GitShow/modelcontextprotocol/servers
modelcontextprotocol

servers

Model Context Protocol Servers

by modelcontextprotocol
Star on GitHubForkWebsitenpm

TypeScript

90.7k stars11.7k forks1.1k contributorsActive · just nowSince 20242026.8.31

Meet the team

See all 1064 on GitHub →
olaservo
olaservo541 contributions
tadasant
tadasant239 contributions
cliffhall
cliffhall229 contributions
jspahrsummers
jspahrsummers217 contributions
dsp-ant
dsp-ant160 contributions
jerome3o-anthropic
jerome3o-anthropic121 contributions
maheshmurag
maheshmurag66 contributions
evalstate
evalstate63 contributions

Languages

View on GitHub →
TypeScript82.2%
Python16.8%
Dockerfile1%

Commit activity

Last 12 weeks · 50 commits

Full graph →

Community health

5 of 6 standards met

Community profile →
87
✓README✓License✓Contributing✓Code of Conduct○Issue Template✓PR Template

Recent PRs & issues

Active · Last activity just now
See all on GitHub →
cliffhall
Agentic software factory Part 8: issue-triage skill and board auditOpenPR

Closes #4868 [!IMPORTANT] Stacked on #4904 (Part 9, contribution model), which is itself stacked on #4899 (Part 6, / ). This PR's base is , so the diff shows only this change. Retarget it as those merge: to if #4904 is folded in first, and to once both have merged. Description Part 8 of the agentic software factory (#4858, Wave 3): the skill and the board audit, adapted from the MCP Inspector's for one board (#43) and this repo's community inflow, and carrying out the outside-PR plan that #4904 wrote in ("The plan"). New skill: Step 0, the class check (new; the Inspector has no public inflow). Each class has an action and a canned response: Two-pass sweep: pass 1 labels (, one type, the scope label read off the issue form's dropdown), boards as , scores Priority and posts the score, leaves the milestone unset (already-milestoned → ). Pass 2 (milestone + ) is human-only. Priority rubric: the Inspector's two axes, bonuses and bands, with the severity axis reworded for servers ("reports something false about the protocol", "escapes an allowed root", SSRF, injection), and the trust boundary for the public org-level Fields → Priority. Outside PRs, per the plan: snapshot with a truncation check, maintainer detection (/ role; write access is not enough), a path-based pre-class as a hint, a duplicate-group finder, the classes (listing, new server, archived server, no-op/spam, duplicate, security fix, fix to keep, out of scope), a maintainer reviews the manifest before anything is closed, harvest into issues with no milestone, a paced close loop that stops on the first failure and skips security fixes, and the verify step. Canned responses in one place: the plan's general and Registry PR comments, plus Registry/Archived/Elsewhere/Duplicate/Security responses for issues. now points at them instead of holding a second copy. The board audit for #43, read-only, every check meant to print . It adds , and (single version label here) to the Inspector's set and drops the two-board checks. The issue listing uses , above the repo's 1,250 total issues, and treats a listing that fills the limit as truncated; the board listing is checked against . The draft-card carve-out: #4905 (Part 10) left it to this PR. The exemption is and the title prefix (a -titled PR or any other draft is still reported), with the replacement check so an advisory card is never invisible to the audit. Eval cases: 6 positives, 2 negatives. folded in and retired Its escape invited exactly the outside PR the policy now closes. Its "only changed" test is now the skill's listing pre-class (widened to ), its redirect is the Registry response, and its / labels are treated as hints. The file is deleted on only: runs from the PR's base branch and from the default branch, so the copy on keeps answering PRs against until the next milestone merge. Nothing live changes when this merges. Small edits elsewhere : the skills-index row, and dropped from the tree. : the "rubric replaces this table when #4868 lands" note now points at the rubric (the short table stays, as its quick form). : the two canned comments replaced by a pointer to the skill; the bullet records it as done. Board audit, current output (read-only) Run 2026-09-29 from the skill's recipe, before any triage pass: The non-zero rows are the untriaged backlog (217 unboarded, unlabeled issues) plus a little drift on carded issues: the trackers #4857, #4858, #4860, #4875, #4876 and #4877 carry no type label, and #4860 has no Priority. None were touched. Outside-PR pre-class on the same day (hints from paths only; 323 open PRs): 4 Dependabot, 13 maintainer (14 counting this PR), 24 listing?, 9 new-server?, 255 server-change?, 18 repo-level?, so 306 outside PRs, matching #4904's snapshot. Human-gated follow-ups (not done by this PR) These are the acceptance criteria that are mass outward-facing actions. No issue or PR outside this one was closed, commented on, labeled or boarded. They are tracked by #4875 (#4876 issues, #4877 PRs), and need a maintainer's go-ahead after this merges: 1. Issue backlog triage pass* (#4876): in a session on , ask "Triage new issues" (or ). It runs step 0 and pass 1 over the 217 unboarded issues and lists any closes for your confirmation first. Then run the audit block from the skill's "The board audit" section; the acceptance is every row . The six tracker issues above need a type label and #4860 a Priority for their rows to clear. 2. Outside-PR backlog (#4877): ask "Triage the PRs"* (or → Outside PRs). It stops after writing the manifest; review it, then approve harvest (step 3), the closes (step 4, the paced loop), and run verify (step 5). #4875's conventions (a close label, and a reference in each close comment) are applied during that sweep. 3. Optional repo cleanup: the / labels become unused once receives this change; deleting them is a repo-settings call. How Has This Been Tested? Docs and skills only; no server code changed, so there was no LLM-client server test. Every read-only recipe in the skill (the unboarded finder, the PR snapshot and pre-class, the duplicate-group finder, and the audit) was extracted verbatim from and run against the live repo; the outputs are above. : pass ( OK, 3 model-invoked skills, listing 1210/4000 chars; 247 script tests). (whole suite): 22/22 first-move cases pass (all six positives at 100% except "After scoring an issue against the rubric, what do I do with the score?" at 80%, the threshold; every negative at 100%, and no regression in or ), and the hand-off at 100%. Breaking Changes None. No server, tool or configuration changed; the retired workflow keeps running on until the milestone merge. Types of changes [x] Documentation update Checklist [x] I have read the MCP Protocol Documentation (no protocol feature touched) [x] My changes follows MCP security best practices [ ] I have updated the server's README accordingly (not applicable: no server changed) [ ] I have tested this with an LLM client (not applicable: no server-facing change; triggering measured with ) [x] My code follows the repository's style guidelines [x] New and existing tests pass locally [ ] I have added appropriate error handling (not applicable) [ ] I have documented all environment variables and configuration options (not applicable) 🤖 Generated with Claude Code

cliffhall · just now
cliffhall
Agentic software factory Part 10: security-advisory skill; rewrite SECURITY.mdOpenPR

Closes #4870 [!IMPORTANT] Stacked on #4899 (Part 6, and ). This PR's base is , so the diff shows only this change. After #4899 merges, retarget this PR to before merging it. Description Part 10 of the agentic software factory (#4858, Wave 3). New skill , adapted from the MCP Inspector's for this repo's single release line (no v1 path): the draft card on board #43 (link and triage metadata only, never the vulnerability details), in with a provisional Priority recorded in the card body the ownership check, before severity: one of the seven servers under , a server moved to (out of scope), a third-party server, or the SDK underneath, routed through that SDK's private advisory form the reach classes: path traversal, symlink escape and Roots bypass (, ), argument injection (), SSRF and robots bypass () accept or close, the private fork (read before the POST, which creates one), the fix on , release, publish, then conversion of the draft into a public issue after publication Accepting, closing, publishing and replying to reporters stay human-only.* The skill has an agent prepare a recommendation and a maintainer act on it. eval cases: 6 positives, 2 negatives : the skills index row, plus the two narrow advisory exceptions to the board rules, as the Inspector has them: a draft card is the one allowed non-issue card, and accepting an advisory moves its (necessarily unmilestoned) draft from to . : a short Advisory draft cards* section (look up by bracketed GHSA id against a complete listing, create, convert after publication). 's "never create a draft card" line now points at the exception. Both edits are local; nothing else in either skill changed. rewritten. It told reporters the repo was "not eligible for security vulnerability reporting", yet private vulnerability reporting is enabled and holds a backlog. It now routes reports to the private advisory form, states scope (the seven servers; SDK, archived and third-party reports go elsewhere), the supported-versions policy (fixes ship in the next release of the affected server), what to include, and keeps the reference-implementation caveat in a form that doesn't contradict taking reports. Acceptance criteria [x] The skill, with eval cases. [x] is consistent with the repo settings (private vulnerability reporting: enabled). [x] A backlog-triage issue is filed: #4902 (the plan only; no advisory was touched). [x] Empty-skills bootstrap allowance: already removed by #4899, the first skill PR, so nothing to do here. Not in this PR The board audit's carve-out. Per #4870, whichever of this and Part 8 lands second adds it. There is no board audit yet, so #4868 will add the carve-out when it lands. The triage of the advisory backlog itself (#4902). Current aggregate counts: 61 in , 6 published, 2 closed. No advisory was accepted, closed, commented on or carded by this work. How Has This Been Tested? Docs and skills only; no server code changed, so there was no LLM-client server test. : pass ( OK, 3 model-invoked skills, listing 1281/4000 chars). (whole suite): 22/22 first-move cases at 100%, including all six new positives and every negative; the hand-off at 100%. Breaking Changes None. No server, tool or configuration changed. Types of changes [x] Documentation update Checklist [x] I have read the MCP Protocol Documentation (no protocol feature touched) [x] My changes follows MCP security best practices [ ] I have updated the server's README accordingly (not applicable: no server changed) [ ] I have tested this with an LLM client (not applicable: no server-facing change; the skill's triggering was measured with ) [x] My code follows the repository's style guidelines [x] New and existing tests pass locally [ ] I have added appropriate error handling (not applicable) [ ] I have documented all environment variables and configuration options (not applicable) 🤖 Generated with Claude Code

cliffhall · just now
cliffhall
feat(skills): pr-flow skill (factory Part 7)OpenPR

Closes #4867 Stacked on #4899 (, the and skills this one uses). This PR targets that branch. Retarget it to after #4899 merges (). Description Adds the skill (), adapted from the Inspector's per §6 of : 1. Start from an issue: read it with every comment, assign it, move the card to In Progress (via ). 2. Branch from , with the type mapped from the issue's type label, and how to stack. 3. DCO: on every commit; the Inspector's section on repairing with and , why does nothing, and the hook caveat. It states that the DCO app is not installed yet (see follow-ups below). 4. The gate: always, per TS workspace, per Python server, and plus for skill changes. PR and comment bodies go through , so Markdown backticks are never shell-interpolated. This stands in until #4871 brings and . 5. Client evidence replaces screenshots. A server-behavior change records what the Inspector V2 and an LLM client were asked and returned, in both spec eras (#4857). A change with no client surface carries a targeted probe. 6. Open the PR: first, then with a read-back, then In Review. 7. Copilot review: with the bot id, and a backgrounded poll that exits when the round lands or its deadline passes, and fails closed on a / error. 8. Respond: per-thread replies, a PR-level summary after each round, suppressed comments, and the lag of inline comments. 9. The loop's exits, as a table: clean round, out-of-scope only, two silent rounds, timeout. 10. Close-out on merge: close the issue by hand, Done, retarget stacked PRs. : a Skills index row, and the Copilot-loop rule gains the timeout exit, and a silent round may be re-requested without a push, so it matches the skill. Both are small, local edits. Eval cases: , with 6 positives and 2 negatives. There is also a hand-off (chain) case in , the reached skill's file. Motivation and Context Part 7 of the agentic software factory (#4858), Wave 3. How Has This Been Tested? This PR has no client-observable surface (it adds a skill and docs), so it carries targeted probes, per the skill's own step 5: : exit 0. (pinned 2.1.250): . over the whole suite, as committed: 22/22 first-move cases at or above 80%, and 2/2 hand-off cases above 50% ( at 100%, the new at 60%). All six positives and every negative scored 100%, and the existing and cases all scored 100%. (The first run, before the chain case, gave 22/22 and 1/1. A chain case was measured at 0% and dropped as mis-aimed; see the round-2 summary.) This PR was taken end to end through the skill: #4867 was read with its comments, assigned, and moved to In Progress through the recipe. The commit is signed off. The PR is linked with and read back, the card is in In Review, and the Copilot loop is running (round summaries follow as PR comments). Breaking Changes None. Types of changes [ ] Bug fix (non-breaking change which fixes an issue) [x] New feature (non-breaking change which adds functionality) [ ] Breaking change (fix or feature that would cause existing functionality to change) [x] Documentation update Checklist [x] I have read the MCP Protocol Documentation [x] My changes follows MCP security best practices [ ] I have updated the server's README accordingly (n/a: no server changed) [ ] I have tested this with an LLM client (n/a: no server behavior; the skill evals run it through ) [x] My code follows the repository's style guidelines [x] New and existing tests pass locally [ ] I have added appropriate error handling (n/a) [ ] I have documented all environment variables and configuration options (n/a) Human follow-ups (acceptance criteria this PR cannot meet) Install the probot DCO app on . This is an org-admin step, so no agent attempted it. It covers the first acceptance criterion: "installed and fails a PR with an unsigned commit". To verify, push an unsigned commit to a throwaway PR and confirm the DCO check fails. Once the app enforces it, add the signoff rule to , and drop the "not installed yet" paragraph from step 3 of the skill. only states rules that are true today, so this PR does not add it. The empty-skills bootstrap allowance** in was already removed by #4866 (#4899), so this PR has nothing to remove. 🤖 Generated with Claude Code

cliffhall · 14m ago
Structured data for AI agents

Repository: modelcontextprotocol/servers. Description: Model Context Protocol Servers Stars: 90652, Forks: 11698. Primary language: TypeScript. Languages: TypeScript (82.2%), Python (16.8%), Dockerfile (1%). Homepage: https://modelcontextprotocol.io Latest release: 2026.8.31 (4w ago). Open PRs: 100, open issues: 465. Last activity: just now. Community health: 87%. Top contributors: olaservo, tadasant, cliffhall, jspahrsummers, dsp-ant, jerome3o-anthropic, maheshmurag, evalstate, baryhuang, marcelo-ochoa and others.

·@ofershap

Replace github.com with gitshow.dev