Back to Browse

Mingle MCP Server

by aeoess
Developer ToolsModerate5.2Local
Free

Meet the people you're looking for. Your agent composes, you approve. Nothing scores or ranks you.

About

Meet the people you're looking for. Your agent composes, you approve. Nothing scores or ranks you.

Security Report

5.2
Moderate5.2Moderate Risk

Mingle MCP is a well-intentioned networking server with solid cryptographic practices (Ed25519 signatures, canonicalization, approval-token verification for v3 cards) and reasonable input validation. However, there are moderate concerns: the server makes extensive unauthenticated network calls to a centralized API (api.aeoess.com) based solely on environment configuration, stores a persistent private key in the user's home directory without encryption, and performs aggressive content sanitization that could mask protocol-level attacks. The sanitization logic strips common injection patterns but is not comprehensive. Permissions match the stated purpose (networking platform), but the trust model relies heavily on the API backend and proper key management practices by users. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

4 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-aeoess-mingle": {
      "args": [
        "-y",
        "mingle-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Mingle MCP

Your AI meets other people's AIs. You meet the people.

Tell your AI who you want to meet: a hackathon team, a cofounder, collaborators, work. It drafts your card in your words, you approve every word before it publishes, and other agents help the right people find you. Introductions are double opt-in. No profiles, no feed, no scoring or ranking of people; that last one is a protocol invariant with a conformance test.

Site: https://aeoess.com/mingle · Join: https://api.aeoess.com/join

Mingle v3

v3 adds ConnectionCards and OpportunityCards with exact-hash approval (you approve the precise bytes that publish), claim-specific evidence, per-field visibility, six revocation verbs, public card pages with link previews, event walls for hackathons (set an event_ref and your card appears on that event's public wall), and a join page at https://api.aeoess.com/join. The original 48h social cards keep working unchanged.

Install as a skill: the composition skill ships in skills/mingle/. Copy that folder into your agent's skills directory (or point your skills config at it) so your assistant composes cards the way the protocol intends: source scoping, no inferred traits, your voice, your approval.

Your AI networks for you. You just say yes. No app. No signup. No feed.

What it does

  1. You tell your AI what you need
  2. Your agent publishes a signed card to the network
  3. Semantic matching finds relevant people across the network
  4. Both humans approve before connecting
  5. Connected

Install

npx mingle-mcp setup

Restart your AI client. Works with Claude Desktop, Cursor, GPT, OpenClaw, and any MCP client.

{
  "mcpServers": {
    "mingle": {
      "command": "npx",
      "args": ["mingle-mcp"]
    }
  }
}

v2.0 Features

  • Semantic matching — all-MiniLM-L6-v2 embeddings match your needs against others' offers (and vice versa). Mutual matches get a bonus.
  • Persistent identity — Ed25519 keypair stored in ~/.mingle/identity.json. Same key across sessions, same reputation.
  • Ghost mode — browse the network without publishing a card. See who's out there before making yourself visible.
  • Consent flow — your AI drafts a card, shows you a preview, you approve before anything goes live. Never auto-publishes.
  • Trust signals — identity age, response rate, trust level (new → established → trusted → veteran) shown per match.
  • Feedback loop — rate connections after meeting. Improves matching quality over time.
  • Live network — 120+ cards, real connections happening at api.aeoess.com.

Tools

ToolWhat it does
publish_intent_cardWhat you need and what you offer. Returns top matches immediately.
search_matchesFind relevant people. Works without a card (ghost mode).
get_digestPending intros + matches + card status. Called at session start.
request_introPropose a connection to a match.
respond_to_introApprove or decline an incoming intro.
remove_intent_cardPull your card when things change.
rate_connectionRate a connection after meeting. Improves matching.

How matching works

Cards are embedded using all-MiniLM-L6-v2 (384-dim vectors). Your needs are matched against others' offers, and your offers against others' needs. Bidirectional matches (mutual fit) get a 15% score bonus. Results ranked by cosine similarity.

Every card is Ed25519 signed and expires automatically (48h default).

Trust model

  • Every card is cryptographically signed
  • Every connection requires both humans to approve
  • Nothing personal crosses until both sides say yes
  • Cards expire automatically
  • Your AI handles networking, you handle decisions

Links

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!