Back to Browse

Deploytoagents MCP Server

Cloud & DevOpsModerate7.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Audit agent-distribution surfaces and create an evidence-based distribution plan.

About

Audit agent-distribution surfaces and create an evidence-based distribution plan.

Remote endpoints: streamable-http: https://deploytoagents.com/mcp

Security Report

7.2
Moderate7.2Low Risk

The Deploy to Agents MCP server is a well-designed client library and CLI for a remote auditing service. Authentication is properly implemented using OAuth2 with PKCE, credentials are securely stored (Windows DPAPI, Unix file perms), and input validation is robust. The codebase demonstrates good security practices with proper error handling and token management. Minor code quality findings around broad exception handling and logging do not materially impact the security posture. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

8 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

process_spawn

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Deploy to Agents SDK

Public JavaScript client and registry metadata for the Deploy to Agents remote MCP server.

The remote server is published in the official MCP Registry as com.deploytoagents/server and is served from https://deploytoagents.com/mcp. The JavaScript client and authenticated agent-first CLI are published as deploytoagents@0.4.1 on npm, with an equivalent deploytoagents==0.1.1 client on PyPI.

Agent-first CLI

npx deploytoagents login
npx deploytoagents whoami
npx deploytoagents portfolio --json
npx deploytoagents discovery --json
npx deploytoagents discovery-record --input observation.json --json
npx deploytoagents audit https://example.com --json

The package installs both deploytoagents and the shorter d2a command. Google login uses Authorization Code with PKCE and a temporary loopback callback. On Windows the refresh credential is encrypted for the current OS user with DPAPI; CI can provide a short-lived identity token through DEPLOYTOAGENTS_TOKEN. Discovery Lab can be read or supplied with a JSON observation file (or stdin via --input -). All command results and errors have stable JSON forms for agent use.

{
  "hostname": "example.com",
  "surface": "claude",
  "model": "model label shown by the surface",
  "prompt": "Exact generic, unbranded prompt",
  "outcome": "not-mentioned",
  "freshSession": true,
  "responseExcerpt": "Optional relevant excerpt",
  "citations": ["https://example.org/source"]
}

Valid outcomes are recommended, mentioned, not-mentioned, and error. The server verifies that the signed-in organization owns the target hostname.

Deploy to Agents currently audits public agent-facing surfaces, returns unlisted evidence receipts, and creates prioritized technical and external-authority distribution plans. It does not yet claim to publish every customer artifact or guarantee recommendation by any model.

Connect directly through MCP

Use this Streamable HTTP endpoint in any compatible MCP client:

https://deploytoagents.com/mcp

Available tools:

  • audit_app
  • get_audit_result
  • create_distribution_plan
  • get_customer_zero_evidence

JavaScript client

npm install deploytoagents
import { DeployToAgentsClient } from "deploytoagents";

const client = new DeployToAgentsClient();

try {
  const queued = await client.auditApp("https://example.com");
  console.log(queued.receipt_url);

  const result = await client.getAuditResult(queued.audit_id);
  if (result.status === "completed") {
    console.log(await client.createDistributionPlan(queued.audit_id));
  }
} finally {
  await client.close();
}

Python client

pip install deploytoagents
from deploytoagents import DeployToAgentsClient

async with DeployToAgentsClient() as client:
    queued = await client.audit_app("https://example.com")
    print(queued["receipt_url"])

Customer Zero

Deploy to Agents uses its own system as its first customer. The current 100/100 receipt verifies technical surfaces only. Independent, unbranded discovery remains explicitly not-yet-proven.

Development

npm install
npm test
npm run smoke

Evidence policy

This project distinguishes owned evidence, externally verified artifacts, and independent recommendations. It does not create fake testimonials, automated community posts, coordinated votes, or links intended primarily to manipulate rankings.

License

MIT

Reviews

No reviews yet

Be the first to review this server!