SkillAgentSearch skills...

cardputer-claude-mcp

Turn an M5Stack Cardputer-Adv into a physical approval + usage surface for an AI coding agent (BLE + MCP).

Install / Use

claude mcp add loml13 -- npx -y github:loml13/cardputer-claude-mcp

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

67/100

Supported Platforms

Claude Code
Claude Desktop

Our assessment of cardputer-claude-mcp

cardputer-claude-mcp scores 67/100 on our quality scale, 3661st of 4,529 Development & Engineering skills we index.

Its MCP Server is 4.6 KB long, split into 7 sections with 1 code example: a solid amount of guidance for an agent.

It has 10 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
26/30
Structure
15/20
Description
12/15
Adoption
4/20
Freshness
11/15

Maintenance, license and trust

  • The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 95/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

cardputer-claude-mcp compared with similar skills

All 4 of these similar skills score higher than cardputer-claude-mcp; compare them before choosing.

SkillScoreStarsUpdatedFormat
cardputer-claude-mcp (this skill)by loml1367104mo agoMCP Server
Agent-Reachby Panniantong10087.2k16d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
rufloby ruvnet10073.6ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install cardputer-claude-mcp?
Run claude mcp add loml13 -- npx -y github:loml13/cardputer-claude-mcp. The install tabs above show the steps for each supported agent.
Which AI agents does cardputer-claude-mcp work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is cardputer-claude-mcp safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 95/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is cardputer-claude-mcp still maintained?
The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

cardputer-claude-mcp

English | 中文

Cardputer-Adv running cardputer-claude-mcp

Turn an M5Stack Cardputer-Adv into a physical control surface for an AI coding agent.

A small MicroPython app on the handheld talks over BLE to a Mac-side MCP bridge, so an agent (Claude Code, etc.) can:

  • notify / ask / confirm — push banners, multiple-choice questions, and physically-confirmed approvals to the device,
  • usage — show a live, always-on dashboard (today's spend + 5h/7d subscription utilization + battery) with a resident pixel-crab mascot,
  • gate the shell — a Claude Code hook routes Bash commands and file edits to the device for approval before they run.

The headline trick is the approval gate: routine commands pass through a whitelist, ordinary ones take a single Enter on the device, and destructive ones (rm -rf, git push, sudo, edits to secrets) take a single Y press — a different key from the ordinary prompt's Enter, and a physical keypress that prompt-injection can't synthesize. If the device is away, it falls back to the normal terminal prompt — the Cardputer is an optional gate, never a dependency.

| Ordinary action — press Enter | Destructive action — press Y | |:---:|:---:| | ordinary approval | danger confirm |

Layout

device/cardputer_mcp.py   MicroPython app: BLE GATT service, idle dashboard,
                          mascot animation, notify/ask/confirm/usage screens
mcp/server.py             Mac bridge: BLE owner + MCP tools + usage monitor +
                          the /hook/confirm route for the approval gate
mcp/auth.py               bearer-token auth for the HTTP transport
mac/                      launchd bridge daemon + the PreToolUse approval hook
mac/README.md             how to install & tune the Mac side  ← start here

Quick start

  1. Bridge: cd mcp && python3 -m venv .venv && .venv/bin/pip install -r requirements.txt, then run mac/install_cardputer_bridge.sh (see mac/README.md).
  2. Device: device/cardputer_mcp.py is not standalone — it deploys into the cardputer-claude-os UIFlow launcher bundle, which provides the app menu, NimBLE bring-up, and the matrix-keyboard driver that this app's run() relies on. Compile it to .mpy (matching mpy-cross), drop it into that bundle's /flash/apps/, and delete the .py (importing the source form OOM-crashes the launcher). This repo intentionally ships only the app, not that launcher framework.
  3. Approval gate: register mac/adv_confirm_hook.py as a PreToolUse hook in ~/.claude/settings.json (snippet in mac/README.md).

Hardware notes (Cardputer-Adv)

  • Audio is an ES8311 codec + NS4150B amp. M5.Speaker.tone() only sounds if the app's main loop calls M5.update() every iteration — without it the chirps are silent. The speaker amp is also muted while the 3.5 mm jack is engaged.
  • The device app must be deployed as compiled .mpy, not source.

Security

The bridge gates every HTTP request behind a bearer token; tokens live only in ~/.config/cardputer-bridge/env (never committed). A physical Y press on the device is the trust anchor for irreversible operations.

BLE threat model. The BLE link itself is unauthenticated (this NimBLE build has no bonding), so a hostile neighbor in radio range could advertise a fake CardputerMCP_* peripheral that acks every confirm. To close that hole, provision a shared secret: write the same long random string to ~/.cardputer-mcp/secret (Mac) and /flash/mcp_secret.txt (device). The firmware then signs confirmed acks with HMAC-SHA256 and the bridge rejects any approval that doesn't verify. With no secret on either side, behavior is the legacy unsigned mode — fine on a desk you trust, not in a shared office.

Headless sessions. In contexts with no terminal to answer a fallback prompt (env LARK_CHANNEL=1 or ADV_CONFIRM_HEADLESS=1), an unreachable device resolves light-tier approvals to allow and danger-tier ones to deny — the gate never gets more permissive for risky commands just because nobody is watching.

Acknowledgements

License

MIT © 2026 neu

Related Skills

View on GitHub
GitHub Stars10
CategoryDevelopment
Updated3mo ago
Forks1

Languages

Python

Trust signals

95/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

2 info