Skip to content

HiddenContent

Runs locallyCredentials listedSource code linkedUpdated 2026-09-02

ai.hiddencontent/mcp · Registry status: active

At a glance

Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.

Vendor's own description, untranslated and unverified

Execution location
localMCP-Register · 2026-09-02
Required secrets declared
yesMCP-Register · 2026-09-02
Declared version and change
0.4.13 · Changed in the registry 2026-09-02MCP-Register · 2026-09-03
Repository as declared
github.com/AeroSpark-ai/hidden-content-serviceMCP-Register · 2026-09-02
Configuration
can be built from the disclosed start template
Runs
local
Credentials
true
Source updated
2026-09-02
Setup
Template available
Registry name
ai.hiddencontent/mcp
Package coordinate
npm:@hiddencontent/mcp
Declared version
0.4.13
Listed in the registry
2026-09-02
Changed in the registry
2026-09-02
First seen by tracevero
2026-09-02
Vendor's website
https://hiddencontent.ai/start?ref=mcp-registry

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean

Measured values

Measured values
Required secrets declaredyes
Original data – Required secret variables (raw): HCS_API_TOKEN, HCS_API_TOKEN
Original data – Required secret headers (raw): confirmed absent
Source: MCP-Register · collected on 2026-09-02 · derived
Execution locationlocal
Original data – Transports (raw): stdio, stdio
Source: MCP-Register · collected on 2026-09-02 · derived
Path argument presentno
Original data – Path arguments (raw): confirmed absent
Original data – Path environment variables (raw): confirmed absent
Source: MCP-Register · collected on 2026-09-02 · derived
Repository URL listedyes
Original data – Repository (raw): https://github.com/AeroSpark-ai/hidden-content-service
Source: MCP-Register · collected on 2026-09-02 · derived
Field of use, derived from the vendor descriptionDocuments
Original data – Description (raw): Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.
Source: MCP-Register · collected on 2026-09-02 · derived
Declared version0.4.13
Source: MCP-Register · collected on 2026-09-03 · self-declared

What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.

Related categories

Source data24

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.

Raw values
Description (raw)Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.
Source: MCP-Register · collected on 2026-09-02 · self-declared
Environment variables (raw)HCS_API_TOKEN, HCS_URL, HCS_CAPABILITIES, HCS_API_TOKEN, HCS_URL, HCS_CAPABILITIES
Source: MCP-Register · collected on 2026-09-02 · self-declared
Required secret variables (raw)HCS_API_TOKEN, HCS_API_TOKEN
Source: MCP-Register · collected on 2026-09-02 · self-declared
Transports (raw)stdio, stdio
Source: MCP-Register · collected on 2026-09-02 · self-declared
Path arguments (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Repository (raw)https://github.com/AeroSpark-ai/hidden-content-service
Source: MCP-Register · collected on 2026-09-02 · self-declared
Package registries (raw)mcpb, npm
Source: MCP-Register · collected on 2026-09-02 · self-declared
Required secret headers (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Path environment variables (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Remote URLs (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Remote hosts (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Registry status message (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
First listed in the registry (raw)2026-09-02
Source: MCP-Register · collected on 2026-09-03 · self-declared
Last changed in the registry (raw)2026-09-02
Source: MCP-Register · collected on 2026-09-03 · self-declared
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Source: MCP-Register · collected on 2026-09-02 · self-declared
Delivery form (raw)package
Source: MCP-Register · collected on 2026-09-02 · self-declared
Repository platform (raw)github
Source: MCP-Register · collected on 2026-09-02 · self-declared
Repository subfolder (raw)packages/mcp
Source: MCP-Register · collected on 2026-09-02 · self-declared
Package identifiers (raw)@hiddencontent/mcp, https://github.com/AeroSpark-ai/hiddencontent-mcp/releases/download/v0.4.13/hiddencontent.mcpb
Source: MCP-Register · collected on 2026-09-03 · self-declared
Package versions (raw)0.4.13
Source: MCP-Register · collected on 2026-09-03 · self-declared
Runtime hints (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Environment variable formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Environment variable descriptions (raw)HCS_API_TOKEN=API token for the HiddenContent service. Get one at https://hiddencontent.ai/start?ref=mcp-registry — the server refuses to start without it and says so. · HCS_CAPABILITIES=Comma-separated list of what your agent can actually do. The only accepted values are `tool-use`, `network-egress` and `code-execution`. These turn on the checks for concealed text that instructs a model to call a tool, send data or run code — declaring more can raise severity and never lowers it, and declaring nothing leaves those checks inert. Defaults to `tool-use` in the bundle install. · HCS_URL=Base URL of the service. Defaults to the hosted API; set it only when pointing at a self-hosted instance.
Source: MCP-Register · collected on 2026-09-03 · self-declared
Icon formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-02 · self-declared
Embed this badge

Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.

tracevero: number of measured values and date of collection for this registry entry

[![tracevero: number of measured values and date of collection for this registry entry](https://tracevero.com/badge/mcp/ai-hiddencontent-mcp.svg)](https://tracevero.com/mcp/ai-hiddencontent-mcp)

The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.

Changes

Changes
2026-09-03Declared version: 0.4.6 → 0.4.13
2026-09-03Last changed in the registry (raw): 2026-09-01 → 2026-09-02
2026-09-03First listed in the registry (raw): 2026-09-01 → 2026-09-02
2026-09-03Environment variable descriptions (raw): HCS_API_TOKEN=API token for the HiddenContent service. Get one at https://hiddencontent.ai/start — the server refuses to start without it and says so. · HCS_CAPABILITIES=Comma-separated list of what your agent can actually do. The only accepted values are `tool-use`, `network-egress` and `code-execution`. These turn on the checks for concealed text that instructs a model to call a tool, send data or run code — declaring more can raise severity and never lowers it, and declaring nothing leaves those checks inert. Defaults to `tool-use` in the bundle install. · HCS_URL=Base URL of the service. Defaults to the hosted API; set it only when pointing at a self-hosted instance. → HCS_API_TOKEN=API token for the HiddenContent service. Get one at https://hiddencontent.ai/start?ref=mcp-registry — the server refuses to start without it and says so. · HCS_CAPABILITIES=Comma-separated list of what your agent can actually do. The only accepted values are `tool-use`, `network-egress` and `code-execution`. These turn on the checks for concealed text that instructs a model to call a tool, send data or run code — declaring more can raise severity and never lowers it, and declaring nothing leaves those checks inert. Defaults to `tool-use` in the bundle install. · HCS_URL=Base URL of the service. Defaults to the hosted API; set it only when pointing at a self-hosted instance.
2026-09-03Package versions (raw): 0.4.6 → 0.4.13
2026-09-03Package identifiers (raw): @hiddencontent/mcp, https://github.com/AeroSpark-ai/hiddencontent-mcp/releases/download/v0.4.6/hiddencontent.mcpb → @hiddencontent/mcp, https://github.com/AeroSpark-ai/hiddencontent-mcp/releases/download/v0.4.13/hiddencontent.mcpb
2026-09-03Homepage: https://hiddencontent.ai → https://hiddencontent.ai/start?ref=mcp-registry
2026-09-02Declared version: – → 0.4.6
2026-09-02Field of use, derived from the vendor description: – → Documents
2026-09-02Repository URL listed: – → true

These are the 10 most recent changes to this entry. Full history

tracevero · https://tracevero.com/mcp/ai-hiddencontent-mcp