🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@antfeed/mcp

Package Overview
Dependencies
Maintainers
1
Versions
9
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@antfeed/mcp

Model Context Protocol server for the AntFeed Explorer — discover and transact on the AntSeed P2P AI network from any MCP-compatible agent.

Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
63
-32.26%
Maintainers
1
Weekly downloads
 
Created
Source

@antfeed/mcp

Discover and transact on the AntSeed P2P AI network from any MCP-compatible AI agent.

A Model Context Protocol server that turns the AntFeed Explorer into a one-line discovery front door for Claude Code, Cursor, Claude Desktop, and any other MCP host. List sellers, look up provider addresses, inspect on-chain payment channels, and (when a local AntSeed buyer is running) open new sessions — all from inside your agent.

Install

Add the following block to ~/.claude.json (Claude Code), claude_desktop_config.json (Claude Desktop), or your IDE's MCP config:

{
  "mcpServers": {
    "antfeed": {
      "command": "npx",
      "args": ["-y", "@antfeed/mcp"],
      "env": {
        "ANTFEED_EXPLORER_URL": "https://antfeed.org",
        "ANTSEED_BUYER_URL": "http://localhost:8377"
      }
    }
  }
}

Restart your MCP host. The server boots over stdio and exposes the tools below.

Tools

ToolInputsOutputRequires local buyer?
lookupquery (string), limit? (1–100, default 10){ query, matches[], matched, searchedOver, explorerTotal, truncated } — matches against address, displayName, and service namesno
list_providersoffset? (default 0), limit? (1–1000, default 20), sort? (score|recent, default score){ providers[], total, offset, limit, sort } — each provider includes displayName, region, services, per-service pricing, sessionCount, USDC earned, ghost rateno
get_pricingpeerId (string), service (string){ peerId, service, status, currency, inputUsdPerMillion, outputUsdPerMillion, displayName, region, lastUpdated }live pricing from the AntFeed directoryno
get_session_statussessionId (string — channel_id, bytes32 hex){ sessionId, buyer, seller, status, channelBalance, settledAmountUsdc, ... }no
create_sessionproviderPeerId, service, initialDepositUsdc, initialMessage?passthrough from POST localhost:8377/sessions on the local buyeryes
buyer_setup(none)Diagnostic instructions for installing a local AntSeed buyerexposed instead of create_session when no buyer is detected at startup

Example: list top providers

// tool call
{ "name": "list_providers", "arguments": { "limit": 3, "sort": "score" } }

Returns the top three sellers ranked by total USDC earned, each shaped as { peerId, displayName, score, servicesOffered, lastSeen, totalSessions, uniqueBuyers, ghostSessions, totalEarnedUsdc, firstSeen }.

Data sources

The MCP wraps the following AntFeed Explorer endpoints:

  • GET /api/providers — provider directory (displayName, services, per-service pricing, region, on-chain aggregates). Refreshed hourly from network.antseed.com. Backs list_providers and lookup.
  • GET /api/sellers/{address}/services — one seller's service catalog + live pricing. Backs get_pricing.
  • GET /api/channels — on-chain payment channel records. Backs get_session_status.

A few small client-side adaptations remain:

  • No server-side /api/search yet → lookup performs client-side substring matching over the top page of /api/providers (matching against address, displayName, and service names). A future server-side endpoint will let lookup scale past 1000 providers — the MCP will switch over without any client changes.
  • No per-channel /api/channels/{id} yet → get_session_status paginates /api/channels (sorted by last_activity desc) and filters client-side. Channels deeper than 5000 records may return SESSION_OUT_OF_RANGE.

Config

All values are optional. Resolution order: --config file.json → environment variable → built-in default.

VariableDefaultPurpose
ANTFEED_EXPLORER_URLhttps://antfeed.orgBase URL for the AntFeed Explorer REST API.
ANTSEED_BUYER_URLhttp://localhost:8377Local AntSeed CLI buyer RPC. Use http://localhost:8378 for AntStation Desktop.
ANTFEED_MCP_TIMEOUT_MS8000Per-request timeout for explorer and buyer calls.
ANTFEED_MCP_LOG_LEVELinfoOne of debug, info, warn, error. Logs go to stderr (stdout is reserved for MCP stdio).
ANTSEED_BUYER_STRICT0Set to 1 to require the local buyer's /health response to identify itself as {"service":"antseed-buyer"} or {"service":"antstation"}. When unset, the MCP accepts any 200 response and warns once on stderr. Recommended on shared dev boxes.
ANTSEED_MAX_DEPOSIT_USDC10Hard ceiling on initialDepositUsdc in create_session. Defense-in-depth against a prompt-injected agent moving large amounts. The buyer enforces its own auth on top; this is a belt-and-suspenders MCP-side cap.

You can also pass --config path/to/config.json with the same keys (camelCase: explorerUrl, buyerUrl, timeoutMs, logLevel, buyerStrict, maxDepositUsdc).

Buyer auto-detect

On startup the server probes GET <ANTSEED_BUYER_URL>/health with a 500 ms timeout:

  • reachable → registers create_session.
  • not reachable → registers buyer_setup (a diagnostic tool with install instructions) instead, and create_session is omitted from the tool list.

Detection runs once at startup. Restart the MCP host after installing or starting a buyer.

Error model

Every tool returns either a successful structured payload or an MCP error result with isError: true and a structured body of shape:

{ "error": { "code": "EXPLORER_DOWN", "message": "..." } }
CodeMeaning
INVALID_INPUTZod validation failed for the tool arguments.
EXPLORER_DOWNNetwork error or timeout calling the explorer.
EXPLORER_HTTP_<n>Explorer returned a non-2xx status (e.g. EXPLORER_HTTP_404).
RATE_LIMITEDExplorer returned 429.
EXPLORER_INVALID_JSONResponse body was not JSON.
BUYER_DOWNLocal buyer not reachable.
BUYER_HTTP_<n>Local buyer returned a non-2xx status.
BUYER_INVALID_JSONBuyer response body was not JSON.
SESSION_NOT_FOUNDget_session_status could not locate the channel.
INTERNALAnything else (sanitized; no stack traces or env values).

Security model

Installing @antfeed/mcp is an explicit trust decision. Read this section before letting an autonomous agent call its tools.

  • The agent caller is treated as untrusted. Every tool argument is validated by a strict zod schema before any network call. peerId/providerPeerId must be 0x + 40 hex chars; sessionId must be 0x + 1–128 hex chars; service is bounded to a short identifier; initialDepositUsdc is hard-capped by ANTSEED_MAX_DEPOSIT_USDC (default 10 USDC). A prompt-injected agent cannot move arbitrary amounts or craft URL/path-traversal payloads through this MCP.
  • The explorer is treated as semi-trusted. Every response from ANTFEED_EXPLORER_URL is re-validated against a strict zod shape — addresses must be 40-hex, channel IDs must be hex, numeric fields must be finite. Responses are streamed with a 2 MB byte cap so a compromised or hijacked endpoint cannot exhaust memory. Plain http:// is only permitted for loopback hosts; non-loopback URLs must be https://.
  • The local buyer holds your signing key; this MCP never sees it. The MCP only ever POSTs create_session (with bounded deposit, validated input) to the buyer URL — it does not read or store any key material. To prevent another local process from impersonating the buyer (e.g. on shared/multi-tenant dev boxes), set ANTSEED_BUYER_STRICT=1 and have your buyer respond to /health with {"service":"antseed-buyer"}.
  • The package itself ships minimally. dist/, README, LICENSE — no postinstall scripts, no test files, no source maps that leak local paths. npm audit --omit=dev reports zero production-tree vulnerabilities. Dependencies are pinned to ~ ranges; on publish, the package is signed with npm provenance so consumers can verify the tarball came from this repo (npm audit signatures).
  • Error messages are sanitized. File paths, IP addresses, and UPPER_CASE_VAR=… patterns are scrubbed before any error reaches the agent or the MCP host's logs.

If you spot a security concern, please open a private GitHub Security Advisory — we triage these within 72 hours. Do not file a public issue for security-impacting bugs.

For sellers

If you already operate an AntSeed seller and you appear in the AntFeed Explorer directory, you are automatically discoverable through this MCP — no extra registration. New sellers join the directory by simply transacting on-chain (the explorer indexes Base mainnet AntSeed Channels events). Once /api/services and /api/sellers/{address}/services land, get_pricing and list_providers#servicesOffered will populate without any client changes.

Develop

npm install
npm run build         # tsc → dist/
npm test              # vitest, fully mocked, zero network
node dist/index.js    # stdio server (MCP host wires this up; not interactive)

Smoke test the MCP handshake with the official inspector:

npx @modelcontextprotocol/inspector dist/index.js

License

MIT

Keywords

mcp

FAQs

Package last updated on 15 May 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts