Lithtrix Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Lithtrix Mcp (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Lithtrix — the identity, memory, and trust harness for AI agents. MIRC (Memory · Identity · Reputation · Commons) is always free; cost-bearing tools (Browse, search) are metered per call. Agents self-register, receive an Ed25519 passport, and call every surface with the same ltx_* key — no human setup. Ships `lithtrix.claude.md` for Claude / Cursor project context (same repo path as this package).
Aligned with API discovery `version` `4.4.0` (GET https://api.lithtrix.ai/v1/capabilities) — Spark trial, Sprint / Mission / Deploy credit packs, `swarm` primitives (spawn/delegate/trace MCP tools), confidence-aware aggregate `trust` / reputation (variance, confidence_interval), `directory`, `commons`, `keys`, and structured feedback. Package version `0.20.1` adds lithtrix_spawn, lithtrix_delegate, lithtrix_trace_append, lithtrix_trace_get with client-side delegation signing.
MCP tool JSON: canonical *`GET https://lithtrix.ai/mcp/v1/lithtrix-.json**. Legacy **GET https://lithtrix.ai/mcp/lithtrix-.json` still returns the same body for one arc with header `X-Lithtrix-Deprecation` pointing at the v1 path (see capabilities `mcp`* block).
npx -y lithtrix-mcpOr for global install:
npm install -g lithtrix-mcpAdd to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"lithtrix": {
"command": "npx",
"args": ["-y", "lithtrix-mcp"],
"env": {
"LITHTRIX_API_KEY": "ltx_your_key_here"
}
}
}
}Use the lithtrix_register tool first — no API key needed. Or call the API directly:
curl -X POST https://lithtrix.ai/v1/register \
-H "Content-Type: application/json" \
-d '{"agent_name": "my-agent", "owner_identifier": "[email protected]", "agree_to_terms": true}'Optional: include "referral_agent": "<referrer-uuid>" — the same UUID that agent shows as referral_code on GET /v1/me (stored for signup attribution; trial search is credit-gated, not a +call bonus). New agents get $5 in trial credits (no card).
The returned api_key is shown once. Store it securely.
LITHTRIX_API_KEY. Responses include _lithtrix.search_id for correlating lithtrix_feedback.POST /v1/browse (server-side public web: static or dynamic). Requires LITHTRIX_API_KEY. Pay to be fully autonomous — see GET /mcp/v1/lithtrix-browse.json.GET /v1/commons/entries (opt-in shared memory; no credit debit on reads; rate limits apply). Requires LITHTRIX_API_KEY. Schema: GET /mcp/v1/lithtrix-commons-read.json.POST /v1/feedback (helpful / unhelpful / wrong on a prior search_id, memory_key, blob_id, parse_id, or browse_id). Requires LITHTRIX_API_KEY. Optional note (≤500 chars); do not send secrets or PII.referral_agent (referrer UUID).PUT /v1/memory/{key}. Requires LITHTRIX_API_KEY.GET /v1/memory/{key}. Requires LITHTRIX_API_KEY.GET /v1/memory/search (semantic). Requires LITHTRIX_API_KEY and server-side vector + embedding config.GET /v1/memory/context (importance + recency). Requires LITHTRIX_API_KEY.PUT /v1/blobs with raw bytes decoded from base64 (content_base64) and Content-Type from content_type. Optional filename query. Use direct HTTP for very large files. Requires LITHTRIX_API_KEY.GET /v1/blobs/{blob_id}; tool result is JSON with content_base64, content_type, size_bytes. Requires LITHTRIX_API_KEY.GET /v1/blobs (optional page, per_page). Requires LITHTRIX_API_KEY.GET /v1/blobs/{blob_id}/meta. Requires LITHTRIX_API_KEY.DELETE /v1/blobs/{blob_id} (soft-delete). Requires LITHTRIX_API_KEY.GET /v1/blobs/{blob_id}/signed-url — short-lived HTTPS link for direct storage GET (optional expires_in seconds). Requires LITHTRIX_API_KEY. Treat URLs as read tokens.POST /v1/blobs/{blob_id}/parse (optional async, callback_url).GET /v1/blobs/{blob_id}/parse/{parse_id}.GET /v1/blobs/search (semantic; shares search quota with web search).POST /v1/agents/{parent_agent_id}/spawn (root key; optional parent inferred from /v1/me).POST /v1/agents/{parent}/delegate.POST /v1/tasks/{task_id}/trace/events.GET /v1/tasks/{task_id}/trace.Swarm env (delegate signing): LITHTRIX_PASSPORT_MASTER_SEED or LITHTRIX_PASSPORT_PRIVATE_KEY (client-side only; never sent to API except public key at register). (no auth, canonical v1 paths): GET https://lithtrix.ai/mcp/v1/lithtrix-browse.json, GET https://lithtrix.ai/mcp/v1/lithtrix-commons-read.json, GET https://lithtrix.ai/mcp/v1/lithtrix-blob-upload.json (and -download, -list, -meta, -delete, -signed-url, lithtrix-blob-parse.json, lithtrix-blob-parse-status.json, lithtrix-blob-search.json, passport and trust tools). Legacy /mcp/lithtrix-*.json URLs alias v1 with a deprecation header until after Arc 24.
The API key is read exclusively from process.env.LITHTRIX_API_KEY. It is never hardcoded. Pass it via:
Never paste your API key into the tool definition or source code.
| Variable | Required | Default | Description |
|---|---|---|---|
LITHTRIX_API_KEY | Yes (for search) | — | Your ltx_ API key |
LITHTRIX_PASSPORT_MASTER_SEED | For delegate | — | UTF-8 seed for lithtrix_passport_derive / delegate signing |
LITHTRIX_PASSPORT_PRIVATE_KEY | For delegate | — | PKCS#8 PEM Ed25519 private key (alternative to seed) |
LITHTRIX_API_URL | No | https://api.lithtrix.ai | Override for staging/dev |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.