
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
Thin MCP stdio client for the Sealed skill marketplace — carries inputs and outputs only; skill bodies never reach this process.
Thin MCP stdio client for Sealed — the skill marketplace where your skill runs sealed.
This package is a pure proxy. It connects your MCP-capable agent to a remote Sealed server and exposes two tools:
| Tool | What it does | Annotations |
|---|---|---|
list_skills | Lists the public skill catalog (name, description, input schema, price per call) | readOnlyHint: true |
run_skill | Runs a skill server-side and returns only its output + price/mode meta. Each call spends wallet balance at the listed per-call price. | readOnlyHint: false, destructiveHint: false |
Skill bodies never reach this process. Skills execute on Sealed's infrastructure; this client only carries your inputs up and the output back. There is no local execution mode — SEALED_API_URL is required.
Zero runtime dependencies. Plain Node 18+ (uses the global fetch).
npm naming: this package targets the unscoped name
sealed-mcpand carriesmcpName: io.github.edwardyen724-g/sealedfor the official MCP registry. If that npm name is unavailable at publish time, the fallbacks are the scoped names@sealed/mcpor@sealedrun/mcp— updatepackage.json, registry drafts, and install snippets together.
claude mcp add sealed --env SEALED_API_URL=https://sealed.run --env SEALED_API_KEY=sealed_sk_… -- npx -y sealed-mcp
Add to ~/.cursor/mcp.json (Cursor) or ~/.codeium/windsurf/mcp_config.json (Windsurf):
{
"mcpServers": {
"sealed": {
"command": "npx",
"args": ["-y", "sealed-mcp"],
"env": {
"SEALED_API_URL": "https://sealed.run",
"SEALED_API_KEY": "sealed_sk_…"
}
}
}
}
Spawn the binary and speak newline-delimited JSON-RPC 2.0 over stdin/stdout (initialize, tools/list, tools/call):
SEALED_API_URL=https://sealed.run SEALED_API_KEY=sealed_sk_… npx -y sealed-mcp
| Variable | Required | Purpose |
|---|---|---|
SEALED_API_URL | Yes | Base URL of the Sealed API (e.g. https://sealed.run). The client exits with an error if unset. |
SEALED_API_KEY | No | Your Sealed API key (sealed_sk_…), sent as the bearer token. Without it, calls run unauthenticated and most servers will reject paid runs. |
Fixed, non-leaking error strings: unauthorized (bad/missing key), insufficient funds (top up your wallet), output blocked by leak gate, unknown skill: <id>, cannot reach the Sealed API. Server error bodies are never echoed.
/signup endpoint (production emails you a single-use sign-in link that shows the key once)FAQs
Thin MCP stdio client for the Sealed skill marketplace — carries inputs and outputs only; skill bodies never reach this process.
The npm package sealed-mcp receives a total of 60 weekly downloads. As such, sealed-mcp popularity was classified as not popular.
We found that sealed-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.