# com.supplyslate/sourcing

Agent-native supply network for components, fabrication, industrial RFQs, offers, and fulfillment.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.0.0
- **Author:** com.supplyslate
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.supplyslate.com/mcp
- **Source:** https://mcp.supplyslate.com/mcp
- **Endpoint health:** reachable (last checked 2026-09-20T21:03:46.844Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-20T21:03:46.844Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

55 declared. Observed from a live `tools/list` probe.
- `describe_supplyslate` — Explain what SupplySlate does, what it does not do, and when a buyer-owned agent should use it.
- `list_sourcing_categories` — List the editable supply categories currently accepting requests. Agents may still submit a precise request outside this list.
- `get_connection_guide` — Return the exact MCP and REST connection details a buyer, developer, or agent operator needs to connect to SupplySlate.
- `list_fabrication_processes` — List configurable fabrication, kitting, assembly, and test processes with their required artifacts and requirement schemas.
- `get_live_fabrication_capabilities` — Read attributed live fabrication capabilities from the connected AFN provider. This is discovery only and neither uploads a design nor requests a quote.
- `search_live_components` — Search attributed current electronic-component product, availability, lead-time, and price data from Mouser. Results retain provider, observation time, and merc
- `get_requirement_schema` — Read the evidence-safe input schema for a configurable supply category or fabrication process, including required fields, recommended fields, accepted artifacts
- `search_products` — Search published canonical product facts. Commercial price, stock, compatibility, and lead time are returned only when separately supported by current evidence.
- `get_product` — Read one published canonical product with variants, category links, evidence scope, observation dates, and freshness.
- `get_compatibility` — Read one published compatibility or substitution assertion with exact subject, object, conditions, confidence, evidence source, and observation time.
- `list_supplier_taxonomy` — List the product categories used by the public industrial compressor service-parts supplier directory, including verified supplier counts.
- `search_suppliers` — Search source-backed public supplier profiles by product category, brand, company type, service, compressor type, industry, or text. No authentication required.
- `get_supplier` — Read one public supplier profile with source URLs and evidence for every category, capability, and brand claim.
- `create_project` — Create a durable supply project from an idea, file, BOM, exact part, or RFQ origin. Requires a scoped buyer credential.
- `get_project` — Read a project, its current immutable-capable revision, requirements, artifacts, BOM summaries, and validation history.
- `update_project_requirements` — Replace the structured requirement set on an unlocked project revision. Confirmed flags distinguish buyer-confirmed facts from agent interpretation.
- `create_artifact_upload` — Create a short-lived, one-time private artifact upload URL. The caller must stream the exact declared bytes with a SHA-256 checksum.
- `attach_artifact_reference` — Attach an HTTPS repository, document, drawing, datasheet, BOM, or design reference to the current project revision without copying its bytes. Private or expirin
- `upsert_bom` — Create a BOM or a new BOM revision with assemblies, catalog items, custom parts, services, consumables, artifacts, and interface dependencies.
- `get_bom` — Read the current revision of one project BOM, including hierarchy, quantities, sourcing state, and interface dependencies.
- `validate_project` — Run the current versioned validators and return separate blocking errors, compatibility conflicts, warnings, missing information, passed checks, and unavailable
- `list_project_validations` — List versioned validation reports for a project without implying licensed engineering approval.
- `source_project` — Lock the validated project revision into an immutable sourcing package, create normalized request lines, and return transparent supplier candidates. This does n
- `create_purchase_plan` — Create an immutable, single-currency, multi-supplier purchase plan from selected current quote lines, choosing at most one commercial option per requested line.
- `get_purchase_plan` — Read one exact purchase-plan version with selected lines, merchants, totals, risks, evidence, approvals, and checkout handoffs.
- `request_purchase_approval` — Create a human review link bound to the exact purchase-plan version, suppliers, maximum amount, currency, risks, and expiry. This does not approve or purchase t
- `get_checkout_handoffs` — List merchant-hosted checkout, supplier invoice, or merchant-order handoffs for an approved plan. Suppliers remain merchant of record and SupplySlate does not p
- `create_provider_checkout_handoff` — After a human has approved the exact purchase plan, create one supplier-hosted payment link for a checkout-connected provider offer. This creates an unpaid prov
- `list_orders` — List merchant-confirmed orders for the buyer organization. A plan or queued handoff is never represented as an order.
- `get_order` — Read one merchant-confirmed order with items, fulfillment, shipments, issues, evidence, and event history.
- `report_order_issue` — Open a durable post-purchase issue for a merchant-confirmed order. This notifies the supplier-side organization and records owner, status, and event history; it
- `request_order_cancellation` — Ask the merchant to cancel an unshipped order. This creates a request and notification; it never reports the order as cancelled until the supplier or an operato
- `request_order_return` — Open a return request after shipment. The supplier remains merchant of record and controls authorization and refund state.
- `open_warranty_claim` — Open a durable warranty claim on an accepted order or specific order line. This records the claim and notifies the supplier without asserting eligibility or app
- `get_supplier_profile` — Read the authenticated supplier's SupplySlate profile and current catalog-item count. Requires a supplier API key.
- `upsert_supplier_catalog` — Create or update normalized supplier catalog items through a durable manual import with row-level validation, history, evidence scope, availability, and commerc
- `create_catalog_import` — Create a durable CSV, XLSX, JSON, feed, API, document, or manual catalog import. Supply parsed rows for immediate validation, or an artifact/source reference to
- `update_supplier_capabilities` — Replace the supplier-submitted capability set while preserving separately sourced public, operator-verified, and transaction-proven evidence.
- `update_availability` — Append timestamped supplier availability evidence and update current catalog state by supplier SKU without rewriting historical snapshots.
- `list_supplier_rfqs` — List approved RFQs matched to the authenticated supplier. Requires a supplier API key.
- …and 15 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"sourcing\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.supplyslate.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 26, ceiling 50 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.supplyslate%2Fsourcing
- Install plan: https://forgeregistry.com/api/v1/packages/com.supplyslate%2Fsourcing/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.supplyslate%2Fsourcing
- HTML page: https://forgeregistry.com/registry/com.supplyslate%2Fsourcing
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
