare Quick Tunnel for remote collaboration:
glintbase mcp --shareComplete 17-Tool Production Catalog
All tools expose typed JSON Schema parameters with strict Zod validation.
Runs full 119-check ARS 3.0 audit against any public URL or local repo.
Retrieves cached ARS score, archetype baseline, and layer breakdown.
Discovers canonical agent entrypoints (/llms.txt, /auth.md, ard.json, OpenAPI).
Executes multi-turn agent simulation with live Journey Tree SVG and replay hash.
Calculates prompt/completion token waste and annualized financial penalty.
Analyzes OpenAPI/JSON Schema for missing types, vague descriptions, and ambiguity.
Proves score upside (+pts) from applying candidate AST remediations in-memory.
Generates production-grade living artifacts (llms.txt, auth.md, ard.json, canary).
Validates documentation curl commands and SDK calls in isolated micro-sandbox.
Inspects client-side window.modelContext tools for visiting AI browser agents.
Evaluates pull request against score threshold and computes PR drift delta.
Generates executive compliance breakdown for enterprise security audits.
Probes randomized paths to verify authentic HTTP 404 vs soft-200 SPA shells.
Validates WorkOS auth.md, RFC 9728 metadata, and token exchange flows.
Verifies Idempotency-Key headers and safe mutation locks on write endpoints.
Retrieves complete skill instruction playbook by URI (skill://glintbase/*).
Scaffolds skill playbook into .agents/skills/ or ~/.claude/skills/ directory.
06 / Machine Integration
API Reference (REST & JSON-RPC 2.0)
Complete specification for Glintbase cloud services. AI agents and backend systems can query endpoints directly with standard JSON payloads. All machine endpoints return standard rate-limit and status headers.
Model Context Protocol JSON-RPC 2.0 Gateway
Standard JSON-RPC 2.0 endpoint implementing official MCP protocol methods: initialize, tools/list, and tools/call. Dispatches to all 17 production tools with multi-modal SVG image and Claude artifact responses.
Request Parameters / Headers
| Name | Type | Required | Description |
|---|---|---|---|
| jsonrpc | string | Yes | Must be exactly '2.0' |
| id | string | number | Yes | Unique client request identifier |
| method | string | Yes | 'initialize' | 'tools/list' | 'tools/call' |
| params | object | No | Method parameters (e.g. { name: 'glintbase_simulate_flight', arguments: { url: 'https://api.example.com' } }) |
Executable Code Examples
curl -X POST https://scan.glintbase.dev/api/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": "req-1",
"method": "tools/call",
"params": {
"name": "glintbase_simulate_flight",
"arguments": {
"url": "https://docs.stripe.com",
"agent": "claude-code",
"intent": "Create a customer and attach payment method"
}
}
}'Expected Response Payload (HTTP 200)
{
"jsonrpc": "2.0",
"id": "req-1",
"result": {
"content": [
{
"type": "text",
"text": "Flight Simulation complete for https://docs.stripe.com\nScore: 94/100 | Tax: $0.012"
},
{
"type": "image",
"data": "PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iNDAwIj4...",
"mimeType": "image/svg+xml"
}
],
"structuredData": {
"score": 94,
"tokenTax": 0.0124,
"frictionIndex": 0.08,
"replayHash": "eJzLSM3JydErys9PLVbISUxPjU8rSgUAXYMHxw=="
}
}
}07 / CI / CD Integration
GitHub Actions PR Drift Shield
Add Glintbase to your pull request pipeline. Automatically audits documentation and API modifications, tests PR drift against the base branch, and posts a Markdown scorecard comment directly onto the pull request.
name: Agent Readiness Quality Gate
on:
pull_request:
branches: [main]
push:
branches: [main]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
- name: Run Glintbase ARS 3.0 Drift Shield
run: |
npx @glintbase/cli ci . \
--fail-under 80 \
--pr-drift \
--github-token ${{ secrets.GITHUB_TOKEN }}08 / Living Implementation
Canonical Machine Surfaces on Glintbase
Glintbase dogfoods the ARS 3.0 standard. All machine entrypoints are verified live and accessible to autonomous web and terminal agents:
Structured H1 catalog of concepts, products, and machine endpoints for LLM context windows.
Token-budgeted complete markdown documentation corpus.
Machine-readable client credentials and token exchange manual with YAML frontmatter.
Agent Resource Discovery (ARD v0.91) manifest listing verified machine surfaces.
Complete OpenAPI 3.1.0 specification with all 17 MCP tools and API routes.
Raw markdown developer manual for zero-overhead LLM ingestion.
Streamable Model Context Protocol HTTP server endpoint active.
Zero-auth testing sandbox for agent request simulation.