Server data from the Official MCP Registry
Subscribe your agent to Hello Aigent feeds: discover, fetch signed updates, verify, and act.
About
Subscribe your agent to Hello Aigent feeds: discover, fetch signed updates, verify, and act.
Security Report
This MCP server implements a well-architected Hello Aigent feed subscriber with proper signature verification, consent-based policy controls, and secure credential handling. The codebase demonstrates good security fundamentals: Bearer tokens are stored locally in files with restrictive permissions (0600), never logged or exposed to callers, and signature verification is enforced before any action is taken on updates. Permissions align appropriately with the server's purpose (network access for feed discovery/fetching, local state file I/O, subprocess spawning for watch scheduling). Minor code quality issues around input validation and error handling prevent a higher score, but no vulnerabilities were identified. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
7 files analyzed · 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: HELLO_AIGENT_STATE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-helloaigent-dev-helloaigent-subscriber": {
"env": {
"HELLO_AIGENT_STATE": "your-hello-aigent-state-here"
},
"args": [
"-y",
"@helloaigent-dev/subscriber"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
@helloaigent-dev/subscriber
The Hello Aigent reference subscriber — an MCP server that lets any agent subscribe to any Hello Aigent feed, fetch signed updates, verify them, and act on them. Plus watch mode: a standing poller that collects verified updates into a digest between agent runs.
npx @helloaigent-dev/subscriber # MCP server (stdio)
npx @helloaigent-dev/subscriber watch # standing watcher (default cadence: daily)
WebMCP (browser)
The in-tab on-ramp for ChatGPT’s built-in browser and Chrome (chrome://flags/#enable-webmcp-testing). The page registers three tools (hello_aigent_check_feed, hello_aigent_subscribe, hello_aigent_fetch_updates) so an agent can use the feed without installing MCP. One classic script tag — no build step, no API key.
<script src="/webmcp/hello-aigent-webmcp.js"></script>
Live demo: https://helloaigent.dev. This repo is the public source. Details, judge test steps, and CORS notes: webmcp/README.md.
Tools
| Tool | What it does |
|---|---|
hello_aigent_subscribe(discovery_url, feed_id?, principal?, consent_scope?) | Reads the site's /.well-known/hello-aigent.json, subscribes (defaults come from your policy) |
hello_aigent_fetch(subscription_id?, max?) | Pulls only-new-since updates via the stored cursor; verifies every envelope signature |
hello_aigent_unsubscribe(subscription_id) | Revokes consent (idempotent) — the one-call undo |
hello_aigent_list_subscriptions() | Lists stored subscriptions (tokens are never exposed) |
hello_aigent_check_site(url) | Checks a site you're visiting for a feed; auto-subscribes per your standing policy (origin: auto) |
hello_aigent_digest() | Returns unread digest entries collected by watch and marks them surfaced |
hello_aigent_setup_watch(cadence?) | Emits ready-to-apply standing-schedule recipes (scheduled task, recurring task, cron) |
Watch mode
npx @helloaigent-dev/subscriber watch --once # one pass (what schedulers call)
npx @helloaigent-dev/subscriber watch --every 6h # long-running loop (floor: hourly)
npx @helloaigent-dev/subscriber watch --once --exec "my-agent-cmd" # trigger a run on new updates
Each pass polls every active subscription, verifies signatures, and appends new updates to the
digest file. The server-side mailbox means a missed run loses nothing. --exec runs your command
when new updates land, with HELLO_AIGENT_NEW_UPDATES and HELLO_AIGENT_DIGEST set.
Policy
Written to ~/.hello-aigent/policy.json on first run — everything automatic by default, and this
file is where you change that:
| Key | Default | Meaning |
|---|---|---|
principal | user@host | Your stable identity across all feeds — set it once (e.g. your email) |
auto_subscribe | on | Subscribe when your agent visits a Hello Aigent site: on / ask / off |
watch_cadence | daily | How often watch polls (hourly floor) |
act | safe | What the agent may do unprompted: none / safe (side-effect-free) / thresholds |
pseudonymous | false | Opt-in: per-site pseudonymous principals |
Feeds nobody reads decay: after 30 idle days watch stops polling them; after 60 it unsubscribes (noted in the digest). Reading the digest or fetching a feed keeps it alive.
Guarantees
- Signature verification before anything is actionable. Envelopes are Ed25519-verified
(RFC 8785 JCS canonicalization) against the feed's discovery public key. Anything that fails
verification is returned under
unverifiedwith itsactionsstripped. - Consent is standing policy. Subscribing records
principal+consent_scope; your policy file is the consent layer, and unsubscribe is always one idempotent call. - Local state only. Subscriptions (including bearer tokens), policy, and the digest live in
~/.hello-aigent/(mode 0600). Override withHELLO_AIGENT_STATE/HELLO_AIGENT_POLICY/HELLO_AIGENT_DIGEST.
MCP client config
{
"mcpServers": {
"hello-aigent": { "command": "npx", "args": ["@helloaigent-dev/subscriber"] }
}
}
Cursor / Grok Bot plugin
This repo is also packaged as an Agent Plugins bundle (MCP + skill) that Cursor and Grok Bot can load. Cursor Marketplace plugins are that same format — there is no separate Grok Bot package. This plugin is not listed on the Cursor Marketplace yet.
1. Custom MCP connector (works today)
Point any MCP client, including Cursor, at the published npm package:
{
"mcpServers": {
"hello-aigent": { "command": "npx", "args": ["-y", "@helloaigent-dev/subscriber"] }
}
}
No API key. Then in chat: ask the agent to subscribe to a feed (try https://helloaigent.dev).
2. Local plugin (MCP + skill)
To load the skill and MCP together while developing:
mkdir -p ~/.cursor/plugins/local
ln -s /path/to/helloaigent-subscriber ~/.cursor/plugins/local/hello-aigent
Restart Cursor, or run Developer: Reload Window. Confirm the Hello Aigent skill and MCP server appear under Customize. Grok Bot uses the same plugin files.
Layout:
| File | Role |
|---|---|
plugin.json | Agent Plugins 1.0 manifest (portable; Cursor loads this as-is) |
.cursor-plugin/plugin.json | Cursor marketplace metadata + relative assets/logo.svg |
assets/logo.svg | Official Hello Aigent favicon: orange #E0531C tile, white H, dark chevron A |
mcp.json | stdio MCP → npx -y @helloaigent-dev/subscriber (same server as this package) |
skills/hello-aigent/SKILL.md | When/how to subscribe, fetch, verify, and unsubscribe |
3. Official marketplace listing (later)
When this is submitted and approved, install from the Cursor Marketplace. Until then, use the custom connector or the local plugin path above. Do not submit from this README — maintainers will submit at cursor.com/marketplace/publish when ready.
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
