Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.cadencercs/cadence

NPM · @CADENCERCS/MCP · SCANNED SEP 20

Send RCS messages from your agent and get typed replies. Automatic SMS fallback.

Available components

+3 this week 73 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency19
  • Repository check failed: the declared repository URL returned HTTP 404. See how to fix → View diagnostics → Fail
  • Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 25 days ago).Pass
  • Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability73
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 2248 tokens (~112/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
  • Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage86
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 57% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "cadence_send" implies "send" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the com.cadencercs/cadence MCP server?

com.cadencercs/cadence runs locally as an npm package, launched with npx -y @cadencercs/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @cadencercs/mcp

# add to Claude Code
claude mcp add com-cadencercs-cadence -- npx -y @cadencercs/mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "com-cadencercs-cadence": {
      "command": "npx",
      "args": [
        "-y",
        "@cadencercs/mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-cadencercs-cadence": {
      "command": "npx",
      "args": [
        "-y",
        "@cadencercs/mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add com-cadencercs-cadence -- npx -y @cadencercs/mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-cadencercs-cadence": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@cadencercs/mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-cadencercs-cadence --command npx --arg -y --arg @cadencercs/mcp
# ~/.hermes/config.yaml
mcp_servers:
  com-cadencercs-cadence:
    command: "npx"
    args: ["-y", "@cadencercs/mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-cadencercs-cadence": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@cadencercs/mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add com-cadencercs-cadence -t stdio -c npx -a -y @cadencercs/mcp
// mcp.json
{
  "mcpServers": {
    "com-cadencercs-cadence": {
      "command": "npx",
      "args": [
        "-y",
        "@cadencercs/mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 10 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

  • 8 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

  • 6 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 3 Sept 26 +4
    • Stability: unverified → 0.27 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed npm/@cadencercs/mcp@0.3.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 96 packages
Packages resolved 96
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 20 exposed · ~2,248 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
cadence_check_brand_readiness ~161

Run the carrier-readiness check: crawls the site, validates the privacy policy, messaging terms, opt-in page, domain age, brand/entity consistency and agent artwork, and generates the copy for anything missing. Every check carries `status`, `blocking` and `permanent`, and the last two are different axes: bad artwork is usually `blocking: false` and `permanent: true`, meaning the brand submits fine and the image freezes forever once verification is requested. Gate on both. `blocking` here means *blocks brand submission*. Whether something blocks agent creation is a different and later gate — cadence_preview_go_live answers that one, and artwork missing entirely stops it even though it only warns here.

NameTypeReqDescription
brandIdstringyes

No output schema declared.

No examples provided.

cadence_check_consent ~59

Whether a brand may message a number, and why not if it may not. Check this rather than attempting a send and reading the error.

NameTypeReqDescription
brandIdstringyes
e164stringyesRecipient in E.164

No output schema declared.

No examples provided.

cadence_close_conversation ~26

Close a conversation. Stops turn counting.

NameTypeReqDescription
conversationIdstringyes

No output schema declared.

No examples provided.

cadence_create_agent ~66

Create an agent under a brand. A local record until it is synced to Google — nothing reaches Google here.

NameTypeReqDescription
brandIdstringyes
displayNamestringyes
useCasestringPERMANENT once synced. Defaults to the brand's.

No output schema declared.

No examples provided.

cadence_create_brand ~45

Create a brand — the business carriers review. Fields are snake_case on brand routes.

NameTypeReqDescription
displayNamestringyesConsumer-facing name, e.g. "Acme Dental"

No output schema declared.

No examples provided.

cadence_get_brand ~36

A brand's details, its latest readiness report, what is blocking submission, and its agents.

NameTypeReqDescription
brandIdstringyes

No output schema declared.

No examples provided.

cadence_get_conversation ~31

State, channel, trust level and turn count for one conversation.

NameTypeReqDescription
conversationIdstringyes

No output schema declared.

No examples provided.

cadence_get_messages ~50

The transcript. Read deliveredText rather than body — on the SMS leg they differ, and body is the composed RCS wording rather than what the recipient actually read.

NameTypeReqDescription
conversationIdstringyes

No output schema declared.

No examples provided.

cadence_get_started ~32

How Cadence works and what to do first. Call this before anything else if you have not used it before.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

cadence_invite_tester ~208

Allowlist a phone number as a test device on an agent, so it can receive real RCS before carrier launch. This is how a message reaches an actual handset without launching to the public. **Invites are a finite, non-refundable resource.** Google allows 20 per agent per day and **200 per agent for its lifetime**, and the lifetime cap cannot be reset by us or by them. Spend them on numbers that will actually be used, not on smoke tests — a sandbox conversation exercises the whole message path for free and costs no invite. The recipient must accept the invitation on the handset. Sending before they accept fails, and that is not a bug in your integration.

NameTypeReqDescription
agentIdstringyesCadence agent id. The agent must exist at Google already — an agent with no RBM agent id has nothing to allowlist against.
e164stringyesThe tester's number in E.164, e.g. +12025550123

No output schema declared.

No examples provided.

cadence_launch_readiness ~45

What is still blocking an agent's carrier launch, while everything is still cheap to change. The launch questionnaire cannot be edited after submission.

NameTypeReqDescription
agentIdstringyes

No output schema declared.

No examples provided.

cadence_list_brands ~23

The brands on your account with each one's carrier-approval status.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

cadence_list_keys ~140

The API keys on this account — prefix, kind, label, brand scope and whether each is revoked. **Never returns a key's secret**; those exist once, at creation, and are not recoverable. Use it to see whether a live key already exists before asking anyone to make one. Creating a key is deliberately not a tool here: a key is a credential, and minting one through this server would write a live secret into a model's context and whatever logs that context reaches. That is a choice for the account owner, in the dashboard or over REST with their own session — not a step an agent should take on their behalf.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

cadence_onboarding_status ~32

The go-live checklist, computed from your account's real state. Each step names the call that completes it.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

cadence_open_conversation ~543

Start a conversation and send the first message. The agent speaks first and opt-in provenance is required. On a sandbox key agentId and brandId are free strings and delivery is simulated.

NameTypeReqDescription
agentIdstringyes
brandIdstringyes
disclaimerstringFrequency, rates, HELP and STOP. Appended to this first message on both legs.
expiresAtstringAn absolute deadline instead. Not both.
expiresInintegerSeconds this message stays worth delivering. Google holds a message for an offline handset up to 30 days — for anything tied to a moment, set this, or a yesterday-shaped question arrives on Thursday…
flowobjectA scripted multi-step survey, driven by us: {id, name, disclaimer, closing|holdOpen, steps:[{id, text, suggestions, smsFallbackText}]}. This is the recommended shape for anything with more than one q…
idempotencyKeystringMakes a retry safe. Without one, a retried send delivers and bills twice.
mediaobjectAn image, chart, PDF or short video to send with this message.
openingTextstringThe first message. Required unless you send `flow`, whose first step is the opening.
optinCapturedAtstringyesISO 8601 timestamp of when consent was given
optinEvidenceRefstringPointer to the proof — a record id or URL
optinMethodstringyesHow consent was captured, e.g. web_form, appointment_booking
smsFallbackTextstringRequired if you send chips or rich content — what the recipient reads on the SMS leg.
suggestionsarrayChips, max 25 chars each, max 11. A string is a quick reply. An object is an action chip — opens a URL, dials, adds a calendar event, shows a location. Reply chips must not be carrier keywords (STOP,…
tostringyesRecipient in E.164, e.g. +12025550123
turnCeilingintegerMax turns before the conversation closes (default 30)
useCasestringyes

No output schema declared.

No examples provided.

cadence_preview_go_live ~99

Rehearse the irreversible step. Creates NOTHING and returns exactly what would be sent to Google: which agents would be created, the fields that can never change afterwards, and anything that would fail. The real call is deliberately not available here. Show this output to the person who owns the account and let them decide — it creates an agent at Google that can never be deleted, by them or by us.

NameTypeReqDescription
brandIdstringyes

No output schema declared.

No examples provided.

cadence_send ~112

Send the next turn in an open conversation. Rich content degrades to smsFallbackText on the SMS leg.

NameTypeReqDescription
conversationIdstringyes
expiresAtstring
expiresIninteger
idempotencyKeystring
mediaobject
smsFallbackTextstring
suggestionsarrayStrings are reply chips; objects are action chips (openUrl, dial, calendar, location).
textstring

No output schema declared.

No examples provided.

cadence_simulate_reply ~248

Deliver a reply as though the recipient sent it. SANDBOX KEYS ONLY — refused on live keys, because it would write words a real person never said into their transcript and consent record. This is how you exercise a conversation end to end without touching a phone.

NameTypeReqDescription
conversationIdstringyes
optionIndexintegerA reply chip on the NEWEST message, 1-based. Arrives as a real postback.
postbackDatastringA chip from ANY recent message, by the slug we generated when we sent it (label lowercased, non-alphanumerics to underscores, then _ and its 1-based position among all chips on that message — e.g. "s…
textstringWhat they typed, e.g. "182.4" or "STOP" or "START"

No output schema declared.

No examples provided.

cadence_update_brand ~233

Set the details carriers verify. Do not guess legalEntity — carriers reconcile it against the site, and a wrong value is worse than a missing one.

NameTypeReqDescription
bannerUrlstring1440x448, under 200 kB, same rules
brandIdstringyes
colorstringHex; needs 4.5:1 contrast against white
contactEmailstringA named individual's mailbox, not a shared alias
descriptionstringAlso sent to Google as the agent description, where the limit is 100 characters.
legalEntitystringExact registered name, e.g. "Salus, Inc."
logoUrlstring224x224, under 50 kB, true-colour PNG or JPEG, no redirects
privacyUrlstringOmit to auto-detect from the website
termsUrlstring
useCasestringPERMANENT at Google once an agent is synced. transactional forbids promotional content forever.
websitestring

No output schema declared.

No examples provided.

cadence_usage ~59

Usage and cost for a calendar month, for the account this server is authenticated as — which is not necessarily the one you have keys for elsewhere. Sandbox conversations are counted and never billed.

NameTypeReqDescription
monthsAgointeger0 is the current month

No output schema declared.

No examples provided.

Common questions

What is the com.cadencercs/cadence MCP server?

com.cadencercs/cadence is an MCP server listed in the public MCP registry as com.cadencercs/cadence. Send RCS messages from your agent and get typed replies. Automatic SMS fallback. This page covers its npm package (@cadencercs/mcp).

Is the com.cadencercs/cadence MCP server safe to use?

com.cadencercs/cadence scores 73 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the com.cadencercs/cadence MCP server expose?

com.cadencercs/cadence exposes 20 tools: cadence_get_started, cadence_onboarding_status, cadence_open_conversation, cadence_send, cadence_simulate_reply, and 15 more. Their descriptions and schemas cost roughly 2,248 tokens of context every time the server is loaded.

Is the com.cadencercs/cadence MCP server still maintained?

com.cadencercs/cadence is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the com.cadencercs/cadence MCP server under?

com.cadencercs/cadence declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.