Doc2Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Doc2Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This repository is not the doc2mcp product. It is the small, GitHub‑OIDC‑authenticated publishing manifest for the official Model Context Protocol Registry.
| What | Where |
|---|---|
| MCP Registry entry | <https://registry.modelcontextprotocol.io/v0.1/servers?search=doc2mcp> |
| Live product | <https://doc2mcp.site> |
| Registry namespace | io.github.doc2mcp/doc2mcp |
| Current version | 1.0.1 |
The MCP Registry uses GitHub OIDC to claim a namespace. Whichever GitHub org or user runs mcp-publisher publish from a workflow gets exclusive publishing rights to io.github.<that-org>/*.
Since we want the public, brandable namespace io.github.doc2mcp/* (instead of io.github.gautammanak1/*), the publish workflow must run inside the doc2mcp GitHub organization. This repository holds only the publishing manifest and workflow — nothing else.
gautammanak1/doc2mcp → product code, Vercel deploy, docs site
doc2mcp/doc2mcp → this repo. server.json + publish workflowTo connect to doc2mcp from Cursor, Claude Desktop, VS Code, Windsurf, the OpenAI Agents SDK, etc., point your MCP host at the remote URL in server.json:
{
"type": "streamable-http",
"url": "https://doc2mcp.site/api/mcp/{project_id}/mcp",
"headers": { "Authorization": "Bearer <your project MCP token>" }
}Get your project_id and Bearer token from
Pushing a vX.Y.Z tag to main triggers .github/workflows/publish-mcp.yml, which:
version field in server.json to match the tag.mcp-publisher CLI.id-token: write).To cut a new version:
# from this repo
git tag v1.0.2
git push origin v1.0.2The workflow validates against the upstream JSON Schema before publish, so a bad description length or missing required field will fail loudly with a clear error.
The manifest in this repo is published under the MIT License. The doc2mcp product itself is licensed in its main repository.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.