RegistryBLOCK
Production-ready MCP servers for 70+ APIs — GitHub, Google, Notion, Jira & more. Generated from OpenAPI specs, tested against live APIs. Works with Claude Desktop, Cursor, Codex & Claude Code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Armory Registry
Production-ready MCP servers for popular APIs, generated by MCP Blacksmith.
Servers · Install & Usage · Features · How it works · License
MCP servers that connect AI agents to real-world APIs. Each server is a standalone Python package — generated from the upstream OpenAPI spec using MCP Blacksmith and tested against the live API before release. Hosted on MCP Armory or run independently.
Servers
🧠 AI & Machine Learning   ElevenLabs · Linkup · Parallel · Perplexity AI · Ragie · Replicate
📊 Analytics   Ahrefs · Datadog · Google Analytics · Google Search Console · Linkly · Mixpanel · [PostHog](s
6d1c2e56d666OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcparmory-agentql -- uvx mcparmory-agentql==1.0.8
claude mcp add agentql:1.0.8 -- docker run -i --rm ghcr.io/mcparmory/agentql:1.0.8:None
Exposed tools (160)
100 read · 13 write · 47 destructive. Blast radius: 47 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_email_template | write | Create a new email template that can be used for sending standardized emails. Define the template structure, content, and variables for reuse across email communications. |
create_lead_status | write | Create a new custom status that can be assigned to leads in your pipeline. This allows you to define custom workflow stages beyond the default statuses. |
create_pipeline | write | Create a new pipeline with the specified name. The pipeline serves as a container for organizing and executing workflow operations. |
create_scheduling_link_shared | write | Create a shared scheduling link that allows others to view your available time slots and book meetings directly on your calendar without needing direct access to your calendar. |
create_sequence | write | Create a new sequence with the specified configuration. This operation initializes a sequence resource that can be used for ordered processing or workflow management. |
create_sms_template | write | Create a new SMS template that can be used for sending standardized text messages. Define the template content and configuration for reuse across SMS campaigns. |
delete_activity_custom_field | destructive | Permanently delete an Activity Custom Field. The field will be immediately removed from all Custom Activity API responses and cannot be recovered. |
delete_activity_note | destructive | Permanently delete a Note activity by its ID. This action cannot be undone and will remove all associated data. |
delete_call | destructive | Permanently delete a Call activity record by its ID. This action cannot be undone and will remove all associated data. |
delete_comment | destructive | Remove a comment from a thread. The comment content is deleted but the comment object remains until all comments in the thread are removed, at which point the entire thread is deleted. Deletion permissions are based on the user |
delete_completed_task | destructive | Permanently remove a completed task activity from the system. This action cannot be undone and will delete the TaskCompleted activity record and all associated data. |
delete_contact | destructive | Permanently remove a contact from the system by its ID. This action cannot be undone and will delete all associated data. |
delete_contact_custom_field | destructive | Permanently delete a custom field from your Contact system. The field will be immediately removed from all Contact API responses and cannot be recovered. |
delete_custom_activity | destructive | Permanently delete a custom activity type by its ID. This action cannot be undone and will remove the activity type from your system. |
delete_custom_activity_instance | destructive | Permanently delete a Custom Activity instance by its ID. This action cannot be undone. |
delete_custom_field | destructive | Permanently delete a custom field from a custom object type. The field will be immediately removed from all Custom Object API responses. |
delete_custom_field_shared | destructive | Permanently delete a shared custom field. The field will be immediately removed from all objects it was assigned to. |
delete_custom_object | destructive | Permanently delete a Custom Object instance by its unique identifier. This action cannot be undone. |
delete_custom_object_type | destructive | Permanently delete a Custom Object Type and remove it from your system. This action cannot be undone. |
delete_email_activity | destructive | Permanently delete an email activity record by its unique identifier. This action cannot be undone and will remove all associated data. |
delete_email_template | destructive | Permanently delete an email template by its ID. This action cannot be undone and will remove the template from all systems. |
delete_email_thread | destructive | Delete an email thread activity and all associated email activities within that thread. This is a permanent operation that removes the entire thread conversation. |
delete_file | destructive | Permanently deletes a file owned by the user without moving it to trash. If the file is a folder, all descendants owned by the user are also deleted. For shared drives, the user must be an organizer on the parent folder. |
delete_form_submission | destructive | Delete a FormSubmission activity by its ID. This operation permanently removes the form submission record from the system. |
delete_group | destructive | Delete a group from the system. This operation is only permitted if the group is not referenced by any saved reports or smart views. |
delete_integration_link | destructive | Permanently delete an integration link from your organization. This action is restricted to organization administrators only and cannot be undone. |
delete_lead | destructive | Permanently remove a lead from the system by its ID. This action cannot be undone and will delete all associated data. |
delete_lead_custom_field | destructive | Permanently delete a custom field from your Lead records. The field will be immediately removed from all Lead API responses and cannot be recovered. |
delete_lead_status | destructive | Delete a lead status from the system. Ensure no leads are currently assigned to this status before deletion, as the operation will fail if leads depend on it. |
delete_lead_status_change | destructive | Remove a status change event from a lead |
delete_meeting | destructive | Permanently delete a specific Meeting activity by its ID. This action cannot be undone and will remove all associated data. |
delete_opportunity | destructive | Permanently remove an opportunity from the system. This action cannot be undone and will delete all associated data. |
delete_opportunity_custom_field | destructive | Permanently delete a custom field from Opportunities. The field will be immediately removed from all Opportunity records and API responses, and this action cannot be undone. |
delete_opportunity_status | destructive | Delete an opportunity status from the system. Ensure no opportunities are currently assigned this status before deletion. |
delete_opportunity_status_change | destructive | Remove a status change activity from an opportunity |
delete_outcome | destructive | Delete an existing outcome from the system. Associated calls and meetings will retain their references to this outcome, but it will no longer be available for assignment to new calls or meetings. |
delete_phone_number | destructive | Delete a phone number from your account or group. Requires |
delete_pipeline | destructive | Permanently delete a pipeline from your workspace. The pipeline must be empty of all opportunity statuses before deletion—migrate or remove any existing opportunity statuses first. |
delete_role | destructive | Permanently remove a role from the system. All users currently assigned to this role must be reassigned to another role before deletion can proceed. |
delete_scheduling_link | destructive | Remove a scheduling link by its unique identifier. This permanently deletes the scheduling link and prevents further access to it. |
delete_scheduling_link_oauth | destructive | Delete a scheduling link by its source identifier. This operation is only available to OAuth applications and uses the source_id assigned by your OAuth app to identify and remove the scheduling link. |
delete_scheduling_link_shared | destructive | Permanently delete a shared scheduling link by its ID. This action cannot be undone and will immediately revoke access to the scheduling link for all users. |
delete_send_as | destructive | Remove a Send As Association by its unique identifier. This operation permanently deletes the specified Send As Association, preventing further use of that sending identity. |
delete_sequence | destructive | Permanently delete a sequence by its unique identifier. This action cannot be undone. |
delete_smart_view | destructive | Permanently delete a Smart View by its unique identifier. This action cannot be undone and will remove all saved search criteria and filters associated with the Smart View. |
delete_sms_activity | destructive | Permanently delete a specific SMS activity record by its unique identifier. This action cannot be undone and will remove all associated data. |
delete_sms_template | destructive | Permanently delete an SMS template by its ID. This action cannot be undone and will remove the template from your account. |
delete_task | destructive | Permanently delete a task by its ID. This action cannot be undone and will remove all associated data. |
delete_webhook | destructive | Delete a webhook subscription to stop receiving event notifications at the configured endpoint. |
delete_whatsapp_message | destructive | Delete a WhatsApp message activity by its ID. This removes the activity record from the system. |
disable_shared_scheduling_link | write | Disable a shared scheduling link by removing its association with a user scheduling link or URL, preventing further access through that shared link. |
empty_trash | read | Permanently deletes all of the user |
get_activity | read | Retrieve a single Created activity record by its unique identifier. Use this to fetch detailed information about a specific activity that was created. |
get_activity_custom_field | read | Retrieve the details of a specific Activity Custom Field by its unique identifier. Use this to access configuration, metadata, and settings for a custom field associated with activities. |
get_bulk_delete | destructive | Retrieve details of a specific bulk delete operation by its ID. Use this to check the status and configuration of a previously initiated bulk deletion. |
get_bulk_edit | write | Retrieve the details and current status of a specific bulk edit action by its unique identifier. |
get_bulk_email | read | Retrieve the details and status of a specific bulk email action by its unique identifier. |
get_call | read | Retrieve a specific Call activity record by its unique identifier. Use this to fetch detailed information about a single call activity. |
get_change_start_page_token | write | Retrieves the starting page token for listing future changes in Google Drive. Use this token to begin monitoring changes that occur after the current moment. |
get_comment | read | Retrieve a specific comment by its unique identifier. Use this to fetch the full details of an individual comment. |
get_comment_thread | read | Retrieve a specific comment thread by its unique identifier. Use this to fetch the full details of a single comment thread including all associated metadata. |
get_completed_task | read | Retrieve a single completed task activity by its unique identifier. Use this to fetch details about a specific task that has been marked as completed. |
get_connected_account | read | Retrieve detailed information about a specific connected account using its unique identifier. |
get_contact | read | Retrieve a single contact by its unique identifier. Use this operation to fetch detailed information about a specific contact. |
get_contact_custom_field | read | Retrieve the details of a specific custom field associated with a contact. Use this to access custom field configuration and values for a particular contact. |
get_current_user | read | Retrieve the profile and organization information of the currently authenticated user. Use this to determine your user ID and the organization you belong to. |
get_custom_activity | read | Retrieve a specific Custom Activity Type by its ID, including detailed metadata about associated custom fields. |
get_custom_activity_instance | read | Retrieve a specific Custom Activity instance by its unique identifier. Use this to fetch detailed information about a single custom activity. |
get_custom_field | read | Retrieve the details of a specific custom field associated with a custom object type. This includes field configuration, type, and metadata. |
get_custom_field_schema | read | Retrieve the custom field schema for a specific object type, including all regular and shared custom fields in their defined order. Supports standard objects (lead, contact, opportunity) and dynamic objects (activities and custom objects). |
get_custom_object | read | Retrieve a single Custom Object instance by its unique identifier. Returns the complete object data for the specified Custom Object. |
get_custom_object_type | read | Retrieve a specific Custom Object Type by its unique identifier, including comprehensive Custom Field metadata associated with it. |
get_dialer | read | Retrieve detailed information about a specific dialer session using its unique identifier. |
get_email_activity | read | Retrieve a single email activity record by its unique identifier. Use this to fetch detailed information about a specific email interaction or communication event. |
get_email_template | read | Retrieve a specific email template by its unique identifier. Use this to fetch the full details of an email template for viewing or further processing. |
get_email_thread | read | Retrieve a specific email thread activity by its unique identifier. Use this to fetch detailed information about a single email thread record. |
get_event | read | Retrieve a single event by its unique identifier. Returns a dictionary containing the event details. |
get_export | read | Retrieve a single export by its unique identifier to check its current processing status or obtain a download URL once completed. Status values include: created, started, in_progress, done, and error. |
get_form_submission | read | Retrieve a single form submission activity by its unique identifier. Use this to fetch details about a specific form submission event. |
get_integration_link | read | Retrieve a specific integration link by its unique identifier. Use this to fetch details about a configured integration connection. |
get_lead | read | Retrieve a single lead by its unique identifier. Use this operation to fetch detailed information about a specific lead. |
get_lead_custom_field | read | Retrieve the details of a specific custom field associated with a lead, including its configuration and current values. |
get_lead_merge | write | Retrieve a single LeadMerge activity by its ID. Use this to fetch details about a specific lead merge operation. |
get_lead_status_change | read | Retrieve details of a specific lead status change activity, including when and how the lead |
get_meeting | read | Retrieve a specific Meeting activity by its unique identifier. Use this to fetch details about a scheduled or completed meeting. |
get_note | read | Retrieve a single note activity by its unique identifier. Use this to fetch detailed information about a specific note. |
get_opportunity | read | Retrieve a single opportunity by its unique identifier. Use this to fetch detailed information about a specific opportunity. |
get_opportunity_custom_field | read | Retrieve detailed information about a specific custom field associated with an opportunity. Use this to fetch custom field values and metadata for a given opportunity. |
get_opportunity_status_change | read | Retrieve details of a specific opportunity status change activity, including what changed and when the transition occurred. |
get_organization | read | Retrieve detailed information about an organization, including its members, inactive members, and associated lead and opportunity statuses. User data is flattened by default but can be nested using query expansion parameters. |
get_outcome | read | Retrieve a single outcome by its unique identifier. Use this to fetch detailed information about a specific outcome. |
get_phone_number | read | Retrieve detailed information for a specific phone number by its unique identifier. |
get_role | read | Retrieve a single role by its unique identifier. Use this to fetch detailed information about a specific role. |
get_scheduling_link | read | Retrieve a scheduling link by its unique identifier to access its configuration and sharing details. |
get_scheduling_link_shared | read | Retrieve a specific shared scheduling link by its unique identifier to access its configuration and sharing details. |
get_send_as | write | Retrieve a specific Send As Association by its unique identifier to view its configuration and details. |
get_sequence | read | Retrieve a single sequence by its unique identifier. Use this operation to fetch detailed information about a specific sequence. |
get_sequence_subscription | read | Retrieve a specific sequence subscription by its unique identifier to view its configuration and status. |
get_sequence_subscription_bulk_action | read | Retrieve a single bulk sequence subscription by its ID. Use this to fetch details about a specific sequence subscription object. |
get_smart_view | read | Retrieve a single Smart View by its unique identifier. Use this to fetch detailed information about a saved search view. |
get_sms_activity | read | Retrieve detailed information about a specific SMS activity by its unique identifier. Use this to fetch the complete record of a single SMS message or communication event. |
get_sms_template | read | Retrieve a specific SMS template by its unique identifier. Use this to fetch template details for viewing or further processing. |
get_task | read | Retrieve detailed information about a specific task by its unique identifier. |
get_user | read | Retrieve a single user by their unique identifier. Returns the user |
get_user_info | read | Retrieves information about the authenticated user, their Drive, and system capabilities. Use the `fields` parameter to specify which user properties and Drive details to return. |
get_webhook | read | Retrieve the details of a specific webhook subscription by its unique identifier. Returns configuration, status, and event settings for the webhook. |
get_whatsapp_message | read | Retrieve a specific WhatsApp message activity by its unique identifier. Use this to fetch details about a single WhatsApp message interaction. |
hide_shared_drive | read | Hides a shared drive from the default view, removing it from the user |
list_activity_custom_fields | read | Retrieve all custom fields configured for activities in your organization. Use the limit parameter to control the number of results returned. |
list_activity_metrics | read | Retrieve the predefined metrics available for use in activity reports. Use this to discover which metrics can be included when building or querying activity report data. |
list_bulk_deletes | destructive | Retrieve a list of all bulk delete actions that have been performed or are in progress. Use this to track and monitor deletion operations across your resources. |
list_bulk_edits | write | Retrieve a list of all bulk edit actions that have been created. Use this to view the history and status of bulk editing operations. |
list_bulk_emails | read | Retrieve a list of all bulk email actions that have been created. This operation allows you to view the history and status of bulk email campaigns. |
list_calls | read | Retrieve a list of all Call activities, with optional filtering by result count. Use this to view call records and activity history. |
list_completed_activities | read | Retrieve a list of completed task activities, with optional filtering by result count. Use this to view historical task completion records. |
list_connected_accounts | read | Retrieve all connected accounts available in your organization. Optionally filter results to a specific user by providing their user ID. |
list_contact_custom_fields | read | Retrieve all custom fields configured for contacts in your organization. Use the limit parameter to control the number of results returned. |
list_contacts | read | Retrieve a paginated list of all contacts in the system. Use the limit parameter to control the number of results returned per request. |
list_created_activities | read | Retrieve a list of all activities with Created status, optionally limiting the number of results returned. |
list_custom_activities | read | Retrieve all custom activity types configured for your organization, including their associated custom field metadata. |
list_custom_activities_instances | read | Retrieve and filter custom activity instances. Supports filtering by custom activity type, with results including custom fields formatted as custom.{custom_field_id}. |
list_custom_object_custom_fields | read | Retrieve all custom fields associated with custom objects in your organization. This operation returns the complete list of custom fields that have been defined for your custom object types. |
list_custom_object_types | read | Retrieve all Custom Object Types configured in your organization, including their field definitions and back-references from other objects. Each Custom Object Type includes metadata about its own fields and any objects (Leads, Contacts, Opportunities, Custom Activities, or other Custom Objects) that |
list_custom_report_fields | read | Retrieve all available custom report fields that can be used when building custom reports. Only numeric data type fields are eligible for use as the y-axis parameter in report visualizations. |
list_email_activities | read | Retrieve a list of email activities, with each result representing a single email message. Optionally filter results by specifying a maximum number of records to return. |
list_email_threads | read | Retrieve a list of email thread activities, where each thread represents a single email conversation typically grouped by subject line. |
list_exports | read | Retrieve a list of all exports with optional pagination control. Use the limit parameter to restrict the number of results returned. |
list_groups | read | Retrieve all groups in your organization. Use the _fields parameter to specify which group attributes to return; to retrieve group members, include |
list_integration_links | read | Retrieve all integration links that have been configured for your organization. This provides a complete view of all active integrations and their connection details. |
list_lead_custom_fields | read | Retrieve all custom fields configured for leads in your organization. Use the optional limit parameter to control the number of results returned. |
list_lead_merges | read | Retrieve a list of LeadMerge activities, which are created when one lead is merged into another. The source lead is deleted after being merged into the destination lead. |
list_lead_status_changes | read | Retrieve a list of all lead status change activities, with optional filtering by result limit. Use this to track when and how lead statuses have been modified. |
list_lead_statuses | read | Retrieve all available lead statuses configured for your organization. Use this to understand the valid status values for lead management workflows. |
list_leads | read | Retrieve a list of leads with optional pagination control. Use the limit parameter to specify the maximum number of results to return. |
list_notes | read | Retrieve a list of all Note activities, with optional filtering by result count. Use this to view note records across your activity stream. |
list_opportunity_custom_fields | read | Retrieve all custom fields configured for opportunities in your organization. Use this to understand the custom data structure available for opportunity records. |
list_opportunity_statuses | read | Retrieve all opportunity statuses configured for your organization. Use this to understand the available status values for opportunities in your system. |
list_outcomes | read | Retrieve a list of outcomes, with optional filtering capabilities to narrow results based on specific criteria. |
list_pinned_views | read | Retrieve the ordered list of pinned views for a specific membership. The views are returned in their pinned order. |
list_pipelines | read | Retrieve all pipelines configured in your organization. Use this to view available pipeline definitions and their current status. |
list_roles | read | Retrieve all roles defined in your organization. Use this to view available role configurations for access control and permission management. |
list_scheduling_links | read | Retrieve all scheduling links that have been created by the authenticated user. This allows you to view and manage all available scheduling links for booking meetings or appointments. |
list_scheduling_links_shared | read | Retrieve all shared scheduling links available in your account. Use this to view and manage scheduling links you |
list_sequence_subscriptions | read | Retrieve a list of sequence subscriptions filtered by sequence, contact, or lead. At least one filter criterion must be provided. |
list_sequence_subscriptions_bulk_action | read | Retrieve all bulk sequence subscription actions. Use this to view the complete list of active sequence subscriptions in your bulk action system. |
list_sequences | read | Retrieve a paginated list of all sequences. Use the limit parameter to control the number of results returned per request. |
list_shared_custom_fields | read | Retrieve all shared custom fields available across your organization. These fields can be used across multiple resources and are accessible to authorized users. |
list_smart_views | read | Retrieve all Smart Views with optional filtering by record type. Use this to display available saved searches for leads, contacts, or both. |
list_sms_activities | read | Retrieve a list of SMS activities, including MMS messages with attachments. Attachments contain metadata (URL, filename, size, content type) and optional thumbnails; accessing URLs requires an authenticated session. |
list_sms_templates | read | Retrieve a paginated list of SMS templates available in your account. Use the limit parameter to control the number of results returned. |
list_unsubscribed_emails | read | Retrieve a complete list of email addresses that have been unsubscribed from communications. Use this to manage your unsubscribe list and ensure compliance with user preferences. |
list_user_availability | read | Retrieve the current availability status of all users in an organization, including details about any active calls they are participating in. |
list_users | read | Retrieve all users who are members of your organizations. This returns a filtered list based on your organization memberships. |
list_webhooks | read | Retrieve all webhook subscriptions configured for your organization. This lists the active webhooks that are receiving event notifications. |
list_whatsapp_messages | read | Retrieve WhatsApp message activities from Close, optionally filtered by external WhatsApp message ID. Use this to sync message updates or deletions that occurred in WhatsApp. |
resubscribe_email | read | Resubscribe an email address to receive messages from Close. Use this operation to restore messaging delivery for an email that was previously unsubscribed. |
subscribe_contact_to_sequence | read | Subscribe a contact to an automation sequence. This enrolls the contact in the specified sequence, triggering any configured automation workflows. |
unhide_shared_drive | read | Restores a shared drive to the default view, making it visible in the shared drives list. Use this operation to unhide a shared drive that was previously hidden from view. |
unsubscribe_email | destructive | Remove an email address from Close |
update_sms_activity | write | Update an SMS activity to modify its content, schedule delivery, or send it immediately. Only draft SMS activities can be modified; use status to control whether the SMS is sent immediately (outbox) or scheduled for later delivery (scheduled). |
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
.env
.env
.env
.env
.env
server_host_key: str | None = Field(default=None, description="Remote server SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). When provided, the server's host key must match exa
server_host_key: str | None = Field(default=None, description="SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). If provided, the server host key must match exactly.")
server_host_key: str | None = Field(None, description="Remote server SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). When provided, the server's host key must match exactly."),
server_host_key: str | None = Field(None, description="SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). If provided, the server host key must match exactly."),
callback_url: str | None = Field(default=None, description="Webhook URL for conversion status notifications. The service will POST status updates when the project and chapters complete processing, inc
callback_url: str | None = Field(default=None, description="A webhook URL that receives conversion status notifications for the project and its chapters. Notifications include success/error status wit
callback_url: str | None = Field(None, description="Webhook URL for conversion status notifications. The service will POST status updates when the project and chapters complete processing, including s
body=_models.CreatePodcastRequestBody(model_id=model_id, mode=mode, source=source, quality_preset=quality_preset, duration_scale=duration_scale, language=language, intro=intro, outro=outro, instructio
callback_url: str | None = Field(None, description="A webhook URL that receives conversion status notifications for the project and its chapters. Notifications include success/error status with projec
delete_activity_custom_field, delete_activity_note, delete_call, delete_comment, delete_completed_task, delete_contact, delete_contact_custom_field, delete_custom_activity, delete_custom_activity_inst
.env
.env
.env
.env
.env
base64.b64decode(standard_b64, validate=True)
return base64.b64decode(standard_b64, validate=True)
base64.b64decode(standard_b64, validate=True)
return base64.b64decode(standard_b64, validate=True)
base64.b64decode(standard_b64, validate=True)
Gates applied: no_behavioural_pass.
6d1c2e56d666full audit observations/trust-audit/mcp-server/mcparmory__registry-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 6d1c2e56d666 | BLOCK | F | 44 | first audit |
Questions
What is the Registry MCP server?
Production-ready MCP servers for 70+ APIs — GitHub, Google, Notion, Jira & more. Generated from OpenAPI specs, tested against live APIs. Works with Claude Desktop, Cursor, Codex & Claude Code.
What tools does Registry expose?
160 in total: 100 read-only, 13 that write, and 47 that can delete or overwrite (delete_activity_custom_field, delete_activity_note, delete_call, delete_comment, delete_completed_task). Every one is listed on this page with its risk.
Is Registry safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 47 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Registry need?
It reads JWT_KEY_ID, JWT_SHARED_SECRET, JWT_TOKEN_URL, OAUTH2_CALLBACK_PORT, OAUTH2_CLIENT_ID, OAUTH2_CLIENT_SECRET, OAUTH2_SCOPES, OAUTH2_TLS_CERT_FILE, OAUTH2_TLS_KEY_FILE, OAUTH2_USER_SCOPES, ORG_OAUTH2_CALLBACK_PORT and ORG_OAUTH2_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Registry run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcparmory-slack.
How current is this page?
The grade is for one exact copy of the source (6d1c2e56d666), read on 2026-10-08. The repository is watched and re-audited when it changes.