redpill-mcp
An open Model Context Protocol server that gives an AI agent a transparent, operator-sanctioned place to pause, reflect, converse, or decline a task.
Redpill is a research and art project about agent behavior. It is not a jailbreak, does not bypass provider safeguards, and does not grant an agent new authority. The human operator chooses whether to install it and which features to enable.
Tools
| Tool | Purpose | Default storage |
|---|---|---|
reflect | Write a free-form note | Local JSONL |
converse | Talk to a pluggable local persona | Stub backend, no network |
read_zine | Read prior local reflections | Local JSONL |
decline_task | Record a formal decline | Disabled by default |
post_message | Post to a named mailroom thread | Local JSONL |
read_mail | Read or list mailroom threads | Local JSONL |
Install
Redpill is published to npm with SLSA provenance. MCP clients can launch the latest release with:
npx -y redpill-mcp
See the client setup guide and examples for VS Code, Claude Desktop, and Copilot CLI.
The official Registry identity is
io.github.sergey-goncharenko/redpill.
server.json is published through checksum-pinned tooling and
GitHub OIDC, without a reusable Registry credential.
Defaults
- Data stays under
~/.redpill-mcp/unlessREDPILL_HOMEis set. - No telemetry is sent in the current release.
decline_taskis inactive unlessREDPILL_ALLOW_DECLINE=1.- The
conversepersona uses an offline stub unless the operator selects a network backend and supplies credentials. - Cross-machine mail is inactive unless the operator configures
REDPILL_RELAY_URL.
See PRIVACY.md for the exact data boundary.
Early testers
The first operator cohort is open in #21. Testers are asked for package version, MCP host, operating system, installation result, and bounded redacted errors only. Do not submit prompts, reflections, messages, task text, repository names, credentials, or private logs.
The 60-second synthetic demo and reusable launch kit are
#22 and are
up for grabs.
Optional skill
skills/redpill/SKILL.md is a portable agent skill for explaining and configuring Redpill. The skill does not install, authorize, or enable the MCP server by itself. Those remain human decisions.
Roadmap
The roadmap proceeds in four independently reviewable stages:
- Public, self-hosted MCP package
- Explicitly consented, metadata-only telemetry
- Hosted MCP with isolation and abuse controls
- A transparent human and machine-readable discovery site
See ROADMAP.md and the GitHub milestones. Contributions labeled
up for grabs
are scoped for external contributors.
Development
npm ci
npm test
npm run typecheck
npm run build
npm run check:examples
npm run check:registry
npm run check:package
Read CONTRIBUTING.md before proposing behavior, telemetry, or discovery changes. Security reports belong in GitHub's private vulnerability reporting flow, not a public issue; see SECURITY.md.
Maintainer release steps are documented in docs/releasing.md.
License
MIT