Spill intercepts oversized MCP tool responses and stores them as local DuckDB tables. Your AI agent gets a compact descriptor and runs SQL instead of reading 50,000 tokens of raw JSON.
Hook fires on every MCP PostToolUse event. Payloads under 32 KiB pass through untouched.
Rows land in ~/.spill/spill.duckdb. No cloud account, no embeddings, no infrastructure.
Filter, aggregate, join. DuckDB runs read-only with external access disabled.
Keyword validator + connection-level read-only mode. Mutations are blocked at two layers.
Cursor, Codex, and Claude Code. One install command per client, fully reversible.
One-line install. No separate tap repo needed — this repo doubles as the tap.
Homebrew builds Spill from source with embedded DuckDB. The first build takes a few minutes; upgrades are instant.
$ brew tap spill-ai/spill https://github.com/spill-ai/spill $ brew trust --formula spill-ai/spill/spill $ brew install spill $ spill install cursor # or: codex claude
Restart your client after install to load the MCP server and hooks.
Use spill uninstall cursor to remove — unrelated config is never touched.
| Client | MCP config | Hook config |
|---|---|---|
| Cursor | ~/.cursor/mcp.json |
~/.cursor/hooks.json |
| Codex | ~/.codex/config.toml |
~/.codex/hooks.json |
| Claude Code | ~/.claude.json |
~/.claude/settings.json |
Serialized tool output must be at least 32 KiB and contain a nonempty array of JSON objects. Three payload shapes are supported:
structuredContent arrayColumns are inferred as BOOLEAN, BIGINT, DOUBLE, or VARCHAR. Nested objects, arrays, and mixed types are stored as JSON text. Missing values become SQL NULL.
-- Agent receives a compact descriptor, then queries directly SELECT state, COUNT(*) AS n FROM spill_list_issues_a81f32 GROUP BY state ORDER BY n DESC;
Only SELECT, WITH, SHOW, DESCRIBE, and EXPLAIN are allowed.
A SQL tokenizer rejects mutations, multiple statements, and semicolons mid-query.
Independently, DuckDB opens in read-only mode with external access and
extension loading disabled.
# Dataset management spill list spill describe spill_list_issues_a81f32 spill sql 'SELECT state, count(*) FROM spill_list_issues_a81f32 GROUP BY state' # Hook and MCP server (normally launched by the client) spill hook cursor # also: codex, claude — reads one JSON event from stdin spill mcp # stdio MCP server # Install / uninstall spill install cursor spill uninstall cursor
The MCP server exposes query, list, and describe.
Query responses have columns and rows in column order.
Full documentation →