
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@gently/mcp-server
Advanced tools
MCP server for gently. Agents query the knowledge graph over stdio; authorization uses gently's device flow (approve in the console — no tokens in your MCP config).
npx -y @gently/mcp-server
On the first tool call without credentials, the server returns a console URL and a short
code. Approve there, then retry the same tool call so gently can finish signing in.
Credentials stay on the machine (owner-only) and refresh automatically. A pending device
code is kept across process restarts so a short-lived npx probe does not mint a new code
after you already approved.
For CI, set GENTLY_TOKEN to a bearer token instead of using the device flow.
Point the server at your gently deployment:
| Variable | Required | Purpose |
|---|---|---|
GENTLY_API_URL | yes | Graph API base URL (include /v1) |
GENTLY_IDENTITY_URL | yes | Identity base URL used for device auth |
GENTLY_GRAPH | no | Graph id (defaults to the deployment default) |
GENTLY_CLIENT_NAME | no | Label shown on the approval screen |
GENTLY_TOKEN | no | Bearer token; skips device flow (CI) |
Example MCP client entry:
{
"mcpServers": {
"gently": {
"command": "npx",
"args": ["-y", "@gently/mcp-server"],
"env": {
"GENTLY_API_URL": "<your-graph-api>/v1",
"GENTLY_IDENTITY_URL": "<your-identity-url>"
}
}
}
}
Writes gently agent guidance into the current repo:
npx -y -p @gently/mcp-server gently-mcp-init
MIT
FAQs
gently MCP server — repo-first graph tools for agents
The npm package @gently/mcp-server receives a total of 55 weekly downloads. As such, @gently/mcp-server popularity was classified as not popular.
We found that @gently/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.