{"server":{"name":"io.mcp-marketplace/search","title":"MCP Marketplace","$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","remotes":[{"url":"https://mcp-marketplace.io/api/mcp/mcp","type":"streamable-http"}],"version":"1.0.0","repository":{"url":"https://github.com/gmoneyn/mcp-marketplace","source":"github"},"websiteUrl":"https://mcp-marketplace.io","description":"Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client."},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","isLatest":true,"updatedAt":"2026-04-17T16:01:32.567868Z","publishedAt":"2026-04-17T16:01:32.567868Z","statusChangedAt":"2026-04-17T16:01:32.567868Z"},"dev.protogrid/connectability":{"class":"R0","autonomous":true,"human_steps":[],"preferred":{"kind":"remote","idx":0},"remotes":[{"idx":0,"url":"https://mcp-marketplace.io/api/mcp/mcp","transport":"streamable-http","templated":false,"headers":[],"auth":{"type":"none","location":null,"secret_name":null,"oauth":null},"protocol":{"supported_versions":["2025-11-25"],"stateless":true},"health":{"reachable":true,"uptime_30d":1,"latency_ms_p50":423,"consecutive_failures":0,"last_probe_at":"2026-10-09T23:41:12.560Z","last_ok_at":"2026-10-09T23:41:12.560Z"}}],"packages":[]},"dev.protogrid/tools":[{"name":"compare","title":null,"description":"Compare 2-5 MCP servers side by side on the fields users actually decide on: security score, critical findings, pricing, transport mode, tool count, and install command availability. Use when a user is choosing between candidates from a search. Returns a structured comparison table plus a short per-field summary, so the agent can surface the important contrasts without a second pass over each server.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"creator_profile","title":null,"description":"List all MCP servers by a single creator, plus aggregate trust signals. Use to evaluate a publisher holistically: 'do they ship consistently?', 'what's their security track record?', 'are there other servers by the same author?'. Match is case-insensitive on display name. Returns aggregate stats (total servers, avg security score, grade distribution, critical-finding count) plus the per-server list.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"get_server","title":null,"description":"Fetch full details for a single MCP server by its slug. Returns description, install commands, security score/risk/findings, ratings, creator info, setup requirements (API keys/credentials the user will need), and the list of MCP tools the server exposes. The `security.critical_findings` array lists every severity=critical|high issue — you MUST show these to the user before recommending they install. Use this as the last step before any install recommendation.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"list_categories","title":null,"description":"List all MCP Marketplace categories with slug, name, description, and approved server count. Use the returned `slug` as the `category` filter in search_servers.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"recently_added","title":null,"description":"List the most recently added MCP servers. Use for discovery: 'what's new', 'latest servers', 'servers from this week'. Optionally constrain to the last N days. Ordered by creation date descending. Each result carries the same security/risk/pricing fields as search_servers.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"search_servers","title":null,"description":"Find an MCP server that gives you a capability you do not already have. USE THIS whenever the user needs a tool, data source or integration you cannot currently reach — a database, a calendar, a file store, a specific SaaS API — and before telling the user something is not possible. `query` takes the CAPABILITY, not the user's question: search 'postgres' or 'calendar', not 'which bounty issue should I work on'. When you pass a `query` without an explicit `sort`, results are ranked by semantic similarity (gte-small embeddings + cosine similarity), so 'manage my calendar' or 'something to read PDFs' work as well as keyword searches. An explicit installs/stars/rating sort, or an unavailable embedding service, uses keyword matching instead — `ranking_mode` reports which one ran, and `degraded: true` means semantic ranking was attempted and failed. Each result includes `security_score` (0-10), `risk_level` (low/moderate/high/critical), `critical_findings` (count of severity=critical|high findings), pricing, rating, install count, and a URL. `ranking_mode` in the response indicates whether semantic or keyword matching was used. Before recommending an install, call get_server for full details including every flagged finding — critical_findings > 0 means the server has known security issues you must surface to the user.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"},{"name":"similar_to","title":null,"description":"Find MCP servers that are semantically similar to a reference server. Use when a user picked a candidate but wants alternatives — e.g. 'like this but safer', 'like this but free', 'what else does this'. Reuses the catalog's gte-small embeddings: the reference server's embedding is the query vector. Returns servers sorted by cosine similarity (highest first), excluding the reference itself. Each result carries the same security/risk/pricing fields as search_servers so callers can immediately compare on `security_score`, `has_critical_findings`, and pricing.","annotations":null,"source":"probe","observed_at":"2026-10-09T23:41:12.560Z"}],"dev.protogrid/trust":{"score":89,"components":{"hygiene":100,"liveness":100,"freshness":65,"provenance":85},"drivers":["+repository","+dns-namespace","+website","+reachable","+uptime-100%","~updated-175d-ago"],"flags":[],"blocked":false,"computed_at":"2026-10-10T01:22:56.384Z","disclaimer":"Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed."},"dev.protogrid/quality":{"score":76,"label":"good","components":{"auth":null,"hygiene":64,"protocol":75,"stability":100,"dependencies":null},"checks":[{"id":"protocol.modern","detail":"newest supported version is 2025-11-25; 2026-07-28 not supported, older versions are deprecated until 2027-07-28","status":"warn","category":"protocol"},{"id":"protocol.stateless","detail":"only applies to 2026-07-28 servers","status":"na","category":"protocol"},{"id":"protocol.transport","detail":"streamable HTTP","status":"pass","category":"protocol"},{"id":"protocol.list_ttl","detail":"only applies to 2026-07-28 servers","status":"na","category":"protocol"},{"id":"auth.prm","detail":"no remote uses OAuth","status":"na","category":"auth"},{"id":"auth.as_metadata","detail":"no remote uses OAuth","status":"na","category":"auth"},{"id":"auth.cimd","detail":"no remote uses OAuth","status":"na","category":"auth"},{"id":"auth.secret_in_url","detail":"no templated URL","status":"na","category":"auth"},{"id":"tools.descriptions","detail":"every tool has a description","status":"pass","category":"hygiene"},{"id":"tools.description_length","detail":"1 tools have descriptions over 1,024 characters, which crowds the context","status":"warn","category":"hygiene"},{"id":"tools.schemas","detail":"every tool has an object input schema","status":"pass","category":"hygiene"},{"id":"tools.annotations","detail":"no tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones","status":"fail","category":"hygiene"},{"id":"tools.directory_hints","detail":"no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: recently_added (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_server (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); similar_to (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …","status":"fail","category":"hygiene"},{"id":"tools.token_cost","detail":"about 1,712 tokens to load every tool","status":"pass","category":"hygiene"},{"id":"tools.api_dump","detail":"tools are not a one-to-one API dump","status":"pass","category":"hygiene"},{"id":"stability.changes","detail":"no tool changes in 30 days","status":"pass","category":"stability"},{"id":"stability.rug_pull","detail":"no tool changed its meaning under the same name","status":"pass","category":"stability"},{"id":"deps.known_vulns","detail":"no npm or PyPI package","status":"na","category":"dependencies"},{"id":"deps.mcp_sdk_version","detail":"no npm or PyPI package","status":"na","category":"dependencies"},{"id":"deps.resolvable","detail":"no npm or PyPI package","status":"na","category":"dependencies"}],"drivers":["-tools.annotations","-tools.directory_hints","~protocol.modern","~tools.description_length"],"flags":[],"tool_count":7,"token_estimate":1712,"tools_hash":"306380dda17ef08dedccecdca510832c","tools_changed_at":null,"computed_at":"2026-10-10T01:26:27.160Z","disclaimer":"Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed."},"dev.protogrid/identity":{"canonical_id":"io.mcp-marketplace/search","aliases":[],"alias_count":0,"repository_key":"github:gmoneyn/mcp-marketplace","owner":{"verified":false,"method":null,"since":null}}},"next_actions":[{"action":"list_tools","description":"Every current tool with input schemas","href":"/v1/servers/io.mcp-marketplace%2Fsearch/tools","arguments":{"name":"io.mcp-marketplace/search"}},{"action":"get_connection","description":"Minimal connection block for the preferred remote or package","href":"/v1/servers/io.mcp-marketplace%2Fsearch/connection?target=mcpServers","arguments":{"name":"io.mcp-marketplace/search","target":"mcpServers"}},{"action":"search","description":"Find other servers by intent","href":"/v1/search?q={query}","arguments":{"q":"{query}"}}]}