Configure the client
FIREDRILL_CREDENTIAL securely in that process’s environment using your
MCP client’s secret settings. Do not commit a token into this JSON or assume
every MCP client expands shell variables in configuration. FIREDRILL_API_URL
defaults to https://api.firedrill.run.
Use a project credential with only the permissions the coding agent needs.
Normal permission checks remain enforced by Firedrill; installing the client
does not grant more access.
Read-only by default
Control MCP exposes explicit, bounded operations rather than a generic HTTP call. It can read resource identities, Tool contracts, saved tests, retained verdicts, comparison summaries and evidence metadata. It does not download original artifacts, inspect hidden live state or forward authored Tool-call payloads. It cannot issue a world credential or run the customer agent. Connection guidance prints a read-only discovery command and a separate explicit issuance command for the operator to run locally. Keep any resulting scoped credential out of chat and unrelated processes.Optional bounded mutations
To expose supported mutations, add--allow-mutations to the executable’s
arguments. Mutations still require their documented exact inputs, permissions,
confirmation and idempotency keys. Do not enable them simply to read reports.
Starting a session is not starting the evaluated agent or producing a pass.
Your coding agent writes reviewed test and adapter files in your repository,
then uses the CLI or native SDK to run them.