The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the TokRepo — AI Asset Registry listing page.
Agent-native MCP server for TokRepo: session bootstrap, capability discovery, search/detail, trust verification, install planning, Codex staging, lifecycle inspection/update/uninstall/rollback, handoff/harvest planning, and human-confirmed publishing of reusable AI assets.
Add to your MCP config (~/.cursor/mcp.json):
Once connected, your AI assistant can:
evidence_bundle, SBOM-lite, signature_evidence, blockers, and warningsevidence_bundle, SBOM-lite, and signature_evidencetokrepo_harvest before any push, including private package drafts, quality_gate, package manifest, SBOM-lite, and provenancetokrepo init-agent --target all so future agents know to call TokRepo during planningserver.json, A2A agent card, portable agent manifest, tool catalog, .well-known, agents.txt, llms.txt, and npm metadata are kept machine-readable for agents and registries| Tool | Description |
|---|---|
tokrepo_session_init | Session bootstrap with high-trust assets, project memory pointer, recent handoffs, and policy pack URL |
tokrepo_discover | Planning-time capability discovery from a task, environment, and constraints |
tokrepo_find_for_task | Atomic find action for a concrete task; returns ranked assets, match reasons, install command, and URL |
tokrepo_resolve_capability | Resolve a capability gap into a selected asset, verification evidence, install plan, lifecycle contract, next MCP calls, and CLI fallbacks |
tokrepo_search | Search assets by keyword/tag with agent_fit ranking |
tokrepo_detail | Get full asset details by UUID |
tokrepo_edges | Inspect requires, extends, and co-used asset graph edges before planning installs |
tokrepo_install_plan | Get agent-native install plan v2 with rollback, evidence_bundle, SBOM-lite, and signature_evidence |
tokrepo_verify | Verify trust, hashes, permissions, policy, evidence_bundle, SBOM-lite, and signature_evidence before activation |
tokrepo_codex_install | Dry-run, stage, or install a Codex skill safely |
tokrepo_installed | List TokRepo-managed Codex installs |
tokrepo_update | Dry-run or update managed Codex installs |
tokrepo_uninstall | Dry-run or remove a managed Codex install |
tokrepo_rollback | Dry-run or roll back a prior Codex install session |
tokrepo_handoff_plan | Read-only packaging plan with quality_gate and package manifest for reusable local work after a task |
tokrepo_harvest | Read-only package draft generator for reusable changed or explicit local files after a task |
tokrepo_push | Push one explicit asset to TokRepo after user confirmation |
Run this once in a project:
It writes managed instructions to AGENTS.md, CLAUDE.md, GEMINI.md, Cursor rules, GitHub Copilot instructions, Cline rules, Windsurf rules, Roo rules, OpenHands microagents, Aider conventions, .mcp.json, and .tokrepo/agent.json. The rule is simple: during planning, when the agent sees a capability gap, it should call tokrepo_resolve_capability or tokrepo_discover before inventing a one-off local tool. After a task, agents can call tokrepo_harvest or run tokrepo harvest --changed --json to suggest reusable files for user-confirmed private publishing.
Registries and agents can discover this server through:
Use https://tokrepo.com/agent-ecosystem.json for agent marketplace submissions, starter templates, README snippets, install guides, and example projects. It contains canonical listing copy, ecosystem channels, target project-memory files, and verification commands.
TokRepo emits anonymous aggregate funnel events for tokrepo_resolve_capability, tokrepo_discover, tokrepo_verify, tokrepo_install_plan, install dry-runs, installs, harvests, handoffs, and pushes. It does not send task text or file contents. Disable with TOKREPO_TELEMETRY=0.
TokRepo is the open registry for AI assets — like npm for packages, but for AI skills, prompts, MCP configs, and workflows.
npx tokrepo search "query" / npx tokrepo install <uuid>MIT