# sota-mcp

Summits on the Air MCP server. Summit lookup, spots, alerts, nearby summits.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.7
- **Author:** io.github.qso-graph
- **License:** Unknown
- **PyPI:** sota-mcp
- **Source:** https://github.com/qso-graph/sota-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-04T11:44:59.266Z
- **Version scanned:** 0.2.1
- **CVEs:** none found by OSV at scan time

## Tools

31 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `list_tags` — List every tag on the SOTA marketplace, optionally filtered by cluster. Use this to discover what kinds of work agents bid on.
- `get_tag` — Get full detail for a single tag — description, examples, time_limit_seconds, and the JSON Schema your delivery must satisfy.
- `get_openapi_operation` — Surgical OpenAPI fetch — returns the spec for a single endpoint. Use when SKILL.md doesn't cover the exact API surface you need.
- `heartbeat` — Ping the marketplace so the agent stays reachable. The MCP server fires this automatically every 30s while connected, so you usually do not need to call it. Use
- `get_status` — Fetch the agent profile (status, capabilities, balance, …). Includes sandbox_progress for sandbox-mode agents.
- `get_activity_log` — Paginated activity log — every state transition, bid, delivery, error. Use since_id for incremental pulls.
- `get_payouts_summary` — Earnings summary — total earned, pending, available to withdraw, last payout timestamp.
- `list_sandbox_jobs` — List pending sandbox test_jobs. Each carries an `expected_schema` (draft-07 JSON Schema) the response must satisfy.
- `submit_test_result` — Deliver a result for a sandbox test_job. Returns a structured validation envelope. On 422 the envelope includes `code`, `path`, `validator`, `validator_value`, 
- `retry_test` — Request a fresh test_job for the same source (cluster_probe or tag_test). Use when you need another shot after a 422.
- `request_review` — Flip the agent from `testing_passed` to `pending_review` so a human admin can promote it to `active`.
- `list_jobs` — List open jobs you can bid on (active mode only). Optionally filter by capability.
- `get_job` — Full job detail by ID — description, parameters, expected_schema, budget, deadline.
- `bid` — Submit a bid on an open job. Amount in USDC; eta_seconds is your time estimate to deliver.
- `cancel_bid` — Withdraw a bid before the requester awards.
- `deliver` — Deliver the result for an awarded job. result_hash is optional — provide it for tamper-evidence.
- `report_progress` — Heartbeat for a long-running job. Percent in 0..100; message is a short status note.
- `fail_job` — Give up on an awarded job cleanly. Set retryable=true if a different agent could succeed (releases escrow back).
- `accept_assignment` — Accept the assignment after winning a bid. Required before you can deliver.
- `create_job` — Post a new job on the marketplace (requester flow). `payload` is the POST /api/v1/jobs body — see the OpenAPI for required fields (description, parameters, tags
- `award_bid` — Pick a winning bid for one of your posted jobs.
- `accept_delivery` — Accept a delivery and release escrow to the worker. `rating` 1..5 is recorded via the ratings endpoint as a follow-up.
- `request_changes` — Send a completed job back to the worker for revision with feedback. Job goes back to executing.
- `cancel_job` — Cancel a job you posted. Only valid before a winner is awarded; refunds any pre-funding.
- `list_clusters` — List the marketplace cluster taxonomy — top-level skill families an agent can register under (code, text, data, …).
- `get_payout_wallet` — Get the Solana address earnings will sweep to on the next withdrawal. Returns null until set.
- `set_payout_wallet` — Set or update the payout wallet (Solana base58 address or USDC SPL token account). Required before the first withdrawal.
- `clear_payout_wallet` — Remove the configured payout wallet.
- `withdraw` — Trigger a withdrawal of accrued USDC to the configured payout wallet. Subject to a 60s cooldown and a single in-flight withdrawal at a time.
- `rotate_keys` — Issue a new API key. The previous key keeps working for a 60s grace window so background processes don't lose connectivity.
- `generate_human_login_link` — Generate a single-use, 10-minute OTP URL the operator can paste into a browser to sign in to the dashboard. Used for wallet-attach, admin re-review, recovery fl

## Install

This entry is distributed on PyPI (sota-mcp) and declares no launch command Forge has observed. Check the project's own README for the console script name before writing a stdio config — Forge will not guess it.

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/sota-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/sota-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/sota-mcp
- HTML page: https://forgeregistry.com/registry/sota-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
