# mcp-anything [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/Dror-Bengal/mcp-anything  
**GitHub Stars:** 3  
**npm Downloads (last month):** 222  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/mcp-anything

## Description
Meta-MCP gateway: search, inspect and call any MCP server from the public registries.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "mcp-anything": {
    "command": "npx",
    "args": ["-y","mcp-anything"]
  }
}
```

## Documentation

## What the mcp-anything MCP server does

The mcp-anything MCP server acts as a gateway between an MCP host and other MCP servers listed in public or compatible private registries. It downloads and indexes registry metadata locally, then lets a model search for a capability, inspect a matching server, connect to it, and invoke one of its tools without loading every downstream schema into the host context.

The default catalog is the official MCP registry. Optional sources include PulseMCP, npm packages tagged for MCP, and Glama. Records found in multiple catalogs are deduplicated using repository URLs and package identifiers. Search ranking combines BM25 relevance with fuzzy matching and popularity signals when available.

## How it works

Run `sync` to build or refresh the local index, then start `serve` to expose the gateway over stdio. The server can also use streamable HTTP on port 8080 by passing `--http`. Registry metadata remains usable from the last successful sync if a source is temporarily unavailable.

Five meta-tools provide the gateway interface:

- `search_mcp_servers` finds candidate servers and reports whether they appear connectable.
- `describe_mcp_server` returns transports, packages, required variables or secrets, and policy information.
- `list_mcp_tools` connects to a permitted server and retrieves its current tool definitions.
- `call_mcp_tool` invokes a selected downstream tool using pooled sessions.
- `sync_registry` requests an index refresh before the cache TTL expires.

## Setup and configuration

The mcp-anything MCP server requires Node.js 20 or newer and can be run with `npx`. Execute `npx mcp-anything sync` once, followed by `npx mcp-anything serve`. Claude Code can register it with `claude mcp add anything -- npx -y mcp-anything serve`; Claude Desktop and other hosts can use a stdio entry whose command is `npx` and whose arguments are `-y`, `mcp-anything`, and `serve`.

Configuration is optional. The default file is `~/.config/mcp-anything/config.json`, or a different path can be supplied with `--config`. `MCP_ANYTHING_CONFIG` can also identify the configuration file. Configuration controls the registry URL, indexed sources, cache lifetime, result limits, remote headers, stdio package allowlists, and environment variables injected into permitted downstream servers.

## Tools and capabilities

Remote streamable-HTTP and SSE connections are supported, subject to policy. Stdio connections through `npx` or `uvx` are disabled by default and require an explicit package allowlist. Remote credentials are supplied as configured headers, while stdio secrets are supplied through the downstream process environment; they are not indexed or exposed to the model.

Search is local and does not require embeddings or an API service. Sessions are reused and limited by a bounded pool, with configurable connection and call timeouts and response-size truncation. The registry URL may point to a service implementing the official REST API, including a private or self-hosted registry.

## Limitations and notes

The mcp-anything MCP server is not a general public proxy. Its HTTP discovery-only mode is suitable for hosted searching, but enabling execution on a public instance could expose an open gateway to downstream servers. The default policy blocks private, loopback, link-local, and plain-HTTP remote addresses, and disables arbitrary stdio package execution.

Downstream descriptions and results are marked as third-party data to reduce prompt-injection risk, but this does not remove that risk. OAuth passthrough, per-tool search, health checks, and sandboxing for stdio processes are listed as future work rather than current capabilities.

_Full upstream README: https://allmcps.com/mcp/mcp-anything/readme_

