Envato Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Envato Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for the Envato API. It lets MCP-compatible AI clients (Claude Desktop, Cursor, and others) search the Envato Market catalog, look up author statistics, inspect a buyer's purchases, and read the authenticated user's account details.
listings across Envato Market sites (ThemeForest, CodeCanyon, etc.).
market-wide totals.
purchase codes.
Every tool validates its input with zod and returns the raw Envato JSON response. API errors (including 401/403 auth failures and 429 rate limiting) are surfaced as clear, actionable messages.
tools.
ENVATO_TOKEN environment variable.
Run directly with npx (no install required):
ENVATO_TOKEN=your-token-here npx envato-mcpThe server communicates over stdio and is intended to be launched by an MCP client rather than used interactively.
Add the server to your claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"envato": {
"command": "npx",
"args": ["-y", "envato-mcp"],
"env": {
"ENVATO_TOKEN": "your-token-here"
}
}
}
}Add the server to ~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{
"mcpServers": {
"envato": {
"command": "npx",
"args": ["-y", "envato-mcp"],
"env": {
"ENVATO_TOKEN": "your-token-here"
}
}
}
}After saving, restart the client so it picks up the new server.
| Tool | Description | Arguments |
|---|---|---|
envato_search_items | Search the catalog for items matching a term. | term (string, required), site (string, optional), page (int, optional), page_size (int 1–100, optional) |
envato_popular_items | Most popular items for a site. | site (string, e.g. themeforest) |
envato_categories | All categories for a site. | site (string, e.g. codecanyon) |
| Tool | Description | Arguments |
|---|---|---|
envato_user_info | Public account details for a user. | username (string) |
envato_user_items_by_site | Number of items a user sells per site. | username (string) |
envato_user_badges | Badges earned by a user. | username (string) |
envato_market_totals | Total users and items across Envato Market. | _none_ |
| Tool | Description | Arguments |
|---|---|---|
envato_list_purchases | List the authenticated buyer's purchases. | filter_by (enum, optional), page (int, optional) |
envato_download_link | Download URL for a purchased item. | item_id (int) |
envato_verify_purchase | Verify a purchase code and return sale details. | code (string) |
| Tool | Description | Arguments |
|---|---|---|
envato_account | The authenticated user's account details. | _none_ |
envato_my_username | The authenticated user's username. | _none_ |
envato_my_email | The authenticated user's email. | _none_ |
npm install # install dependencies
npm run dev # rebuild on change (tsup --watch)
npm run typecheck # type-check with tsc (no emit)
npm run lint # lint with ESLint
npm run build # bundle to dist/ with tsupThe build outputs an executable ESM bundle to dist/index.js with a Node shebang, wired up as the envato-mcp bin.
MIT © 2026 Scott McAuley
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.