Occasio runs on your own machine — the client starts it, so there is no endpoint to ping. 77 installs a week from npm. Last commit 24 Jun 2026.
Tamper-evident, Sigstore-signed audit trail for Claude Code agents.
We read the source, 18 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
command_regex: '\b(systemctl|sudo|pkexec|doas)\b|(^|[\s;&|])su\b'
'\n', '\r\n', '\x00', ';rm -rf /', '`whoami`', '$(id)',
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
const candidate = path.join(root, encoded);
child = spawn(cmd, args, { stdio: ['pipe', 'ignore', 'ignore'], shell: process.platform === 'win32' });
- "**/id_rsa" # SSH private keys by filename, anywhere (not just ~/.ssh)
ul.innerHTML = html;
"payload": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJwcmVkaWNhdGUiOnsiYWdlbnQiOnsiZW5kZWRfYXQiOiIyMDI2LTAxLTE1VDA5OjAwOjA1LjAwMFoiLCJtb2RlbCI6bnVsbCwicGxhdGZvcm0iOiJjbGF1ZGUtY29kZSIsInNlc3Npb25faWQiOiIxMTExMTExMS0yMjIyLTQzMzMtODQ0NC01NTU1NTU1NTU1NTUiLCJzdG…
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Occasio and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add occasio -- npx -y @occasiolabs/occasio
{
"mcpServers": {
"occasio": {
"args": [
"-y",
"@occasiolabs/occasio"
],
"command": "npx"
}
}
}
[mcp_servers.occasio]
command = "npx"
args = ["-y", "@occasiolabs/occasio"]
{
"mcpServers": {
"occasio": {
"args": [
"-y",
"@occasiolabs/occasio"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"occasio": {
"args": [
"-y",
"@occasiolabs/occasio"
],
"command": "npx"
}
}
}
Persistent, evidence-backed code graph for coding agents.
Cryptographic audit trail for Claude Code workflows — tamper-proof timestamps, IETF TTTPS compliant.
Signed, cited, replayable workflows for Claude, Codex, Gemini, DeepSeek, and other agents.
Live SEO workflow tools for Claude Code, Codex, and AI agents.
Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.
Mines your Claude Code and Cursor sessions into evidence-based CLAUDE.md / AGENTS.md rules.
No-key travel MCP for Claude Desktop, Codex-style agents, Hermes, and other clients.
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
Answers built from our own checks of this server.