One address, every client

Tools. Memory. Skills. Any harness.

Helm holds the tools your agent may call, the memory it reads and writes, and the skills that say how you work. Point any MCP client at one address and the setup is already there.

Start for $19 a month -> Bring your own model keys. Open to everyone today.
Address https://app.helm.mom/mcp/<your-agent-id> unchanged across clients
Connect the client you already have open

One command in the folder that should reach this agent.

# Claude Code
claude mcp add --transport http helm https://app.helm.mom/mcp/<your-agent-id>
Paste it into the agent you have open.

The prompt fetches the skills Helm has published to you, asks once, and installs the ones you say yes to.

The address does not change between rows. That is the whole point.  Green dot: run and confirmed. The rest get the same address and the same protocol. We have not run them, so we do not call them tested.
02

One setup. Every harness.

Three things decide whether an agent knows what to do. All three live on Helm, not inside one app.

Tools

What it may call

Gmail, Drive, Calendar, Outlook, GitHub, Linear, Notion, Zendesk and more. Set every tool for every agent to allow, ask, or block.

  • gmail_search allow
  • gmail_create_draft allow
  • gmail_send_draft ask me
  • gmail_delete blocked
Your agent can read your inbox. It cannot delete it. A blocked tool is not refused later. It never appears in the list, so the model never learns it exists.
Memory

What it remembers

One vault for you, split into scopes that never mix. Grant the work agent the work scope and it cannot reach home.

The wall is real, not a prompt. A link written across two scopes does not resolve. If you need the same fact in both, you write it twice. That is the cost of a hard wall, and we would rather you knew.

The memory follows the address, so the same agent recalls the same things in every client you point at it.

Skills

How you work

Skills are written playbooks the agent reads before it acts. How you triage mail. How you keep notes. What a project record has to contain.

Write a skill once. Helm rewrites the tool names for whichever client asked, so the same words work in all of them.

A skill says which services it needs. Attach it to an agent that lacks one and Helm refuses instead of failing halfway.

18

Tool services in the Helm repo today, each one declaring its own tools and its own permission split. That is the count in the code, not a projection. Two of the eighteen are privileged and one is development only.

03

From the person who runs it

Founder's noteFelipe Saint-Jean

I am Felipe. I built Helm because I run agents against my own Gmail, Calendar and Drive, and I kept building the same setup again every time I changed tools.

The tools, the memory and the skills now sit on Helm. When I open a different client I point it at the same address and my agent is already itself. My permissions come with it.

Helm does not stop a prompt injection. Nothing does. It decides what an injected agent is able to reach, which is the part I can actually control. New agents are closed until a client signs in, and the agent never holds my credentials.

It is $19 a month and you bring your own model keys. If it is not carrying its weight, cancel it.

Felipe Saint-Jean, Helm

Keep your setup. Change your mind about the harness.

Start for $19 a month ->