
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
soma-verify-mcp
Advanced tools
Soma MCP server — execution-verified code generation and verification with signed, offline-checkable certificates.
Give your AI agent the one thing it can't do for itself: actually run code against tests and prove it passed.
Soma is an execution-verified code service. This MCP server exposes two tools:
soma_verify_code — run candidate code against tests inside an isolated sandbox; get a PASS/FAIL verdict plus a signed, offline-checkable certificate (Ed25519). Use it to independently confirm code works before trusting it.soma_generate_verified_code — ask Soma to write code for a task; when the task is verifiable, the returned code has already been executed against derived tests, with a certificate attached.15+ languages are supported for verification (Python, JavaScript/TypeScript, Go, C/C++, Java, Rust, Ruby, PHP, Bash, and more).
Requires Node.js 18+. Runs over stdio.
Add to your MCP client config (Claude Desktop, Cursor, etc.):
{
"mcpServers": {
"soma": {
"command": "npx",
"args": ["-y", "soma-verify-mcp"],
"env": {
"SOMA_API_KEY": "YOUR_SOMA_KEY"
}
}
}
}
Settings → Developer → Edit Config, add the block above, restart.Settings → MCP → Add, or drop the same block in ~/.cursor/mcp.json.| Env var | Required | Default | Purpose |
|---|---|---|---|
SOMA_API_KEY | yes | — | Your Soma API key. |
SOMA_BASE_URL | no | https://170-9-236-56.sslip.io | Soma API base URL. |
SOMA_TIMEOUT_MS | no | 300000 | Per-request timeout. |
Get a free preview key: contact centrum.arvind@gmail.com (free tier during the preview).
soma_verify_codeRun code against tests and return a signed verdict.
language (string) — e.g. python, javascript, go, rust.code (string) — the complete source to verify.tests (array) — one of:
[{ "input": [arg1, arg2], "expected": value }] plus entrypoint (the function name).mode: "stdio" and [{ "stdin": "...", "expected_stdout": "..." }]; no entrypoint.entrypoint (string, optional) — function name for function mode.mode ("function" | "stdio", optional).Returns: verdict, tests_passed, tests_total, and a signature / public_key / sig_alg you can check offline.
soma_generate_verified_codeGet code for a task, executed against derived tests before it's returned.
prompt (string) — the coding task. Include concrete input/output examples (e.g. >>> f(2) == 4) so the result is verifiable rather than best-effort.max_tokens (int, optional, default 1500).Returns: the code, certified (bool), and a certificate (verdict, tests_passed, tests_total) when verification passed. If a task isn't verifiable, output is returned uncertified and clearly labeled — never a false "verified".
A certificate attests that the listed tests passed inside an isolated sandbox at generation time. It is signed (Ed25519) and checkable offline against the returned public key. It is not a warranty of fitness for any purpose — review output before production use.
No training on your prompts. See the Soma Privacy & Data Policy at ${SOMA_BASE_URL}/privacy.
MIT.
FAQs
Soma MCP server — execution-verified code generation and verification with signed, offline-checkable certificates.
The npm package soma-verify-mcp receives a total of 19 weekly downloads. As such, soma-verify-mcp popularity was classified as not popular.
We found that soma-verify-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.