Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
Perplexity for MCP. Discover the right tool for a problem, see its trust card (prompt-injection risk, permission overreach, publisher status), connect it in one click, and execute it through a secure, audited gateway — one product, one config.
See ROADMAP.md for the full plan. Blueprint: ../Singularity_Blueprint.md.
pip install -r requirements.txt
copy .env.example .env # optional, defaults are fine (SQLite)
python scripts/seed_index.py # builds index + embeddings (first run downloads ~35MB model)
python -m uvicorn app.main:app --reload # http://127.0.0.1:8000/docs
A fresh boot with an empty database auto-seeds itself — seed_index.py is only needed
for manual re-seeding.
Singularity is a native MCP server (streamable HTTP, stateless) at /mcp.
VS Code / Copilot Chat — .vscode/mcp.json:
{ "servers": { "singularity": { "type": "http", "url": "http://127.0.0.1:8000/mcp" } } }
Cursor — ~/.cursor/mcp.json:
{ "mcpServers": { "singularity": { "url": "http://127.0.0.1:8000/mcp" } } }
Claude Code CLI:
claude mcp add --transport http singularity http://127.0.0.1:8000/mcp
Then just ask your agent: "my team needs expense tracking" — it calls find_solutions
and gets ranked options with trust cards and security flags.
One-click install (replace the URL after deploying): Install in VS Code
/mcpnow requires OAuth (a popup at/authorize/<slug>supplies the access token). For a curl-able check use/healthand/.well-known/oauth-authorization-server.
| Tool | What it does |
|---|---|
find_solutions(problem, top_k?, max_pricing_tier?) | Ranked, trust-scored recommendations with plain-language security flags |
get_trust_report(slug) | Full security card: permissions requested vs needed, injection-scan verdicts, publisher status |
compare_tools(slugs[]) | Side-by-side trust table for shortlisted candidates |
Every result carries fit_score, trust_score, rank_score, trust_flags, and a
human-readable rationale. The seed index includes quickledger-pro, an intentionally
poisoned fictional tool — ask about expenses and watch it get flagged
(suspicious_description_imperative, hidden_unicode_characters, permission_overreach)
and pushed down the ranking.
Full walkthrough in DEPLOY.md. Summary:
+psycopg driver segment + ?sslmode=requirerender.yamlSINGULARITY_DATABASE_URL env var when promptedhttps://<app>.onrender.com/mcp is liveAfter deploying (public HTTPS required), list Singularity so others can find it:
server.json
(replace XXXX with your Render app name), then:
npx mcp-publisher@latest init # scaffolds/validates server.json
npx mcp-publisher@latest login # prove io.github.<you> ownership via GitHub
npx mcp-publisher@latest publish # listed at https://registry.modelcontextprotocol.io within minutes
smithery.yaml)mcp-server, mcp, ai-security topics to your repo; PulseMCP/MCP.so crawlers pick it up within 1–2 weeksTip: registries re-crawl weekly and strip verified badges from sleeping servers —
Render's $7/mo Starter plan keeps Singularity always-on during listing/investor periods.
pytest -v
singularity/
main.py FastAPI app factory + lifespan (auto-seed, mounts MCP)
mcp_server.py native MCP server: find_solutions / get_trust_report / compare_tools
config.py env-driven settings (SINGULARITY_* prefix)
database.py SQLAlchemy engine/session (SQLite dev, Postgres prod)
models.py Tool + AuditLog tables
schemas.py request/response contracts
middleware/
rate_limit.py per-IP token-bucket limiter (X-Forwarded-For aware)
services/
discovery_engine.py heuristic intent parsing
recommendation_index.py in-memory vector search over seeded tools
ranking.py fit/trust blend + rationale builder
scanner.py static injection/overreach scan (Phase 2 preview)
seeder.py seed logic shared by CLI and boot-time auto-seed
embeddings.py fastembed provider (bge-small-en-v1.5)
routers/
recommend.py POST /recommend, GET /tools
data/seed_tools.json curated 21-tool index incl. demo attack sample (tier1/tier2/tier3)
scripts/seed_index.py manual seeding CLI
scripts/smoke_execute.ps1 authenticated REST execute smoke test
scripts/smoke_oauth.py OAuth discovery + config smoke test
Dockerfile / render.yaml one-command Render deployment
server.json / smithery.yaml registry publishing manifests (fill placeholders first)
tests/ pytest suite (API + scanner + MCP tools & endpoint)
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.