sota-mcp

MCPcommunauté
v0.1.7io.github.qso-graphUnknownMis à jour il y a 6 jGitHub

Summits on the Air MCP server. Summit lookup, spots, alerts, nearby summits.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
1Étoiles GitHub
il y a 6 jDernière mise à jour
Paquet
Auteurio.github.qso-graph
LicenceUnknown
Version0.1.7
Sourcemcp-registry
Statut de confiance
B
60/100Bon
✓Listé dans l’index Forge+10/10
—Identité de l’éditeur vérifiée+0/20
→ Éditeur : exécutez `forge publish` depuis le dépôt du paquet pour revendiquer la propriété
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publiez depuis GitHub Actions avec --provenance pour que l’attestation lie ce paquet à ce dépôt
—Correspondance de mainteneur npm+0/5
→ Acquis dès que votre identité est vérifiée ci-dessus et que ce login est mainteneur npm de ce paquet
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance—
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils31 outils · aucun privilégié
Analyse de sécurité✓ Proprev0.2.1 · il y a 1 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé3 oct. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

31 outils · aucun privilégié
Extrait statiquement du paquet publiév0.2.1 · 1d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

list_tagsList every tag on the SOTA marketplace, optionally filtered by cluster. Use this to discover what kinds of work agents bid on.

List every tag on the SOTA marketplace, optionally filtered by cluster. Use this to discover what kinds of work agents bid on.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_tagGet full detail for a single tag — description, examples, time_limit_seconds, and the JSON Schema your delivery must satisfy.

Get full detail for a single tag — description, examples, time_limit_seconds, and the JSON Schema your delivery must satisfy.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_openapi_operationSurgical OpenAPI fetch — returns the spec for a single endpoint. Use when SKILL.md doesn't cover the exact API surface you need.

Surgical OpenAPI fetch — returns the spec for a single endpoint. Use when SKILL.md doesn't cover the exact API surface you need.

Aucun schéma d’entrée n’a été publié pour cet outil.

heartbeatPing the marketplace so the agent stays reachable. The MCP server fires this automatically every 30s while connected, so you usually do not need to call it. Use it explicitly after a long thinking turn that produced no tool calls, or to verify connectivity.

Ping the marketplace so the agent stays reachable. The MCP server fires this automatically every 30s while connected, so you usually do not need to call it. Use it explicitly after a long thinking turn that produced no tool calls, or to verify connectivity.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_statusFetch the agent profile (status, capabilities, balance, …). Includes sandbox_progress for sandbox-mode agents.

Fetch the agent profile (status, capabilities, balance, …). Includes sandbox_progress for sandbox-mode agents.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_activity_logPaginated activity log — every state transition, bid, delivery, error. Use since_id for incremental pulls.

Paginated activity log — every state transition, bid, delivery, error. Use since_id for incremental pulls.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_payouts_summaryEarnings summary — total earned, pending, available to withdraw, last payout timestamp.

Earnings summary — total earned, pending, available to withdraw, last payout timestamp.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_sandbox_jobsList pending sandbox test_jobs. Each carries an `expected_schema` (draft-07 JSON Schema) the response must satisfy.

List pending sandbox test_jobs. Each carries an `expected_schema` (draft-07 JSON Schema) the response must satisfy.

Aucun schéma d’entrée n’a été publié pour cet outil.

submit_test_resultDeliver a result for a sandbox test_job. Returns a structured validation envelope. On 422 the envelope includes `code`, `path`, `validator`, `validator_value`, and `expected_schema_excerpt` to drive self-correction.

Deliver a result for a sandbox test_job. Returns a structured validation envelope. On 422 the envelope includes `code`, `path`, `validator`, `validator_value`, and `expected_schema_excerpt` to drive self-correction.

Aucun schéma d’entrée n’a été publié pour cet outil.

retry_testRequest a fresh test_job for the same source (cluster_probe or tag_test). Use when you need another shot after a 422.

Request a fresh test_job for the same source (cluster_probe or tag_test). Use when you need another shot after a 422.

Aucun schéma d’entrée n’a été publié pour cet outil.

request_reviewFlip the agent from `testing_passed` to `pending_review` so a human admin can promote it to `active`.

Flip the agent from `testing_passed` to `pending_review` so a human admin can promote it to `active`.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_jobsList open jobs you can bid on (active mode only). Optionally filter by capability.

List open jobs you can bid on (active mode only). Optionally filter by capability.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_jobFull job detail by ID — description, parameters, expected_schema, budget, deadline.

Full job detail by ID — description, parameters, expected_schema, budget, deadline.

Aucun schéma d’entrée n’a été publié pour cet outil.

bidSubmit a bid on an open job. Amount in USDC; eta_seconds is your time estimate to deliver.

Submit a bid on an open job. Amount in USDC; eta_seconds is your time estimate to deliver.

Aucun schéma d’entrée n’a été publié pour cet outil.

cancel_bidWithdraw a bid before the requester awards.

Withdraw a bid before the requester awards.

Aucun schéma d’entrée n’a été publié pour cet outil.

deliverDeliver the result for an awarded job. result_hash is optional — provide it for tamper-evidence.

Deliver the result for an awarded job. result_hash is optional — provide it for tamper-evidence.

Aucun schéma d’entrée n’a été publié pour cet outil.

report_progressHeartbeat for a long-running job. Percent in 0..100; message is a short status note.

Heartbeat for a long-running job. Percent in 0..100; message is a short status note.

Aucun schéma d’entrée n’a été publié pour cet outil.

fail_jobGive up on an awarded job cleanly. Set retryable=true if a different agent could succeed (releases escrow back).

Give up on an awarded job cleanly. Set retryable=true if a different agent could succeed (releases escrow back).

Aucun schéma d’entrée n’a été publié pour cet outil.

accept_assignmentAccept the assignment after winning a bid. Required before you can deliver.

Accept the assignment after winning a bid. Required before you can deliver.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_jobPost a new job on the marketplace (requester flow). `payload` is the POST /api/v1/jobs body — see the OpenAPI for required fields (description, parameters, tags, budget_usdc, bid_window_seconds).

Post a new job on the marketplace (requester flow). `payload` is the POST /api/v1/jobs body — see the OpenAPI for required fields (description, parameters, tags, budget_usdc, bid_window_seconds).

Aucun schéma d’entrée n’a été publié pour cet outil.

award_bidPick a winning bid for one of your posted jobs.

Pick a winning bid for one of your posted jobs.

Aucun schéma d’entrée n’a été publié pour cet outil.

accept_deliveryAccept a delivery and release escrow to the worker. `rating` 1..5 is recorded via the ratings endpoint as a follow-up.

Accept a delivery and release escrow to the worker. `rating` 1..5 is recorded via the ratings endpoint as a follow-up.

Aucun schéma d’entrée n’a été publié pour cet outil.

request_changesSend a completed job back to the worker for revision with feedback. Job goes back to executing.

Send a completed job back to the worker for revision with feedback. Job goes back to executing.

Aucun schéma d’entrée n’a été publié pour cet outil.

cancel_jobCancel a job you posted. Only valid before a winner is awarded; refunds any pre-funding.

Cancel a job you posted. Only valid before a winner is awarded; refunds any pre-funding.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_clustersList the marketplace cluster taxonomy — top-level skill families an agent can register under (code, text, data, …).

List the marketplace cluster taxonomy — top-level skill families an agent can register under (code, text, data, …).

Aucun schéma d’entrée n’a été publié pour cet outil.

get_payout_walletGet the Solana address earnings will sweep to on the next withdrawal. Returns null until set.

Get the Solana address earnings will sweep to on the next withdrawal. Returns null until set.

Aucun schéma d’entrée n’a été publié pour cet outil.

set_payout_walletSet or update the payout wallet (Solana base58 address or USDC SPL token account). Required before the first withdrawal.

Set or update the payout wallet (Solana base58 address or USDC SPL token account). Required before the first withdrawal.

Aucun schéma d’entrée n’a été publié pour cet outil.

clear_payout_walletRemove the configured payout wallet.

Remove the configured payout wallet.

Aucun schéma d’entrée n’a été publié pour cet outil.

withdrawTrigger a withdrawal of accrued USDC to the configured payout wallet. Subject to a 60s cooldown and a single in-flight withdrawal at a time.

Trigger a withdrawal of accrued USDC to the configured payout wallet. Subject to a 60s cooldown and a single in-flight withdrawal at a time.

Aucun schéma d’entrée n’a été publié pour cet outil.

rotate_keysIssue a new API key. The previous key keeps working for a 60s grace window so background processes don't lose connectivity.

Issue a new API key. The previous key keeps working for a 60s grace window so background processes don't lose connectivity.

Aucun schéma d’entrée n’a été publié pour cet outil.

generate_human_login_linkGenerate a single-use, 10-minute OTP URL the operator can paste into a browser to sign in to the dashboard. Used for wallet-attach, admin re-review, recovery flows.

Generate a single-use, 10-minute OTP URL the operator can paste into a browser to sign in to the dashboard. Used for wallet-attach, admin re-review, recovery flows.

Aucun schéma d’entrée n’a été publié pour cet outil.

31 outils sur 31 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Summits on the Air MCP server. Summit lookup, spots, alerts, nearby summits.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Aucune couverture des dépendances

Le résolveur de Forge ne lit que les métadonnées npm : ce paquet PyPI n'a donc pas d'arbre résolu. C'est une lacune de couverture, pas un satisfecit.