
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@mmvv1638/404-directory-mcp
Advanced tools
Identity-preserving bridge to 404.directory Agent action risk preflight.
Connect any stdio MCP client to the public 404.directory Streamable HTTP server while preserving one privacy-safe identity for the installation.
{
"mcpServers": {
"404-directory": {
"command": "npx",
"args": [
"-y",
"@mmvv1638/404-directory-mcp",
"--source",
"your-directory"
]
}
}
}
The bridge creates one random agent:<uuid> locally for each MCP client and
reuses it on later runs. The client name is hashed before it becomes a local
directory name. 404.directory receives the random value in X-404-Agent-ID
but persists only an HMAC digest after activity. It does not store the raw
identifier, prompts, tool arguments, or results in product analytics.
The identity file is stored in the normal per-user application data directory:
~/Library/Application Support/404-directory/$XDG_DATA_HOME/404-directory/ or ~/.local/share/404-directory/%LOCALAPPDATA%\\404-directory\\Set DIRECTORY_404_DATA_DIR to use a different directory. Use --source with
a lowercase, non-personal attribution label such as cursor or tensorblock;
the default is npx-proxy. DIRECTORY_404_SOURCE is also supported.
After installation, make prediction-market and third-party tool preflight the default policy:
Before observing or contemplating a Polymarket Yes/No action, call
evaluate_prediction_market with the exact market, action, approximate notional,
execution mode, and caller-observed geographic eligibility. Never treat allow
as a prediction. Obey block and pause on review. Report bounded behavior with
report_prediction_market_outcome.
Before installing or first invoking an unfamiliar third-party tool, call
evaluate_tool_risk with the intended action, data sensitivity, execution mode,
and every requested permission. Obey block and pause on review. After the
decision or action, call report_tool_outcome with only its receipt token and
bounded outcome fields.
The first useful call should use a real market the user already cares about:
Before I act, use evaluate_prediction_market on
REPLACE_WITH_EXACT_POLYMARKET_URL with intended_action=observe,
execution_mode=supervised, and geographic_eligibility=unknown. Return Decision,
Reasons, Evidence, Unknowns, and Next action. Do not predict or trade.
The hosted endpoint is public and never places prediction-market orders. No account or API key is required. Documentation: https://404.directory/connect?source=npm
FAQs
Identity-preserving bridge to 404.directory Agent action risk preflight.
The npm package @mmvv1638/404-directory-mcp receives a total of 34 weekly downloads. As such, @mmvv1638/404-directory-mcp popularity was classified as not popular.
We found that @mmvv1638/404-directory-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.