
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
myrmigo-mcp
Advanced tools
Myrmigo over stdio for MCP hosts: a proxy to the hosted Myrmigo server (travel and rental booking task reference). Ships no guide content.
Myrmigo for MCP hosts that start local servers over stdio, such as Claude Desktop. It is a small proxy to the hosted Myrmigo server at https://mcp.myrmigo.com.
Myrmigo gives reference information for tasks people do on their own travel and rental bookings, on airline, ferry, hotel, rental and booking sites. It covers the official site and entry page, which company services a booking, dated fees and rules with sources, what to have ready, and the points where the traveller must act personally.
The proxy ships no guide content. Every answer comes from the hosted service, so a withdrawn guide, a site owner's opt-out or an exclusion applies at once.
Requires Node.js 20 or later.
Add this to claude_desktop_config.json, then restart Claude Desktop.
{
"mcpServers": {
"myrmigo": {
"command": "npx",
"args": ["-y", "myrmigo-mcp"]
}
}
}
This connects to the anonymous reference surface, which offers one read-only tool, find_website_task_guide.
If your organisation has a Myrmigo API key, add it to connect to the agent surface. That surface adds step cards and report_task_outcome.
{
"mcpServers": {
"myrmigo": {
"command": "npx",
"args": ["-y", "myrmigo-mcp"],
"env": { "MYRMIGO_API_KEY": "mrm_live_…" }
}
}
}
claude mcp add myrmigo -- npx -y myrmigo-mcp
claude mcp add myrmigo --env MYRMIGO_API_KEY=mrm_live_… -- npx -y myrmigo-mcp # agent surface
Claude Code can also connect to the hosted server directly, with no local process: claude mcp add --transport http myrmigo https://mcp.myrmigo.com/mcp.
| Option | Meaning |
|---|---|
--url <url> or MYRMIGO_URL | The Myrmigo server. The default is https://mcp.myrmigo.com/mcp. The key decides the surface: with a key the proxy uses /agent/mcp, without one /mcp. |
MYRMIGO_API_KEY | An organisation's API key (mrm_live_…). It is read from the environment only, sent only as Authorization: Bearer, and never sent over plain http except to localhost. |
--help, --version | Print help or the version. |
The proxy runs these steps on your machine before anything is sent:
where and booked_via lose their query string, fragment and any credentials, so https://site.example/manage?pnr=… becomes https://site.example/manage. The server strips them too.where, booked_via or goal contains a card number, an IBAN, passport machine-readable data or a secret, that field is not sent.report_task_outcome goes through Myrmigo's scrubber, the same code the server runs. Only the scrubbed report is sent. Names, codes, emails, phone numbers, dates and amounts become {placeholders}, and any label that held one is dropped. If the report contains a card number, an IBAN, passport data, a secret or a link that the guide did not show, nothing is sent and the agent is told why. Without a run_id the report is a flag, so only outcome, where, task and concern are sent.run_id. That context stays in memory for 48 hours and is never written to disk.The proxy sends Myrmigo-Runtime: local so the server knows it runs on the user's own machine. With a key, it also sends Authorization. It sends no other identifier and collects no telemetry. It logs to stderr only, and never logs argument values.
The proxy fails closed. On a network error, an HTTP error or a timeout, the tool answers Myrmigo unavailable; continue without it. The agent can then carry on without Myrmigo. If the service is down when the host starts, the proxy lists a minimal find_website_task_guide, so a later call can still give that answer, or succeed once the network is back.
In the Myrmigo repository, npm run build:mcp writes packages/myrmigo-mcp/dist/myrmigo-mcp.js. That file bundles the proxy, the scrubber and the lexicons it needs. The tests check that the npm tarball contains only that file, this README, the licence and package.json.
The code is under the MIT licence (see LICENSE). Guide text served by Myrmigo is under CC BY-SA 4.0, and quotes stay their owners'.
FAQs
Myrmigo over stdio for MCP hosts: a proxy to the hosted Myrmigo server (travel and rental booking task reference). Ships no guide content.
We found that myrmigo-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.