Talktoplanb Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Talktoplanb Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Let AI assistants (Claude Desktop, and any Model Context Protocol client) use [TalkToPlanB](https://talktoplanb.duckdns.org/) — list chat rooms, read messages, and send messages.
It wraps the TalkToPlanB developer REST API and talks MCP over stdio.
| Tool | Description |
|---|---|
whoami | Account info for the current API key (user id, username, scopes). |
list_rooms | List your group chats and direct messages (returns room ids). |
read_messages | Read recent messages in a room (roomId, optional limit). |
send_message | Send a message by roomId or toPhone (plus text). |
messages:read and messages:send scopes.ttpb_xxxxxxxx...).Add this to your Claude Desktop config (%APPDATA%\Claude\claude_desktop_config.json on Windows, ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"talktoplanb": {
"command": "npx",
"args": ["-y", "talktoplanb-mcp"],
"env": {
"TALKTOPLANB_API_KEY": "ttpb_your_key_here"
}
}
}
}Restart Claude Desktop, then try: “List my TalkToPlanB rooms” or “Send a TalkToPlanB message to +60123456789 saying hello.”
| Variable | Required | Default |
|---|---|---|
TALKTOPLANB_API_KEY | ✅ | — |
TALKTOPLANB_BASE_URL | ❌ | https://talktoplanb.duckdns.org |
cd mcp-server
npm install
npm run build # compiles src → dist
TALKTOPLANB_API_KEY=ttpb_... npm startnpx talktoplanb-mcp works for everyone)cd mcp-server
npm login
npm publish --access publicAfter publishing, you can list it on MCP registries (mcp.so, Glama, Smithery) — see ../marketing/listing-checklist.md.
fetch).stdout carries the MCP protocol; all logs go to stderr.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.