MCPLow riskUnclaimed

HiddenContent

Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.

hiddencontent.aihiddencontent.ai/mcpUpdated Sep 27, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "ai.hiddencontent/mcp",
  "description": "Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.",
  "title": "HiddenContent",
  "repository": {
    "url": "https://github.com/AeroSpark-ai/hidden-content-service",
    "source": "github",
    "subfolder": "packages/mcp"
  },
  "version": "0.4.15",
  "websiteUrl": "https://hiddencontent.ai/start?ref=mcp-registry",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@hiddencontent/mcp",
      "version": "0.4.15",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "API token for the HiddenContent service. Get one at https://hiddencontent.ai/start?ref=mcp-registry — the server refuses to start without it and says so.",
          "isRequired": true,
          "isSecret": true,
          "name": "HCS_API_TOKEN"
        },
        {
          "description": "Base URL of the service. Defaults to the hosted API; set it only when pointing at a self-hosted instance.",
          "name": "HCS_URL"
        },
        {
          "description": "Comma-separated list of what your agent can actually do. The only accepted values are `tool-use`, `network-egress` and `code-execution`. These turn on the checks for concealed text that instructs a model to call a tool, send data or run code — declaring more can raise severity and never lowers it, and declaring nothing leaves those checks inert. Defaults to `tool-use` in the bundle install.",
          "name": "HCS_CAPABILITIES"
        }
      ]
    },
    {
      "registryType": "mcpb",
      "identifier": "https://github.com/AeroSpark-ai/hiddencontent-mcp/releases/download/v0.4.15/hiddencontent.mcpb",
      "fileSha256": "b206ded6795cf40f367a4ab7617a0b9fdfa1bdf46b7d40d3ac784c91eaef3005",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "API token for the HiddenContent service. Get one at https://hiddencontent.ai/start?ref=mcp-registry — the server refuses to start without it and says so.",
          "isRequired": true,
          "isSecret": true,
          "name": "HCS_API_TOKEN"
        },
        {
          "description": "Base URL of the service. Defaults to the hosted API; set it only when pointing at a self-hosted instance.",
          "name": "HCS_URL"
        },
        {
          "description": "Comma-separated list of what your agent can actually do. The only accepted values are `tool-use`, `network-egress` and `code-execution`. These turn on the checks for concealed text that instructs a model to call a tool, send data or run code — declaring more can raise severity and never lowers it, and declaring nothing leaves those checks inert. Defaults to `tool-use` in the bundle install.",
          "name": "HCS_CAPABILITIES"
        }
      ]
    }
  ],
  "remotes": [
    {
      "type": "streamable-http",
      "url": "https://api.hiddencontent.ai/v1/mcp"
    }
  ]
}

Permissions

DeclaredDetected
Runs code—bundlenode
Installs—npm:@hiddencontent/mcp@0.4.15mcpb:https://github.com/AeroSpark-ai/hiddencontent-mcp/releases/download/v0.4.15/hiddencontent.mcpb
Runs install scripts—None
Networkapi.hiddencontent.aiapi.hiddencontent.ai
Needs credentialsHCS_API_TOKENHCS_API_TOKEN
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.4.15latestOct 7, 2026