io.github.falsalama/mylegend

MyLegend — public profiles, rich cards and personal agents

Find owner-published people, display rich profile cards and ask approved public questions. No login.

1.0.0
Version
remote
Transport
5
Tools

Security review

Partly reviewed

Reviewed 1h ago. Tool definitions changed on Oct 11, 2026.

  • tools: 5 tools scanned
  • metadata: scanned
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    save_my_agent_draft
  • mediumReviewTool definitions changed after an earlier review

    A server that changes its tool descriptions after being approved ("rug pull") can slip new instructions to agents. Re-check what changed before trusting it.

    changed 2026-10-11

Tools (5)

  • find_person

    Use this when locating a person's owner-published MyLegend profile by name, headline, job title or organisation. Returns at most 10 matches with approved job, organisation and location context, including labelled fictional demos. Compare supplied context with those fields; ask for clarification if multiple plausible people remain. Location is not a search field. When the user requests a profile or rich card and the person is resolved, call get_profile once with the returned slug. A match is not independent verification.

  • get_profile

    Use this when the user asks to see a person's MyLegend profile or interactive rich card. Shows the card, with questions and a private message composer, in a compatible connected MCP Apps host. Invoke once to display the card; use ask_person for follow-up answers without another card. Use the resolved slug from find_person or a known MyLegend profile URL. No MyLegend login is needed for public cards.

  • ask_person

    Use this for a specific question about a resolved published person, including follow-ups to their displayed rich card. Answers use approved information. Ask explicitly for technical detail, equations or a derivation to receive longer approved material when available. A question-only request does not require a card. If a card is requested, use get_profile once. No raw CV or P3 data is exposed.

  • get_my_agent_draft

    Use this to review the signed-in owner's suggested public introduction. Excludes private CV, knowledge, rules and unpublished personal notes. Never reads another account.

  • save_my_agent_draft

    Use this only when the signed-in owner explicitly asks to create or edit their MyLegend agent. Save only the fields they choose to share from this conversation, never the whole chat. Read the current revision first (0 if no draft). Saves a PRIVATE draft, never publishes. Show the proposed text for review and link to MyLegend for owner approval. Do not invent credentials or infer sensitive details.