Public registry distribution for the hosted Motecloud MCP server
SaferSkills independently audited Motecloud Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This directory contains the public distribution metadata for the hosted Motecloud MCP server.
server.json is the registry-ready descriptor for:
io.github.motecloud/motecloud-mcp-serverhttps://motecloud.io/mcpThe descriptor follows the MCP Registry server.json format and is intended for registries such as the official MCP Registry and downstream registries that consume the same metadata, including GitHub MCP Registry surfaces.
https://motecloud.io/mcphttps://motecloud.io/.well-known/oauth-authorization-serverhttps://motecloud.io/.well-known/oauth-protected-resource/mcphttps://motecloud.io/.well-known/jwks.jsonThe release-mcp workflow validates server.json, publishes a GitHub release, and can be used as the source artifact for registry submissions.
Official registry publishing currently uses the MCP Registry publisher flow. The expected namespace is GitHub-owned:
mcp-publisher publish packaging/mcp/server.jsonThe public distribution repository includes .github/workflows/publish-mcp-registry.yml, which uses GitHub Actions OIDC:
gh workflow run publish-mcp-registry.yml --repo motecloud/motecloud-mcp-serverManual publishing is also supported with an authenticated GitHub login that can prove ownership of the motecloud organization.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.