AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

Sourced

mcp-ryancodrai-sourced · by RyanCodrai

Source code search for every package on PyPI and npm.

No reviews yet
0 installs
22 views
0.0% view→install

Install

$ agentstack add mcp-ryancodrai-sourced

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v1.0.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v1.0.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
5mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Sourced? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Sourced.dev

[](https://sourced.dev) [](LICENSE) [](https://sourced.dev) [](https://sourced.dev) [](https://modelcontextprotocol.io)

Source code search for every package on PyPI and npm.

Sourced.dev provides coding agents with direct access to dependency source code through the Model Context Protocol (MCP). Instead of relying on training data or web searches, agents can read, search, and navigate the actual source of any package — as if it were on your local machine.

Currently tracking all 800,000+ Python packages and all 3,000,000+ npm packages. New releases are indexed within 5 minutes of publication.

Quick Start

Install the MCP server in one command. It authenticates via GitHub and configures your coding agents automatically:

curl -sL sourced.dev/install | sh

The installer will:

  1. Authorize with GitHub.
  2. Create an API key.
  3. Configure the MCP server for your selected agents.

Restart your coding agents after installation to start using Sourced.

Supported Agents

The following coding agents are supported out of the box:

Capabilities

Sourced.dev exposes the following tools to your coding agent via MCP:

| Tool | Description | |------|-------------| | read | Read a file from a package's source code with line numbers. | | grep | Search for a regex pattern across a package's source tree. | | glob | Find files matching a glob pattern within a package. |

All tools accept an ecosystem (e.g. pypi, npm), a package_name, and an optional version (defaults to latest).

Ecosystem Support

  • PyPI — 800,000+ packages
  • npm — 3,000,000+ packages
  • Maven/Gradle — planned
  • RubyGems — planned
  • Crates.io (Rust) — planned

Next Steps

License

MIT License — see [LICENSE](LICENSE) for details.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v1.0.0 Imported from the upstream source.