
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@phasefolio/mcp
Advanced tools
PhaseFolio MCP client — biotech rNPV / probability-of-success engine for AI agents. One-line install for Claude, Codex, Cursor, and any MCP-compatible client.
The PhaseFolio MCP client — exposes PhaseFolio's biotech rNPV / probability-of-success engine to any AI agent that speaks the Model Context Protocol.
PhaseFolio is an audit-grade asset valuation workspace for healthcare investors and tech transfer offices. This MCP server gives AI agents direct access to the same engine, scenarios, evidence registers, signed dossier exports, methodology, and competitive landscape that human analysts use in the product.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"phasefolio": {
"command": "npx",
"args": ["-y", "@phasefolio/mcp"]
}
}
}
For org-scoped tools (your own scenarios, projects, evidence, signed exports), set your bearer token:
{
"mcpServers": {
"phasefolio": {
"command": "npx",
"args": ["-y", "@phasefolio/mcp"],
"env": {
"PHASEFOLIO_TOKEN": "pft_..."
}
}
}
}
Restart Claude Desktop.
HTTP-native — no wrapper needed:
claude mcp add --scope user --transport http phasefolio https://app.phasefolio.com/api/mcp
# with bearer:
claude mcp add --scope user --transport http phasefolio https://app.phasefolio.com/api/mcp \
--header "Authorization: Bearer pft_..."
codex mcp add phasefolio --http https://app.phasefolio.com/api/mcp
Use the Claude Desktop snippet above (stdio) or point your client at https://app.phasefolio.com/api/mcp if it speaks streamable HTTP.
Nine tools across two auth tiers.
Public (no token)
query_benchmarks — anonymized network statistics across the PhaseFolio scenario base (PoS by indication × modality, cost / duration percentiles)verify_export — verify a signed PhaseFolio dossier by content hash or URL; returns issued timestamp, methodology version, originating-org identifierget_methodology — fetch any methodology section in citable form (backtest, PoS calibration, IRA framework, evidence standards, network benchmarks)Bearer (PHASEFOLIO_TOKEN env var, scoped to your org)
get_project — project metadata: indication, sub-indication, modality, biomarker, asset name, stage at entrylist_scenarios — scenarios in a project with top-line eNPV / rNPVget_scenario — full scenario inputs + computed outputs (eNPV, rNPV, cumulative PoS, per-stage breakdown, top sensitivity drivers)get_evidence — evidence-register entries: citations, sources, supporting documentsget_dossier — structured dossier JSON, mirroring the IC Dossier PDF / Excel exportsquery_landscape — asset-anchored competitive landscape (comparable trials, competing programs, sponsor activity, biomarker overlap) sourced from CT.gov + FDA + curated enrichmentBearer tokens are issued per organization. Sign up at app.phasefolio.com (free Research Tier available for academics) — token issuance is currently manual for design partners; contact us at phasefolio.com/contact for access.
Every PhaseFolio dossier export carries a cryptographic signature that ties the file content to the engine version and methodology version that produced it. AI agents can verify any PhaseFolio file in one call:
verify_export({ hash: "<sha256-of-the-file>" })
or by URL:
verify_export({ artifact_url: "https://..." })
The public key lives at https://app.phasefolio.com/.well-known/phasefolio-pubkey.pem. Methodology versions and the verify endpoint are documented at https://app.phasefolio.com/methodology.
MIT
FAQs
PhaseFolio MCP client — biotech rNPV / probability-of-success engine for AI agents. One-line install for Claude, Codex, Cursor, and any MCP-compatible client.
We found that @phasefolio/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.