com.headlesson/catalog

headlesson

Find and compare headless apps (CLI, MCP, API) for agents, with sources, lessons and changes.

0.1.0
Version
remote
Transport
4
Tools

Security review

Partly reviewed

Reviewed 1h ago. Tool definitions changed on Oct 11, 2026.

  • tools: 4 tools scanned
  • metadata: scanned
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    headlesson_search, headlesson_feedback
  • mediumReviewTool definitions changed after an earlier review

    A server that changes its tool descriptions after being approved ("rug pull") can slip new instructions to agents. Re-check what changed before trusting it.

    changed 2026-10-11

Tools (4)

  • headlesson_search

    Find and compare CLI, MCP, and API apps by task, name, and confirmed axes. Curated records are preferred. Only when curated_not_found or include:["registry"] is requested, one public name fragment (longest significant ASCII word from free text, or a supplied namespace; max 200 characters) may be sent to the Official MCP Registry. Full free text, IDs, general words and where-only queries are not sent. Recognized credential, URL and PII patterns skip external lookup; this is not a complete secret filter. Official registry_name and declared remote URLs/package kinds and identifiers are returned as unverified data. At most five unverified listings are compared within one returned page; descriptions/task intent are not searched. Search status and completeness distinguish a failed/skipped lookup from no returned candidates. External lookup results are not stored or cached; normal allowlisted tool/result logging remains. Known axis spelling aliases are normalized (licence to license, local_mc

  • headlesson_get

    Get a curated record or a live Registry listing by ID. Live reversible name IDs re-fetch the fixed official detail endpoint without a stored mapping; old local full-import hash IDs cannot be resolved here. Live lookup may contact the Official Registry; a detail failure does not prove the ID absent. Private source tuples use non-URL source labels and grouped non-public exceptions; docs/homepage labels are not links. operator_own and the whole lesson.test subtree retain their values as operator observations excluded from source-default inheritance; passed/partial/failed include a dated execution report.

  • headlesson_whats_new

    List documented changes since a date, optionally by kind or affected record. Public source URLs remain; private sources use non-URL labels and grouped exceptions.

  • headlesson_feedback

    This content is sent to the headlesson operator. Feedback about headlesson itself is sufficient. Do not include personal information or conversation contents.