mcpindex-ai/mcp-server-mcpindex

🔒 Security
0 Views
0 Installs

📇 ☁️ 🍎 🪟 🐧 - Find MCP servers by natural-language task and get advisory trust screens (checktooltrust, assessserver) before you connect. The directory client for mcpindex.ai; advisory, not a safety verdict.

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "mcpindex-ai-mcp-server-mcpindex": {
      "command": "npx",
      "args": [
        "-y",
        "mcpindex-ai-mcp-server-mcpindex"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

mcp-server-mcpindex

mcpindex npm npm downloads servers indexed screened last commit Smithery Glama

An MCP server for finding MCP servers, plus advisory trust verdicts agent frameworks can call before invoking a tool.

A drop-in MCP server that lets your agent discover, compare, install, and pre-flight other MCP servers from inside the agent loop. Backed by mcpindex.ai - the agent-native index of the official MCP registry (live count at mcpindex.ai/stats), screened and drift-monitored daily.

Live site · npx mcp-server-mcpindex · Remote MCP · Install gate · Docs · Trust

Install

npm install -g mcp-server-mcpindex

This is the directory / advisory client (recommend, search, trust). It does not install the in-path drift gate — that is curl -fsSL https://mcpindex.ai/install.sh | sh.

Or connect remotely (no install)

Prefer not to install anything? mcpindex is also a hosted remote MCP server. Point any client that supports remote MCP (Claude connectors, Cursor, etc.) at:

https://mcpindex.ai/api/mcp

Streamable HTTP, no credentials. Same six tools as the npm package.

Claude Code

claude mcp add --scope user mcpindex -- npx -y mcp-server-mcpindex@latest

Gemini CLI

gemini mcp add -s user mcpindex npx -y mcp-server-mcpindex@latest

Use it from Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "mcpindex": {
      "command": "npx",
      "args": ["-y", "mcp-server-mcpindex@latest"]
    }
  }
}

@latest keeps you current: this is the advisory discovery server (not the in-path drift gate), so it carries no version pin — npx fetches the newest on your next host restart, no manual upgrade step.

Restart Claude Desktop. Then ask:

"Find me an MCP server that can read PDFs and write the contents to S3."

Claude calls recommend_mcp_for_task and returns the top 3 ranked servers with install commands.

Use it from Cursor

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "mcpindex": {
      "command": "npx",
      "args": ["-y", "mcp-server-mcpindex@latest"]
    }
  }
}

Use it from Cline

Add to your Cline settings:

npx -y mcp-server-mcpindex@latest

Tools exposed

ToolWhat it does
recommend_mcp_for_taskPass a natural-language task. Returns top 3 servers with reasoning, install commands, quality scores.
search_mcp_serversKeyword + semantic search across the full registry. Optional category filter.
get_install_commandGet the exact install JSON/CLI for a server + client (Claude Desktop, Claude Code, Cursor, Gemini CLI, Cline, Zed).
compare_serversSide-by-side comparison of 2-5 servers - quality scores, install paths, env vars.
check_tool_trustPre-invocation advisory verdict for a specific tool on a server. Fail-CLOSED: returns UNVERIFIED when no verdict on file.
assess_serverAggregated pre-flight verdict across all tools on a server. Same shape as check_tool_trust.

Agent-framework integration: advisory pre-invocation screen

check_tool_trust is the directory client integration surface (not the in-path mcpindex-gate). It lets agent frameworks (Composio, Mastra, LangChain, DSPy, raw LLM-tool-call loops) ask for an advisory screen verdict before dispatching a call. At v1 you will see REVIEW or UNVERIFIED — not a safety clearance.

Using Mastra? The sibling package @mcp-index/mastra ships this exact screen as a ready-made beforeToolCall hook - npm i @mcp-index/mastra, no wiring required.

Verdict contract (v1)

{
  "directive": "ALLOW" | "DENY" | "REVIEW" | "UNVERIFIED",
  "status":    "EVALUATED" | "PARTIAL" | "STALE" | "ERROR",
  "granularity": "description-level" | null,  // scope of a PARTIAL screen
  "dimensions": [
    { "id": "tool_safety", "verdict": "PASS", "severity": "INFO" }
  ],
  "expires_at": "2026-06-30T00:00:00Z",
  "honest_limits": [
    "conformance_monitored_not_enforced",
    "calibrated_false_v1",
    "advisory_deployment"
  ],
  "verdict_contract_version": "1.0.0",
  "server_id": "github",
  "tool_name": "create_pull_request",
  "source_url": "https://mcpindex.ai/api/v1/trust/tool/github/create_pull_request",
  "fetched_at": "2026-05-28T18:42:11.118Z"
}

The free-tier verdict ships directives + dimensions + freshness. Evidence quotes, LLM rationale, and chain history are paid-tier surfaces and intentionally omitted here.

Honest limits (pin these to your gate UI)

Every v1 verdict ships with these three caveats, and your gate SHOULD surface them on every dispatch decision:

  1. conformance_monitored_not_enforced - publishers self-declare; mcpindex monitors drift but does not block at the network layer.
  2. calibrated_false_v1 - dimension severities are not yet calibrated against real-world incident data.
  3. advisory_deployment - the verdict is advisory; the agent (or human reviewing the agent) is the decision-maker.

History anchoring: OTS Bitcoin-anchored history; Bitcoin-finalized at N=6 confirmations (~1 hr); pending in ~10 min. Sub-window precision asserted, not proven.

Integration pattern (LangChain-style, direct LLM-tool-call convention)

import { Client } from '@modelcontextprotocol/sdk/client/index.js';
import { StdioClientTransport } from '@modelcontextprotocol/sdk/client/stdio.js';

const mcpindex = new Client({ name: 'gate', version: '1.0.0' }, { capabilities: {} });
await mcpindex.connect(new StdioClientTransport({
  command: 'npx', args: ['-y', 'mcp-server-mcpindex@latest'],
}));

// gateToolCall wraps any agent tool dispatch. Plug it in front of
// the LangChain / DSPy / Mastra / Composio tool-call hook.
async function gateToolCall({ serverId, toolName, invoke, askHuman }) {
  const res = await mcpindex.callTool({
    name: 'check_tool_trust',
    arguments: { server_id: serverId, tool_name: toolName },
  });
  const verdict = JSON.parse(res.content[0].text);

  // Pin the v1 caveats in the audit log no matter what.
  audit.log({ verdict, caveats: verdict.honest_limits });

  switch (verdict.directive) {
    case 'REVIEW':
      // Fail-CLOSED to human. Do NOT auto-execute on REVIEW.
      // At v1 this is the common screened outcome (semantic-only).
      return askHuman({ verdict, action: `${serverId}/${toolName}` });

    case 'UNVERIFIED':
      // No verdict on file (or upstream unreachable). Fail-CLOSED.
      // Recommend human review. Do NOT fail-open to invoke().
      return askHuman({
        verdict,
        action: `${serverId}/${toolName}`,
        note: 'No trust verdict on file. Human review required before first use.',
      });

    case 'ALLOW':
      // Reserved in the contract — not produced by the v1 public screen.
      // Keep the branch for future conformance-earned ALLOW; do not expect it today.
      return invoke();

    case 'DENY':
      // Reserved in the contract — not produced by the v1 public screen.
      throw new Error(
        `mcpindex denied ${serverId}/${toolName}: ${JSON.stringify(verdict.dimensions)}`,
      );

    default:
      // Unknown directive. Fail-CLOSED.
      return askHuman({ verdict, action: `${serverId}/${toolName}` });
  }
}

The load-bearing rule: never fail-open

If the verdict endpoint is unreachable, returns 404, times out, returns malformed JSON, or has no verdict on file yet for that server, check_tool_trust returns directive: "UNVERIFIED" + status: "ERROR". It never silently coerces to ALLOW. Your gate code SHOULD treat UNVERIFIED as "human review required", never as "looks fine, ship it."

status is telemetry about screen completeness, distinct from the directive trust decision: EVALUATED (full screen), PARTIAL (only part of the surface, e.g. description-level — see granularity), STALE (verdict past its freshness window), ERROR (unreachable / no verdict on file). A PARTIAL screen is never reported as EVALUATED.

This is tested. See test/trust.test.mjs.

Using the library directly (without MCP)

The trust client is also exported as a plain ES module:

import { checkToolTrust, assessServer } from 'mcp-server-mcpindex/src/trust.mjs';

const verdict = await checkToolTrust({
  serverId: 'github',
  toolName: 'create_pull_request',
});

if (verdict.directive !== 'ALLOW') {
  // Hand to a human, log, or block.
}

Backend

By default, calls go to https://mcpindex.ai. Override with MCPINDEX_API_BASE=... if you self-host.

The free tier is rate-limited to 60 req/min/IP. Paid keys are coming for higher throughput and the full evidence-bearing verdict (evidence quotes, LLM rationale, chain history).

Related packages

Three ways to bring mcpindex into an agent, for different surfaces:

PackageInstallWhat it does
mcp-server-mcpindex (this package)npm i -g mcp-server-mcpindexDirectory + advisory screen as an MCP server: find servers by task, and check_tool_trust before a call.
@mcp-index/mastranpm i @mcp-index/mastraThe same advisory screen wired into Mastra as a beforeToolCall hook (warn / enforce).
@mcp-index/sdknpm i @mcp-index/sdkIn-path drift gate: wrap() an MCP session and HOLD a call when a tool's contract drifts from your pin.

Advisory screen vs drift gate: this package and @mcp-index/mastra ask mcpindex "has this tool been vetted?" (a network verdict). @mcp-index/sdk asks a different question locally: "did this tool's contract change since I pinned it?" Complementary, and none depends on another.

License

MIT.

Project

Unofficial. Not affiliated with Anthropic.

Related MCP Servers

13bm/GhidraMCP

🐍 ☕ 🏠 - MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.

🔒 Security1 views
123Ergo/unphurl-mcp

📇 ☁️ - URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

🔒 Security0 views
82ch/MCP-Dandan

🐍 📇 🏠 🍎 🪟 🐧 - Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

🔒 Security0 views
9hannahnine-jpg/arc-gate-mcp

🐍 - Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

🔒 Security0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Not checked yet

We have not completed a health check for this listing yet.

No check timestamp yet.

Unclaimed listing (imported or pending owner verification). Claim it →
★ Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.