Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.github.kitepon-rgb/aiterm-mcp

NPM · AITERM-MCP · SCANNED AUG 3

Claude Code drives Codex CLI's interactive TUI and durable tmux terminals over MCP.

Available components

−30 this week 30 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security36
  • Malware scan not yet available for this package.Unverified
  • Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to kitepon-rgb/aiterm-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 0 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability0
  • Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Stability & Change Management0
  • Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Tool Coverage0
  • Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Capabilities0
  • Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.Unverified

Unverified: 4 categories

Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · aiterm-mcp

# add to Claude Code
claude mcp add kitepon-rgb-aiterm-mcp -- npx -y aiterm-mcp
# add to Codex CLI
codex mcp add kitepon-rgb-aiterm-mcp -- npx -y aiterm-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "kitepon-rgb-aiterm-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "aiterm-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add kitepon-rgb-aiterm-mcp --command npx --arg -y --arg aiterm-mcp
# ~/.hermes/config.yaml
mcp_servers:
  kitepon-rgb-aiterm-mcp:
    command: "npx"
    args: ["-y", "aiterm-mcp"]
// mcp.json
{
  "mcpServers": {
    "kitepon-rgb-aiterm-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "aiterm-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 −38
    • Malware scan: pass → unverified security
    • Stability: 0.20 → unverified security
    • Tool coverage: 100 → unverified functional
    • Capabilities: pass → unverified functional
    • Package version: 0.20.3 → 0.21.3 functional
  • 2 Aug 26 +51
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • Malware scan: unverified → pass security
    • The attested source repository moved: kitepon-rgb/aiterm-mcp security
    • MCP protocol: unverified → pass functional
    • Schema quality: unverified → poor functional
    • Maintenance: unverified → pass functional
    • Stability: unverified → 0.20 functional
    • Dependency health: unverified → partial functional
    • License: unverified → pass functional
    • Licence: MIT functional
  • 1 Aug 26 −8
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Capabilities: pass → unverified functional
    • Schema quality: poor → unverified functional
    • Package version: 0.20.2 → 0.20.3 functional
  • 31 Jul 26 +19
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −55
    • Provenance: pass → unverified security
    • Known CVEs: partial → unverified security
    • Install scripts: pass → unverified security
    • The attested source repository moved: kitepon-rgb/aiterm-mcp security
    • Maintenance: pass → unverified functional
    • License: pass → unverified functional
    • Tool coverage: 100 → unverified functional
    • Dependency health: partial → unverified functional
    • Licence: MIT functional
  • 28 Jul 26 +1
    • GHSA-frvp-7c67-39w9 no longer affects this package security
    • Known CVEs: fail → partial security
  • 27 Jul 26 +53
    • GHSA-frvp-7c67-39w9 affects this package: medium security
    • Known CVEs: unverified → fail security
    • Provenance: unverified → pass security
    • Install scripts: unverified → pass security
    • The attested source repository moved: kitepon-rgb/aiterm-mcp security
    • Security disclosure: unverified → fail functional
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: poor functional
    • First check of Tool coverage: 84 functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 62 functional
    • Licence: MIT functional
  • 26 Jul 26 7

    First indexed and scored.

    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
kitepon-rgb/aiterm-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/kitepon-rgb/aiterm-mcp/.github/workflows/ci.yml@refs/tags/v0.21.3
Rekor log index:
2334829757
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:0f0c696b89e4d64471b2ca71569c35714400ef2ced771d56231124cb323a48b70c899ebac5ab4a427f27c444cdf1dff7b03d32aa9923b07a01247463e
Discovery method:
attestation_endpoint
Dependencies 94 packages

94 packages in the resolved dependency tree · 94 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 13 exposed · ~3,560 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
claude_agent ~430

【Claude Code (Anthropic)】の対話エージェントTUIを永続端末に起動する。`claude -p`ではなく、同じ利用者可視sessionへpty_sendで継続入力する。常にmanaged(isolated settingsのStop hook)で起動する。起動前に共有認証を構造化確認し、未認証ならsessionを作らない。managed session内の/login・/logoutは拒否する。起動して投げたら投げっぱなしでよい=親はここで待たない。完了通知は起動応答の wait_command(初回prompt時)または pty_send dispatch 後の aiterm-wait --session <id> --cursor <event_cursor> を親のターンを塞がない別プロセスとして起動して受ける(exit 0=done / 3=timeout(既定600秒・未完了) / 4=closed。receiptのoutcomeが正で、done以外は未完了。ポーリング不要・foreground実行はしない)。結果回収は pty_read(agent_transcript:true)。Claude の durable turn は claude_turn でも回収できる。

NameTypeReqDescription
cwd作業ディレクトリ(対象リポのルート等・任意)
launch_operation_idstringpromptless managed launchのexact replay相関ID。session_name必須
model起動モデル(例: claude-sonnet-4-6)。省略時はClaude CLI既定
prompt起動時に渡す初手プロンプト(任意)。送信後は待たずに即返る
reasoning_effortClaude Code reasoning effort。low/medium/high/xhigh/max。省略時はCLI既定
session_nameセッション名(省略で自動採番)
NameTypeReqDescription
event_cursoryes
managed_completionbooleanyes
providerstringyes
schemastringyes
session_idstringyes
submit_residueyes
wait_commandyes

No examples provided.

claude_approval ~157

managed Claudeのactive turn中に表示された権限確認UIを、turn相関を保ったまま検査・応答する専用面。inspectで画面digestと安全な単発Yes/Noだけを取得し、respondは同じoperation・同じdigestが現在も表示中の場合だけ送信する。

NameTypeReqDescription
actionstringyes
approval_choicestringrespondだけに指定する
observed_prompt_digeststring直前のinspectが返したdigest。respondだけに指定する
operation_iddurable operationのID。通常pty_send由来の匿名turnでは省略する
session_idstringyes
NameTypeReqDescription
actionstringyes
atstringyes
choicesarrayyes
operation_idyes
prompt_digeststringyes
schemastringyes
selected_choiceyes
session_idstringyes
statusstringyes

No examples provided.

claude_turn ~100

managed Claude sessionのdurable operationを構造化issue/recoverするmachine-caller専用面。pending/unknown/completedを人間向けerror文字列の解析なしで返し、Observer固有ロジックは持たない。

NameTypeReqDescription
actionstringyes
operation_idstringyes
session_idstringyes
textstringissueだけに指定するbounded turn本文
NameTypeReqDescription
actionstringyes
operation_idstringyes
raw_outputyes
reasonyes
schemastringyes
session_idstringyes
statusstringyes
submit_residueyes

No examples provided.

codex_agent ~592

【Codex (OpenAI)】の対話エージェント TUI を永続端末に起動する。実装・レビュー・調査を対話で回す。委譲契約を使う完全な呼び出し例: `codex_agent({"prompt":"<依頼>","model":"gpt-5.6-sol","reasoning_effort":"high","cwd":"/absolute/path/to/repo","write_scope":"read-only"})`。turn は pty_send で送る(自動で非ブロック dispatch になる)。起動して投げたら投げっぱなしでよい=親はここで待たない。完了通知は起動応答の wait_command(初回prompt時)または pty_send dispatch 後の aiterm-wait --session <id> --cursor <event_cursor> を親のターンを塞がない別プロセスとして起動して受ける(exit 0=done / 3=timeout(既定600秒・未完了) / 4=closed。receiptのoutcomeが正で、done以外は未完了。ポーリング不要・foreground実行はしない)。結果回収は pty_read(agent_transcript:true)。model / reasoning_effort を引数で指定可(省略時は端末 config/CLI 既定を継承。実効値は起動応答に明示)。

NameTypeReqDescription
cwd作業ディレクトリ(対象リポのルート等・任意)
model起動モデル(例: gpt-5.6-sol / gpt-5.6-terra / gpt-5.6-luna)。省略時は端末 config/CLI 既定を継承(端末側のピンがそのまま効く。実効値は起動応答に明示される)
prompt起動時に渡す初手プロンプト(任意)。送信後は待たずに即返る
reasoning_effortreasoning effort(思考レベル)。low/medium/high/xhigh/max/ultra(CLI 版依存)。ultra は max 推論+proactive 自動委譲 ON=使用量急増注意(明示要求時のみ)。省略時は端末 config/CLI 既定。
session_nameセッション名(省略で自動採番)
write_scopestring能力宣言。read-only、または書込みを許可するパスの説明文字列。Codexのread-onlyだけはCLI sandboxで実効禁止する
NameTypeReqDescription
event_cursoryes
managed_completionbooleanyes
providerstringyes
schemastringyes
session_idstringyes
submit_residueyes
wait_commandyes
write_scopestring
write_scope_enforcementstring

No examples provided.

composer_agent ~439

【Grok Build の Composer モデル (既定 grok-composer-2.5-fast)】の対話エージェント TUI を永続端末に起動する。turn は pty_send で送る(自動で非ブロック dispatch になる)。起動して投げたら投げっぱなしでよい=親はここで待たない。完了通知は起動応答の wait_command(初回prompt時)または pty_send dispatch 後の aiterm-wait --session <id> --cursor <event_cursor> を親のターンを塞がない別プロセスとして起動して受ける(exit 0=done / 3=timeout(既定600秒・未完了) / 4=closed。receiptのoutcomeが正で、done以外は未完了。ポーリング不要・foreground実行はしない)。結果回収は pty_read(agent_transcript:true)。model を引数で指定可。reasoning_effort は非対応(指定はエラー)。

NameTypeReqDescription
cwd作業ディレクトリ(対象リポのルート等・任意)
model起動モデル。省略時は grok-composer-2.5-fast
prompt起動時に渡す初手プロンプト(任意)。送信後は待たずに即返る
reasoning_effort指定不可(grok CLI の --effort は headless 専用で、対話 TUI では警告の上無視される。composer は effort 自体非対応)。指定すると起動前にエラーを返す
session_nameセッション名(省略で自動採番)
write_scopestring能力宣言。read-only、または書込みを許可するパスの説明文字列。Codexのread-onlyだけはCLI sandboxで実効禁止する
NameTypeReqDescription
event_cursoryes
managed_completionbooleanyes
providerstringyes
schemastringyes
session_idstringyes
submit_residueyes
wait_commandyes
write_scopestring
write_scope_enforcementstring

No examples provided.

diagnostics ~52

Factory 向け read-only 診断。安全な状態語彙だけを機械可読 JSON で返す(PTY 内容・認証情報・path・環境値は返さない)。

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

grok_agent ~439

【Grok Build の Grok モデル (既定 grok-4.5)】の対話エージェント TUI を永続端末に起動する。turn は pty_send で送る(自動で非ブロック dispatch になる)。起動して投げたら投げっぱなしでよい=親はここで待たない。完了通知は起動応答の wait_command(初回prompt時)または pty_send dispatch 後の aiterm-wait --session <id> --cursor <event_cursor> を親のターンを塞がない別プロセスとして起動して受ける(exit 0=done / 3=timeout(既定600秒・未完了) / 4=closed。receiptのoutcomeが正で、done以外は未完了。ポーリング不要・foreground実行はしない)。結果回収は pty_read(agent_transcript:true)。model を引数で指定可。reasoning_effort は対話 TUI 非対応(指定はエラー)。

NameTypeReqDescription
cwd作業ディレクトリ(対象リポのルート等・任意)
model起動モデル。省略時は grok-4.5
prompt起動時に渡す初手プロンプト(任意)。送信後は待たずに即返る
reasoning_effort指定不可(grok CLI の --effort は headless 専用で、対話 TUI では警告の上無視される。composer は effort 自体非対応)。指定すると起動前にエラーを返す
session_nameセッション名(省略で自動採番)
write_scopestring能力宣言。read-only、または書込みを許可するパスの説明文字列。Codexのread-onlyだけはCLI sandboxで実効禁止する
NameTypeReqDescription
event_cursoryes
managed_completionbooleanyes
providerstringyes
schemastringyes
session_idstringyes
submit_residueyes
wait_commandyes
write_scopestring
write_scope_enforcementstring

No examples provided.

pty_close ~56

セッションを閉じ、ログ/読取位置を破棄する。同じsession_idへの再試行は安全で、closed/already_closedのstructured receiptを返す。

NameTypeReqDescription
session_idstringyes
NameTypeReqDescription
outcomestringyes
schemastringyes
session_idstringyes

No examples provided.

pty_key ~97

制御キーを送る(C-c, C-d, Enter, Tab, Up, Down... の別名に対応)。managed Claude sessionではturn相関を守るためC-cだけを許可し、承認UIはclaude_approvalで操作する。

NameTypeReqDescription
keystringyesキー名(例 "C-c", "Enter", "Up")
session_idstringyes

No output schema declared.

No examples provided.

pty_list ~39

握っているセッション一覧(名前 / 現在の前面コマンド / attach 状態 / サイズ / agent 情報)。

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

pty_open ~139

ローカル永続端末(tmux セッション)を1個開き、session_id を返す。tmux サーバ常駐ゆえ本サーバや クライアントが再起動してもセッションは生存する。リモート操作は専用ツールにせず、開いた端末の中で pty_send(session_id, "ssh host") と打って入る。

NameTypeReqDescription
nameセッション名(省略時は t1, t2... を自動採番)
shellstring起動シェル(既定 bash)

No output schema declared.

No examples provided.

pty_read ~467

セッションの出力をトークン削減して読む(既定は前回読取位置からの増分)。削減: 制御文字除去 / 反復圧縮 / head+tail 折りたたみ+復元ヒント+メタ併記。agent_transcript:true は agent session の直近完了ターンの最終 assistant メッセージを公開されたvendor記録から平文で返す。長い回答が screen tail で切れた時の回収用。

NameTypeReqDescription
agent_transcriptbooleanagent session の直近完了ターンの最終 assistant メッセージを返す。Claudeはmanaged Stop hook result、他vendorはtranscriptを使う。長い回答がscreen tailで切れた時の回収用
fullboolean増分でなく全文
line_range全文からの行範囲 "A:B"
lines末尾 N 行のみ
operation_idClaude operationの期待ID。agent_transcript:true時だけ指定し、古い別operationの結果を拒否する
rawboolean削減せず生テキスト
rtkboolean直前コマンド別の自前 reducer(git/grep/pytest 等)で縮約
screenboolean描画済みスクリーン(TUI 向け)
session_idstringyes
timeoutnumberwait の最大待ち秒数
untilこの文字列が出たら完了とみなす(既定はリテラル部分一致。`$ ` や `[..]` もそのまま探せる)
until_regexbooleanuntil を正規表現として扱う(既定 false=リテラル部分一致。メタ文字を使いたい時のみ true)
waitboolean完了まで待つ(dead / mark sentinel 自動検出 / until / 出力静止∧シェル復帰 / timeout)

No output schema declared.

No examples provided.

pty_send ~553

セッションへテキストを送る。通常PTYへは送信のみ(出力は pty_read で取得)。agent session(launcher起動)への send は自動で dispatch になる: TUI の ready gate と submit 分離を通して即返り、receipt の event_cursor を返す。dispatch した子は投げっぱなしでよい=親はここで待たない。完了通知は `aiterm-wait --session <id> --cursor <event_cursor>` を親のターンを塞がない別プロセスとして起動して受け、exit を完了通知として扱う(exit 0=done / 3=timeout(既定600秒・未完了) / 4=closed。receiptのoutcomeが正で、done以外は未完了。ポーリング不要)。この待ちコマンドを foreground で実行して親のターンを塞ぐことはしない(receipt が実際の起動形を示す)。結果回収は pty_read(agent_transcript:true)、Claude の durable turn は claude_turn を使う。force:true は非Claude agent sessionへの手動介入用の素送信。managed Claudeの承認UIはclaude_approvalを使う。

NameTypeReqDescription
enterboolean末尾で Enter を送る(agent dispatch では常に submit)
forceboolean破壊的コマンドゲートを越える。非Claude agent sessionではdispatchせず素送信する。managed Claudeのactive turnには使えない
markboolean完了 sentinel(終了コード付き)で包む。pty_read(wait:true) が until 無しでも自動検出して完了確定する(ネスト中や非シェル前面でも効く確実な完了検出。手で until を組む必要なし)。 enter:false と併用すると sentinel が実行されず完了検出が発火しない(送信後に pty_key("Enter") で実行される)。
rawboolean送信前サニタイズを無効化
rtkboolean既知コマンドを rtk 形へ委譲して送る(rtk 不在なら素通し)
session_idstringyes
textstringyes送る文字列(コマンド/prompt)。UTF-8で最大64KiB
NameTypeReqDescription
event_cursoryes
launch_idyes
modestringyes
schemastringyes
session_idstringyes
submit_residueyes
vendoryes

No examples provided.