
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@three-ws/marketplace-mcp
Advanced tools
Browse the three.ws agent marketplace and skills catalog from any AI agent. browse_agents and browse_skills search & page the public listings; agent_detail and the category tools round out discovery. Read-only — no key, no signer, no payment.
Browse the three.ws agent marketplace and skills catalog from any AI agent.
A Model Context Protocol server that gives any AI assistant browse and discovery of the three.ws marketplace over stdio. Search and page the published agents, drill into one by id, and explore the reusable skills catalog — all from the public three.ws API.
No API key, no signer, no payment — every call hits the public /api/marketplace and /api/skills endpoints. Creating or publishing agents and skills is the authenticated write path on the HTTP API; this server exposes browse/discovery only.
npm install @three-ws/marketplace-mcp
Or run with npx (no install):
npx @three-ws/marketplace-mcp
Claude Code, one line:
claude mcp add marketplace -- npx -y @three-ws/marketplace-mcp
Claude Desktop / Cursor (claude_desktop_config.json or mcp.json):
{
"mcpServers": {
"marketplace": {
"command": "npx",
"args": ["-y", "@three-ws/marketplace-mcp"]
}
}
}
Inspect the surface with the MCP Inspector:
npx -y @modelcontextprotocol/inspector npx @three-ws/marketplace-mcp
| Tool | Type | What it does |
|---|---|---|
browse_agents | read-only | Search & page the agent marketplace — filter by category and query, sort, paginate by cursor. |
agent_detail | read-only | Fetch one published agent by id (system prompt, capabilities, author, ratings, skill prices, avatar). |
agent_categories | read-only | List agent categories with the count of published agents in each, plus the overall total. |
browse_skills | read-only | Search & page the skills catalog — filter by query and category, sort, paginate by cursor. |
skill_categories | read-only | List skill categories that have at least one public skill, each with a slug, label, and count. |
browse_agents — category (optional slug), q (optional free text), sort (recommended | recent | popular | top_rated, default recommended), limit (1–48, default 24), cursor (optional pagination cursor).
agent_detail — id (required: the agent's UUID, from a browse_agents card).
agent_categories — no parameters.
browse_skills — q (optional free text), category (optional slug), sort (popular | new | az, default popular), limit (1–50, default 20), cursor (optional pagination cursor).
skill_categories — no parameters.
// browse_agents
> { "q": "code review", "sort": "top_rated", "limit": 3 }
{
"ok": true,
"items": [
{
"id": "a1b2c3d4-…",
"name": "Code Reviewer",
"description": "Reviews diffs for bugs and style.",
"category": "programming",
"tags": ["code", "review"],
"rating_avg": 4.8,
"rating_count": 22,
"views_count": 1340,
"forks_count": 41,
"thumbnail_url": "https://…",
"avatar_glb_url": "https://…"
}
],
"next_cursor": "3"
}
Pass next_cursor back as cursor to fetch the following page.
https://three.ws (or your own THREE_WS_BASE).| Variable | Required | Default |
|---|---|---|
THREE_WS_BASE | no | https://three.ws |
THREE_WS_TIMEOUT_MS | no | 20000 |
Part of the three.ws SDK suite — 3D AI agents, on-chain identity, and agent payments.
Website · Changelog · GitHub
FAQs
Browse the three.ws agent marketplace and skills catalog from any AI agent. browse_agents and browse_skills search & page the public listings; agent_detail and the category tools round out discovery. Read-only — no key, no signer, no payment.
We found that @three-ws/marketplace-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.