Distrify Mcp Runtime — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Distrify Mcp Runtime (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A FastMCP runtime that lets AI tools (Claude, ChatGPT) search electronic components, prices and availability across the Distrify distributor network through one connection — discovering distributors, requesting access, and federating a single query across every distributor the user can access.
This is the protocol + routing plane. It is deliberately separate from:
automates ERP instance for usage/event telemetry) —unrelated and untouched.
Identity, the distributor directory and access grants live in a separate Frappe "MCP management" instance (distrify_mcp_mgmt), reached over a service-token API.
Claude / ChatGPT
│ Streamable HTTP /mcp + OAuth 2.1 (DCR via FastMCP OAuth Proxy)
▼
distrify-mcp-server (this repo — Python/FastMCP, dedicated vserver)
- tools: list_distributors, request_distributor_access, search/fetch,
search_components, get_price, get_availability, get_datasheet
- federated router (parallel fan-out, merge, partial-on-rate-limit)
│ reads directory + grants (service token) │ outbound X-DISTRIFY-* headers
▼ ▼
Frappe "MCP management" instance distributor PUBLIC API /api/v1/...
(directory, network users, grants, OAuth AS) (search_keyword, get_product_detail,
get_component_pricing — list + custom)| Path | Purpose |
|---|---|
src/distrify_mcp/server.py | FastMCP app + tool definitions + entrypoint |
src/distrify_mcp/router.py | Distributor public-API client + federated fan-out |
src/distrify_mcp/mgmt_client.py | Client for the Frappe management service API (+ dev fallback) |
src/distrify_mcp/normalize.py | Tolerant extractors for public-API payloads |
src/distrify_mcp/config.py | Env-sourced settings (DISTRIFY_MCP_*) |
Dockerfile, .github/workflows/build.yml | Containerization + GHCR publish for Watchtower |
deploy/docker-compose.yml | vserver stack (service + Watchtower auto-update) |
pip install -e ".[dev]"
cp .env.example .env # set DEV_CLIENT_ID / DEV_API_KEY from an API Key Management doc
distrify-mcp # serves Streamable HTTP at http://localhost:8000/mcpInspect the tools without an AI client:
npx @modelcontextprotocol/inspector
# connect to http://localhost:8000/mcp (Streamable HTTP)Read-only MVP, built in stages (see the plan). dev_mode runs against a single hardcoded distributor until the management service API and OAuth are wired in. OAuth (FastMCP OAuth Proxy → Frappe management IdP) and the management API are tracked as follow-up work.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.