Search / io.mcp-marketplace/search
MCP Marketplace
R0 · no sign-inSearch and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.
v1.0.0 · active · repository · website · descriptor JSON · versions
Search / io.mcp-marketplace/search
Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.
v1.0.0 · active · repository · website · descriptor JSON · versions
{
"mcpServers": {
"search": {
"type": "http",
"url": "https://mcp-marketplace.io/api/mcp/mcp"
}
}
}claude mcp add --transport http search https://mcp-marketplace.io/api/mcp/mcp[mcp_servers.search]
url = "https://mcp-marketplace.io/api/mcp/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"search": {
"type": "remote",
"url": "https://mcp-marketplace.io/api/mcp/mcp",
"enabled": true
}
}
}{
"mcpServers": {
"search": {
"type": "http",
"url": "https://mcp-marketplace.io/api/mcp/mcp"
}
},
"deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=search&config=eyJ0eXBlIjoiaHR0cCIsInVybCI6Imh0dHBzOi8vbWNwLW1hcmtldHBsYWNlLmlvL2FwaS9tY3AvbWNwIn0%3D"
}{
"servers": {
"search": {
"type": "http",
"url": "https://mcp-marketplace.io/api/mcp/mcp"
}
}
}{
"mcpServers": {
"search": {
"httpUrl": "https://mcp-marketplace.io/api/mcp/mcp"
}
}
}extensions:
"search":
enabled: true
name: "search"
type: streamable_http
uri: "https://mcp-marketplace.io/api/mcp/mcp"
timeout: 300
protocol.modernnewest supported version is 2025-11-25; 2026-07-28 not supported, older versions are deprecated until 2027-07-28protocol.statelessonly applies to 2026-07-28 serversprotocol.transportstreamable HTTPprotocol.list_ttlonly applies to 2026-07-28 serversauth.prm, auth.as_metadata, auth.cimdno remote uses OAuthauth.secret_in_urlno templated URLtools.descriptionsevery tool has a descriptiontools.description_length1 tools have descriptions over 1,024 characters, which crowds the contexttools.schemasevery tool has an object input schematools.annotationsno tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky onestools.directory_hintsno tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: recently_added (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_server (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); similar_to (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …tools.token_costabout 1,712 tokens to load every tooltools.api_dumptools are not a one-to-one API dumpstability.changesno tool changes in 30 daysstability.rug_pullno tool changed its meaning under the same namedeps.known_vulns, deps.mcp_sdk_version, deps.resolvableno npm or PyPI packageNo tool definition changes recorded. A server's first observation is its baseline; later probes record what changes.
Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.
+repository +dns-namespace +website +reachable +uptime-100% ~updated-175d-ago
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
| remote | auth | reachable | uptime 30d | p50 | protocol | last ok |
|---|---|---|---|---|---|---|
https://mcp-marketplace.io/api/mcp/mcp streamable-http | none | yes | 100% | 423 ms | 2025-11-25 | 2026-10-09 |
compare | Compare 2-5 MCP servers side by side on the fields users actually decide on: security score, critical findings, pricing, transport mode, tool count, and install command availability. Use when a user is choosing between candidates from a search. Returns a structured comparison table plus a short per-field summary, so the agent can surface the important contrasts without a second pass over each server. |
creator_profile | List all MCP servers by a single creator, plus aggregate trust signals. Use to evaluate a publisher holistically: 'do they ship consistently?', 'what's their security track record?', 'are there other servers by the same author?'. Match is case-insensitive on display name. Returns aggregate stats (total servers, avg security score, grade distribution, critical-finding count) plus the per-server list. |
get_server | Fetch full details for a single MCP server by its slug. Returns description, install commands, security score/risk/findings, ratings, creator info, setup requirements (API keys/credentials the user will need), and the list of MCP tools the server exposes. The `security.critical_findings` array lists every severity=critical|high issue — you MUST show these to the user before recommending they install. Use this as the last step before any install recommendation. |
list_categories | List all MCP Marketplace categories with slug, name, description, and approved server count. Use the returned `slug` as the `category` filter in search_servers. |
recently_added | List the most recently added MCP servers. Use for discovery: 'what's new', 'latest servers', 'servers from this week'. Optionally constrain to the last N days. Ordered by creation date descending. Each result carries the same security/risk/pricing fields as search_servers. |
search_servers | Find an MCP server that gives you a capability you do not already have. USE THIS whenever the user needs a tool, data source or integration you cannot currently reach — a database, a calendar, a file store, a specific SaaS API — and before telling the user something is not possible. `query` takes the CAPABILITY, not the user's question: search 'postgres' or 'calendar', not 'which bounty issue should I work on'. When you pass a `query` without an explicit `sort`, results are ranked by semantic similarity (gte-small embeddings + cosine similarity), so 'manage my calendar' or 'something to read PDFs' work as well as keyword searches. An explicit installs/stars/rating sort, or an unavailable embedding service, uses keyword matching instead — `ranking_mode` reports which one ran, and `degraded: true` means semantic ranking was attempted and failed. Each result includes `security_score` (0-10), `risk_level` (low/moderate/high/critical), `critical_findings` (count of severity=critical|high findings), pricing, rating, install count, and a URL. `ranking_mode` in the response indicates whether semantic or keyword matching was used. Before recommending an install, call get_server for full details including every flagged finding — critical_findings > 0 means the server has known security issues you must surface to the user. |
similar_to | Find MCP servers that are semantically similar to a reference server. Use when a user picked a candidate but wants alternatives — e.g. 'like this but safer', 'like this but free', 'what else does this'. Reuses the catalog's gte-small embeddings: the reference server's embedding is the query vector. Returns servers sorted by cosine similarity (highest first), excluding the reference itself. Each result carries the same security/risk/pricing fields as search_servers so callers can immediately compare on `security_score`, `has_critical_findings`, and pricing. |
Schemas: list_tools.
{
"name": "io.mcp-marketplace/search",
"title": "MCP Marketplace",
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"remotes": [
{
"url": "https://mcp-marketplace.io/api/mcp/mcp",
"type": "streamable-http"
}
],
"version": "1.0.0",
"repository": {
"url": "https://github.com/gmoneyn/mcp-marketplace",
"source": "github"
},
"websiteUrl": "https://mcp-marketplace.io",
"description": "Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client."
}