headlesson
Find and compare headless apps (CLI, MCP, API) for agents, with sources, lessons and changes.
- 0.1.0
- Version
- remote
- Transport
- 4
- Tools
Security review
Partly reviewedReviewed 1h ago. Tool definitions changed on Oct 11, 2026.
- tools: 4 tools scanned
- metadata: scanned
- mediumReviewRemote tools take credentials as input
Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.
headlesson_search, headlesson_feedback - mediumReviewTool definitions changed after an earlier review
A server that changes its tool descriptions after being approved ("rug pull") can slip new instructions to agents. Re-check what changed before trusting it.
changed 2026-10-11
Tools (4)
headlesson_search
Find and compare CLI, MCP, and API apps by task, name, and confirmed axes. Curated records are preferred. Only when curated_not_found or include:["registry"] is requested, one public name fragment (longest significant ASCII word from free text, or a supplied namespace; max 200 characters) may be sent to the Official MCP Registry. Full free text, IDs, general words and where-only queries are not sent. Recognized credential, URL and PII patterns skip external lookup; this is not a complete secret filter. Official registry_name and declared remote URLs/package kinds and identifiers are returned as unverified data. At most five unverified listings are compared within one returned page; descriptions/task intent are not searched. Search status and completeness distinguish a failed/skipped lookup from no returned candidates. External lookup results are not stored or cached; normal allowlisted tool/result logging remains. Known axis spelling aliases are normalized (licence to license, local_mc
headlesson_get
Get a curated record or a live Registry listing by ID. Live reversible name IDs re-fetch the fixed official detail endpoint without a stored mapping; old local full-import hash IDs cannot be resolved here. Live lookup may contact the Official Registry; a detail failure does not prove the ID absent. Private source tuples use non-URL source labels and grouped non-public exceptions; docs/homepage labels are not links. operator_own and the whole lesson.test subtree retain their values as operator observations excluded from source-default inheritance; passed/partial/failed include a dated execution report.
headlesson_whats_new
List documented changes since a date, optionally by kind or affected record. Public source URLs remain; private sources use non-URL labels and grouped exceptions.
headlesson_feedback
This content is sent to the headlesson operator. Feedback about headlesson itself is sufficient. Do not include personal information or conversation contents.