sota-mcp

MCPcommunity
v0.1.7io.github.qso-graphUnknownUpdated 6d agoGitHub

Summits on the Air MCP server. Summit lookup, spots, alerts, nearby summits.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1GitHub stars
6d agoLast update
Package
Authorio.github.qso-graph
LicenseUnknown
Version0.1.7
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface31 tools · none privileged
Security scan✓ Cleanv0.2.1 · todayHow well does this scan work?
EvalsNone
IndexedOct 3, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

31 tools · none privileged
Statically extracted from the published packagev0.2.1 · 23h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

list_tagsList every tag on the SOTA marketplace, optionally filtered by cluster. Use this to discover what kinds of work agents bid on.

List every tag on the SOTA marketplace, optionally filtered by cluster. Use this to discover what kinds of work agents bid on.

No input schema was published for this tool.

get_tagGet full detail for a single tag — description, examples, time_limit_seconds, and the JSON Schema your delivery must satisfy.

Get full detail for a single tag — description, examples, time_limit_seconds, and the JSON Schema your delivery must satisfy.

No input schema was published for this tool.

get_openapi_operationSurgical OpenAPI fetch — returns the spec for a single endpoint. Use when SKILL.md doesn't cover the exact API surface you need.

Surgical OpenAPI fetch — returns the spec for a single endpoint. Use when SKILL.md doesn't cover the exact API surface you need.

No input schema was published for this tool.

heartbeatPing the marketplace so the agent stays reachable. The MCP server fires this automatically every 30s while connected, so you usually do not need to call it. Use it explicitly after a long thinking turn that produced no tool calls, or to verify connectivity.

Ping the marketplace so the agent stays reachable. The MCP server fires this automatically every 30s while connected, so you usually do not need to call it. Use it explicitly after a long thinking turn that produced no tool calls, or to verify connectivity.

No input schema was published for this tool.

get_statusFetch the agent profile (status, capabilities, balance, …). Includes sandbox_progress for sandbox-mode agents.

Fetch the agent profile (status, capabilities, balance, …). Includes sandbox_progress for sandbox-mode agents.

No input schema was published for this tool.

get_activity_logPaginated activity log — every state transition, bid, delivery, error. Use since_id for incremental pulls.

Paginated activity log — every state transition, bid, delivery, error. Use since_id for incremental pulls.

No input schema was published for this tool.

get_payouts_summaryEarnings summary — total earned, pending, available to withdraw, last payout timestamp.

Earnings summary — total earned, pending, available to withdraw, last payout timestamp.

No input schema was published for this tool.

list_sandbox_jobsList pending sandbox test_jobs. Each carries an `expected_schema` (draft-07 JSON Schema) the response must satisfy.

List pending sandbox test_jobs. Each carries an `expected_schema` (draft-07 JSON Schema) the response must satisfy.

No input schema was published for this tool.

submit_test_resultDeliver a result for a sandbox test_job. Returns a structured validation envelope. On 422 the envelope includes `code`, `path`, `validator`, `validator_value`, and `expected_schema_excerpt` to drive self-correction.

Deliver a result for a sandbox test_job. Returns a structured validation envelope. On 422 the envelope includes `code`, `path`, `validator`, `validator_value`, and `expected_schema_excerpt` to drive self-correction.

No input schema was published for this tool.

retry_testRequest a fresh test_job for the same source (cluster_probe or tag_test). Use when you need another shot after a 422.

Request a fresh test_job for the same source (cluster_probe or tag_test). Use when you need another shot after a 422.

No input schema was published for this tool.

request_reviewFlip the agent from `testing_passed` to `pending_review` so a human admin can promote it to `active`.

Flip the agent from `testing_passed` to `pending_review` so a human admin can promote it to `active`.

No input schema was published for this tool.

list_jobsList open jobs you can bid on (active mode only). Optionally filter by capability.

List open jobs you can bid on (active mode only). Optionally filter by capability.

No input schema was published for this tool.

get_jobFull job detail by ID — description, parameters, expected_schema, budget, deadline.

Full job detail by ID — description, parameters, expected_schema, budget, deadline.

No input schema was published for this tool.

bidSubmit a bid on an open job. Amount in USDC; eta_seconds is your time estimate to deliver.

Submit a bid on an open job. Amount in USDC; eta_seconds is your time estimate to deliver.

No input schema was published for this tool.

cancel_bidWithdraw a bid before the requester awards.

Withdraw a bid before the requester awards.

No input schema was published for this tool.

deliverDeliver the result for an awarded job. result_hash is optional — provide it for tamper-evidence.

Deliver the result for an awarded job. result_hash is optional — provide it for tamper-evidence.

No input schema was published for this tool.

report_progressHeartbeat for a long-running job. Percent in 0..100; message is a short status note.

Heartbeat for a long-running job. Percent in 0..100; message is a short status note.

No input schema was published for this tool.

fail_jobGive up on an awarded job cleanly. Set retryable=true if a different agent could succeed (releases escrow back).

Give up on an awarded job cleanly. Set retryable=true if a different agent could succeed (releases escrow back).

No input schema was published for this tool.

accept_assignmentAccept the assignment after winning a bid. Required before you can deliver.

Accept the assignment after winning a bid. Required before you can deliver.

No input schema was published for this tool.

create_jobPost a new job on the marketplace (requester flow). `payload` is the POST /api/v1/jobs body — see the OpenAPI for required fields (description, parameters, tags, budget_usdc, bid_window_seconds).

Post a new job on the marketplace (requester flow). `payload` is the POST /api/v1/jobs body — see the OpenAPI for required fields (description, parameters, tags, budget_usdc, bid_window_seconds).

No input schema was published for this tool.

award_bidPick a winning bid for one of your posted jobs.

Pick a winning bid for one of your posted jobs.

No input schema was published for this tool.

accept_deliveryAccept a delivery and release escrow to the worker. `rating` 1..5 is recorded via the ratings endpoint as a follow-up.

Accept a delivery and release escrow to the worker. `rating` 1..5 is recorded via the ratings endpoint as a follow-up.

No input schema was published for this tool.

request_changesSend a completed job back to the worker for revision with feedback. Job goes back to executing.

Send a completed job back to the worker for revision with feedback. Job goes back to executing.

No input schema was published for this tool.

cancel_jobCancel a job you posted. Only valid before a winner is awarded; refunds any pre-funding.

Cancel a job you posted. Only valid before a winner is awarded; refunds any pre-funding.

No input schema was published for this tool.

list_clustersList the marketplace cluster taxonomy — top-level skill families an agent can register under (code, text, data, …).

List the marketplace cluster taxonomy — top-level skill families an agent can register under (code, text, data, …).

No input schema was published for this tool.

get_payout_walletGet the Solana address earnings will sweep to on the next withdrawal. Returns null until set.

Get the Solana address earnings will sweep to on the next withdrawal. Returns null until set.

No input schema was published for this tool.

set_payout_walletSet or update the payout wallet (Solana base58 address or USDC SPL token account). Required before the first withdrawal.

Set or update the payout wallet (Solana base58 address or USDC SPL token account). Required before the first withdrawal.

No input schema was published for this tool.

clear_payout_walletRemove the configured payout wallet.

Remove the configured payout wallet.

No input schema was published for this tool.

withdrawTrigger a withdrawal of accrued USDC to the configured payout wallet. Subject to a 60s cooldown and a single in-flight withdrawal at a time.

Trigger a withdrawal of accrued USDC to the configured payout wallet. Subject to a 60s cooldown and a single in-flight withdrawal at a time.

No input schema was published for this tool.

rotate_keysIssue a new API key. The previous key keeps working for a 60s grace window so background processes don't lose connectivity.

Issue a new API key. The previous key keeps working for a 60s grace window so background processes don't lose connectivity.

No input schema was published for this tool.

generate_human_login_linkGenerate a single-use, 10-minute OTP URL the operator can paste into a browser to sign in to the dashboard. Used for wallet-attach, admin re-review, recovery flows.

Generate a single-use, 10-minute OTP URL the operator can paste into a browser to sign in to the dashboard. Used for wallet-attach, admin re-review, recovery flows.

No input schema was published for this tool.

31 of 31 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Summits on the Air MCP server. Summit lookup, spots, alerts, nearby summits.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.