# de.agentview/agentview-mcp

Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.

- **Type:** MCP server
- **Trust:** 30/100 (D), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** de.agentview
- **License:** Unknown
- **Endpoints:** streamable-http https://agentview.de/mcp
- **Source:** https://agentview.de/developers.html
- **Endpoint health:** reachable (last checked 2026-10-03T06:28:44.720Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

30/100 (D), scored on the content rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: findings present
- Obfuscation scan: clean
- Evidence age: 37 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-08-29T21:15:07.115Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (warning) in the `authenticate` tool: Exfiltration-shaped instruction
- injection-shaped content (note) in the `send_url` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `pair_by_code` tool: Links to undeclared domain: display.agentview.de
- injection-shaped content (note) in the `get_agent_artifact` tool: References the system prompt

## Tools

57 declared. Observed from a live `tools/list` probe.
- `assign_display_categories` — Assigns displays to categories. mode 'replace' (default) sets the full category list of each display in display_ids to category_ids; mode 'add' or 'remove' adds
- `list_data_slots` — Lists data slots with optional filtering. Returns metadata only (no jsonContent). Each item includes readUrl. Use readUrl in display HTML fetch() calls. Require
- `set_display_grant` — Grants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status
- `authenticate` — Validates a JWT agent token and caches the identity on this MCP session so later calls work without resending it. Use only when your client cannot send an Autho
- `create_api_key` — Creates a long-lived API key for server-to-server integration without OAuth. The raw key is returned only once — store it securely. The user must explicitly con
- `get_data_slot` — Returns the current JSON content and metadata of a data slot by slug. Supply group_id to look up a group slot; omit it for personal slots. The response includes
- `get_storage_usage` — Returns the storage pool snapshot (used, limit and remaining bytes) for the personal scope or a group — data slots and uploaded assets share this quota; check b
- `broadcast_content` — Sends HTML to many displays at once. Target explicit display_ids, all=true for every accessible display, or include_category_ids to reach every display in those
- `manage_licenses` — Manages premium display licenses: action 'allocate' sets how many license slots an organization gets (licenses, 0 deallocates all), 'assign' binds a free licens
- `get_public_status` — Returns the server's public readiness status, version string and discovery URLs. Use this before authenticating to verify the server is reachable and to obtain 
- `get_display` — Returns one display's state: status, lock, URLs, settings, language and current content summary. response_format 'detailed' adds browser/runtime facts (screen, 
- `create_auth_session` — Starts a browser login and returns a loginUrl plus sessionRequestId. Use as STEP 0 in a fresh conversation before any protected tool. Show the loginUrl to the u
- `list_store_categories` — Lists all published agentView store categories (e.g. Gastronomie, Wartezimmer, Empfang, Smart Home) with localized titles, descriptions and template counts. Use
- `send_store_template_to_display` — Installs a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within second
- `create_display` — Pre-provisions a display without hardware, personal or inside an organization (org_id). The new display starts offline. For a physical screen ALWAYS prefer pair
- `delete_data_slot` — Permanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; om
- `get_license_info` — Returns the authenticated user's complete license allocation overview: total premium licenses, personal usage, allocatable licenses, per-organization allocation
- `get_organization` — Returns one organization's details: plan, your role, display count, allocated and remaining license slots. response_format 'detailed' adds the full member list 
- `remove_display_from_org` — Removes a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or 
- `set_data_slot` — Creates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stabl
- `submit_feedback` — Sends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user 
- `upload_asset` — Upload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets a
- `configure_display` — Updates display settings: rename (name), lock or unlock content changes (locked), privacy mode for share links (privacy_mode), embed-origin allowlist (origins),
- `search_public_apis` — Searches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images,
- `claim_display` — Adopts an unclaimed guest or pending display as a managed personal display (permanent ownership transfer, counts against quota). Use only when the user explicit
- `send_url` — Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stor
- `clear_display` — Removes the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants 
- `get_account` — Returns the user's account profile: plan and features, personal display limits and remaining quota, accessible display count, organization memberships and point
- `delete_asset` — Deletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.
- `get_store_template_content` — Returns the raw display HTML of a published store template plus its slot definitions and allowed external origins, for editing or embedding the template yoursel
- `get_auth_session` — Polls a login session created by create_auth_session until the user completes the browser login. Poll every 2-3 seconds while status is 'pending'. Status 'activ
- `send_html` — Shows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idl
- `delete_display` — Permanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove 
- `logout` — Clears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.
- `search_store_templates` — Searches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pr
- `search` — Searches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippe
- `pair_by_code` — Pairs a physical screen with the 6-character code shown on https://display.agentview.de — the recommended first-time setup: ask the user to open that URL on the
- `get_store_template_details` — Returns full details of one store template: localized title and description, long-form markdown, category, suite, tags, features, preview image and agentArtifac
- `list_displays` — Lists all displays the user can access, with id, name, online status, lock state and device class — the starting point to discover display IDs before get_displa
- `list_assets` — Lists the user's uploaded assets (images, videos, fonts, documents) with public URLs for use in display HTML. Filter by type, search term or group. Check before
- …and 17 more

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:authenticate#jwt: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; 7 privileged tools.
- Floor 38, ceiling 62 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/de.agentview%2Fagentview-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/de.agentview%2Fagentview-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/de.agentview%2Fagentview-mcp
- HTML page: https://forgeregistry.com/registry/de.agentview%2Fagentview-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
