
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@project-aegis/mcp-server
Advanced tools
Dependency-free stdio MCP server for Aegis Smart Accounts.
It gives agents typed live account discovery, readiness diagnosis, permission/quota reads, error decoding, current v14 deployment metadata, DeFi selector support, policy amount conversion, and optional authenticated Aegis API calls.
From npm:
npx -y @project-aegis/mcp-server
From a local checkout:
node mcp/aegis/server.mjs
Example MCP client config:
{
"mcpServers": {
"aegis": {
"command": "npx",
"args": ["-y", "@project-aegis/mcp-server"],
"env": {
"AEGIS_API_URL": "https://api.projectaegis.ai",
"AEGIS_DASHBOARD_API_KEY": "optional-api-key",
"AEGIS_RPC_URL": "optional-rpc-url"
}
}
}
}
Local checkout config:
{
"mcpServers": {
"aegis": {
"command": "node",
"args": ["/absolute/path/to/aegis/mcp/aegis/server.mjs"],
"env": {
"AEGIS_API_URL": "https://api.projectaegis.ai",
"AEGIS_DASHBOARD_API_KEY": "optional-api-key",
"AEGIS_RPC_URL": "optional-rpc-url"
}
}
}
}
aegis_supported_chainsaegis_get_contractsaegis_get_defi_supportaegis_amount_to_base_unitsaegis_resolve_account_contextaegis_doctoraegis_get_permission_stateaegis_decode_erroraegis_preflight_transactionaegis_api_endpointsaegis_api_requestaegis_doctor and aegis_api_request require AEGIS_DASHBOARD_API_KEY or AEGIS_API_KEY. Generic API requests only accept /api/v1/... paths.
aegis_resolve_account_context and aegis_get_permission_state follow the account's on-chain enforcer() to its registries. They do not assume the current deployment applies to an older account.
aegis_preflight_transaction requires a chain RPC URL via AEGIS_RPC_URL or the tool's rpc_url argument. It calls the live v14 PermissionEnforcer.checkAction(agentId, permissionId, actionHash, actionData) path and checks EntryPoint deposit/native ETH prefund readiness for a supplied UserOperation gas envelope. It does not submit a UserOperation and does not replace bundler simulation.
cd mcp/aegis
npm run smoke
FAQs
Dependency-free stdio MCP server for Aegis Smart Accounts.
The npm package @project-aegis/mcp-server receives a total of 42 weekly downloads. As such, @project-aegis/mcp-server popularity was classified as not popular.
We found that @project-aegis/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.