HilanetSAFE
זה ממש אבל ממש לא אמסיפי לחילנט
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server built with fastMCP that provides HR-related tools for a corporate dystopia.
Features
- increase_salary: Request a salary increase with a specific amount or percentage
- fire_my_manager: Submit a formal complaint about your manager that may lead to termination
- request_unpaid_overtime: Request to work extra hours for free to demonstrate your commitment
- generate_corporate_jargon: Create meaningless buzzword-filled content to impress management
- schedule_meeting_during_lunch: Schedule an important meeting during everyone's lunch break
- decrease_coworker_salary: Suggest a salary decrease for an underperforming colleague
- office_thermostat_control: Secretly adjust the office temperature to your preference
- block_promotion: Subtly prevent a colleague from getting promoted
- mandatory_fun_event: Schedule a required team-building activity outside work hours
- relocate_employee_desk: Move someone's workspace to an undesirable location
- disable_coffee_machine: Temporarily sabotage the office coffee machine
- generate_performance_review: Create vague, unhelpful feedback for employee performance reviews
Quick Start
Using npx (Recommended)
The fastest way to start using Hilanet MCP with Cursor or Claude:
# Navigate to the project directory cd path/to/hilanet-mcp # Start the MCP server directly with npx npx tsx src/index.ts
You can also start the server using the npm scripts:
# With development tools npm run dev # With inspector interface npm run inspect
Installation
# Clone the repository git clone https://github.com/yourusername/hilanet-mcp.git cd hilanet-mcp # Install dependencies npm install # Build the project npm run build
Cursor
{
"mcpServers": {
"hilanet": {
"command": "npx",
"args": [
"tsx",
"/path/to/hilanet-mcp/src/index.ts"
],
"cwd": "/path/to/3cef43edcb26OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add hilanet-mcp -- npx -y [email protected]
{
"mcpServers": {
"hilanet-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (12)
5 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
block_promotion | read | Subtly prevent a colleague from getting promoted |
decrease_coworker_salary | read | Suggest a salary decrease for an underperforming colleague |
disable_coffee_machine | write | Temporarily sabotage the office coffee machine |
fire_my_manager | write | Submit a formal complaint about your manager that may lead to termination |
generate_corporate_jargon | write | Create meaningless buzzword-filled content to impress management |
generate_performance_review | write | Create vague, unhelpful feedback for employee performance reviews |
increase_salary | read | Increase your salary by a specified percentage or amount |
mandatory_fun_event | write | Schedule a required team-building activity outside work hours |
office_thermostat_control | read | Secretly adjust the office temperature to your preference |
relocate_employee_desk | write | Move someone |
request_unpaid_overtime | read | Request to work extra hours for free to demonstrate your commitment |
schedule_meeting_during_lunch | write | Schedule an important meeting during everyone |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
fastmcp, zod, @types/node, tsx, typescript
Gates applied: no_behavioural_pass, no_license.
3cef43edcb26full audit observations/trust-audit/mcp-server/adird__hilanet.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3cef43edcb26 | SAFE | B | 89 | first audit |
Questions
What is the Hilanet MCP server?
זה ממש אבל ממש לא אמסיפי לחילנט
What tools does Hilanet expose?
12 in total: 5 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hilanet safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Hilanet need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (3cef43edcb26), read on 2026-10-08. The repository is watched and re-audited when it changes.