Monnet Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Monnet Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server for Monnet.
Exposes motions, plans, and approvals to MCP-compatible clients (Claude Desktop, Cursor, etc.) so you can work with your Monnet workspace from your terminal without leaving your AI assistant.
Add this to your MCP client config (e.g. ~/Library/Application Support/Claude/claude_desktop_config.json for Claude Desktop):
{
"mcpServers": {
"monnet": {
"command": "npx",
"args": ["-y", "@monnet/mcp"],
"env": {
"MONNET_API_KEY": "mnk_..."
}
}
}
}Generate an API key at https://app.monnet.ai/settings (API Keys tab).
| Variable | Required | Default | Purpose |
|---|---|---|---|
MONNET_API_KEY | yes | — | API key (mnk_*), sent as the X-API-Key header on every request |
MONNET_API_URL | no | https://api.monnet.ai | Override for self-hosted or local dev backends |
| Tool | Purpose |
|---|---|
monnet_whoami | Verify the connection and list the API keys on your account |
list_workspaces | List the workspaces you belong to |
get_inbox | Fetch your inbox |
list_motions | List motions in a workspace |
get_motion | Read a motion — summary, body, plan, members, comments |
create_motion | Create a new draft motion from a free-form prompt |
update_motion | Update a motion's summary, body, priority, or plan |
comment | Post a comment on a motion (approval-gated, see below) |
approve | Approve a plan step |
reject | Reject a plan step (with an optional reason) |
ask_monnet | Ask Monnet a question on a motion |
Tools that send a message under your identity (e.g. comment) never dispatch automatically. Before the message leaves the MCP server, your client shows a confirmation dialog (MCP elicitation) with a preview; nothing is sent unless you explicitly approve. If your MCP client does not support elicitation, the send is aborted — the gate fails closed.
npm install
npm run buildPoint your MCP client at the local build:
{
"mcpServers": {
"monnet": {
"command": "node",
"args": ["/absolute/path/to/monnet-mcp/dist/index.js"],
"env": {
"MONNET_API_KEY": "mnk_...",
"MONNET_API_URL": "http://localhost:8000"
}
}
}
}Restart your MCP client after editing the config.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.