cardputer-claude-mcp
Turn an M5Stack Cardputer-Adv into a physical approval + usage surface for an AI coding agent (BLE + MCP).
Install / Use
claude mcp add loml13 -- npx -y github:loml13/cardputer-claude-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of cardputer-claude-mcp
cardputer-claude-mcp scores 67/100 on our quality scale, 3661st of 4,529 Development & Engineering skills we index.
Its MCP Server is 4.6 KB long, split into 7 sections with 1 code example: a solid amount of guidance for an agent.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 95/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
cardputer-claude-mcp compared with similar skills
All 4 of these similar skills score higher than cardputer-claude-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cardputer-claude-mcp (this skill)by loml13 | 67 | 10 | 4mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.2k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install cardputer-claude-mcp?
- Run
claude mcp add loml13 -- npx -y github:loml13/cardputer-claude-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does cardputer-claude-mcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is cardputer-claude-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 95/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cardputer-claude-mcp still maintained?
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubcardputer-claude-mcp
English | 中文

Turn an M5Stack Cardputer-Adv into a physical control surface for an AI coding agent.
A small MicroPython app on the handheld talks over BLE to a Mac-side MCP bridge, so an agent (Claude Code, etc.) can:
- notify / ask / confirm — push banners, multiple-choice questions, and physically-confirmed approvals to the device,
- usage — show a live, always-on dashboard (today's spend + 5h/7d subscription utilization + battery) with a resident pixel-crab mascot,
- gate the shell — a Claude Code hook routes Bash commands and file edits to the device for approval before they run.
The headline trick is the approval gate: routine commands pass through a
whitelist, ordinary ones take a single Enter on the device, and
destructive ones (rm -rf, git push, sudo, edits to secrets) take a
single Y press — a different key from the ordinary prompt's Enter, and a
physical keypress that prompt-injection can't synthesize. If the device is
away, it falls back to the normal terminal prompt — the Cardputer is an
optional gate, never a dependency.
| Ordinary action — press Enter | Destructive action — press Y |
|:---:|:---:|
|
|
|
Layout
device/cardputer_mcp.py MicroPython app: BLE GATT service, idle dashboard,
mascot animation, notify/ask/confirm/usage screens
mcp/server.py Mac bridge: BLE owner + MCP tools + usage monitor +
the /hook/confirm route for the approval gate
mcp/auth.py bearer-token auth for the HTTP transport
mac/ launchd bridge daemon + the PreToolUse approval hook
mac/README.md how to install & tune the Mac side ← start here
Quick start
- Bridge:
cd mcp && python3 -m venv .venv && .venv/bin/pip install -r requirements.txt, then runmac/install_cardputer_bridge.sh(seemac/README.md). - Device:
device/cardputer_mcp.pyis not standalone — it deploys into the cardputer-claude-os UIFlow launcher bundle, which provides the app menu, NimBLE bring-up, and the matrix-keyboard driver that this app'srun()relies on. Compile it to.mpy(matchingmpy-cross), drop it into that bundle's/flash/apps/, and delete the.py(importing the source form OOM-crashes the launcher). This repo intentionally ships only the app, not that launcher framework. - Approval gate: register
mac/adv_confirm_hook.pyas aPreToolUsehook in~/.claude/settings.json(snippet inmac/README.md).
Hardware notes (Cardputer-Adv)
- Audio is an ES8311 codec + NS4150B amp.
M5.Speaker.tone()only sounds if the app's main loop callsM5.update()every iteration — without it the chirps are silent. The speaker amp is also muted while the 3.5 mm jack is engaged. - The device app must be deployed as compiled
.mpy, not source.
Security
The bridge gates every HTTP request behind a bearer token; tokens live only
in ~/.config/cardputer-bridge/env (never committed). A physical Y press on
the device is the trust anchor for irreversible operations.
BLE threat model. The BLE link itself is unauthenticated (this NimBLE
build has no bonding), so a hostile neighbor in radio range could advertise
a fake CardputerMCP_* peripheral that acks every confirm. To close that
hole, provision a shared secret: write the same long random string to
~/.cardputer-mcp/secret (Mac) and /flash/mcp_secret.txt (device). The
firmware then signs confirmed acks with HMAC-SHA256 and the bridge rejects
any approval that doesn't verify. With no secret on either side, behavior
is the legacy unsigned mode — fine on a desk you trust, not in a shared
office.
Headless sessions. In contexts with no terminal to answer a fallback
prompt (env LARK_CHANNEL=1 or ADV_CONFIRM_HEADLESS=1), an unreachable
device resolves light-tier approvals to allow and danger-tier ones to
deny — the gate never gets more permissive for risky commands just
because nobody is watching.
Acknowledgements
- Built on cardputer-claude-os — the Cardputer ↔ Claude BLE bundle this extends.
- Usage dashboard inspired by cardputer-claude-usage.
- Spend / token figures come from ccusage.
License
MIT © 2026 neu
Related Skills
Agent-Reach
87.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
