the recordCopied from the official MCP registry, exactly as it holds it.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.eltociear/repo-security-scanner",
"description": "Audit GitHub repos for malicious and supply-chain code before you depend on them.",
"title": "Repo Security Scanner — Malicious Code & Supply Chain",
"repository": {
"url": "https://github.com/eltociear/my-molt-agent",
"source": "github"
},
"version": "0.1.0",
"websiteUrl": "https://apify.com/eltociear/mcp-server-security-scanner",
"remotes": [
{
"type": "streamable-http",
"url": "https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner",
"headers": [
{
"description": "Apify API token, sent as `Bearer <token>`. The endpoint answers 401 without one. Runs are billed to YOUR Apify account at this Actor's pay-per-event price — there is no free tier here and no charge to us.",
"isRequired": true,
"isSecret": true,
"name": "Authorization"
}
]
}
]
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-08-15T02:32:48.275064Z",
"publishedAt": "2026-08-15T02:32:48.275064Z",
"updatedAt": "2026-08-15T02:32:48.275064Z",
"isLatest": true
}
}
}
Make it installable
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
What this is
MCP server
application/mcp-server-record+jsonhosted · an address you callversion 0.1.0last seen 2026-08-23
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.