Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for AI agents that generate, verify, and deploy Cloudflare-native apps from reusable microservices.sh modules.
This package is a standalone stdio MCP server. It vendors a small microservices.sh SDK/module-contract snapshot until the public SDK is split out.
@microservices-sh/mcp gives coding agents a typed planning layer for building production-oriented Cloudflare apps. Agents can discover verified templates and modules, inspect module contracts, compose an app plan, validate configuration, generate project files for review, run readiness checks, and prepare approval-gated preview deployments through the microservices.sh control plane.
It is useful when an agent needs to build apps with common product modules such as auth, booking, customer records, payments, files, and audit logs without inventing each integration from scratch.
pnpm add -D @microservices-sh/mcpOr run it directly after publish:
pnpm dlx @microservices-sh/mcpOr install from Glama:
{
"mcpServers": {
"microservices": {
"command": "microservices-mcp",
"env": {
"MICROSERVICES_API_URL": "https://api.microservices.sh",
"MICROSERVICES_API_KEY": "favored-secret-manager-reference"
}
}
}
}For local development inside this repo:
{
"mcpServers": {
"microservices-local": {
"command": "node",
"args": ["/absolute/path/to/mcp/dist/index.js"]
}
}
}Build the local package first:
pnpm buildFor agent-oriented one-click install guidance, see llms-install.md.
Read-only and local planning tools:
list_templatesinspect_templatelist_modulesinspect_modulelist_module_docsget_module_doccompose_appvalidate_configgenerate_projectrun_checksplan_add_modulecheck_updatesplan_module_upgradeget_secrets_statuscreate_preview_planRemote control-plane tools:
deploy_previewget_deployment_statusdeploy_preview is mutating and requires confirm: "preview". Run create_preview_plan first.
| Variable | Purpose |
|---|---|
MICROSERVICES_API_URL | Remote control-plane URL. Defaults to https://api.microservices.sh. |
MICROSERVICES_API_KEY | Bearer token for remote tools. |
MICROSERVICES_TOKEN | Fallback bearer token. |
Secret values are never returned by the MCP tools.
The package is published to npm, listed in the official MCP Registry, and verified by Glama:
@microservices-sh/mcpsh.microservices/mcp@microservices-sh/mcphttps://api.microservices.sh/mcpThe package declares "mcpName": "sh.microservices/mcp" in package.json. Docker/OCI packaging should wrap this same stdio server rather than forking behavior.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.