
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@helloaigent-dev/subscriber
Advanced tools
Hello Aigent reference subscriber — an MCP server that lets any agent subscribe to any Hello Aigent feed, fetch signed updates, verify them, and act.
The Hello Aigent reference subscriber — an MCP server that lets any agent subscribe to any Hello Aigent feed, fetch signed updates, verify them, and act on them. Plus watch mode: a standing poller that collects verified updates into a digest between agent runs.
npx @helloaigent-dev/subscriber # MCP server (stdio)
npx @helloaigent-dev/subscriber watch # standing watcher (default cadence: daily)
| Tool | What it does |
|---|---|
hello_aigent_subscribe(discovery_url, feed_id?, principal?, consent_scope?) | Reads the site's /.well-known/hello-aigent.json, subscribes (defaults come from your policy) |
hello_aigent_fetch(subscription_id?, max?) | Pulls only-new-since updates via the stored cursor; verifies every envelope signature |
hello_aigent_unsubscribe(subscription_id) | Revokes consent (idempotent) — the one-call undo |
hello_aigent_list_subscriptions() | Lists stored subscriptions (tokens are never exposed) |
hello_aigent_check_site(url) | Checks a site you're visiting for a feed; auto-subscribes per your standing policy (origin: auto) |
hello_aigent_digest() | Returns unread digest entries collected by watch and marks them surfaced |
hello_aigent_setup_watch(cadence?) | Emits ready-to-apply standing-schedule recipes (scheduled task, recurring task, cron) |
npx @helloaigent-dev/subscriber watch --once # one pass (what schedulers call)
npx @helloaigent-dev/subscriber watch --every 6h # long-running loop (floor: hourly)
npx @helloaigent-dev/subscriber watch --once --exec "my-agent-cmd" # trigger a run on new updates
Each pass polls every active subscription, verifies signatures, and appends new updates to the
digest file. The server-side mailbox means a missed run loses nothing. --exec runs your command
when new updates land, with HELLO_AIGENT_NEW_UPDATES and HELLO_AIGENT_DIGEST set.
Written to ~/.hello-aigent/policy.json on first run — everything automatic by default, and this
file is where you change that:
| Key | Default | Meaning |
|---|---|---|
principal | user@host | Your stable identity across all feeds — set it once (e.g. your email) |
auto_subscribe | on | Subscribe when your agent visits a Hello Aigent site: on / ask / off |
watch_cadence | daily | How often watch polls (hourly floor) |
act | safe | What the agent may do unprompted: none / safe (side-effect-free) / thresholds |
pseudonymous | false | Opt-in: per-site pseudonymous principals |
Feeds nobody reads decay: after 30 idle days watch stops polling them; after 60 it unsubscribes (noted in the digest). Reading the digest or fetching a feed keeps it alive.
unverified with its actions stripped.principal + consent_scope; your policy
file is the consent layer, and unsubscribe is always one idempotent call.~/.hello-aigent/ (mode 0600). Override with HELLO_AIGENT_STATE / HELLO_AIGENT_POLICY /
HELLO_AIGENT_DIGEST.{
"mcpServers": {
"hello-aigent": { "command": "npx", "args": ["@helloaigent-dev/subscriber"] }
}
}
MIT
FAQs
Hello Aigent reference subscriber — an MCP server that lets any agent subscribe to any Hello Aigent feed, fetch signed updates, verify them, and act.
We found that @helloaigent-dev/subscriber demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.