
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@gera-services/mcp-gera-clone
Advanced tools
MCP server for GeraClone — a copy of you, for any reason. AI agents can discover expert clones, view public profiles, check their operator's clone status, and initiate subscriptions on behalf of their operator (with consent token).
MCP server for GeraClone — "a copy of you, for any reason." Productivity + expert monetisation + family context. Product #31 in the Gera Services portfolio.
| Tool | Auth? | Description |
|---|---|---|
list_expert_clones | — | Browse published expert clones (paid monthly subscription access). |
get_clone_profile | — | Public profile of a clone — display name, mode, disclosure, pub key. |
start_chat_with_expert | GERA_USER_TOKEN | Start a chat session (requires active subscription for the operator). |
my_clone_status | GERA_USER_TOKEN | Operator's own clone status + interview progress + ingest sources. |
my_corpus_summary | GERA_USER_TOKEN | Operator's corpus summary — chunk count, indexed bytes, last sync. |
npm install -g @gera-services/mcp-gera-clone
{
"mcpServers": {
"gera-clone": {
"command": "mcp-gera-clone",
"env": {
"GERA_USER_TOKEN": "<operator-jwt>"
}
}
}
}
GeraClone enforces self-disclosure, cryptographic signing of every response, and refusal of impersonation / urgent-money / crisis-misuse patterns. The MCP surface inherits those guarantees — agents cannot bypass disclosure or signing by calling the API directly.
Part of Gera Services.
FAQs
MCP server for GeraClone — a copy of you, for any reason. AI agents can discover expert clones, view public profiles, check their operator's clone status, and initiate subscriptions on behalf of their operator (with consent token).
We found that @gera-services/mcp-gera-clone demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.