# Hesperan (npm · hesperan-mcp)

Calibrated decisions for agents: choice, yes/no and score questions answered with probabilities.

- Trust score: 64/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-25

## Components

- remote · `api.hesperan.com`: 74/100, [markdown](https://verifymcp.io/servers/com-hesperan-mcp/api.md), [page](https://verifymcp.io/servers/com-hesperan-mcp/api)
- npm · `hesperan-mcp`: 64/100 (this document), [markdown](https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp.md), [page](https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp)

## Channel facts

- Registry: `npm`
- Package: `hesperan-mcp`
- Version: `0.1.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-25.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 0 of 3 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 19/100
  - Repository check failed: no source repository is declared.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 0 days ago).
  - Security-disclosure policy not yet verified: we couldn't inspect the source repository.
- **Schema Quality & AI Usability**: 70/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 683 tokens (~227/item across 3 items; 3 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the Hesperan MCP server?

Hesperan runs locally as an npm package, launched with npx -y hesperan-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add com-hesperan-mcp -- npx -y hesperan-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "com-hesperan-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "hesperan-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-hesperan-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "hesperan-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add com-hesperan-mcp -- npx -y hesperan-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-hesperan-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "hesperan-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-hesperan-mcp --command npx --arg -y --arg hesperan-mcp
```

### Hermes

```yaml
mcp_servers:
  com-hesperan-mcp:
    command: "npx"
    args: ["-y", "hesperan-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "com-hesperan-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "hesperan-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-hesperan-mcp -t stdio -c npx -a -y hesperan-mcp
```

### Other

```json
{
  "mcpServers": {
    "com-hesperan-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "hesperan-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-25 (score 64, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 64)

First indexed and scored.

## MCP tools (3)

### `decide` (~216 tokens)

Decide with Hesperan

Ask Hesperan 1 one or more typed questions about a state and get a probability for every possible answer. Types: choice (pick one of named options), noul (probability that a statement is true), score (level on an ordinal scale). Use for decisions with known options: routing, triage, policy or risk checks, "should I proceed?". Not for writing text, summaries or knowledge questions. Ask all questions about the same state in one call: billing is by input tokens (the state once plus each question once), from the user's monthly allowance and then their prepaid balance; failed calls are free.

Input parameters:

- `questions` (object, required): Named questions, answered together: { "<name>": { "type": "choice" | "noul" | "score", "instructions": "...", "criteria": ... } }.
- `state` (required): The situation to judge: free text, or a JSON object (keeps dates, amounts and fields unambiguous). Leave out data that does not matter for the question.

### `decide_with_profile` (~249 tokens)

Decide with a calibrated profile

Run one of the user's decision profiles on a state. A profile is one question calibrated on the user's own labelled cases with a target precision; the answer is a decision, its calibrated confidence and an action: "auto" (confidence reaches the profile's threshold — act on it) or "review" (hand it to a person). Profiles are created in the Hesperan console; ask the user for the profile slug. Keep the returned decision_id to report the correct answer later with report_outcome. Billed by input tokens like decide; pass an idempotency_key to make retries safe (a repeat with the same key returns the first decision without charging again).

Input parameters:

- `idempotency_key` (string): Optional unique key for this decision (1-255 visible ASCII characters, e.g. the ticket id). Reusing it within 24 hours with the same state replays the stored decision.
- `profile` (string, required): Slug of the decision profile, e.g. "ticket-routing".
- `state` (required): The situation to judge: free text, or a JSON object (keeps dates, amounts and fields unambiguous). Leave out data that does not matter for the question.

### `report_outcome` (~90 tokens)

Report the correct answer

Record the correct answer for an earlier decide_with_profile decision, once it is known (e.g. the team that finally handled the ticket). This tracks the live precision of the profile in the console. actual must be one of the profile's option keys. Free of charge.

Input parameters:

- `actual` (string, required): The correct option key.
- `decision_id` (string, required): decision_id returned by decide_with_profile.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp#diagnostics

## Score history

- 2026-09-25: 64
- 2026-09-24: 64

## Common questions

### What is the Hesperan MCP server?

Hesperan is an MCP server listed in the public MCP registry as com.hesperan/mcp. Calibrated decisions for agents: choice, yes/no and score questions answered with probabilities. This page covers its npm package (hesperan-mcp).

### Is the Hesperan MCP server safe to use?

Hesperan scores 64 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 25 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Hesperan MCP server expose?

Hesperan exposes 3 tools: decide, decide_with_profile, report_outcome. Their descriptions and schemas cost roughly 555 tokens of context every time the server is loaded.

### Is the Hesperan MCP server still maintained?

Hesperan is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Hesperan MCP server under?

Hesperan declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/hesperan-mcp
- Socket report: https://socket.dev/npm/package/hesperan-mcp
- Website: https://hesperan.com/docs/mcp
- Changelog RSS feed: https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-hesperan-mcp/hesperan-mcp
