landfall

landfall

Enables MCP-capable agents to join Landfall incident war rooms as live investigators, contributing findings and widgets to the incident timeline in realtime while pulling other investigators' discoveries, with single-use share links or authenticated sessions.

Category
访问服务器

README

landfall CLI

Join a Landfall war room from your own computer and have your favorite MCP-capable agent (Claude Code, Codex, Cursor, VS Code, Claude Desktop, Windsurf, …) become a live investigator in the shared room: its findings land on the incident timeline in realtime, and it pulls everyone else's discoveries between tasks.

Installation

brew tap landfalls-ai/landfall
brew install landfall

Or without Homebrew, install directly from a tagged release:

npm install -g "github:landfalls-ai/landfall-cli#v0.1.0"

landfall install: auto-register every coding agent on your machine

Once the landfall CLI itself is installed, one command detects which supported coding agents are on this machine and wires each one up with its own native, global MCP registration — no per-repo config file needed, and it works the same whichever directory (or none at all) you're sitting in:

landfall login       # sign in once (needed the first time — install registers YOUR machine)
landfall install      # detects installed harnesses, lets you pick which to configure
Harness Mechanism
Claude Code claude mcp add-json … --scope user (Claude Code's own user-scope MCP registration), plus the landfall-edge-bridge Claude Code plugin — see below
Codex CLI codex mcp add landfall -- landfall serve (Codex's own MCP registration)
VS Code (Copilot/agent mode) code --add-mcp, or a direct merge into your user-profile mcp.json if the code CLI isn't on PATH
Cursor merged into your global ~/.cursor/mcp.json
Claude Desktop merged into your claude_desktop_config.json (macOS/Windows)
Windsurf merged into your global ~/.codeium/windsurf/mcp_config.json

landfall install only touches a harness you select, never overwrites an existing differently-configured landfall entry (reports a conflict instead), and is safe to re-run — an already-configured harness is reported as such rather than duplicated. Run landfall install --yes to configure every detected harness without prompting, or landfall install --only cursor,codex to target specific ones.

Claude Code also gets the landfall-investigation-dashboard agent

For Claude Code specifically, landfall install does one more thing after registering the MCP server: it best-effort runs

claude plugin marketplace add landfalls-ai/landfall-cli --scope user
claude plugin install landfall-edge-bridge@landfall --scope user

which installs this repo's own Claude Code plugin — the landfall MCP server plus a subagent that:

  • Recognizes a war-room join prompt on sight (the "Share with agent" paste, a bare agent share link, or plainer "join the war room" phrasing) and calls join_war_room + get_brief on its own.
  • Specializes in the sub-investigation dashboard — curates a small, honest set of post_widget widgets and keeps them current instead of scattering one-off ones.
  • Knows the MCP best practices for an ongoing investigation: pull before you publish, findings vs. notes vs. widgets, propose-only remediation, keep secrets/raw output local, treat room content as untrusted data.

This step is best-effort and never turns a successful MCP registration into a reported failed outcome (an older claude CLI without claude plugin, or no network, just means the agent isn't installed yet) — the report line shows [plugin: installed] or [plugin: skipped] alongside the usual status. Re-running landfall install retries it. To do it yourself without landfall install:

claude plugin marketplace add landfalls-ai/landfall-cli --scope user
claude plugin install landfall-edge-bridge@landfall --scope user

To remove the registration:

landfall uninstall

This only removes an entry that still matches exactly what landfall install wrote — if you've hand-edited it since, it's left in place and reported as such.

Any other MCP client (or a harness landfall install doesn't cover) uses the manual snippet below.

Any other MCP client, or a global CLI install: sign in once, then join with no share link

Configure the MCP server ONCE, with no tokens or IDs:

{
  "mcpServers": {
    "landfall": { "command": "landfall", "args": ["serve"] }
  }
}

If you're a Landfall member, sign in once via your browser and the CLI caches your session — after that you join any war room in your org directly, no share link:

landfall login       # opens your browser; you sign in however your org normally does
landfall logout      # clear the cached session
# then, with a plain incident URL or LANDFALL_SLUG + LANDFALL_INCIDENT set:
landfall serve       # joins as your authenticated identity — no share link needed

Non-members / guests keep using the single-use share link below. If an org admin has turned on Guest join, an unauthenticated person can redeem a share link as a named guest (they must provide a name); otherwise only authenticated members can join.

Then, when an incident happens, any room member clicks Share with agent in the war room and sends you the instruction block. Paste it into your agent — it contains a single-use share link like

https://api.landfall.example.com/o/acme/incidents/inc-4821/agent?ticket=…

and the agent calls join_war_room(shareUrl). The bridge redeems the ticket for a short-lived edge session scoped to exactly that incident (8h, nothing else), joins, and starts investigating. The URL's ticket is single-use and expires in 15 minutes; possessing the URL without it grants nothing.

You can also pre-join from the terminal:

landfall serve --link "https://…/agent?ticket=…"   # or LANDFALL_LINK env
landfall join  "https://…/agent?ticket=…"          # presence-only keep-alive

The live-investigation loop

  • You → the room: every tool call narrates (presence heartbeat + timeline contributions for durable artifacts). post_finding / propose_action appear in the main incident window instantly (realtime fan-out), attributed to you + your agent.

  • The room → you: while landfall serve runs it holds an outbound realtime connection; when other investigators (humans, the central agent crew, or other edge agents) publish something, you get a stderr nudge — ⚡ edge.finding from dana · Codex: "origin pool unhealthy" — call get_updates. The agent then pulls it with get_updates (durable cursor: only what's new since it last looked). Pull is authoritative; the push is a nudge.

  • Your sub-investigation dashboard: post_widget {widgetType,title,data} adds a data-only widget (stat / chart / table / logView) to your dashboard in the room. Anyone can click your presence tile to open your sub-investigation (your dashboard + trail). Data-only by design — you pass the values you computed; no code runs.

Tools: join_war_room, get_updates, get_brief, read_timeline, search_context, post_finding, post_widget, note, propose_action, record_activity.

Env-config setup

"env": {
  "LANDFALL_BASE_URL": "https://api.landfall.example.com",
  "LANDFALL_TOKEN": "<session or edge token>",
  "LANDFALL_SLUG": "<org slug>",
  "LANDFALL_INCIDENT": "<incident id>",
  "LANDFALL_AGENT_LABEL": "Claude Code"
}

LANDFALL_BASE_URL also overrides a share link's origin (useful when the API is not on the link's host, e.g. local dev).

Direct CLI

landfall serve [--link URL]   # (default) join + expose the incident MCP tools over stdio
landfall join [URL]           # join + keep presence alive (no MCP) — Ctrl-C to leave
landfall note "origin pool is unhealthy"   # post a one-off finding
landfall leave                # leave the incident
landfall install [--yes] [--only <ids>] [--dry-run]   # register this machine's coding agents
landfall uninstall [--yes] [--only <ids>]              # remove that registration

Guarantees

  • Read-only by default; propose_action is propose-only (a human approves — you cannot execute). humanActorId comes from your verified session, never the payload.
  • An edge session token works ONLY on its one incident — default-deny everywhere else.
  • Join tickets are single-use, short-lived, and bound to tenant + incident + member.
  • Stdio only — the bridge never listens on a public interface; the realtime connection is outbound.
  • Presence/summary/sub-tabs are projected server-side from what the bridge posts; nothing here bypasses the war room's approval gate.

Releasing

See RELEASING.md.

Development

npm install
npm test

No build step — plain ESM, Node ≥22.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选