Hooksense Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Hooksense Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol server for HookSense — the webhook & callback layer for AI agents. Lets Claude Desktop, Cursor, Claude Code, Continue, and any MCP client create a callback URL, wait for the result instead of polling, and verify its signature — all from the agent session.
Agents that kick off async work — a deploy, a render, a human-in-the-loop approval, a long tool call, another agent — need the result back without burning context on polling loops. With this server the agent creates a callback endpoint, hands the URL to the job, then calls wait_for_callback and is woken the instant the webhook lands — signature-verified and decrypted. Stop polling for async results; await them.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"hooksense": {
"command": "npx",
"args": ["-y", "@hooksense/mcp"],
"env": {
"HOOKSENSE_TOKEN": "hsk_your_token_here"
}
}
}
}Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"hooksense": {
"command": "npx",
"args": ["-y", "@hooksense/mcp"],
"env": {
"HOOKSENSE_TOKEN": "hsk_your_token_here"
}
}
}
}Once configured, ask your agent:
create_callback_endpoint and gets back a callbackUrl like https://hooksense.com/w/ab12cd.curl -X POST <callbackUrl> -d '{"status":"done"}' from another terminal).wait_for_callback and blocks until the webhook lands, then receives { status: "received", request: { body, headers, … } }.verify_signature confirms the payload is authentic before the agent acts on it.No polling, no dashboards, no copy-paste.
| Tool | Description |
|---|---|
create_callback_endpoint | Create a callback endpoint; returns the callbackUrl |
wait_for_callback | Block until the next callback lands, then return it (timeoutMs, after cursor) |
list_callbacks | List callbacks received by an endpoint (summary view) |
get_callback_payload | Fetch one callback with full headers + decrypted body |
verify_signature | Timing-safe HMAC check against the endpoint's configured secret |
replay_callback | POST a received callback to any target URL |
list_endpoints | List your endpoints |
get_endpoint | Get one endpoint's full settings |
| Variable | Default | Notes |
|---|---|---|
HOOKSENSE_TOKEN | _(required)_ | API token from /account/tokens |
HOOKSENSE_API | https://hooksense.com | Override for self-hosted/staging |
"Create a callback endpoint, use it as the webhook for my Replicate prediction, and wait for the result — then summarize the output."
"Open a callback URL, give it to the approval step, and block until a human approves before continuing."
"Wait for the next Stripe callback on payments-prod, verify its signature, and tell me the amount."MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.