
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
@tessera-llm/mcp-server
Advanced tools
MCP server exposing Tessera's LLM cost optimization layer as tools for Claude Desktop, Claude Code, Cursor, Cline, Continue, and other MCP-aware clients. Returns savings decisions (anchored spend, drift detection, recommendation approval), not raw logs.
The MCP server that returns money, not data.
Status: v0.1.2 — published 2026-05-27 on npm with sigstore SLSA provenance v1, listed on registry.modelcontextprotocol.io.
Tessera is an LLM proxy that optimizes API spend through multi-provider routing, prompt compression, audit-immutable logging, output-length prediction, and batch arbitrage. This package exposes Tessera as an MCP server for tool-using agents — Claude Desktop, Claude Code, Cursor, Cline, Continue, Goose, Zed.
Where other LLM-infrastructure MCP servers return logs, traces, or prompt metadata, this one returns savings decisions: what's drifting, what to switch, what to approve, what to audit.
npx @tessera-llm/mcp-server
Or add to your client config:
Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"tessera": {
"command": "npx",
"args": ["-y", "@tessera-llm/mcp-server"],
"env": {
"TESSERA_API_KEY": "tk_..."
}
}
}
}
Claude Code (.mcp.json in project root):
{
"mcpServers": {
"tessera": {
"command": "npx",
"args": ["-y", "@tessera-llm/mcp-server"],
"env": {
"TESSERA_API_KEY": "tk_..."
}
}
}
}
Cursor (~/.cursor/mcp.json):
{
"mcpServers": {
"tessera": {
"command": "npx",
"args": ["-y", "@tessera-llm/mcp-server"],
"env": { "TESSERA_API_KEY": "tk_..." }
}
}
}
Get a TESSERA_API_KEY at tesseraai.io/dev — Free Sandbox is 60M tokens/month with no card.
v0.1 exposes 6 tools (5 read + 1 mutate). Hard cap — no tool sprawl.
| Tool | Read/Write | Purpose |
|---|---|---|
tessera_list_workloads | read | List your mapped workloads with anchor cost + current m-stack. |
tessera_get_savings_report | read | Anchored spend + measured savings + performance-fee accrual for a window. |
tessera_get_recommendation_queue | read | Pending Optimize-tab recommendations with expected lift + confidence. |
tessera_get_ledger_entries | read | Audit-immutable Monthly Reading rows (provider call, mechanic stack applied, savings). |
tessera_get_quality_snapshot | read | SLA floor + p50/p95 quality scores + drift events. |
tessera_approve_recommendation | mutate | Move a queued mechanic from "suggested" to "active" with audit-trail entry. |
Provider config writes, API-key management, composition cap changes, and Stripe operations are deliberately NOT in this surface — they live in the dashboard, where blast-radius requires explicit modal confirmation.
TESSERA_MCP_TRANSPORT=http to bind on localhost:8788 for remote / Goose / Zed-via-mcp-remoteSSE (deprecated in MCP spec 2025-11-25) is not supported.
TESSERA_API_KEY env var or Authorization: Bearer <key> header (HTTP transport). Same API key as the SDK — tk_* format. Future v0.2: OAuth 2.1 (aligned with MCP spec RC 2026-07-28).
__untrusted__ to prevent prompt-injection cascade per the Supabase/Cursor 2025 pattern.mcp-scan (Invariant Labs) runs in CI to catch tool-poisoning attacks in tool descriptions.execute_code escape hatch. Typed verbs only.Apache-2.0. Tessera is a product of Fintechagency OÜ (Estonia, Tallinn).
FAQs
MCP server exposing Tessera's LLM cost optimization layer as tools for Claude Desktop, Claude Code, Cursor, Cline, Continue, and other MCP-aware clients. Returns savings decisions (anchored spend, drift detection, recommendation approval), not raw logs.
The npm package @tessera-llm/mcp-server receives a total of 615 weekly downloads. As such, @tessera-llm/mcp-server popularity was classified as not popular.
We found that @tessera-llm/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.