AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Xhost

mcp-yairl-xhost-sdk · by yairl

Agent-first hosting: create apps, commit code, deploy, get HTTPS URLs. OAuth sign-in, no tokens.

— No reviews yet
0 installs
43 views
0.0% view→install

Install

$ agentstack add mcp-yairl-xhost-sdk

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.3.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ● Network access Used
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.3.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-yairl-xhost-sdk)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 3mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Xhost? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

xhost SDK

Claude Code plugin for xhost — deploy static sites and dynamic applications. Push code, get HTTPS URLs.

Install

/plugin marketplace add yairl/xhost-sdk
/plugin install xhost@xhost-sdk

Installing the plugin registers both the xhost skill and the remote MCP server (https://mcp.xhostd.com/mcp/).

After installing, reload plugins in your current session:

/reload-plugins

Connect

Run /mcp, select xhost, and choose Authenticate. Your browser opens for Google sign-in — no token needed.

Usage

Just use /xhost — it handles everything:

"deploy my website"          → signs up, creates app, pushes, deploys
"check my app status"        → shows apps, channels, URLs, deploy state
"create a preview for this branch" → pushes branch, creates preview URL

Or invoke it explicitly:

/xhost

The single /xhost skill handles account setup, app creation, deploys, previews, and status checks. Claude figures out what you need from context.

What xhost supports

  • Static sites — HTML/CSS/JS served by nginx
  • Node.js apps — Express, Next.js, Fastify, Vite (provide install.sh + launch.sh)
  • Python apps — FastAPI, Flask, Django (provide install.sh + launch.sh)
  • Any language — if the runtime is in the base image, just write your scripts

How it works

  1. You push code to xhost's git server
  2. You trigger a deploy (explicitly, via /xhost or the API)
  3. xhost runs your install.sh (install deps) then launch.sh (start app on $PORT)
  4. Your app is live over HTTPS with a wildcard cert

Requirements

  • Git installed locally
  • An API token (from xhostd.com/tokens) only if you push over git or call the API with raw curl — the MCP connection itself uses OAuth, no token

License

MIT

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.3.0 Imported from the upstream source.