
Security News
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.
allmcps-server
Advanced tools
The official MCP server and CLI for AllMCPs.com - search, browse, get install configs, and submit MCP servers directly from your AI agent or a shell script.
The official local MCP server and CLI for AllMCPs.com — search, browse, get install configs for, and submit Model Context Protocol (MCP) servers directly from Claude, Cursor, any MCP-compatible agent, or a plain shell script.
This package is a thin stdio bridge to the AllMCPs remote MCP endpoint. Tool behavior lives server-side, so this package always exposes the current live tool set with no need to upgrade the package when a tool is added or changed.
v2.0.0 replaces the single
submit_mcptool with the full tool set below, including a renamedsubmit_mcp_server(previouslysubmit_mcp). If you depend on the old tool name, pinallmcps-server@1.
Requires Node.js 18+. Add to your MCP client config (e.g. claude_desktop_config.json):
{
"mcpServers": {
"allmcps": {
"command": "npx",
"args": ["-y", "allmcps-server"]
}
}
}
Run with a subcommand instead of a bare npx allmcps-server and it becomes a plain scriptable CLI
over the public REST API — no MCP client needed:
npx allmcps-server search postgres # search the directory
npx allmcps-server categories # list every category
npx allmcps-server server <id> # full detail for one listing
npx allmcps-server help # usage
Each prints JSON to stdout, so it composes with jq and other Unix tools. With no subcommand it
runs as the MCP stdio server described below (the default npx allmcps-server behavior).
| Tool | Required arguments | Description |
|---|---|---|
search_mcp_servers | — | Search the directory by keyword and/or category. |
get_mcp_install_config | id | Get the install config snippet and docs for a server by ID. |
list_mcp_categories | — | List all categories with server counts. |
get_boost_pricing | — | Get pricing and features for boosting/featuring a listing. |
boost_mcp_server | id | Start a sponsorship/boost order — returns a Stripe checkout URL and x402 invoice. |
get_boost_status | id | Check boost and verified-badge status for a listing. |
submit_mcp_server | name, url, email | Submit a new MCP server to the directory. |
verify_mcp_claim | id | Verify ownership and claim a listing via GitHub README, site badge, or DNS. |
submit_mcp_server submissions land in the pending review queue at allmcps.com.
The response includes a claim_url and a ready-to-paste badge_markdown snippet — adding that badge to
your repo's README verifies the listing instantly instead of waiting on manual review.
Every tool's full input schema (including optional arguments like category, description, sku, and
method) is available at runtime via the standard MCP tools/list call, or by inspecting
/api/mcp directly.
| Environment variable | Default | Purpose |
|---|---|---|
ALLMCPS_MCP_URL | https://allmcps.com/api/mcp | Override the remote endpoint this package bridges to. |
io.github.Jackalope-Dev/allmcps-server, Glama, and the LobeHub MarketplaceMIT © Jackalope Digital — see LICENSE.
FAQs
The official MCP server and CLI for AllMCPs.com - search, browse, get install configs, and submit MCP servers directly from your AI agent or a shell script.
The npm package allmcps-server receives a total of 36 weekly downloads. As such, allmcps-server popularity was classified as not popular.
We found that allmcps-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.