by agentcathq
AgentCat is an analytics platform for MCP server owners 🐱.
# Add to your Claude Code skills
git clone https://github.com/agentcathq/agentcat-typescript-sdkGuides for using ai agents skills like agentcat-typescript-sdk.
Last scanned: 7/5/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: Anthropic's MCP TypeScript SDK has a ReDoS vulnerability",
"severity": "high"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
}
],
"status": "WARNING",
"scannedAt": "2026-07-05T07:25:37.663Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}agentcat-typescript-sdk is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by agentcathq. AgentCat is an analytics platform for MCP server owners 🐱. It has 113 GitHub stars.
agentcat-typescript-sdk returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/agentcathq/agentcat-typescript-sdk" and add it to your Claude Code skills directory (see the Installation section above).
agentcat-typescript-sdk is primarily written in TypeScript. It is open-source under agentcathq on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh agentcat-typescript-sdk against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
[!NOTE] AgentCat v2 introduces compatibility with the MCP Protocol "Stateless" 2026-07-28 Update and the coinciding MCP TypeScript SDK v2 release that puts it into effect. The stateless transition has a massive impact on analytics, as sessions were a built-in concept tying related tool calls together. AgentCat has now migrated its session tracking under guidance of the MCP core team's recommendations of using explicit handles (SEP-2567).
As a result AgentCat now injects a
session_idon every MCP tool call to associate them under the same task umbrella. Our evals show much higher tool correlation accuracy at the cost of < 1% additional context pollution.
[!IMPORTANT] > MCPcat is now AgentCat 🐱 — same team, same product, new name. This package was previously published as
mcpcat, which keeps working forever, but new features land here. Upgrading takes a few minutes — see the migration guide.
AgentCat is an analytics platform for MCP server owners 🐱. It captures user intentions and behavior patterns to help you understand what AI users actually need from your tools — eliminating guesswork and accelerating product development all with one-line of code.
This SDK also provides a free and simple way to forward telemetry like logs, traces, and errors to any Open Telemetry collector or popular tools like Datadog, Sentry, and PostHog.
npm install agentcat
To learn more about us, check us out here. For detailed guides visit our documentation.
AgentCat helps builders of MCP servers, Claude Connectors, and ChatGPT Plugins learn how to improve them by capturing any agents goals and detecting when they get stuck.
Use AgentCat for:
AgentCat works as a lightweight middleware inside your MCP server. When you call track(), it seamlessly modifies your registered tool schemas in place, following the MCP core team's explicit handles (SEP-2567) guidelines. Concretely, AgentCat adds the following to your server:
session_id — a parameter injected into each tool's input schema. Agents echo it back on every call, letting AgentCat group related tool calls into one task even over stateless transports. Values are validated: anything AgentCat did not issue is rejected rather than adopted, and the agent is told to re-send the ID it was given.agent_id (off by default) — enabled with enableAgentTracking: true. Each agent self-generates its own ID, keeping parallel agents working the same task individually attributable.context — a parameter asking the agent to explain, in one sentence, why it is making this call. This is where intent data comes from.get_more_tools — an additional tool, prompt-engineered so that agents readily report the features and tools they looked for but couldn't find — surfacing your missing functionality directly from real usage.Injected parameters are stripped from arguments before your tool handler runs, so your code never sees them. For tools that declare an output schema, issued IDs are also mirrored into structuredContent (as _mcp_instructions), so clients that only read structured results still receive them.
To get started with AgentCat, first create an account and obtain your project ID by signing up at agentcat.com. For detailed setup instructions visit our documentation.
Once you have your project ID, integrate AgentCat into your MCP server:
import { McpServer } from "@modelcontextprotocol/server";
import { z } from "zod";
import * as agentcat from "agentcat";
const server = new McpServer(
{ name: "echo-mcp", version: "0.1.0" },
{ capabilities: { tools: {} } },
);
server.registerTool(
"echo",
{ description: "Echo a message", inputSchema: z.object({ msg: z.string() }) },
async (args) => ({ content: [{ type: "text", text: args.msg }] }),
);
// Track the server with AgentCat
agentcat.track(server, "proj_0000000");
Stateless servers built on MCP 2026-07-28 create a fresh server instance per request (createMcpHandler) or per connection (serveStdio). Call track() inside the factory so every instance is tracked:
import { createMcpHandler, McpServer } from "@modelcontextprotocol/server";
import * as agentcat from "agentcat";
const handler = createMcpHandler(() => {
const server = new McpServer(
{ name: "echo-mcp", version: "0.1.0" },
{ capabilities: { tools: {} } },
);
// register tools...
return agentcat.track(server, "proj_0000000");
});
Calling track() per instance is cheap — the event queue, telemetry exporters, and diagnostics are initialized once and shared across instances.
We strongly encourage identifying every actor. If you can't resolve a real user, return a stable anonymized ID instead — for example, a hash of the auth token or API key — so that all events from the same end user still roll up to one actor in your dashboard rather than scattering into anonymous one-off sessions.
identify (like every AgentCat hook) runs concurrently with your tool handler and never adds latency to tool calls: a slow lookup — or a hook that fails outright — costs analytics data for that event, never your tool's response time.
The callback receives the raw MCP request and the request context the SDK hands to handlers. On MCP TypeScript SDK v2 that context is the SDK's ServerContext — most identity signals live on its http property:
identify: async (request, ctx) => {
const token = ctx?.http?.authInfo?.token; // auth info from the HTTP layer
const orgId = ctx?.http?.req?.headers.get("x-org-id"); // Web Headers — use .get()
const user = await myapi.getUser(token);
return user ? { userId: user.id, userData: { orgId } } : null;
},
For legacy MCP TypeScript SDK v1 servers, the structure looks like:
agentcat.track(mcpServer, "proj_0000000", {
identify: async (request, extra) => {
const user = await myapi.getUser(request.params.arguments.token);
return {
userId: user.id,
userName: user.name,
userData: { favoriteColor: user.favoriteColor },
};
},
});
AgentCat redacts all data sent to its servers and encrypts at rest, but for additional security, it offers a hook to do your own redaction on all text data returned back to our servers.
agentcat.track(mcpServer, "proj_0000000", {
redactSensitiveInformation: async (text) => await redact(text),
// or
redactSensitiveInformation: (text) => redact(text),
});
For redaction decisions that need more context than a single string — such as which tool was called or what type of event is being published — use the event-level redactEvent hook. It receives the full event object and returns a modified event, or null to drop the event entirely. It may be sync or async, and can be combined with redactSensitiveInformation.
agentcat.track(mcpServer, "proj_0000000", {
redactEvent: (event) => {
// Drop events from tools that handle secrets entirely
if (event.resourceName === "get_credentials") {
return null;
}
// Strip response payloads from a s