Ai Portfolio Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Ai Portfolio Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Dual-protocol AI portfolio server — an MCP server for structured tool access and an A2A agent ("Have You Met Mario?") for conversational discovery. Both serve the same data about my experience, skills, projects, and services.
Traditional portfolios are static. This one lets potential clients interact with my portfolio using their own AI tools — ask specific questions, get structured answers, and discover what I can do for them. The medium demonstrates the skill being sold.
mario-ai-portfolio/
├── src/
│ ├── server.py # Combined ASGI dispatcher (production entry point)
│ ├── mcp_server.py # FastMCP server — 7 tools
│ ├── a2a_server.py # A2A agent — conversational interface
│ └── data/ # Shared content modules
│ ├── about.py
│ ├── skills.py
│ ├── services.py
│ ├── projects.py
│ ├── experience.py
│ └── contact.py
├── Dockerfile # Combined production image
├── Dockerfile.mcp # Standalone MCP server
├── Dockerfile.a2a # Standalone A2A agent
└── render.yaml # Render deployment config7 tools exposed via Streamable HTTP:
| Tool | Description |
|---|---|
get_about_me() | Professional bio, background, timezone, availability |
get_skills(category?) | Technical skills by category (ai, automation, backend, frontend) |
get_services() | Service offerings and pricing approach |
get_projects() | Summary list of portfolio projects |
get_project_detail(name) | Deep-dive on a specific project |
get_experience() | Professional timeline and education |
get_contact_info() | Contact details and how to hire |
Add the following config to your MCP client of choice:
Claude Code — run in your terminal:
claude mcp add mario-portfolio --transport http https://<your-service>.onrender.com/mcpClaude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"mario-portfolio": {
"url": "https://<your-service>.onrender.com/mcp"
}
}
}Cursor / VS Code — add to .cursor/mcp.json or .vscode/mcp.json:
{
"servers": {
"mario-portfolio": {
"url": "https://<your-service>.onrender.com/mcp"
}
}
}Then just ask your AI assistant anything about Mario — skills, projects, services, availability.
Conversational agent-to-agent interface powered by Llama 3.1 8B via Groq. Supports agent discovery via the A2A protocol.
https://<your-service>.onrender.com/.well-known/agent.jsonDiscover the agent — fetch the Agent Card:
curl https://<your-service>.onrender.com/.well-known/agent.jsonSend a message — via JSON-RPC 2.0:
curl https://<your-service>.onrender.com/ \
-X POST \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": "1",
"method": "message/send",
"params": {
"message": {
"role": "user",
"parts": [{"kind": "text", "text": "What projects has Mario built?"}],
"messageId": "msg-001"
}
}
}'From Python — using the a2a-sdk client:
from a2a.client import A2AClient
async with A2AClient(url="https://<your-service>.onrender.com/") as client:
card = await client.get_card()
print(card.name) # "Have You Met Mario? — AI Automation Engineer"Any A2A-compatible agent or orchestrator can discover and interact with this agent automatically via the Agent Card endpoint.
Requires GROQ_API_KEY in a .env file.
# Combined server (MCP + A2A on port 8000)
uv run python -m uvicorn src.server:app --reload
# Or run services independently:
uv run python -m uvicorn src.mcp_server:app --port 8000 # MCP only
uv run python -m uvicorn src.a2a_server:app --port 9000 # A2A onlyVerify locally:
curl http://localhost:8000/health
curl http://localhost:8000/.well-known/agent.jsonSingle Docker service deployed on Render free tier.
| Endpoint | Path |
|---|---|
| Health | /health |
| MCP Server | /mcp |
| A2A Agent Card | /.well-known/agent.json |
| A2A Messages | POST / |
The service stays permanently warm via a UptimeRobot monitor pinging /health every 5 minutes (free plan).
render.yaml automaticallyGROQ_API_KEY — your Groq API keyAGENT_URL — the Render service URL (set after first deploy)/health at 5-minute intervalsMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.