Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/mahmoud20138/mcp-lookupWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/mahmoud20138/mcp-lookup/mcp-search)<a href="https://agentmods.dev/commands/mahmoud20138/mcp-lookup/mcp-search"><img src="https://agentmods.dev/badge/commands/mahmoud20138/mcp-lookup/mcp-search/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/mahmoud20138/mcp-lookup/mcp-search"><img src="https://agentmods.dev/badge/commands/mahmoud20138/mcp-lookup/mcp-search.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.00423 |
| Opus 5 | $0.00007 | $0.00211 |
| Sonnet 5 | $0.00003 | $0.00085 |
| Haiku 4.5 | $0.00001 | $0.00042 |
Grade A, and why
mcp-search scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/mcp-search
Search 2425+ MCP servers and get ready-to-use configs.
Arguments
The user invoked this command with: $ARGUMENTS
Instructions (LAZY LOAD — never read the full file)
- Parse the user's search query from
$ARGUMENTS - Use Grep on
skills/mcp-lookup/references/mcp-servers-lookup.md— NEVER read the full file (1.1MB) - Search using Grep for the query terms
- If
--domainis specified, filter to that domain section only - Present the results in a clean format
Output Format
For each match, show:
- Server name with GitHub link
- Install command
- Domain tags
- Description
- Config JSON (ready to copy into
mcpServers)
If No Results
- Suggest related domains from the catalog
- Offer to browse a specific domain
- Suggest alternative search terms
If Too Many Results
- Show the top 10 most relevant matches
- Suggest narrowing with
--domain - Group results by domain
Performance Rules
- NEVER read the full reference file — always use Grep
- Limit output: Max 10 results per search
- Suggest narrowing if >10 matches
Available Domains
AI, Analytics, Web, Search, Finance, Design, Security, Productivity, Files, Geo, Knowledge, Database, HR, Automation, DevOps, Ecommerce, Blockchain, Media, Communication, Cloud, Science, Testing, Translation, Government, Networking, Legal, Social, ERP, News, Audio, Gaming, Travel, Healthcare, IoT, Weather, Education, Caching, Utility, Messaging, Food, CRM, Fitness, CMS
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 54 lines · 14 tokens per session scan A 62712774ba31
mcp-search is a command published in the GitHub repository mahmoud20138/mcp-lookup (2 stars, last pushed 3mo ago), licensed MIT. It adds 14 tokens to every session and 423 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
data-mesh-contract
Create federated data product contracts for mesh architectures with SLAs, governance, and interoperability guarantees (project).
audit-web
A command for requesting a website security assessment through an MCP tool, a way for an agent to call an external service. It requires proof of permission before any network checks.
atrs
Generate Algorithmic Transparency Recording Standard (ATRS) record for AI/algorithmic tools.
fr-rgpd
You are helping an enterprise architect generate a French CNIL Compliance Assessment — the French-specific GDPR layer applied by the CNIL (Commission Nationale de l'Informatique et des Libertés). Run this after /arckit-eu:eu-rgpd to add French obligations that go beyond the EU GDPR baseline.
servicenow
Create comprehensive ServiceNow service design with CMDB, SLAs, incident management, and change control.
eval
Legacy slash-entry shim for the eval-harness skill. Prefer the skill directly.