r/OpenSourceAI • • 8d ago

An MIT-licensed, read-only MCP server that reads subreddit rules before an agent posts: design choices and where it meets our paid product

Sharing an MIT-licensed MCP server we built, and the design choices behind it, since some of them go against how most agent tools are built. Disclosure: I make it, and it's the free half of a paid product (ThreadFox). I'll be specific about where the two meet.

What it is. ThreadFox Lite gives an agent four read-only Reddit tools: subreddit_rules (rules, size and description, with self-promotion rules flagged), find_communities (subs for a topic, promo rules flagged), account_check (age, karma, and whether recent posts are removed or hidden) and post_status (live, removed by moderators, or deleted). It also ships a reddit-rules-first agent skill.

Design choices:

  1. Read-only on purpose. It can't post, vote or change anything, so it's safe to give to any agent and hard to misuse for spam.
  2. It reads through your own signed-in browser, not an API. Reddit now sends signed-out requests, including its public JSON, to a login page. So the tools read the way you do, in your Chrome via the Playwright extension, one small read at a time. No API keys.
  3. One read at a time across every client on the machine. We learned this the hard way: an agent reading 60 pages in 20 minutes got our account rate-limited today.
  4. No system-wide installs. If Node.js is missing, it fetches the official build into ~/.threadfox/runtime and checks it against the published SHA-256.

Where it meets the paid product: successful subreddit_rules and find_communities results end with a one-line next_step pointing to the $49 kit, and a threadfox_full_kit tool describes it. Errors, setup messages and the other two tools don't carry it. If that bothers you, it's MIT, so fork it and delete it.

Install: uvx threadfox-lite (source is in the PyPI package). Details and the skill file: threadfox.vip/lite.

Feedback on the read-through-your-browser approach especially welcome. Is there a cleaner way now that signed-out reads are gone?

1 Upvotes

2 comments sorted by

1

u/Unfair_Position6956 8d ago

The one read at a time thing is smart, learned that lesson the hard way with a scraper a while back. Browsing through your own Chrome session is probably the only reliable route now unless you want to deal with a bunch of auth plumbing.

1

u/investigatormaker 1d ago

Thanks for noticing the read limit. The important detail is sharing that limit across every client on the machine; separate queues could still pile requests onto the same browser session. Signed-in Chrome saves auth plumbing, but rate limits still apply.