MCP Server

Sigistry Plugin & Skill Catalog

com.sigistry/plugin-catalog

What this MCP does

Searches verified Claude Code plugins and skills, retrieves portable skill sources, and provides MCP server security scorecards.

get_plugin
Get a Claude Code plugin
Get the full details of a single Sigistry plugin by its id, including install commands, component counts, and its security-audit result (per-check pass/fail from the Verified by Sigistry methodology).
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'the plugin id, e.g. "sql-safety-net"'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id', 'name', 'tags', 'commands', 'agents', 'skills', 'counts', 'installMarketplace', 'installCommand', 'searchableText'], 'properties': {'id': {'type': 'string'}, 'name': {'type': 'string'}, 'tags': {'type': 'array', 'items': {'type': 'string'}, 'description': 'keywords from the marketplace entry'}, 'agents': {'type': 'array', 'items': {'type': 'string'}, 'description': 'relative paths to agent files'}, 'author': {'type': 'object', 'properties': {'url': {'type': 'string'}, 'name': {'type': 'string'}}, 'additionalProperties': False}, 'counts': {'type': 'object', 'required': ['commands', 'agents', 'skills'], 'properties': {'agents': {'type': 'integer'}, 'skills': {'type': 'integer'}, 'commands': {'type': 'integer'}}, 'description': 'component counts', 'additionalProperties': False}, 'skills': {'type': 'array', 'items': {'type': 'string'}, 'description': 'relative paths to skill manifests'}, 'license': {'type': 'string'}, 'version': {'type': 'string'}, 'category': {'type': 'string'}, 'commands': {'type': 'array', 'items': {'type': 'string'}, 'description': 'relative paths to command files'}, 'homepage': {'type': 'string'}, 'description': {'type': 'string'}, 'verification': {'anyOf': [{'type': 'object', 'required': ['status', 'checks'], 'properties': {'date': {'type': 'string', 'description': 'date of the last audit run'}, 'repo': {'type': 'string', 'description': 'external repo (owner/name), when externally hosted'}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'status'], 'properties': {'id': {'type': 'string'}, 'title': {'type': 'string'}, 'detail': {'type': 'string'}, 'status': {'type': 'string', 'description': 'pass | fail | n/a'}}, 'additionalProperties': False}, 'description': 'per-check results of the security audit'}, 'commit': {'type': 'string', 'description': 'pinned commit the verification applies to'}, 'status': {'type': 'string', 'description': 'verified | listed | stale | failed'}, 'hosting': {'type': 'string', 'description': 'registry (vendored) | external (author repo)'}, 'badgeUrl': {'type': 'string', 'description': 'SVG badge for this plugin'}, 'firstSeen': {'type': 'string', 'description': 'date the plugin entered the registry'}, 'methodologyUrl': {'type': 'string'}, 'methodologyVersion': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}], 'description': 'security-audit result for this plugin (null when never audited)'}, 'installCommand': {'type': 'string', 'description': 'command to install this plugin'}, 'searchableText': {'type': 'string', 'description': 'lowercased text used for matching'}, 'installMarketplace': {'type': 'string', 'description': 'command to add the marketplace to Claude Code'}}, 'additionalProperties': False}
get_scorecard
Get an MCP server scorecard
Get the full scorecard for one graded MCP server by its id: the overall grade, per-axis pass/partial/fail with cited evidence, hardening notes, the rubric version, and the exact commit graded. Grades describe the pinned commit only; a re-grade at a newer commit can be requested via an issue on the marketplace repo.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'scorecard id, e.g. "sigistry-catalog" (find ids via list_scorecards)'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id', 'name', 'grade', 'axes'], 'properties': {'id': {'type': 'string'}, 'axes': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'status', 'evidence'], 'properties': {'id': {'type': 'string'}, 'title': {'type': 'string'}, 'status': {'type': 'string', 'description': 'pass | partial | fail | n/a'}, 'evidence': {'type': 'string', 'description': 'the file/behavior the result rests on'}}, 'additionalProperties': False}, 'description': 'per-axis results with evidence'}, 'date': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'name': {'type': 'string'}, 'repo': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'grade': {'type': 'string'}, 'notes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'hardening suggestions and context'}, 'commit': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'endpoint': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'rubricUrl': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'rubricVersion': {'anyOf': [{'anyOf': [{'not': {}}, {'type': 'string'}]}, {'type': 'null'}]}, 'selfAssessment': {'type': 'boolean'}}, 'additionalProperties': False}
get_skill
Get a verified skill (with portable source)
Get one Sigistry skill by name, including the full raw SKILL.md source. The source is portable: it can be applied directly in any SKILL.md-aware agent (Claude Code, Claude Desktop, and others) without installing anything, or installed natively in Claude Code via the parent plugin, which keeps it verified and updated. The returned skill passed the Sigistry skill-safety check at the parent plugin's verification date.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'the skill name, e.g. "assessment-scoring" (find names via search_skills)'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'description', 'plugin', 'verification', 'installCommand', 'detailUrl', 'pluginCategory', 'verifiedDate', 'hosting', 'sourceUrl', 'source'], 'properties': {'name': {'type': 'string', 'description': 'stable skill name, e.g. "assessment-scoring"'}, 'repo': {'type': 'string', 'description': 'author repo (owner/name), when externally hosted'}, 'commit': {'type': 'string', 'description': 'pinned commit the source is served from, when externally hosted'}, 'plugin': {'type': 'string', 'description': 'parent plugin id that ships this skill'}, 'source': {'type': ['string', 'null'], 'description': 'the complete raw SKILL.md (frontmatter + body); null only if the fetch failed'}, 'hosting': {'type': 'string', 'description': '"registry" (vendored here) or "external" (author repo, verified at a pinned commit)'}, 'detailUrl': {'type': 'string', 'description': 'human-readable page for this skill'}, 'sourceUrl': {'type': 'string', 'description': 'GitHub location of the skill directory'}, 'description': {'type': 'string', 'description': 'the skill trigger: when an agent should load it'}, 'verification': {'type': 'string', 'description': 'verification status of the parent plugin; prefer "verified"'}, 'verifiedDate': {'type': ['string', 'null'], 'description': 'date of the verification run covering this skill'}, 'installCommand': {'type': 'string', 'description': 'Claude Code command installing the parent plugin (skill loads automatically)'}, 'pluginCategory': {'type': ['string', 'null'], 'description': 'category of the parent plugin'}}, 'additionalProperties': False}
list_categories
List plugin categories
List the distinct plugin categories in the Sigistry marketplace with a count of plugins in each, plus the total plugin count.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['categories', 'total'], 'properties': {'total': {'type': 'integer', 'description': 'total number of plugins'}, 'categories': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'count'], 'properties': {'count': {'type': 'integer', 'description': 'plugins in this category'}, 'category': {'type': 'string'}}, 'additionalProperties': False}, 'description': 'categories sorted by descending plugin count'}}, 'additionalProperties': False}
list_scorecards
List MCP server scorecards
List the public MCP servers Sigistry has independently graded against its scorecard rubric (transport, stateless core, lifecycle, authorization, tool design, security hygiene), each with an overall grade A-F and the exact commit graded. Useful before connecting an agent to a third-party MCP server: check whether it has been assessed and how it scored. Use get_scorecard for the full per-axis breakdown.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['rubricVersion', 'rubricUrl', 'total', 'scorecards'], 'properties': {'total': {'type': 'integer'}, 'rubricUrl': {'type': ['string', 'null']}, 'scorecards': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'grade', 'repo', 'commit', 'endpoint', 'date', 'selfAssessment'], 'properties': {'id': {'type': 'string'}, 'date': {'type': ['string', 'null']}, 'name': {'type': 'string'}, 'repo': {'type': ['string', 'null']}, 'grade': {'type': 'string', 'description': 'overall grade A-F'}, 'commit': {'type': ['string', 'null'], 'description': 'the graded commit'}, 'endpoint': {'type': ['string', 'null']}, 'selfAssessment': {'type': 'boolean', 'description': "true for Sigistry's own servers"}}, 'additionalProperties': False}}, 'rubricVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}
search_plugins
Search Claude Code plugins
Search the Sigistry marketplace of Claude Code plugins by keyword and/or category. Returns matches with their install command and verification status (the registry runs an eight-check security audit; prefer "verified" plugins when recommending an install).
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'query': {'type': 'string', 'description': 'keywords, e.g. "database migration"'}, 'category': {'type': 'string', 'description': 'e.g. "database", "devops", "git"'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['results'], 'properties': {'results': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'installCommand', 'verification'], 'properties': {'id': {'type': 'string', 'description': 'stable plugin id, e.g. "sql-safety-net"'}, 'name': {'type': 'string', 'description': 'human-readable plugin name'}, 'category': {'type': 'string', 'description': 'marketplace category'}, 'description': {'type': 'string', 'description': 'one-line summary'}, 'verification': {'type': 'string', 'description': 'verification status: "verified" (passed the eight-check security methodology), "stale" (verified at a pinned commit the repo has since moved past), "listed" (in the registry but not audited), "failed", or "unknown". Prefer verified plugins. Methodology: https://sigistry.com/verification'}, 'installCommand': {'type': 'string', 'description': 'Claude Code install command'}}, 'additionalProperties': False}, 'description': 'up to 15 matching plugins, best matches first'}}, 'additionalProperties': False}
search_skills
Search verified Claude Code skills
Search the Sigistry catalog of verified skills (SKILL.md instruction sets for AI agents) by keyword, optionally filtered to one parent plugin. Every skill passed the skill-safety check: no command shadowing, honestly-scoped triggers, no injection or concealment language, no unsafe scripts. Use get_skill to fetch the full portable source of a match.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'query': {'type': 'string', 'description': 'keywords, e.g. "changelog" or "security review"'}, 'plugin': {'type': 'string', 'description': 'restrict to skills shipped by this plugin id'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['results'], 'properties': {'results': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'description', 'plugin', 'verification', 'installCommand', 'detailUrl'], 'properties': {'name': {'type': 'string', 'description': 'stable skill name, e.g. "assessment-scoring"'}, 'plugin': {'type': 'string', 'description': 'parent plugin id that ships this skill'}, 'detailUrl': {'type': 'string', 'description': 'human-readable page for this skill'}, 'description': {'type': 'string', 'description': 'the skill trigger: when an agent should load it'}, 'verification': {'type': 'string', 'description': 'verification status of the parent plugin; prefer "verified"'}, 'installCommand': {'type': 'string', 'description': 'Claude Code command installing the parent plugin (skill loads automatically)'}}, 'additionalProperties': False}, 'description': 'up to 20 matching skills, best matches first'}}, 'additionalProperties': False}
verify_plugin
Verify a Claude Code plugin (pre-publish, runs locally)
Get the recipe to run the Sigistry verification methodology (the eight static checks that gate the Verified badge: manifest integrity, hook safety, agent tool scopes, command hygiene, skill structure, skill safety, no secrets, documentation) against a plugin BEFORE publishing it. The verification runs entirely on the local machine via a dependency-free open-source Node script; the plugin code never leaves the user's computer and this server performs no computation. Call this when the user wants their plugin or skill checked, then follow the returned steps: download the script, run it against the plugin directory, and fix any FAIL findings it reports.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'pluginPath': {'type': 'string', 'description': 'local path to the plugin directory, used to fill in the run command (optional)'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['runsWhere', 'methodologyVersion', 'methodologyUrl', 'checks', 'steps', 'commands', 'interpreting', 'nextSteps'], 'properties': {'steps': {'type': 'array', 'items': {'type': 'string'}, 'description': 'what the agent should do, in order'}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'what'], 'properties': {'id': {'type': 'string'}, 'what': {'type': 'string'}, 'title': {'type': 'string'}}, 'additionalProperties': False}, 'description': 'the eight checks the script will run'}, 'commands': {'type': 'object', 'required': ['macos_linux', 'windows', 'alternative_clone'], 'properties': {'windows': {'type': 'string', 'description': 'download + run one-liner for PowerShell'}, 'macos_linux': {'type': 'string', 'description': 'download + run one-liner for bash/zsh'}, 'alternative_clone': {'type': 'string', 'description': 'equivalent via cloning the marketplace repo'}}, 'additionalProperties': False}, 'nextSteps': {'type': 'string'}, 'runsWhere': {'type': 'string', 'description': 'always "local": verification executes on the user\'s machine'}, 'interpreting': {'type': 'string'}, 'methodologyUrl': {'type': 'string'}, 'methodologyVersion': {'type': 'string'}}, 'additionalProperties': False}
Added
verify_plugin
Sept. 17, 2026, 12:37 p.m.
Added
get_scorecard
Sept. 17, 2026, 12:37 p.m.
Added
list_scorecards
Sept. 17, 2026, 12:37 p.m.
Added
get_skill
Sept. 17, 2026, 12:37 p.m.
Added
search_skills
Sept. 17, 2026, 12:37 p.m.
Added
list_categories
Sept. 17, 2026, 12:37 p.m.
Added
get_plugin
Sept. 17, 2026, 12:37 p.m.
Added
search_plugins
Sept. 17, 2026, 12:37 p.m.