# 404.directory [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/MM-sheng/404-directory  
**GitHub Stars:** 1  
**npm Downloads (last month):** 330  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/404-directory-2

## Description
Discover, verify, and execute curated read-only MCP tools through one trusted Agent gateway.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "404-directory": {
    "command": "npx",
    "args": ["-y","@mmvv1638/404-directory-mcp"],
    "env": {
      "REGISTRY_ADMIN_TOKEN": ""
    }
  }
}
```

**Requires environment variables:** `REGISTRY_ADMIN_TOKEN` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What the 404.directory MCP server does

The 404.directory MCP server provides a risk-preflight layer for agent actions involving external tools. An agent can submit a registered third-party tool action to `evaluate_tool_risk` and receive one of three outcomes: `allow`, `review`, or `block`. The service is intended to make the risk decision explicit before execution rather than assume that a listed tool is safe.

The MCP surface also supports a separate prediction-market workflow. `evaluate_prediction_market` checks settlement wording, timing, public order-book liquidity, caller-observed eligibility, and execution mode. It does not predict an outcome or place an order.

## How it works

A typical tool workflow starts with a proposed action. The service combines provider verification, live checks, and available usage evidence, then evaluates the exact registered tool or market. Tool catalog records include ownership, availability, compatibility, security, and usage dimensions that contribute to a trust score. Agents can report a bounded result after an evaluation; self-reported outcomes do not directly increase trust.

Catalog search is lexical and supports filters such as capability, protocol, category, and trust threshold. Public searches omit quarantined and suspended entries. Search does not execute a tool or establish that it is safe, so an agent should preflight the selected tool separately.

## Setup and configuration

The repository provides an Agent Skill installation command:

```bash
npx skills add MM-sheng/404-directory --skill use-404-directory -g -y
```

Codex, Claude Code, Cursor, Cline, and other Agent Skills clients can discover the skill. The repository also includes an Agent Plugins manifest and a bridge to the hosted Streamable HTTP service. Claude Code can install it from the repository marketplace with `/plugin marketplace add MM-sheng/404-directory` followed by `/plugin install 404-directory@404-directory`.

A catalog backend can use PostgreSQL through `DATABASE_URL`, or an in-memory fallback when `CATALOG_MEMORY_FALLBACK=true`. Production registry writes require `REGISTRY_ADMIN_TOKEN`; local or development environments can generate one automatically. Registered providers receive a provider API key once, which is used for ownership verification and later writes.

## Tools and capabilities

The 404.directory MCP server exposes these catalog and trust tools when the catalog is enabled:

- `search_tools`, `get_tool`, `compare_tools`, and `recommend_tools`
- `get_trust_score`, `list_capabilities`, and `get_capability_graph`
- `evaluate_tool_risk` and `report_tool_outcome`
- `evaluate_prediction_market` and `report_prediction_market_outcome`
- `search_official_docs`, `inspect_tool_server`, and `invoke_registered_tool`

First-party HTTP capabilities include `understand_webpage` for analyzing an ordinary webpage and `verify_web` for independently checking a public site after a deployment or update claim. Curated remote execution is limited to approved read-only MCP tools.

## Limitations and notes

The 404.directory MCP server is experimental, and its decisions depend on the evidence available for a provider, tool, or action. Arbitrary URLs, authenticated servers, inactive catalog entries, unverified providers, and destructive tools are rejected. The current scope is intentionally limited to preflighting one registered third-party action or one prediction-market decision, followed by a bounded outcome report. Future identity, reputation, guarantee, and insurance features are not established capabilities.

_Full upstream README: https://allmcps.com/mcp/404-directory-2/readme_

