Developer · Local MCP server

Sourcery

Sourcery security findings: MCP server, CLI, and fix-prompt builder over the Sourcery API.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.abyssbugg-labs/sourcery
Version
0.2.4
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-09-30
Updated
2026-09-30
Publisher
abyssbugg-labs (GitHub)
Repository
github.com/abyssbugg-labs/sourcery-agent-bundle
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npm@abyssbugg/sourcery0.2.4stdioSOURCERY_API_KEY (required, secret)

How to connect Sourcery

Sourcery runs locally from a Node.js package published to the npm registry: @abyssbugg/sourcery version 0.2.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @abyssbugg/sourcery@0.2.4. It reads the environment variable SOURCERY_API_KEY (required, secret); set it in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "sourcery": {
      "command": "npx",
      "args": [
        "-y",
        "@abyssbugg/sourcery@0.2.4"
      ],
      "env": {
        "SOURCERY_API_KEY": "<secret>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
SourcedSource code search for every package on PyPI and npm.Remote · HTTPmcp.sourced.dev
Sourcegraph MCPSearch public code on Sourcegraph. No key required.Local · stdionpm: sourcegraph-mcp
Sourcemap Retrace MCPDecodes minified production stack traces back to original TypeScript source using source maps.Local · stdionpm: sourcemap-retrace-mcp
SourcerightReference verification MCP server for CSL bibliographies, evidence, and audited writes.Local · stdioOCI image (Docker): ghcr.io/edithatogo/sourceright-mcp:0.1.20
SourceyStdio bridge to Sourcey startup offers and Agent Readiness report cards.Local · stdionpm: @sourcey/mcp-server
Sovereign GatewayGating proxy for MCP servers: policy, verification and one audit trail across upstreams.Local · stdioPyPI: sovereign-mcp-gateway
Spa Reader MCPMCP Server that renders JavaScript SPA pages and extracts LLM-ready Markdown content.Local · stdionpm: spa-reader-mcp
SpamTitanMCP server for SpamTitan email security — quarantine, allow/block lists, and policy management.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/spamtitan-mcp:v1.3.3