Run the scanner
Once published to npm:Read the result
Four outcomes, because “graded F” is the wrong answer to three of them:fix: line naming the change that clears it, and a spec: line citing the requirement it enforces.
Exit codes
For CI,--junit report.xml writes the same verdict as JUnit XML (one test case per check) alongside the exit code.
Next steps
What gets checked
The full check catalogue and what each one cites.
Watch for drift
Save a baseline and get alerted when the configuration moves.
Diagnose a failure
Name the failing layer — and the exact known client bug — with
mcpcomp doctor.