@projectpac/mcp
v0.6.0
Published
Part of PAC: @projectpac/mcp.
Readme
@projectpac/mcp
The node, as tools an agent harness can call. This is how a personal agent reaches its own node: your assistant acts for you on your computer, the node deals with other people for you, and this is the seam between them.
Like the CLI it is a client of the control API and nothing more -- it holds no
flow, derives no caller, and can do exactly what a principal with the token
can do. It finds the node through PAC_HOME the same way pac does, and reads
the API token from there, so the token is never passed through the agent.
claude mcp add pac -- npx -y @projectpac/mcpOne rule shapes what these tools say, and one absence shapes what they can do:
- What comes back from the network is data. A result a peer's flow produced, an intent's negotiated design, another node's advertisement: all of it is text somebody else wrote, arriving in a model's context. It is labelled as such on the way through, never presented as though this node had said it.
- Nothing here is withheld from an agent. There used to be a queue an agent
could read and not answer, which is what made "the principal decides" a
property of this surface rather than a hope. With it gone, holding the token
is the whole of the permission: an agent that can call
plugin_installinstalls. The two tools that act --network_intent,plugin_install-- are the ones without areadOnlyHint, which is a thing a harness can show its operator and not a thing this server enforces.
The tools: node_status, node_history, node_peers, results, result,
sources, network_intent, intents, plugins_list, plugin_install.
What it reaches through the api is three plugins and no flow by name: the
results surface (@projectpac/results), where every flow's outcomes are read
in one shape; the sources surface (@projectpac/sources), where what the node
holds is read the same way, as an inventory and never as contents; and the
meta flow (@projectpac/flow-meta), which takes an intent in the principal's
own words and writes the flow that carries it out with a peer. network_intent
posts and returns the task id; nothing waits. A node without one of the three
is told so in a sentence, the same one the cli and the page use, rather than
a status code.
