Back to Browse

Agentsim MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Control plane for agent auth walls. Connector 0 handles SMS OTP with US test numbers.

About

Control plane for agent auth walls. Connector 0 handles SMS OTP with US test numbers.

Remote endpoints: streamable-http: https://mcp.agentsim.dev/mcp

Security Report

4.8
Use Caution4.8High Risk

AgentSIM MCP server is well-designed with proper authentication via API key, appropriate permission scoping, and clean code structure. The server requires AGENTSIM_API_KEY for all operations, validates input schemas rigorously, and makes authenticated HTTP calls to a backend service. Minor code quality observations exist (broad exception handling, missing validation of legacy tool parameters), but these do not materially impact security. Permissions align well with the server's purpose as an authentication challenge provisioning tool. Supply chain analysis found 6 known vulnerabilities in dependencies (1 critical, 3 high severity).

8 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

agentsim-mcp

MCP server that exposes AgentSIM challenge tools to AI coding assistants: Claude Code, Cursor, Windsurf, and any other MCP-compatible host. Primary tools: open_challenge, wait_for_verdict. Aliases: provision_number, wait_for_otp.

Setup

Claude Code

claude mcp add agentsim -e AGENTSIM_API_KEY=asm_live_xxx -- uvx agentsim-mcp

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "agentsim": {
      "command": "uvx",
      "args": ["agentsim-mcp"],
      "env": {
        "AGENTSIM_API_KEY": "asm_live_xxx"
      }
    }
  }
}

Cursor / Windsurf

Add agentsim-mcp as a stdio MCP server with AGENTSIM_API_KEY in the environment config.

Remote (no install)

Connect directly to the hosted MCP server without installing anything locally:

{
  "mcpServers": {
    "agentsim": {
      "type": "streamable-http",
      "url": "https://mcp.agentsim.dev/mcp",
      "headers": {
        "x-api-key": "asm_live_..."
      }
    }
  }
}

The hosted endpoint uses stateless HTTP and does not issue mcp-session-id headers. The session_id returned by AgentSIM tools identifies a challenge and remains valid across tool calls.

Tools

Control-Plane Nouns (Recommended)

ToolDescription
open_challengeOpen an authentication challenge session — accepts channel (sms_otp | email_otp | magic_link | webauthn_required), returns session ID + identifier (phone number or email address)
wait_for_verdictLong-poll for the challenge verdict — returns structured outcome including otp_code, magic_link, webauthn_required, or policy_denied
get_messagesList raw SMS messages received on a session
release_numberRelease a session early (allocation returned to pool)
list_numbersList all active sessions for this account

Legacy Aliases (Backward Compatibility)

ToolMaps toDescription
provision_numberopen_challenge(channel=sms_otp)Provision a temporary programmable US number for SMS OTP — kept for backward compatibility
wait_for_otpwait_for_verdictLong-poll until an OTP arrives — kept for backward compatibility

Auth

Set AGENTSIM_API_KEY in your environment. Get your key at console.agentsim.dev.

Supported Countries

US (more coming soon)

Reviews

No reviews yet

Be the first to review this server!