io.github.Luca-Blight/devmatch

MCPcommunitylive
v0.2.3io.github.Luca-BlightUnknownUpdated 1mo ago

DevMatch — evidence-based engineer hiring for mission-driven teams.

Endpoint healthlive
checked 10 days ago · 178ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorio.github.Luca-Blight
LicenseUnknown
Version0.2.3
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface3 tools · none privileged
Security scan✓ Cleanvlive · 1mo agoHow well does this scan work?
PROMPTtool:get_profile#handleLinks to undeclared domain: orcid.org
EvalsNone
IndexedSep 5, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

3 tools · none privileged
Observed live from the vendor's endpoint1mo ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://mcp.dev-match.xyz/mcp3 tools · 146ms
find_candidatesRank engineers for a role or project by their verified open-source contributions and other public work. Input: pass the richest context you have — (1) a full job description (most common), (2) a synthesized brief after reviewing a company's public repo (README + stack + role needs — preferred over…

Rank engineers for a role or project by their verified open-source contributions and other public work. Input: pass the richest context you have — (1) a full job description (most common), (2) a synthesized brief after reviewing a company's public repo (README + stack + role needs — preferred over…

ParameterTypeDescription
excludearrayOptional. GitHub logins or org names to exclude from results (case-insensitive). Matches a candidate's login AND the owner/org of every repo they matched on —…
input*stringSearch brief: full JD, repo-derived summary (preferred when you've reviewed the project), README excerpt, informal role brief, or a PUBLIC github.com repo URL.…
limitintegerMax candidates to return. Default 20, max 20.
locationstringOptional. Restrict results to a place — a city ("Bozeman"), US state ("MT" / "Montana"), country name ("Germany"), or ISO country code ("US"). Matched against…
get_profileFetch one contributor's profile card by GitHub login, ORCID iD (or orcid.org URL), or a find_candidates `id` (source:name such as ntrs:Ada Lovelace). Do not invent a GitHub handle for research or deep-tech people — pass their id. find_candidates already returns full inline profiles; use get_profile…

Fetch one contributor's profile card by GitHub login, ORCID iD (or orcid.org URL), or a find_candidates `id` (source:name such as ntrs:Ada Lovelace). Do not invent a GitHub handle for research or deep-tech people — pass their id. find_candidates already returns full inline profiles; use get_profile…

NOTEIn parameter handle: Links to undeclared domain: orcid.org
ParameterTypeDescription
handle*stringPerson to look up: a GitHub login (no '@'), an ORCID iD or https://orcid.org/<id> URL, or a find_candidates id (source:name such as ntrs:Ada Lovelace). Do not…
idstringAlias for handle. Pass a find_candidates `id` (GitHub login, ORCID iD, or source:name).
find_similar_projectsFind open-source projects similar to a seed GitHub repo, ranked by semantic similarity to its description/topics/README. Each result includes top contributors as leads — not JD-ranked candidates. Returns structuredContent (view=similar_projects). Agents: consume structuredContent only. Use for lan…

Find open-source projects similar to a seed GitHub repo, ranked by semantic similarity to its description/topics/README. Each result includes top contributors as leads — not JD-ranked candidates. Returns structuredContent (view=similar_projects). Agents: consume structuredContent only. Use for lan…

ParameterTypeDescription
limitintegerNumber of similar projects to return. Defaults to 10, max 25.
repo*stringSeed repo in `owner/name` form (e.g. 'karpathy/llm.c'). A full github.com URL is also accepted; the server strips the prefix.

3 of 3 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

DevMatch — evidence-based engineer hiring for mission-driven teams.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.