mcp-server-mcpindex
Officialmcp-server-mcpindex
Ein MCP-Server zum Finden von MCP-Servern, plus beratende Vertrauensurteile, die Agent-Frameworks aufrufen können, bevor sie ein Tool aufrufen – von mcpindex.ai.
Ein Drop-in-MCP-Server, mit dem Ihr Agent andere MCP-Server direkt aus der Agent-Schleife heraus entdecken, vergleichen, installieren und vorab prüfen kann. Unterstützt von mcpindex.ai – dem agenten-nativen MCP-Server-Index des offiziellen Registries (Live-Zähler unter mcpindex.ai/stats), täglich gescreent und auf Drift überwacht.
Live-Website · npx mcp-server-mcpindex · Remote-MCP · Installations-Gate · Dokumentation · Vertrauen
Installation
npm install -g mcp-server-mcpindexDies ist der Verzeichnis-/Beratungs-Client (empfehlen, suchen, vertrauen). Er installiert nicht das Drift-Gate im Pfad – das erledigt curl -fsSL https://mcpindex.ai/install.sh | sh.
Erfordert Node 20+. Spricht beide Protokoll-Ären über stdio: die Revision vom 2026-07-28 (server/discover, Pro-Request-_meta-Envelope) und den initialize-Handshake, den jeder aktuelle Client verwendet (2025-11-25 bis hinunter zu 2024-10-07), ausgewählt pro Verbindung.
Oder remote verbinden (ohne Installation)
Lieber nichts installieren? mcpindex ist auch ein gehosteter Remote-MCP-Server. Richten Sie jeden Client, der Remote-MCP unterstützt (Claude-Connectors, Cursor usw.), auf Folgendes aus:
https://mcpindex.ai/api/mcpClaude Code
claude mcp add --scope user mcpindex -- npx -y mcp-server-mcpindex@latestGemini CLI
gemini mcp add -s user mcpindex npx -y mcp-server-mcpindex@latestRelated MCP server: filesystem-mcp
Verwendung mit Claude Desktop
Fügen Sie Folgendes zu ~/Library/Application Support/Claude/claude_desktop_config.json hinzu:
{
"mcpServers": {
"mcpindex": {
"command": "npx",
"args": ["-y", "mcp-server-mcpindex@latest"]
}
}
}
@latesthält Sie aktuell: Dies ist der Advisory-Discovery-Server (nicht das Drift-Gate im Pfad), trägt also keinen Versions-Pin –npxholt beim nächsten Neustart des Hosts die neueste Version, ohne manuellen Upgrade-Schritt.
Starten Sie Claude Desktop neu. Fragen Sie dann:
„Finde mir einen MCP-Server, der PDFs lesen und den Inhalt nach S3 schreiben kann.“
Claude ruft recommend_mcp_for_task auf und gibt die Top-3-Server mit Installationsbefehlen zurück.
Verwendung mit Cursor
Fügen Sie zu .cursor/mcp.json hinzu:
{
"mcpServers": {
"mcpindex": {
"command": "npx",
"args": ["-y", "mcp-server-mcpindex@latest"]
}
}
}Verwendung mit Cline
Fügen Sie zu Ihren Cline-Einstellungen hinzu:
npx -y mcp-server-mcpindex@latestVerfügbare Tools
Tool | Funktion |
| Nimmt eine natürlichsprachliche Aufgabe entgegen. Liefert die Top-3-Server mit Begründung, Installationsbefehlen und Qualitätsbewertungen. |
| Stichwort- und semantische Suche über das gesamte Registry. Optionaler Kategoriefilter. |
| Liefert das exakte Installations-JSON/CLI für einen Server + Client (Claude Desktop, Claude Code, Cursor, Gemini CLI, Cline, Zed). |
| Nebeneinander-Vergleich von 2-5 Servern – Qualitätsbewertungen, Installationspfade, Umgebungsvariablen. |
| Beratendes Urteil vor dem Aufruf für ein bestimmtes Tool auf einem Server. Fail-CLOSED: gibt UNVERIFIED zurück, wenn kein Urteil vorliegt. |
| Aggregiertes Pre-Flight-Urteil über alle Tools eines Servers. Gleiche Struktur wie |
Agent-Framework-Integration: beratendes Screening vor dem Aufruf
check_tool_trust ist die Integrationsfläche des Verzeichnis-Clients (nicht das In-Pfad-mcpindex-gate). Es ermöglicht Agent-Frameworks (Composio, Mastra, LangChain, DSPy, reine LLM-Tool-Aufrufschleifen), vor dem Absenden eines Aufrufs ein beratendes Screening-Urteil anzufragen. In v1 sehen Sie REVIEW oder UNVERIFIED – keine Sicherheitsfreigabe.
Nutzen Sie Mastra? Das Schwesterpaket
@mcp-index/mastraliefert genau dieses Screening als fertigenbeforeToolCall-Hook –npm i @mcp-index/mastra, keine Verkabelung nötig.
Urteilsvertrag (v1)
{
"directive": "ALLOW" | "DENY" | "REVIEW" | "UNVERIFIED",
"status": "EVALUATED" | "PARTIAL" | "STALE" | "ERROR",
"granularity": "description-level" | null, // scope of a PARTIAL screen
"dimensions": [
{ "id": "tool_safety", "verdict": "PASS", "severity": "INFO" }
],
"expires_at": "2026-06-30T00:00:00Z",
"honest_limits": [
"conformance_monitored_not_enforced",
"calibrated_false_v1",
"advisory_deployment"
],
"verdict_contract_version": "1.0.0",
"server_id": "github",
"tool_name": "create_pull_request",
"source_url": "https://mcpindex.ai/api/v1/trust/tool/github/create_pull_request",
"fetched_at": "2026-05-28T18:42:11.118Z"
}Das Urteil der kostenlosen Stufe enthält Directives + Dimensionen + Aktualität. Beweis-Zitate, LLM-Begründungen und Chain-Verlauf sind Funktionen der kostenpflichtigen Stufe und hier bewusst weggelassen.
Ehrliche Grenzen (heften Sie diese an Ihre Gate-UI)
Jedes v1-Urteil enthält diese drei Warnhinweise, und Ihr Gate SOLLTE sie bei jeder Entscheidung über einen Aufruf anzeigen:
conformance_monitored_not_enforced– Anbieter deklarieren selbst; mcpindex überwacht Drift, blockiert aber nicht auf Netzwerkebene.calibrated_false_v1– Die Schweregrade der Dimensionen sind noch nicht anhand realer Incident-Daten kalibriert.advisory_deployment– Das Urteil ist beratend; der Agent (oder der Mensch, der den Agenten überprüft) trifft die Entscheidung.
Historien-Verankerung: OTS-Bitcoin-verankerte Historie; Bitcoin-finalisiert bei N=6 Bestätigungen (~1 Std.); ausstehend in ~10 Min. Sub-Fenster-Präzision wird behauptet, nicht bewiesen.
Integrationsmuster (LangChain-Stil, direkte LLM-Tool-Aufruf-Konvention)
import { Client } from '@modelcontextprotocol/sdk/client/index.js';
import { StdioClientTransport } from '@modelcontextprotocol/sdk/client/stdio.js';
const mcpindex = new Client({ name: 'gate', version: '1.0.0' }, { capabilities: {} });
await mcpindex.connect(new StdioClientTransport({
command: 'npx', args: ['-y', 'mcp-server-mcpindex@latest'],
}));
// gateToolCall wraps any agent tool dispatch. Plug it in front of
// the LangChain / DSPy / Mastra / Composio tool-call hook.
async function gateToolCall({ serverId, toolName, invoke, askHuman }) {
const res = await mcpindex.callTool({
name: 'check_tool_trust',
arguments: { server_id: serverId, tool_name: toolName },
});
const verdict = JSON.parse(res.content[0].text);
// Pin the v1 caveats in the audit log no matter what.
audit.log({ verdict, caveats: verdict.honest_limits });
switch (verdict.directive) {
case 'REVIEW':
// Fail-CLOSED to human. Do NOT auto-execute on REVIEW.
// At v1 this is the common screened outcome (semantic-only).
return askHuman({ verdict, action: `${serverId}/${toolName}` });
case 'UNVERIFIED':
// No verdict on file (or upstream unreachable). Fail-CLOSED.
// Recommend human review. Do NOT fail-open to invoke().
return askHuman({
verdict,
action: `${serverId}/${toolName}`,
note: 'No trust verdict on file. Human review required before first use.',
});
case 'ALLOW':
// Reserved in the contract — not produced by the v1 public screen.
// Keep the branch for future conformance-earned ALLOW; do not expect it today.
return invoke();
case 'DENY':
// Reserved in the contract — not produced by the v1 public screen.
throw new Error(
`mcpindex denied ${serverId}/${toolName}: ${JSON.stringify(verdict.dimensions)}`,
);
default:
// Unknown directive. Fail-CLOSED.
return askHuman({ verdict, action: `${serverId}/${toolName}` });
}
}Die tragende Regel: niemals Fail-Open
Wenn der Verdict-Endpoint nicht erreichbar ist, 404 zurückgibt, eine Zeitüberschreitung auftritt, fehlerhaftes JSON zurückgegeben wird oder für diesen Server noch kein Urteil vorliegt, gibt check_tool_trust directive: "UNVERIFIED" + status: "ERROR" zurück. Es wird niemals stillschweigend auf ALLOW gesetzt. Ihr Gate-Code SOLLTE UNVERIFIED als „menschliche Prüfung erforderlich“ behandeln, niemals als „sieht gut aus, schick es ab.“
status ist Telemetrie über die Vollständigkeit des Screenings, getrennt von der directive-Vertrauensentscheidung: EVALUATED (vollständiges Screening), PARTIAL (nur ein Teil der Oberfläche, z. B. Beschreibungsebene – siehe granularity), STALE (Urteil außerhalb seines Aktualitätsfensters), ERROR (nicht erreichbar / kein Urteil vorliegend). Ein PARTIAL-Screening wird niemals als EVALUATED gemeldet.
Dies ist getestet. Siehe test/trust.test.mjs.
Bibliothek direkt verwenden (ohne MCP)
Der Trust-Client wird auch als einfaches ES-Modul exportiert:
import { checkToolTrust, assessServer } from 'mcp-server-mcpindex/src/trust.mjs';
const verdict = await checkToolTrust({
serverId: 'github',
toolName: 'create_pull_request',
});
if (verdict.directive !== 'ALLOW') {
// Hand to a human, log, or block.
}Backend
Standardmäßig gehen Aufrufe an https://mcpindex.ai. Überschreiben Sie das mit MCPINDEX_API_BASE=..., falls Sie selbst hosten.
Die kostenlose Stufe ist auf 60 req/min/IP begrenzt. Kostenpflichtige Schlüssel sind in Kürze verfügbar für höheren Durchsatz und das vollständige, mit Beweisen versehene Urteil (Beweis-Zitate, LLM-Begründung, Chain-Verlauf).
Verwandte Pakete
Drei Möglichkeiten, mcpindex in einen Agenten zu integrieren, für verschiedene Einsatzbereiche:
Paket | Installation | Beschreibung |
|
| Verzeichnis- und Advisory-Screening als MCP-Server: Server nach Aufgabe finden und vor einem Aufruf |
|
| Dasselbe Advisory-Screening als |
|
| In-Pfad-Drift-Gate: |
Advisory-Screening vs. Drift-Gate: Dieses Paket und @mcp-index/mastra fragen mcpindex: „Wurde dieses Tool geprüft?“ (ein Netzwerk-Urteil). @mcp-index/sdk stellt lokal eine andere Frage: „Hat sich der Vertrag dieses Tools geändert, seit ich es gepinnt habe?“ Komplementär, und keins hängt vom anderen ab.
Lizenz
MIT.
Projekt
Website: mcpindex.ai
Methodik: mcpindex.ai/methodology
Server prüfen: mcpindex.ai/screen
Leitfaden: Den richtigen MCP-Server anhand der Aufgabe finden
Quellcode: github.com/mcpindex-ai
Inoffiziell. Nicht mit Anthropic verbunden.
Available Tools
6 toolsassess_serverA
Aggregated pre-flight trust assessment across all tools on an MCP server. Same verdict shape as check_tool_trust. Use for "is THIS server worth integrating?" decisions. v1 advisory; conformance monitored not enforced; verdicts may be UNVERIFIED if not yet probed.
| Name | Required | Description | Default |
|---|---|---|---|
| server_id | Yes | Server slug to assess. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description discloses behavioral traits: advisory nature, conformance monitoring not enforced, and potential UNVERIFIED verdicts. This adds valuable context beyond a simple read operation, though no side effects or auth needs are mentioned.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three concise sentences without redundancy: purpose, use, and behavioral notes. Front-loaded with the core action, efficient and clear.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers purpose, usage guidance, verdict shape, and advisory nature. For a simple one-parameter tool with no output schema, it provides sufficient context, though explicit mention of return format would be slightly better.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The single parameter 'server_id' is described in the schema as 'Server slug to assess.' The description does not add new meaning beyond usage context. With 100% schema coverage, a baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool performs an aggregated pre-flight trust assessment across all tools on a server, using the specific verb 'assess' and resource 'server'. It distinguishes from sibling 'check_tool_trust' by noting aggregation, and clarifies the verdict shape is identical.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states the use case: 'is THIS server worth integrating?' decisions. It also provides context on when to be cautious with 'v1 advisory; conformance monitored not enforced; verdicts may be UNVERIFIED if not yet probed', guiding appropriate reliance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
check_tool_trustA
Pre-invocation advisory screen for a specific tool on an MCP server. Returns an advisory verdict object (directive ALLOW | DENY | REVIEW | UNVERIFIED, dimensions, freshness). At v1 the public screen produces REVIEW or UNVERIFIED only — ALLOW/DENY are reserved. Not the in-path gate (mcpindex-gate). Agents SHOULD treat UNVERIFIED as "human review required", never as ALLOW.
| Name | Required | Description | Default |
|---|---|---|---|
| server_id | Yes | Server slug (e.g. "github", "filesystem"). Same id used by search_mcp_servers. | |
| tool_name | Yes | Tool name as exposed by the server (e.g. "create_pull_request"). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided, so description carries full burden. It accurately describes behavior: returns advisory verdict with specific fields, v1 only produces REVIEW or UNVERIFIED. Does not mention side effects, but none expected. Could add authentication requirements, but sufficient for a read-only check.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, no fluff. Front-loads purpose, then constraints, then usage guideline. Every sentence adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple two-parameter tool with no output schema, the description covers purpose, return value, version limitations, and usage advice. No gaps for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% (both parameters described in schema). Description adds no extra meaning beyond what schema provides. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: a pre-invocation advisory screen for a specific tool. It uses specific verb 'check' and resource 'tool trust', and distinguishes from siblings like assess_server and search_mcp_servers by focusing on a single tool's trust level.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when to use (pre-invocation advisory) and when not (not the in-path gate). Provides clear directive: treat UNVERIFIED as human review required. Distinguishes from sibling tools effectively.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
compare_serversA
Side-by-side comparison of 2-5 MCP servers - quality scores, install paths, transport types, env vars.
| Name | Required | Description | Default |
|---|---|---|---|
| slugs | Yes | Server slugs to compare. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full burden. It discloses the output content (quality scores, install paths, etc.) but does not mention any side effects, auth requirements, or that it is a read-only operation. It assumes a non-destructive nature, but this is not explicit.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
One sentence encapsulates the core functionality without any wasted words. It is front-loaded with the key action 'Side-by-side comparison' and details the compared attributes.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simple one-parameter tool with no output schema, the description is relatively complete by listing the compared attributes. However, it does not mention output format, ordering, or whether results are aggregated, which would enhance completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% for the single parameter 'slugs', with min/max items already defined. The description does not add semantic detail beyond what the schema provides, so it meets the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool compares 2-5 MCP servers side-by-side, listing specific attributes (quality scores, install paths, etc.). This distinguishes it from siblings like assess_server (single server) and recommend_mcp_for_task (recommendation).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use for comparing multiple servers but does not explicitly state when to use it versus alternatives or any prerequisites. It could benefit from guidance on when to choose compare_servers over assess_server or search_mcp_servers.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_install_commandA
Get the exact install command for a given MCP server and client. Returns a JSON block ready to paste into the client config.
| Name | Required | Description | Default |
|---|---|---|---|
| client | Yes | Target client. | |
| server_slug | Yes | Slug of the server (from search_mcp_servers or recommend_mcp_for_task results). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Without annotations, the description discloses the tool returns a JSON command ready to paste. It does not mention any side effects or authentication, but for a retrieval tool this is sufficiently transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, no wasted words, perfectly front-loaded with the action and output.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with two well-described parameters and no output schema, the description is complete: it explains what it does and what it returns.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and both parameters have descriptions. The description adds marginal value beyond the schema, so baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool retrieves the install command for a given server and client, and specifies the output format (JSON block). This distinguishes it from sibling tools like search or recommend.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the description, but there is no explicit guidance on when to use this tool versus alternatives, nor conditions to avoid usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
recommend_mcp_for_taskA
Recommend the best MCP servers for a natural-language task. Returns top 3 ranked picks with reasoning, install commands, and quality scores. Use this when the user asks for the right MCP server for a task they want to do.
| Name | Required | Description | Default |
|---|---|---|---|
| task | Yes | Natural-language description of the task, e.g. "read PDFs and write to S3" or "search GitHub and open a PR". |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses the output structure: 'Returns top 3 ranked picks with reasoning, install commands, and quality scores.' This is sufficient for a read-only recommendation tool. It could mention ranking criteria or data sources for greater transparency, but the current description is clear.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first states purpose and output, the second gives usage guidance. It is front-loaded with key information and contains no superfluous words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, no output schema), the description adequately covers what the tool does and returns. It mentions the top 3 picks, reasoning, install commands, and quality scores. It could be enhanced by referencing sibling tools for alternative uses, but it is sufficiently complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% coverage with a description for the 'task' parameter. The tool description does not add additional examples or constraints beyond the schema's example. Thus, per the baseline, a score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Recommend the best MCP servers for a natural-language task.' It specifies the verb (recommend), resource (MCP servers), and context (natural-language task). This distinguishes it from sibling tools like search_mcp_servers (which lists servers) and assess_server (which evaluates a single server).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says when to use the tool: 'Use this when the user asks for the right MCP server for a task they want to do.' It lacks explicit when-not-to-use or alternatives, but the context is clear enough for most agents.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_mcp_serversA
Keyword + semantic search across the full MCP server registry. Use when the user knows what tool category they want but not which server.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max results (default 10, max 50). | |
| query | Yes | Search query. | |
| category | No | Optional category filter (e.g. database, browser, github, productivity). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are present, so the description bears full responsibility for behavioral disclosure. It only states the search capability, missing details on read-only nature, authentication, rate limits, or any side effects. Minimal transparency beyond basic function.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with the action and purpose. Every word adds value. No redundancy or unnecessary details.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple search tool with 3 parameters and no output schema, the description is adequate but has gaps. It does not explain result format, pagination, or search behavior beyond 'keyword + semantic'. Could be more complete given lack of annotations and output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3. The description does not add meaning beyond the schema; it mentions keyword + semantic search but that is already implicit. No additional parameter guidance.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool performs keyword + semantic search across the MCP server registry, with a specific use case ('when the user knows what tool category they want but not which server'). This distinguishes it from sibling tools like assess_server or get_install_command.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit context for when to use the tool, but does not mention when not to use it or list alternatives. The guidance is clear and useful, but lacks exclusion criteria.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.3.7- First observed
assess_server - First observed
check_tool_trust - First observed
compare_servers - First observed
get_install_command - First observed
recommend_mcp_for_task - First observed
search_mcp_servers
TDQS
Scored across 6 tools
Each tool targets a clearly distinct purpose: search, recommend, compare, install, and two levels of trust assessment (server-level and tool-level). Even the trust tools are well-differentiated by scope.
All tool names follow a consistent verb_noun pattern using snake_case: assess_server, check_tool_trust, compare_servers, get_install_command, recommend_mcp_for_task, search_mcp_servers.
With 6 tools covering search, recommendation, comparison, installation, and trust, the number is well-scoped for a server registry/helper. No tools feel redundant or unnecessary.
The set covers the core workflow of finding, evaluating, and installing MCP servers. A minor gap is the lack of a tool to retrieve full metadata for a single server (e.g., description, version), but search and comparison partially fill that need.
Maintenance
Related MCP Connectors
Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.
Search and get install details on MCP servers, right from your agent -- a unified marketplace index.
Search, vet & assemble MCP servers from your agent: verified tools, risk labels, and trust scores.
Capability registry for the agentic economy. Semantic search over verified MCP server listings.
Related MCP Servers
- AlicenseAqualityNot gradedmaintenanceEnables browser automation through Playwright using accessibility tree snapshots instead of screenshots. Supports web scraping, form interactions, testing, and connecting to existing browser sessions with logged-in accounts.237,762 npm5-
- AlicenseAqualityAmaintenanceMCP Server that enables LLMs to interact with the local filesystem.4131,779 npm23MIT

agentskill-mcpofficial
AlicenseAqualityFmaintenanceMCP server for discovering and installing AI agent skills from agentskill.sh. Search skills across platforms, browse trending skills, and install them with built-in security scanning.426 npm3MIT- AlicenseAqualityDmaintenanceEnables searching and retrieving details of 9,000+ MCP servers from the Agent Almanac catalog, allowing agents to discover, inspect, and install tools directly.331 npmMIT