Mcp Oci Registry — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Oci Registry (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for querying OCI container registries. Built with the fastmcp framework, this server provides tools and prompts for interacting with container registries like Docker Hub, GHCR, and other OCI-compatible registries.
Tools:
ping - Health check toollist_oci_tags - List all tags for an OCI repositoryget_oci_details - Fetch manifest details including architectures, digest, and annotationsPrompts:
list_tags_prompt - Instructions for listing repository tagslist_architectures_prompt - Instructions for listing supported architectureslist_digests_prompt - Instructions for retrieving image digestslist_annotations_prompt - Instructions for listing OCI annotationsAdditional Features:
NonValidatingRegistry class that bypasses jsonschema validation for manifest lists/indexes/healthz)python -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
pip install -r requirements.txt#### Run in stdio mode (default) By default, the server runs over stdio which is what most MCP clients expect:
python server.pyThe process will wait for JSON-RPC requests over stdin/stdout. Typically you do not run it manually; it is launched by an MCP-compatible client.
#### Run with uvicorn (HTTP) For HTTP access, use the Makefile:
make runOr manually:
uvicorn server:asgi_app --host 127.0.0.1 --port 8888#### Run with Docker Compose For development with hot reload:
make compose-upOr manually:
docker compose up --buildList tags:
# Using FastMCP Client
from fastmcp import Client, FastMCP
import server
client = Client(server.mcp)
async with client:
tags = await client.call_tool("list_oci_tags", {
"registry": "registry-1.docker.io",
"repository": "library/alpine"
})
print(tags.data) # ['latest', '3.22.2', 'edge', ...]Get OCI details:
details = await client.call_tool("get_oci_details", {
"registry": "registry-1.docker.io",
"repository": "library/alpine",
"reference": "3.22.2"
})
print(details.data)
# {
# "digest": "sha256:...",
# "architectures": ["amd64", "arm64", ...],
# "annotations": {...}
# }Add an entry in your Claude Desktop MCP config (~/.cursor/mcp.json or similar):
{
"mcpServers": {
"mcp-oci-registry": {
"command": "/path/to/.venv/bin/python",
"args": [
"/path/to/mcp-oci-registry/server.py"
],
"env": {}
}
}
}Adjust paths as needed for your environment.
mcp-oci-registry/
├── server.py # MCP server entrypoint
├── tools.py # Tool functions (ping, list_oci_tags, get_oci_details)
├── prompts.py # Prompt templates
├── registry.py # NonValidatingRegistry class
├── __init__.py # Package initialization
├── requirements.txt # Python dependencies
├── Dockerfile # Container image definition
├── docker-compose.yml # Development environment
├── Makefile # Common operations
└── tests/ # Test suite
├── test_tools.py
└── test_integration_http.pyRun tests:
make testAvailable Make targets:
make install - Install dependenciesmake run - Run server with uvicornmake test - Run test suitemake docker-build - Build Docker imagemake docker-run - Run Docker containermake compose-up - Start with docker-composemake compose-down - Stop docker-composemake compose-logs - View docker-compose logsThe project includes both unit tests and integration tests:
tests/test_tools.py) - Test individual tool functions with mocked dependenciestests/test_integration_http.py) - Test full MCP protocol flow using FastMCP ClientRun all tests:
pytest -vAdd new tools:
tools.pyserver.py: mcp.tool(your_function)Add new prompts:
prompts.pyserver.py: mcp.prompt(your_prompt)Apache
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.