Skip to main content
Glama
Arnon-hs
by Arnon-hs

Purpose

AtlasRepo MCP adapts the public AtlasRepo catalog contract to Model Context Protocol clients. It supports local stdio and hosted Streamable HTTP, exposes three bounded read-only tools, and contains no private scoring, account or billing logic.

Owns

Does not own

MCP protocol, schemas and tool descriptions

Catalog ingestion, scoring or moderation

Bounded API client, timeouts and result truncation

Authentication, accounts or payments

stdio executable and Streamable HTTP endpoint

Web/Admin UI or database access

Origin/host validation and health endpoints

Arbitrary URL fetching or code execution

Related MCP server: ContractAudit MCP Server

Architecture

flowchart LR
  Client["MCP client"] -->|"stdio"| Server["AtlasRepo MCP"]
  Remote["Remote MCP client"] -->|"Streamable HTTP /mcp"| Server
  Server --> Validate["Zod input validation"]
  Validate --> Tools{"Read-only tools"}
  Tools --> Recommend["atlasrepo_recommend"]
  Tools --> Search["atlasrepo_search_tools"]
  Tools --> Repo["atlasrepo_get_repository"]
  Recommend --> API["Public AtlasRepo API"]
  Search --> API
  Repo --> API

Tools

Tool

Input

Result

atlasrepo_recommend

A bounded problem/use-case query

Evidence-backed repository recommendations

atlasrepo_search_tools

Search text and bounded filters

Matching tools from the approved catalog

atlasrepo_get_repository

Repository owner and name

One repository evidence record

All inputs are schema-validated. Upstream calls have a timeout and responses are truncated to a safe maximum. The connector never executes discovered repositories.

Technology

Area

Choice

Language/runtime

TypeScript, Node.js 20+

Protocol

Model Context Protocol SDK

HTTP

Express 5, Streamable HTTP

Validation

Zod 4

Distribution

npm executable and Docker/Zeabur service

Install in one command

The public tools work through the anonymous free fallback. ATLASREPO_API_KEY is optional and should only be added through the client's environment when account limits or private features are needed.

Codex:

codex mcp add atlasrepo -- npx -y atlasrepo-mcp

Claude Code:

claude mcp add atlasrepo -- npx -y atlasrepo-mcp

Other stdio MCP clients can launch the published package with npx -y atlasrepo-mcp and the hosted Streamable HTTP endpoint is https://mcp.atlasrepo.com/mcp.

Full Codex plugin

The repository also ships a validated Codex plugin bundle. Add its marketplace once, then install the plugin:

codex plugin marketplace add Arnon-hs/atlasrepo-mcp && codex plugin add atlasrepo@atlasrepo

The plugin uses the same published npm executable. The first command is no longer needed after the AtlasRepo marketplace has been configured.

Generic MCP client configuration

{
  "mcpServers": {
    "atlasrepo": {
      "command": "npx",
      "args": ["-y", "atlasrepo-mcp"]
    }
  }
}

Local development

npm ci
npm run check
npm test
npm run build
node dist/index.js

HTTP service

PORT=8080 MCP_ALLOWED_HOSTS=localhost npm run start:http

Variable

Purpose

ATLASREPO_API_BASE_URL

Upstream public API origin

ATLASREPO_API_KEY

Optional upstream key; keep secret

ATLASREPO_REQUEST_TIMEOUT_MS

Bounded upstream timeout

PORT

HTTP listener port

MCP_ALLOWED_HOSTS

Comma/space/semicolon-separated Host allowlist

Use .env.example as the non-secret template. Never remove immutable or inherited Zeabur variables.

Verification, deployment and publishing

Every pull request runs secret-free hosted quality gates. After merge, the trusted main workflow runs on one ephemeral JIT runner and performs:

  1. Build and test - typecheck, tests, package smoke and dependency audit.

  2. Image verification - build and inspect the production Docker image.

This repository does not deploy, migrate or probe production from its main workflow. Production releases are owned by the pinned contract in Arnon-hs/atlasrepo-schema/.github/workflows/release.yml, which deploys services sequentially and verifies the release. npm publication is separate: create a reviewed semantic-version tag and let the trusted-publishing workflow publish the package.

Engineering rules

  • Preserve read-only behavior and bounded inputs, timeouts and result sizes.

  • Keep stdout protocol-clean in stdio mode; diagnostics go to stderr without secrets.

  • Never log API keys, authorization headers or full upstream payloads.

  • Add schemas and tests with every tool/contract change.

  • Conventional Commits: feat(mcp): ..., fix(http): ..., docs(mcp): ....

Pull request checklist

  • npm run check, npm test, npm run build and npm run smoke pass.

  • stdio stdout contains protocol messages only.

  • HTTP host/origin protections and health contracts remain intact.

  • No private Platform/Scout logic or write operation was added.

  • The main JIT workflow built and inspected the MCP container image.

  • Any production release was initiated only from the Schema release contract.

License

MIT. See LICENSE.

Available Tools

3 tools
atlasrepo_get_repositoryGet AtlasRepo repository evidenceA

Load the AtlasRepo decision record and linked evidence for one GitHub repository.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYes
ownerYes

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It indicates a read-style operation ('Load') and names what is loaded, but does not disclose return format, error behavior, authentication needs, or whether linked evidence is embedded or referenced.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, focused sentence with no filler. It front-loads the action and resource, and every word earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple two-parameter get operation, the description covers the core purpose and scope. However, with no output schema and no annotations, it omits return details and failure semantics, leaving some ambiguity about what the agent will receive.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It mentions 'one GitHub repository' but does not explain that owner and name identify the repository or clarify their roles. The parameter names are self-explanatory, but the description adds little semantic value beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Load') and identifies the exact resource ('AtlasRepo decision record and linked evidence') scoped to 'one GitHub repository'. This clearly distinguishes it from the sibling tools, which are about recommending and searching.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clearly implies use when a specific repository's decision record is needed, and the 'one GitHub repository' scope distinguishes it from search-oriented siblings. However, it does not explicitly state when not to use it or mention alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

atlasrepo_recommendRecommend open-source solutionsA

Find evidence-backed repositories and workflows for a concrete engineering or content-production problem.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum recommendations
queryYesProblem or outcome to solve

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the behavioral disclosure burden. It tells the agent that recommendations are evidence-backed and that outputs are repositories/workflows, but it does not explain how recommendations are produced, what limits or failures may occur, or any caveats about the evidence sources.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, focused sentence that front-loads the key action and output. There is no filler, repeated boilerplate, or unnecessary structure.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simplicity of the tool (two parameters, no nested objects, no output schema), the description provides adequate context for invocation: input is a problem statement, output is repositories/workflows. It could be more complete by describing the result format or evidence presentation, but the core usage is readable.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already covers both parameters well (100% coverage), giving a baseline of 3. The description adds extra meaning by making clear that the query should be a concrete engineering or content-production problem rather than a generic keyword lookup, which helps an agent phrase the query effectively.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('find') with a clear resource ('repositories and workflows') and a clear target scenario ('a concrete engineering or content-production problem'). It communicates the tool's function well, though it does not explicitly contrast against sibling tools like atlasrepo_search_tools or atlasrepo_get_repository.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides a clear use context: use this when you have a concrete problem or outcome and want evidence-backed repository/workflow recommendations. It does not provide when-non-to-use guidance or explicitly name alternatives, so it stops short of a top score.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

atlasrepo_search_toolsSearch AtlasRepo toolsB

Search normalized open-source tools by text, kind, and quality threshold.

ParametersJSON Schema
NameRequiredDescriptionDefault
qNoFree-text search
kindNoTool kind or category
minQualityNoMinimum normalized quality score

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must carry the full behavioral burden. It only states the action and filters; it does not disclose whether the operation is read-only, how results are ordered, whether pagination exists, or what the response shape looks like. For a search tool, one might expect a statement like 'returns a list of matching tools,' but that is absent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no filler. It front-loads the action and lists the three filtering dimensions in a compact, scannable way. Every word carries meaning, and there is no redundant phrasing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is relatively simple (3 optional params, no output schema). However, given that siblings exist and no output shape is defined, the description leaves out what the search returns (list? count? tool objects?) and any caveats (e.g., empty query behavior). It is adequate for a basic search but not fully complete for an agent that needs to interpret results.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so each parameter already has explicit meaning (free-text, kind/category, quality between 0 and 1). The description merely names these in prose ('text, kind, and quality threshold') without adding new semantics like how the kind field matches (exact? partial?) or how minQuality interacts with the score. This meets the baseline for full schema coverage but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('search'), a specific resource ('normalized open-source tools'), and the key filtering dimensions (text, kind, quality threshold). This clearly distinguishes it from its siblings 'atlasrepo_recommend' and 'atlasrepo_get_repository' — one suggests tools, the other fetches a single repository. The agent can immediately tell what this tool does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives no context on when to choose this tool over its siblings. It does not mention that 'atlasrepo_recommend' is for getting curated suggestions or that 'atlasrepo_get_repository' returns details for a specific repo. An agent would have to infer that 'search' is for finding tools by criteria, but no explicit guidance or exclusions are provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updatesv0.1.0
    • First observedatlasrepo_get_repository
    • First observedatlasrepo_recommend
    • First observedatlasrepo_search_tools

TDQS

A3.7/5.0

Scored across 3 tools

Disambiguation4/5

The tools are mostly distinct: atlasrepo_recommend is problem-driven, atlasrepo_search_tools is structured query-based, and atlasrepo_get_repository is a targeted detail fetch. However, recommend and search_tools could both return repositories/tools, so an agent might occasionally be unsure which path to use for discovery.

Naming Consistency4/5

All tools share the atlasrepo_ prefix and use a verb-first style. atlasrepo_search_tools and atlasrepo_get_repository follow a clear verb_noun pattern, but atlasrepo_recommend lacks an object, creating a minor inconsistency.

Tool Count5/5

Three tools is well-scoped for this domain: one for problem-level recommendation, one for structured search, and one for inspecting a specific repository record. Each tool covers a distinct part of the workflow without redundancy.

Completeness4/5

The read-only decision-record workflow is well covered: discover by problem, search by criteria, and load detailed evidence for a repository. Minor gaps include no explicit list-all/browse capability or a dedicated workflow-detail fetch, but these are workable through the existing tools.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    B
    maintenance
    Provides read-only hybrid RAG search and discovery over a local-first AI knowledge corpus, enabling semantic and keyword search, browse, digest, and status tools.
    4
    PolyForm Noncommercial 1.0.0
  • A
    license
    A
    quality
    C
    maintenance
    Provides read access to community-written summaries, scores, and reviews of open-source repositories via the RepoCritics corpus. Enables search and retrieval of wiki pages, reviews, metadata, and AI reports for repositories.
    7
    6 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Provides read-only, provenance-first repository navigation for agents and humans, with ranked lexical retrieval, exact query, document handles, symbol context, and change impact analysis.
    42 npm
    Apache 2.0