Atlas / MCP servers / mcparmory / Registry

RegistryBLOCK

mcp/mcparmory/registry-6

Production-ready MCP servers for 70+ APIs — GitHub, Google, Notion, Jira & more. Generated from OpenAPI specs, tested against live APIs. Works with Claude Desktop, Cursor, Codex & Claude Code.

Verdict
BLOCK
Grade
F
Trust score
44 /100
Exposed tools
160 100r · 13w · 47d
Transport
sse · stdio · streamable-http
License
NOASSERTION
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Armory Registry

Production-ready MCP servers for popular APIs, generated by MCP Blacksmith.

Servers · Install & Usage · Features · How it works · License

MCP servers that connect AI agents to real-world APIs. Each server is a standalone Python package — generated from the upstream OpenAPI spec using MCP Blacksmith and tested against the live API before release. Hosted on MCP Armory or run independently.

Servers

🧠 AI & Machine Learning   ElevenLabs · Linkup · Parallel · Perplexity AI · Ragie · Replicate

📊 Analytics   Ahrefs · Datadog · Google Analytics · Google Search Console · Linkly · Mixpanel · [PostHog](s

Read from source at commit 6d1c2e56d666OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcparmory-agentql -- uvx mcparmory-agentql==1.0.8
claude-code (oci)
claude mcp add agentql:1.0.8 -- docker run -i --rm ghcr.io/mcparmory/agentql:1.0.8:None
03

Exposed tools (160)

100 read · 13 write · 47 destructive. Blast radius: 47 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_email_templatewriteCreate a new email template that can be used for sending standardized emails. Define the template structure, content, and variables for reuse across email communications.
create_lead_statuswriteCreate a new custom status that can be assigned to leads in your pipeline. This allows you to define custom workflow stages beyond the default statuses.
create_pipelinewriteCreate a new pipeline with the specified name. The pipeline serves as a container for organizing and executing workflow operations.
create_scheduling_link_sharedwriteCreate a shared scheduling link that allows others to view your available time slots and book meetings directly on your calendar without needing direct access to your calendar.
create_sequencewriteCreate a new sequence with the specified configuration. This operation initializes a sequence resource that can be used for ordered processing or workflow management.
create_sms_templatewriteCreate a new SMS template that can be used for sending standardized text messages. Define the template content and configuration for reuse across SMS campaigns.
delete_activity_custom_fielddestructivePermanently delete an Activity Custom Field. The field will be immediately removed from all Custom Activity API responses and cannot be recovered.
delete_activity_notedestructivePermanently delete a Note activity by its ID. This action cannot be undone and will remove all associated data.
delete_calldestructivePermanently delete a Call activity record by its ID. This action cannot be undone and will remove all associated data.
delete_commentdestructiveRemove a comment from a thread. The comment content is deleted but the comment object remains until all comments in the thread are removed, at which point the entire thread is deleted. Deletion permissions are based on the user
delete_completed_taskdestructivePermanently remove a completed task activity from the system. This action cannot be undone and will delete the TaskCompleted activity record and all associated data.
delete_contactdestructivePermanently remove a contact from the system by its ID. This action cannot be undone and will delete all associated data.
delete_contact_custom_fielddestructivePermanently delete a custom field from your Contact system. The field will be immediately removed from all Contact API responses and cannot be recovered.
delete_custom_activitydestructivePermanently delete a custom activity type by its ID. This action cannot be undone and will remove the activity type from your system.
delete_custom_activity_instancedestructivePermanently delete a Custom Activity instance by its ID. This action cannot be undone.
delete_custom_fielddestructivePermanently delete a custom field from a custom object type. The field will be immediately removed from all Custom Object API responses.
delete_custom_field_shareddestructivePermanently delete a shared custom field. The field will be immediately removed from all objects it was assigned to.
delete_custom_objectdestructivePermanently delete a Custom Object instance by its unique identifier. This action cannot be undone.
delete_custom_object_typedestructivePermanently delete a Custom Object Type and remove it from your system. This action cannot be undone.
delete_email_activitydestructivePermanently delete an email activity record by its unique identifier. This action cannot be undone and will remove all associated data.
delete_email_templatedestructivePermanently delete an email template by its ID. This action cannot be undone and will remove the template from all systems.
delete_email_threaddestructiveDelete an email thread activity and all associated email activities within that thread. This is a permanent operation that removes the entire thread conversation.
delete_filedestructivePermanently deletes a file owned by the user without moving it to trash. If the file is a folder, all descendants owned by the user are also deleted. For shared drives, the user must be an organizer on the parent folder.
delete_form_submissiondestructiveDelete a FormSubmission activity by its ID. This operation permanently removes the form submission record from the system.
delete_groupdestructiveDelete a group from the system. This operation is only permitted if the group is not referenced by any saved reports or smart views.
delete_integration_linkdestructivePermanently delete an integration link from your organization. This action is restricted to organization administrators only and cannot be undone.
delete_leaddestructivePermanently remove a lead from the system by its ID. This action cannot be undone and will delete all associated data.
delete_lead_custom_fielddestructivePermanently delete a custom field from your Lead records. The field will be immediately removed from all Lead API responses and cannot be recovered.
delete_lead_statusdestructiveDelete a lead status from the system. Ensure no leads are currently assigned to this status before deletion, as the operation will fail if leads depend on it.
delete_lead_status_changedestructiveRemove a status change event from a lead
delete_meetingdestructivePermanently delete a specific Meeting activity by its ID. This action cannot be undone and will remove all associated data.
delete_opportunitydestructivePermanently remove an opportunity from the system. This action cannot be undone and will delete all associated data.
delete_opportunity_custom_fielddestructivePermanently delete a custom field from Opportunities. The field will be immediately removed from all Opportunity records and API responses, and this action cannot be undone.
delete_opportunity_statusdestructiveDelete an opportunity status from the system. Ensure no opportunities are currently assigned this status before deletion.
delete_opportunity_status_changedestructiveRemove a status change activity from an opportunity
delete_outcomedestructiveDelete an existing outcome from the system. Associated calls and meetings will retain their references to this outcome, but it will no longer be available for assignment to new calls or meetings.
delete_phone_numberdestructiveDelete a phone number from your account or group. Requires
delete_pipelinedestructivePermanently delete a pipeline from your workspace. The pipeline must be empty of all opportunity statuses before deletion—migrate or remove any existing opportunity statuses first.
delete_roledestructivePermanently remove a role from the system. All users currently assigned to this role must be reassigned to another role before deletion can proceed.
delete_scheduling_linkdestructiveRemove a scheduling link by its unique identifier. This permanently deletes the scheduling link and prevents further access to it.
delete_scheduling_link_oauthdestructiveDelete a scheduling link by its source identifier. This operation is only available to OAuth applications and uses the source_id assigned by your OAuth app to identify and remove the scheduling link.
delete_scheduling_link_shareddestructivePermanently delete a shared scheduling link by its ID. This action cannot be undone and will immediately revoke access to the scheduling link for all users.
delete_send_asdestructiveRemove a Send As Association by its unique identifier. This operation permanently deletes the specified Send As Association, preventing further use of that sending identity.
delete_sequencedestructivePermanently delete a sequence by its unique identifier. This action cannot be undone.
delete_smart_viewdestructivePermanently delete a Smart View by its unique identifier. This action cannot be undone and will remove all saved search criteria and filters associated with the Smart View.
delete_sms_activitydestructivePermanently delete a specific SMS activity record by its unique identifier. This action cannot be undone and will remove all associated data.
delete_sms_templatedestructivePermanently delete an SMS template by its ID. This action cannot be undone and will remove the template from your account.
delete_taskdestructivePermanently delete a task by its ID. This action cannot be undone and will remove all associated data.
delete_webhookdestructiveDelete a webhook subscription to stop receiving event notifications at the configured endpoint.
delete_whatsapp_messagedestructiveDelete a WhatsApp message activity by its ID. This removes the activity record from the system.
disable_shared_scheduling_linkwriteDisable a shared scheduling link by removing its association with a user scheduling link or URL, preventing further access through that shared link.
empty_trashreadPermanently deletes all of the user
get_activityreadRetrieve a single Created activity record by its unique identifier. Use this to fetch detailed information about a specific activity that was created.
get_activity_custom_fieldreadRetrieve the details of a specific Activity Custom Field by its unique identifier. Use this to access configuration, metadata, and settings for a custom field associated with activities.
get_bulk_deletedestructiveRetrieve details of a specific bulk delete operation by its ID. Use this to check the status and configuration of a previously initiated bulk deletion.
get_bulk_editwriteRetrieve the details and current status of a specific bulk edit action by its unique identifier.
get_bulk_emailreadRetrieve the details and status of a specific bulk email action by its unique identifier.
get_callreadRetrieve a specific Call activity record by its unique identifier. Use this to fetch detailed information about a single call activity.
get_change_start_page_tokenwriteRetrieves the starting page token for listing future changes in Google Drive. Use this token to begin monitoring changes that occur after the current moment.
get_commentreadRetrieve a specific comment by its unique identifier. Use this to fetch the full details of an individual comment.
get_comment_threadreadRetrieve a specific comment thread by its unique identifier. Use this to fetch the full details of a single comment thread including all associated metadata.
get_completed_taskreadRetrieve a single completed task activity by its unique identifier. Use this to fetch details about a specific task that has been marked as completed.
get_connected_accountreadRetrieve detailed information about a specific connected account using its unique identifier.
get_contactreadRetrieve a single contact by its unique identifier. Use this operation to fetch detailed information about a specific contact.
get_contact_custom_fieldreadRetrieve the details of a specific custom field associated with a contact. Use this to access custom field configuration and values for a particular contact.
get_current_userreadRetrieve the profile and organization information of the currently authenticated user. Use this to determine your user ID and the organization you belong to.
get_custom_activityreadRetrieve a specific Custom Activity Type by its ID, including detailed metadata about associated custom fields.
get_custom_activity_instancereadRetrieve a specific Custom Activity instance by its unique identifier. Use this to fetch detailed information about a single custom activity.
get_custom_fieldreadRetrieve the details of a specific custom field associated with a custom object type. This includes field configuration, type, and metadata.
get_custom_field_schemareadRetrieve the custom field schema for a specific object type, including all regular and shared custom fields in their defined order. Supports standard objects (lead, contact, opportunity) and dynamic objects (activities and custom objects).
get_custom_objectreadRetrieve a single Custom Object instance by its unique identifier. Returns the complete object data for the specified Custom Object.
get_custom_object_typereadRetrieve a specific Custom Object Type by its unique identifier, including comprehensive Custom Field metadata associated with it.
get_dialerreadRetrieve detailed information about a specific dialer session using its unique identifier.
get_email_activityreadRetrieve a single email activity record by its unique identifier. Use this to fetch detailed information about a specific email interaction or communication event.
get_email_templatereadRetrieve a specific email template by its unique identifier. Use this to fetch the full details of an email template for viewing or further processing.
get_email_threadreadRetrieve a specific email thread activity by its unique identifier. Use this to fetch detailed information about a single email thread record.
get_eventreadRetrieve a single event by its unique identifier. Returns a dictionary containing the event details.
get_exportreadRetrieve a single export by its unique identifier to check its current processing status or obtain a download URL once completed. Status values include: created, started, in_progress, done, and error.
get_form_submissionreadRetrieve a single form submission activity by its unique identifier. Use this to fetch details about a specific form submission event.
get_integration_linkreadRetrieve a specific integration link by its unique identifier. Use this to fetch details about a configured integration connection.
get_leadreadRetrieve a single lead by its unique identifier. Use this operation to fetch detailed information about a specific lead.
get_lead_custom_fieldreadRetrieve the details of a specific custom field associated with a lead, including its configuration and current values.
get_lead_mergewriteRetrieve a single LeadMerge activity by its ID. Use this to fetch details about a specific lead merge operation.
get_lead_status_changereadRetrieve details of a specific lead status change activity, including when and how the lead
get_meetingreadRetrieve a specific Meeting activity by its unique identifier. Use this to fetch details about a scheduled or completed meeting.
get_notereadRetrieve a single note activity by its unique identifier. Use this to fetch detailed information about a specific note.
get_opportunityreadRetrieve a single opportunity by its unique identifier. Use this to fetch detailed information about a specific opportunity.
get_opportunity_custom_fieldreadRetrieve detailed information about a specific custom field associated with an opportunity. Use this to fetch custom field values and metadata for a given opportunity.
get_opportunity_status_changereadRetrieve details of a specific opportunity status change activity, including what changed and when the transition occurred.
get_organizationreadRetrieve detailed information about an organization, including its members, inactive members, and associated lead and opportunity statuses. User data is flattened by default but can be nested using query expansion parameters.
get_outcomereadRetrieve a single outcome by its unique identifier. Use this to fetch detailed information about a specific outcome.
get_phone_numberreadRetrieve detailed information for a specific phone number by its unique identifier.
get_rolereadRetrieve a single role by its unique identifier. Use this to fetch detailed information about a specific role.
get_scheduling_linkreadRetrieve a scheduling link by its unique identifier to access its configuration and sharing details.
get_scheduling_link_sharedreadRetrieve a specific shared scheduling link by its unique identifier to access its configuration and sharing details.
get_send_aswriteRetrieve a specific Send As Association by its unique identifier to view its configuration and details.
get_sequencereadRetrieve a single sequence by its unique identifier. Use this operation to fetch detailed information about a specific sequence.
get_sequence_subscriptionreadRetrieve a specific sequence subscription by its unique identifier to view its configuration and status.
get_sequence_subscription_bulk_actionreadRetrieve a single bulk sequence subscription by its ID. Use this to fetch details about a specific sequence subscription object.
get_smart_viewreadRetrieve a single Smart View by its unique identifier. Use this to fetch detailed information about a saved search view.
get_sms_activityreadRetrieve detailed information about a specific SMS activity by its unique identifier. Use this to fetch the complete record of a single SMS message or communication event.
get_sms_templatereadRetrieve a specific SMS template by its unique identifier. Use this to fetch template details for viewing or further processing.
get_taskreadRetrieve detailed information about a specific task by its unique identifier.
get_userreadRetrieve a single user by their unique identifier. Returns the user
get_user_inforeadRetrieves information about the authenticated user, their Drive, and system capabilities. Use the `fields` parameter to specify which user properties and Drive details to return.
get_webhookreadRetrieve the details of a specific webhook subscription by its unique identifier. Returns configuration, status, and event settings for the webhook.
get_whatsapp_messagereadRetrieve a specific WhatsApp message activity by its unique identifier. Use this to fetch details about a single WhatsApp message interaction.
hide_shared_drivereadHides a shared drive from the default view, removing it from the user
list_activity_custom_fieldsreadRetrieve all custom fields configured for activities in your organization. Use the limit parameter to control the number of results returned.
list_activity_metricsreadRetrieve the predefined metrics available for use in activity reports. Use this to discover which metrics can be included when building or querying activity report data.
list_bulk_deletesdestructiveRetrieve a list of all bulk delete actions that have been performed or are in progress. Use this to track and monitor deletion operations across your resources.
list_bulk_editswriteRetrieve a list of all bulk edit actions that have been created. Use this to view the history and status of bulk editing operations.
list_bulk_emailsreadRetrieve a list of all bulk email actions that have been created. This operation allows you to view the history and status of bulk email campaigns.
list_callsreadRetrieve a list of all Call activities, with optional filtering by result count. Use this to view call records and activity history.
list_completed_activitiesreadRetrieve a list of completed task activities, with optional filtering by result count. Use this to view historical task completion records.
list_connected_accountsreadRetrieve all connected accounts available in your organization. Optionally filter results to a specific user by providing their user ID.
list_contact_custom_fieldsreadRetrieve all custom fields configured for contacts in your organization. Use the limit parameter to control the number of results returned.
list_contactsreadRetrieve a paginated list of all contacts in the system. Use the limit parameter to control the number of results returned per request.
list_created_activitiesreadRetrieve a list of all activities with Created status, optionally limiting the number of results returned.
list_custom_activitiesreadRetrieve all custom activity types configured for your organization, including their associated custom field metadata.
list_custom_activities_instancesreadRetrieve and filter custom activity instances. Supports filtering by custom activity type, with results including custom fields formatted as custom.{custom_field_id}.
list_custom_object_custom_fieldsreadRetrieve all custom fields associated with custom objects in your organization. This operation returns the complete list of custom fields that have been defined for your custom object types.
list_custom_object_typesreadRetrieve all Custom Object Types configured in your organization, including their field definitions and back-references from other objects. Each Custom Object Type includes metadata about its own fields and any objects (Leads, Contacts, Opportunities, Custom Activities, or other Custom Objects) that
list_custom_report_fieldsreadRetrieve all available custom report fields that can be used when building custom reports. Only numeric data type fields are eligible for use as the y-axis parameter in report visualizations.
list_email_activitiesreadRetrieve a list of email activities, with each result representing a single email message. Optionally filter results by specifying a maximum number of records to return.
list_email_threadsreadRetrieve a list of email thread activities, where each thread represents a single email conversation typically grouped by subject line.
list_exportsreadRetrieve a list of all exports with optional pagination control. Use the limit parameter to restrict the number of results returned.
list_groupsreadRetrieve all groups in your organization. Use the _fields parameter to specify which group attributes to return; to retrieve group members, include
list_integration_linksreadRetrieve all integration links that have been configured for your organization. This provides a complete view of all active integrations and their connection details.
list_lead_custom_fieldsreadRetrieve all custom fields configured for leads in your organization. Use the optional limit parameter to control the number of results returned.
list_lead_mergesreadRetrieve a list of LeadMerge activities, which are created when one lead is merged into another. The source lead is deleted after being merged into the destination lead.
list_lead_status_changesreadRetrieve a list of all lead status change activities, with optional filtering by result limit. Use this to track when and how lead statuses have been modified.
list_lead_statusesreadRetrieve all available lead statuses configured for your organization. Use this to understand the valid status values for lead management workflows.
list_leadsreadRetrieve a list of leads with optional pagination control. Use the limit parameter to specify the maximum number of results to return.
list_notesreadRetrieve a list of all Note activities, with optional filtering by result count. Use this to view note records across your activity stream.
list_opportunity_custom_fieldsreadRetrieve all custom fields configured for opportunities in your organization. Use this to understand the custom data structure available for opportunity records.
list_opportunity_statusesreadRetrieve all opportunity statuses configured for your organization. Use this to understand the available status values for opportunities in your system.
list_outcomesreadRetrieve a list of outcomes, with optional filtering capabilities to narrow results based on specific criteria.
list_pinned_viewsreadRetrieve the ordered list of pinned views for a specific membership. The views are returned in their pinned order.
list_pipelinesreadRetrieve all pipelines configured in your organization. Use this to view available pipeline definitions and their current status.
list_rolesreadRetrieve all roles defined in your organization. Use this to view available role configurations for access control and permission management.
list_scheduling_linksreadRetrieve all scheduling links that have been created by the authenticated user. This allows you to view and manage all available scheduling links for booking meetings or appointments.
list_scheduling_links_sharedreadRetrieve all shared scheduling links available in your account. Use this to view and manage scheduling links you
list_sequence_subscriptionsreadRetrieve a list of sequence subscriptions filtered by sequence, contact, or lead. At least one filter criterion must be provided.
list_sequence_subscriptions_bulk_actionreadRetrieve all bulk sequence subscription actions. Use this to view the complete list of active sequence subscriptions in your bulk action system.
list_sequencesreadRetrieve a paginated list of all sequences. Use the limit parameter to control the number of results returned per request.
list_shared_custom_fieldsreadRetrieve all shared custom fields available across your organization. These fields can be used across multiple resources and are accessible to authorized users.
list_smart_viewsreadRetrieve all Smart Views with optional filtering by record type. Use this to display available saved searches for leads, contacts, or both.
list_sms_activitiesreadRetrieve a list of SMS activities, including MMS messages with attachments. Attachments contain metadata (URL, filename, size, content type) and optional thumbnails; accessing URLs requires an authenticated session.
list_sms_templatesreadRetrieve a paginated list of SMS templates available in your account. Use the limit parameter to control the number of results returned.
list_unsubscribed_emailsreadRetrieve a complete list of email addresses that have been unsubscribed from communications. Use this to manage your unsubscribe list and ensure compliance with user preferences.
list_user_availabilityreadRetrieve the current availability status of all users in an organization, including details about any active calls they are participating in.
list_usersreadRetrieve all users who are members of your organizations. This returns a filtered list based on your organization memberships.
list_webhooksreadRetrieve all webhook subscriptions configured for your organization. This lists the active webhooks that are receiving event notifications.
list_whatsapp_messagesreadRetrieve WhatsApp message activities from Close, optionally filtered by external WhatsApp message ID. Use this to sync message updates or deletions that occurred in WhatsApp.
resubscribe_emailreadResubscribe an email address to receive messages from Close. Use this operation to restore messaging delivery for an email that was previously unsubscribed.
subscribe_contact_to_sequencereadSubscribe a contact to an automation sequence. This enrolls the contact in the specified sequence, triggering any configured automation workflows.
unhide_shared_drivereadRestores a shared drive to the default view, making it visible in the shared drives list. Use this operation to unhide a shared drive that was previously hidden from view.
unsubscribe_emaildestructiveRemove an email address from Close
update_sms_activitywriteUpdate an SMS activity to modify its content, schedule delivery, or send it immediately. Only draft SMS activities can be modified; use status to control whether the SMS is sent immediately (outbox) or scheduled for later delivery (scheduled).
04

Trust audit

BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
servers/agentql/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
servers/ahrefs/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
servers/airtable/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
servers/alchemy-nft/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
servers/algolia-search/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
servers/files-com/_models.py:1641
server_host_key: str | None = Field(default=None, description="Remote server SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). When provided, the server's host key must match exa
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
servers/files-com/_models.py:1685
server_host_key: str | None = Field(default=None, description="SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). If provided, the server host key must match exactly.")
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
servers/files-com/server.py:8430
server_host_key: str | None = Field(None, description="Remote server SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). When provided, the server's host key must match exactly."),
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
servers/files-com/server.py:8553
server_host_key: str | None = Field(None, description="SSH host key in OpenSSH format (as would appear in ~/.ssh/known_hosts). If provided, the server host key must match exactly."),
Why it matters. touches a credential store
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
servers/elevenlabs/_models.py:807
callback_url: str | None = Field(default=None, description="Webhook URL for conversion status notifications. The service will POST status updates when the project and chapters complete processing, inc
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
servers/elevenlabs/_models.py:841
callback_url: str | None = Field(default=None, description="A webhook URL that receives conversion status notifications for the project and its chapters. Notifications include success/error status wit
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
servers/elevenlabs/server.py:3208
callback_url: str | None = Field(None, description="Webhook URL for conversion status notifications. The service will POST status updates when the project and chapters complete processing, including s
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
servers/elevenlabs/server.py:3216
body=_models.CreatePodcastRequestBody(model_id=model_id, mode=mode, source=source, quality_preset=quality_preset, duration_scale=duration_scale, language=language, intro=intro, outro=outro, instructio
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
servers/elevenlabs/server.py:3353
callback_url: str | None = Field(None, description="A webhook URL that receives conversion status notifications for the project and its chapters. Notifications include success/error status with projec
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_activity_custom_field, delete_activity_note, delete_call, delete_comment, delete_completed_task, delete_contact, delete_contact_custom_field, delete_custom_activity, delete_custom_activity_inst
Why it matters. 47 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
servers/agentql/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
servers/ahrefs/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
servers/airtable/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
servers/alchemy-nft/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
servers/algolia-search/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
servers/agentql/_validators.py:88
base64.b64decode(standard_b64, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
servers/agentql/server.py:554
return base64.b64decode(standard_b64, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
servers/ahrefs/_validators.py:88
base64.b64decode(standard_b64, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
servers/ahrefs/server.py:558
return base64.b64decode(standard_b64, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
servers/airtable/_validators.py:88
base64.b64decode(standard_b64, validate=True)

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6d1c2e56d666full audit observations/trust-audit/mcp-server/mcparmory__registry-6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086d1c2e56d666BLOCKF44first audit
06

Questions

What is the Registry MCP server?

Production-ready MCP servers for 70+ APIs — GitHub, Google, Notion, Jira & more. Generated from OpenAPI specs, tested against live APIs. Works with Claude Desktop, Cursor, Codex & Claude Code.

What tools does Registry expose?

160 in total: 100 read-only, 13 that write, and 47 that can delete or overwrite (delete_activity_custom_field, delete_activity_note, delete_call, delete_comment, delete_completed_task). Every one is listed on this page with its risk.

Is Registry safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (44/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 47 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Registry need?

It reads JWT_KEY_ID, JWT_SHARED_SECRET, JWT_TOKEN_URL, OAUTH2_CALLBACK_PORT, OAUTH2_CLIENT_ID, OAUTH2_CLIENT_SECRET, OAUTH2_SCOPES, OAUTH2_TLS_CERT_FILE, OAUTH2_TLS_KEY_FILE, OAUTH2_USER_SCOPES, ORG_OAUTH2_CALLBACK_PORT and ORG_OAUTH2_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Registry run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcparmory-slack.

How current is this page?

The grade is for one exact copy of the source (6d1c2e56d666), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement