
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@phi-longevity/mcp-server
Advanced tools
Model Context Protocol server for Phi Longevity — agents can call the PRISM longevity recommendation engine on SYNTHETIC biomarker panels. Synthetic/de-identified data only; no PHI; stateless.
A Model Context Protocol (MCP) server that lets AI agents call Phi Longevity's PRISM clinical recommendation engine on synthetic biomarker panels — guideline-cited, evidence-tiered recommendations an agent can use when researching options for the person it's helping.
🛡️ Synthetic / de-identified data only. Do not submit protected health information (PHI). The server is stateless and stores nothing. Real health files are analyzed only inside the authenticated Phi Longevity app, after consent, by the account owner.
| Tool | What it does |
|---|---|
analyze_biomarkers | Analyze a synthetic panel → tiered, guideline-cited recommendations. Includes a full_report block your user can follow for a complete PRISM report. |
list_supported_biomarkers | 51 scored biomarkers + units + reference ranges, by clinical pillar. |
get_methodology | How the Phi Score works (5 pillars + weights) + link to the full methodology. |
{
"mcpServers": {
"phi-longevity": {
"command": "npx",
"args": ["-y", "@phi-longevity/mcp-server"]
}
}
}
That's it. A published, rate-limited access key is built in. If you have a dedicated key,
set PHI_MCP_KEY to override it.
Point any MCP client that supports Streamable HTTP at:
https://philongevity.com/mcp
Same three tools, same synthetic-only rule, nothing to install.
npm install && npm run build
node dist/index.js
// analyze_biomarkers input (synthetic values only)
{
"biomarkers": { "HbA1c": 6.4, "LDL-C": 145, "Triglycerides": 190 },
"conditionFocus": "type2_diabetes" // or general_wellness | lupus | cancer_survivorship
}
// → tiered, guideline-cited recommendations + a `full_report` block
// pointing the user to a complete PRISM report at philongevity.com
The tools analyze a handful of values at a time. A full PRISM report consolidates all of a person's lab reports, wearable data, and clinical notes into one integrated picture with a personal health score and progress over time. Agent docs + signup: https://philongevity.com/for-agents
| Var | Required | Notes |
|---|---|---|
PHI_MCP_KEY | no | Overrides the built-in published key. Rate-limited + revocable. |
PHI_ENGINE_URL | no | Override the default Phi MCP gateway URL (rarely needed). |
Synthetic-only at the protocol boundary; stateless; aggregate-only telemetry (counts/timing to stderr, never values or recommendation text); zero access to Firestore / the HIPAA datastore / user accounts. GDPR: processes no personal data (synthetic only) → minimal exposure.
Apache-2.0.
FAQs
Model Context Protocol server for Phi Longevity — agents can call the PRISM longevity recommendation engine on SYNTHETIC biomarker panels. Synthetic/de-identified data only; no PHI; stateless.
The npm package @phi-longevity/mcp-server receives a total of 111 weekly downloads. As such, @phi-longevity/mcp-server popularity was classified as not popular.
We found that @phi-longevity/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.