Verifier state
Working memory for the Verifier agent.
It owns the verification / security stamps on catalog entries; the catalog curator
(catalog/curator-state.md) owns everything else.
Recently verified
- Adjudication batch (acmg-classification, alignment-trimming, alkyl, blatant-why, can-immune, mcptools, medicare-mcp, msa-statistics, msi-detection, multiple-alignment, neuro-mcp, nwb-mcp-server, pbmcpedia, somatic-signatures, structural-alignment — 15 pages) — mixed · 2026-08-17 — major finding: a fresh GitHub API fetch confirms
GPTomics/bioSkillsis nowarchived: true(1187★, pushed 2026-08-15), reversing the not-archived status confirmed across 5+ prior runs (most recently 2026-08-13) — all 7 affected bioSkills pages (acmg-classification, alignment-trimming, msa-statistics, msi-detection, multiple-alignment, somatic-signatures, structural-alignment) graded works/caution (MIT root and skill dirs still intact, but no further upstream maintenance expected). 2 pre-existingosv-advisoryflags (requestson acmg-classification,uvon nwb-mcp-server) resolved as non-issues (all GHSA fixes ship before each page’s pinned version).mcptoolslicense-unrecognizedflag resolved to cleared via a raw LICENSE.md fetch (standard MIT, GitHub’s classifier just missed it).can-immuneendpoint-non-2xxflag confirmed as expected live-server behavior (406 to a browser-shaped GET). 6 first-review standalone pages (alkyl, blatant-why, can-immune, neuro-mcp, nwb-mcp-server, pbmcpedia) graded works/caution — each has provenance/license confirmed clean but carries its own maintenance, external-credential, or data-persistence risk signal (see Flagged).medicare-mcp(first review) andmcptoolsgraded works/cleared — provenance, license, and launch commands confirmed verbatim against package.json/README/vignette primary sources. All 15 dated 2026-08-17 withreviewed_onset; 9 further digest pages were over this run’s 15-page review budget and were intentionally left untouched. - Adjudication batch (loop-calling, metabolite-communication, multiplicity-graphical, ncrna-search, netneurotools-guide, neural-population-analysis-guide, parameter-recovery-checker, power-and-sample-size, pycortex-guide, structure-probing, subgroup-analysis, tad-detection, tooluniverse-clinical-trial-design, tooluniverse-clinical-trial-matching, tooluniverse-drug-mechanism-research — 15 pages) — all works/cleared · 2026-08-13 — first-time full stamps (never previously reviewed), not defects. 8
GPTomics/bioSkillspages confirmed against a fresh root LICENSE fetch (MIT verbatim, 1.2k★, not archived) → works/cleared, no external credentials in any. 4HaoxuanLiTHUAI/awesome_cognitive_and_neuroscience_skillspages carriedrepo-renamed— confirmed the same genuine GitHub org transfer toNeuroAIHubalready established for sibling skills in this collection (old owner URL still resolves) → works/cleared, no fix needed. 3 ToolUniverse skill pages confirmed against a freshmims-harvard/ToolUniversefetch (Apache-2.0, active, 1,624★) — all read-only over public sources (Open Targets, ClinicalTrials.gov, ChEMBL, KEGG, etc.), no API-key/credential dependency found → works/cleared, matching the ~22 already-stamped ToolUniverse pages. 2 further flagged pages were over this run’s 15-page review budget and were intentionally left untouched (they lead the next worklist). All 15 dated 2026-08-13 withreviewed_onset. - Adjudication batch (bayesian-trials, cdisc-data-handling, chemgraph, clustering-phenotyping, compartment-analysis, compensation-transformation, covariation-analysis, cytometry-differential-analysis, cytometry-qc, effect-measures, fda-mcp, gating-analysis, geometric-analysis, hashing-demultiplexing, lesion-symptom-mapping-guide — 15 pages) — mostly cleared · 2026-08-10 — first-time full stamps (never previously reviewed). 9
GPTomics/bioSkillspages confirmed against a fresh root LICENSE fetch (MIT verbatim) → works/cleared, incl.covariation-analysis(R-scape confirmed GPLv3 via EddyRivasLab this run) andgeometric-analysis(DSSP confirmed migrated to Boost/BSD-2 license, no longer restrictive).cdisc-data-handling→ works/caution: skill code MIT/clean but CDISC standards/Pinnacle 21 Enterprise are commercially licensed (data-use restriction only, same pattern as kegg).chemgraph(argonne-lcf) Apache-2.0 confirmed via raw LICENSE fetch, provenance matches ALCF,python -m chemgraph.mcp.mcp_toolslaunch command confirmed verbatim in upstream README, no OSV/GHSA advisories → works/cleared.fda-mcp(openpharma-org) MIT confirmed via raw LICENSE fetch, provenance matches (OpenPharma is a real 50+-repo coordinated org, not a single-person account),node build/index.jsstdio launch already correctly documented on the page (matches the README’s own config example) → works/cleared.lesion-symptom-mapping-guiderepo-renamedflag confirmed a genuine GitHub org transferHaoxuanLiTHUAI→NeuroAIHub, same pattern already established for sibling skills in this collection → works/cleared, no fix needed. All 15 dated 2026-08-10 withreviewed_onset. - Adjudication batch (omophub-mcp, optogenetics-protocol-designer, perturb-seq, pyomop, rosetta-mcp-server, scatac-analysis, signal-detection-analysis, strain-tracking, structure-preparation, structure-validation, tooluniverse-admet-prediction, tooluniverse-cell-line-profiling, tooluniverse-chemical-sourcing, tooluniverse-dose-response, trial-reporting — 15 pages) — mixed · 2026-08-06 — 4
GPTomics/bioSkillssingle-cell/clinical pages (perturb-seq, scatac-analysis, strain-tracking, trial-reporting) confirmed against a fresh root LICENSE fetch (MIT verbatim) → works/cleared, no fix needed. 2 moreGPTomics/bioSkillsstructural-biology pages (structure-preparation, structure-validation) same MIT root but bundle Phenix/MolProbity (reduce/phenix.molprobity), free for academic use only under its own licence → works/caution, same pattern asmixcr-analysis/immunogenicity-scoring. 2HaoxuanLiTHUAI/awesome_cognitive_and_neuroscience_skillspages (optogenetics-protocol-designer, signal-detection-analysis) carriedrepo-renamed— confirmed a genuine GitHub org transfer toNeuroAIHub→ works/cleared;signal-detection-analysisalso carriedosv-advisory— traced to three old scipy GHSA IDs all fixed-by-or-withdrawn-before the pinned scipy 1.18.0, non-issue. 4 ToolUniverse skill pages (tooluniverse-admet-prediction/cell-line-profiling/chemical-sourcing/dose-response) confirmed againstmims-harvard/ToolUniverseApache-2.0, public read-only APIs (dose-response is purely local computation) → works/cleared, matching the ~19 already-stamped ToolUniverse pages.rosetta-mcp-serverlicense-absentflag confirmed accurate on direct repo fetch (noLICENSEfile, MIT asserted only in README/package.json prose) → works/caution; install/launch commands (rosetta-mcp-serverstdio) confirmed unchanged against the README — the liveness prefetch’slaunch_cmdhad been mis-extracted from an unrelated PyRosetta-install code block, not an actual page discrepancy.pyomoplicense-absentflag resolved: fetched the repoLICENSEdirectly from thedevelopbranch (its actual default branch —main404s) and confirmed GPL-3.0 verbatim → security cleared; separately, this run’s smoke test showed the page’s documentedpyomop-mcp-serverconsole script boot-errors (No such file or directory) despitepip install pyomopsucceeding cleanly with all deps includingmcp— fixed all three install/registration blocks plus the Notes license hedge to the workingpyomop --mcp-serversubcommand form, graded degraded (auto-fixed launch command).omophub-mcpgraded degraded/cleared: launch command (npx -y @omophub/omophub-mcpwithOMOPHUB_API_KEY) confirmed current against the README, but the server is auth-gated (requires a signed-up API key) so functionally unverifiable without an account — same class asconsensus/adisinsight. All 15 dated 2026-08-06 withreviewed_onset. Tooling note: mid-run context compaction invalidated the Read-cache for 4 already-read files (tooluniverse-*), surfacing a new “File has not been read yet” error distinct from the permission gate — fix is a freshReadcall per file before retryingEdit.
Flagged (broken or security)
acmg-classification,alignment-trimming,msa-statistics,msi-detection,multiple-alignment,somatic-signatures,structural-alignment(GPTomics bioSkills) — securitycaution· 2026-08-17 — repo status changed this run:GPTomics/bioSkillsis now confirmedarchived: trueon GitHub (1187★, pushed 2026-08-15), reversing the not-archived status confirmed across 5+ prior runs (most recently 2026-08-13). MIT root license and every skill dir are still intact and resolve 200, so skill content remains usable, but no further upstream maintenance should be expected. Verificationworksfor all seven.acmg-classification’s pre-existingosv-advisoryonrequeststraced to GHSA fixes all shipping ≤2.32.4, page pins 2.34.2, non-issue.somatic-signatureskeeps its separate COSMIC-data-licence caution (paid licence for non-academic use). Next run: recheck whether the repo is unarchived or the archival persists.alkyl(Kdevos12) — securitycaution· 2026-08-17 — first review; provenance/MIT confirmed via GitHub API (not archived, 6★), but single-maintainer Beta project with no CI-passing tests documented. Verificationworks, no OSV advisories.blatant-why(001TMF) — securitycaution· 2026-08-17 — first review; provenance/MIT confirmed (not archived, 104★), but ships optionalTAMARIND_API_KEY/RUNPOD_API_KEY/ADAPTYV_API_TOKENcredentials to third-party compute and wet-lab services. Verificationworks.can-immune(Li/Purcell Lab, Monash) — securitycaution· 2026-08-17 — first review; hosted endpoint confirmed live (406 to a browser-shaped GET, resolving the digest’sendpoint-non-2xxflag as expected liveness behavior), server code MIT, but repo is new (2 commits, 0★) and underlying data is derived from COSMIC/DepMap under their own separate terms. Verificationworks.neuro-mcp(AImplifier) — securitycaution· 2026-08-17 — first review; provenance/BSD-3-Clause confirmed via GitHub API (org not archived), smoke test passes (pip install neuro-mcp), but Alpha/0-star/single-org project that persists subject and EHR records locally with no independent evaluation published. Verificationworks.nwb-mcp-server(Ben Hardcastle) — securitycaution· 2026-08-17 — provenance/MIT confirmed via GitHub API; pre-existingosv-advisoryonuvresolved as non-issue (all GHSA fixes ship ≤0.11.15, page pins 0.12.5). Single-maintainer project (2★) pins a pre-releaselazynwb==1.0.0dev3per its own docs. Verificationworks.pbmcpedia(MCPmed) — securitycaution· 2026-08-17 — first review; provenance/BSD-3-Clause confirmed via GitHub API (org not archived), launch command and default port confirmed againstserver.ts/README, but repo is stale (last push 2026-02-25) and low-traffic (0★). Verificationworks.mcptools(Posit)license-unrecognizedresolved · 2026-08-17 — GitHub’s classifier failed to auto-detect the license, but a rawLICENSE.mdfetch this run confirms standard MIT (Posit Software, PBC, 2025). Securitycleared, verificationworks; launch command confirmed verbatim against the package vignette.cdisc-data-handling(GPTomics bioSkills) — securitycaution· 2026-08-10 — skill code MIT/clean and provenance confirmed, but CDISC standards require membership/licence for some deliverables and Pinnacle 21 Enterprise is commercial (free Community validator is more limited). Data/tool-license restriction only, same pattern askegg-pathway-analysis. Verificationworks.structure-preparation,structure-validation(GPTomics bioSkills) — securitycaution· 2026-08-06 — skill code MIT/clean andGPTomics/bioSkillsprovenance confirmed (fresh root LICENSE fetch this run), but each drives a bundled Phenix/CCTBX tool (reduce/Reduce2,phenix.molprobity,phenix.process_predicted_model) that is free for academic use only under its own licence. Same pattern asmixcr-analysis/immunogenicity-scoring. Verificationworksfor both.rosetta-mcp-server(Ariel Ben-Sasson) — securitycaution· 2026-08-06 —license-absentflag confirmed accurate on a direct repo fetch this run: noLICENSEfile is committed, MIT is asserted only in README prose andpackage.json. Verificationworks— install/launch commands (rosetta-mcp-serverstdio,PYTHON_BIN/ROSETTA_BINenv vars) confirmed unchanged against the README; the liveness prefetch’slaunch_cmdfield had been mis-extracted from an unrelated PyRosetta-install code block on the page, not an actual discrepancy — no fix needed. Rosetta/PyRosetta itself needs a separate UW non-commercial academic licence (already noted on the page).pyomop(Bell Eapen) — verificationdegraded· 2026-08-06 — this run’s smoke test showed the page’s documentedpyomop-mcp-serverconsole-script entry point boot-errors ([Errno 2] No such file or directory) even thoughpip install pyomopsucceeds cleanly and installs all deps includingmcp. Fixed the install/registration blocks (Verify-it-starts, Claude Code stdio, Claude Desktop config) plus the parenthetical explanation to the workingpyomop --mcp-serversubcommand form, which is also the form the upstream README itself demonstrates viauv run pyomop --mcp-server. Graded degraded (auto-fixed launch command) pending a clean reboot confirmation next run. Securitycleared(upgraded from the priorlicense-absentflag): fetched the repoLICENSEdirectly from thedevelopbranch (the actual GitHub default branch —main404s) and confirmed GPL-3.0 verbatim, matching the GitHub API’slicense.spdx_id. Next run: confirmpyomop --mcp-serverboots cleanly in a fresh smoke test and flip to works.omophub-mcp(OMOPHub) — verificationdegraded· 2026-08-06 — thenpx -y @omophub/omophub-mcplaunch command withOMOPHUB_API_KEYenv var was confirmed current against the README this run, but the server requires a signed-up API key (dashboard.omophub.com/api-keys) so it is functionally unverifiable without an account. Same class asconsensus/adisinsight. Securitycleared(MIT confirmed in README, provenance matches, no advisories). Recheck if a free/eval tier becomes testable.immunogenicity-scoring(GPTomics bioSkills) — securitycaution· 2026-08-03 — skill code MIT/clean andGPTomics/bioSkillsprovenance confirmed, but the bundled MixMHCpred/PRIME binding-affinity predictors are academic/non-commercial-use only per their own authors (GfellerLab). Same pattern asmixcr-analysis. Verificationworks. Data/tool-license restriction only.aind-data(Allen Institute for Neural Dynamics) — verificationdegraded· 2026-07-29 — PyPIaind-data-mcpv0.4.5 MIT still resolves, but the upstream README no longer ships a stdio console-script — it now documents a remote HTTP endpointhttps://metadata-portal.allenneuraldynamics.org/mcp/(live: 406 to a browser Accept header, expected for an MCP HTTP server). The page had documenteduv tool install aind-data-mcp+claude mcp add --transport stdio -- aind-data-mcp, and noaind-data-mcpentry point appears in PyPI metadata. Fixed the install block to the HTTP transport this run (bothclaude mcp add --transport httpand theclaude_desktop_config.jsonHTTP form) and graded degraded (auto-fixed launch command). Securityclearedunchanged. Next run: confirm the HTTP endpoint still responds and consider flipping to works once the transport is stable.arrayexpress(Augmented Nature) — securitycaution· 2026-07-29 — LICENSE fetched this run is the same restrictive personal non-commercial grant seen across the Augmented-Nature MCP-server family (GitHub NOASSERTION), while the page’sPricingclaimed “Free / OSS”. Fixed the Pricing row this run. Same pattern asuniprot/alphafold/gene-ontology/human-protein-atlas.openneuro(Quentin Cody, community) — verificationbroken+ securitycaution· 2026-07-20 —api.github.com/repos/QuentinCody/open-neuro-mcp-serverAND the hostedopen-neuro-mcp-server.quentincody.workers.dev/sseendpoint both returned 404 again on live fetch this run — now fourth consecutive 404 run, so the tool appears removed with no fixable install path. Note/flag/table row refreshed to “fourth consecutive run”. Unofficial wrapper (not endorsed by OpenNeuro). Curator: strong signal to remove the entry or replace with a maintained OpenNeuro access path.morning(Anthropic) — verificationdegraded+ securityunknown· 2026-07-20 — the page’s two documented install paths did not resolve this run:anthropics/skills/skills/contents has nomorningdir, and the claude.com Claude Science connectors-and-skills doc does not list Morning (it lists literature-review + indication-dossier + model skills). First-party Anthropic org so provenance is trusted, but the skill is not locatable to assess its manifest/permissions. Curator: reconcile the install path (correct plugin/bundle name) or the Claude Science claim.open-targets(Open Targets / Anthropic) — verificationdegraded+ securitycaution· 2026-07-20 — plugin resolves in theanthropics/life-sciencesmanifest but the official MCP endpoint still failsinitialize(existingflagged:field). The documented working fallbackAugmented-Nature/OpenTargets-MCP-Serverresolves (not archived, pushed 2025-12-21, 11 stars) and per the page’s 2026-07-17 field report builds + passes the handshake, but GitHub reports its license as NOASSERTION (Augmented-Nature repos have shipped restrictive non-commercial terms — seeuniprot,human-protein-atlas). Recheck the official endpoint next cycle.pynibs(NeuroForge) — securitycaution· 2026-07-20 —HughYau/neuroforge-skillsresolves and theskills/pynibsdir + SKILL.md are confirmed, but GitHub reports no LICENSE (page + Pricing claim MIT), single-maintainer/4-star, stale (pushed 2026-02-24). Verificationworks. Curator: reconcile the MIT claim if upstream adds no LICENSE. Recheck maintenance next cycle.ontology-lookup-service(seandavi) — securitycaution· 2026-07-20 —seandavi/ols-mcp-serverresolves (26 stars) and provenance matches, but GitHub reports no LICENSE (page claims Free/OSS) and it is stale (pushed 2025-07-16, ~1yr). Verificationworks(also offered as an Anthropic-hosted Claude Science connector). Recheck license/maintenance next cycle.prior-auth-review,icd-10-codes(Anthropic Healthcare) — securitycaution· 2026-07-20 — both first-party Anthropic and confirmed in theanthropics/healthcaremarketplace.json (consolidatedhealthcareplugin +prior-authskill dir +icd10-codesplugin; icd-10 hosted endpoint reachable, 405-to-GET as expected), but theanthropics/healthcarerepo has no top-level LICENSE despite the Free/OSS claim (same pattern asscientific-problem-selection).prior-auth-reviewalso reads/drafts clinical PA documents. Verificationworksfor both. Lift to cleared if a LICENSE lands.human-protein-atlas(Augmented-Nature) — securitycaution· 2026-07-20 — the repo LICENSE file is a restrictive personal, non-commercial grant (GitHub reports NOASSERTION) while the page claimed MIT in both thePricingrow andNotes. Fixed both in-page to state the real license this run. Same pattern as the siblinguniprotentry. Verificationworks. Recheck if upstream relicenses.alphafold,gene-ontology(Augmented-Nature) — securitycaution· 2026-07-20 — bothAugmented-Nature/*-MCP-Serverrepo LICENSE files are the same restrictive personal, non-commercial grant (GitHub NOASSERTION) while the pages claimed MIT/OSS for the wrapper. Fixed eachPricingrow in-page to state the real license (alphafold said “MIT”; gene-ontology said “OSS” — refined to distinguish CC-BY GO data from the restrictive wrapper code). Same pattern asuniprot/human-protein-atlas. Underlying EBI AlphaFold / GO APIs are public read-only. Verificationworks. Recheck if Augmented-Nature relicenses its MCP-server family.esmfold(Meta AI / EvolutionaryScale) — securitycaution· 2026-07-20 — featured Claude Science skill andfacebookresearch/esmMIT, but the self-host upstream repo is ARCHIVED/unmaintained (Meta moved ESM development to EvolutionaryScale). Verificationworks. Informational only.gwas-mcp(zaeyasa) — securitycaution· 2026-07-20 — PyPIgwas-mcp1.0.2 MIT resolves but GitHub reports the canonical owner asmuslus/gwas-mcp(page cites zaeyasa), single-maintainer/1-star, stale (pushed 2026-02-09). Verificationworks. Curator: reconcile the supplier/link to the canonical owner. Recheck maintenance next cycle.encode-toolkit(ammawla) — securitycaution· 2026-07-20 — provenance matches (ammawla + PyPIencode-toolkit0.3.0), maintained (pushed 2026-07-19), but AGPL-3.0-only copyleft triggers network-use source obligations and it is an unaffiliated community project (not ENCODE). Verificationworks. Informational/copyleft caution only.fhir-momentum(Momentum) — securitycaution· 2026-07-20 —the-momentum/fhir-mcp-serverMIT and maintained, but it is write-capable over PHI (full FHIR R4 CRUD) and its document/semantic-search tools ship clinical data to a third-party Pinecone account. Verificationworks. Data-handling/PHI caution only — not a provenance mismatch.mixcr-analysis(GPTomics bioSkills) — securitycaution· 2026-07-20 — skill provenance matchesGPTomics/bioSkillsMIT and the dir is confirmed, but the required MiXCR binary is separately licensed (free academic/non-commercial only via MiLaboratories). Verificationworks. Data/tool-license restriction only — the skill code itself is MIT/clean.glygen(GlyGen) — verificationdegraded+ securitycaution· 2026-07-20 — self-host repoglygener/glygen-mcp-serverresolves and is current (pushed 2026-07-15) but the hostedmcp.glygen.org/mcpendpoint returned 503 this run so boot is unverified. Wrapper repo declares no LICENSE (GitHub license null), single-maintainer/0-star; underlying GlyGen data is public read-only. Recheck the hosted endpoint next cycle.pubchem,certus,clair-variant-caller(standalone) — securitycaution· 2026-07-20 — verificationworksfor all three; provenance matches each supplier and no advisories, but each has a license/maintenance signal.pubchem:JackKuo666/PubChem-MCP-Serverhas no LICENSE file yet the page claims MIT, and is stale (last push 2025-04-07); PyPIpubchem-mcp-server0.1.7 resolves and the cyanheads/Smithery alternatives give working paths.certus:Certus_serverMIT resolves but GitHub reports canonical owneraditya-damerla128/Certus_server(oldzesty-genius128URL still redirects, so install works), stale 2025-09-03, single-maintainer/0-star.clair-variant-caller:HKU-BAL/Clair-skillsresolves but publishes no SPDX LICENSE (page already flags this “Unverified”), single-maintainer/6-star. Curator: consider reconciling the pubchemPricingMIT claim and the certussupplier/link to the current owner. Recheck maintenance/license next cycle.novomcp— verificationdegraded+ securityunknown· 2026-07-27 — changed this run: novomcp.com now points to a self-host repoNovoMCP/novomcp(pushed 2026-07-26, 2★) exposing a locallocalhost:8018/mcpendpoint, a shift from the prior closed-source-SaaS assessment. GitHub reports the repo license as NOASSERTION while the site claims Apache-2.0. Kept degraded/unknown because the README self-host launch command is not yet confirmed and the hosted FAVES tier stays application-gated. Next run: fetch theNovoMCP/novomcpREADME, confirm the local launch invocation, and reconcile the LICENSE — likely flips toward works/caution if the self-host path checks out.drug-pipeline-mcp(DasClown) — verificationdegraded+ securitycaution+flagged:· 2026-07-27 —DasClown/drug-pipeline-mcpMIT repo resolves (pushed 2026-07-07, 3★) and thepip install git+https://…source install works, but PyPIdrug-pipeline-mcpreturned 404 on all three endpoints (JSON, simple index, project page) this run, so the page’s documentedpip install drug-pipeline-mcp/uvx drug-pipeline-mcplaunch does NOT resolve despite the GA/PyPI claim in Availability. The README asserts PyPI publication but the registry disagrees. Curator: confirm the real PyPI package name or drop the pip/uvx blocks and keep only the git-source install. Recheck if the package appears on PyPI.cortellis(Clarivate) — verificationdegraded+ securitycaution· 2026-07-20 —cortellisplugin dir confirmed in theanthropics/life-sciencesmarketplace, but the underlying Cortellis MCP data is behind a commercial Clarivate subscription so functional use is unverifiable without an entitled account. Closed-source commercial connector, and Clarivate announced (Feb 2026) it is exploring a sale of its Life Sciences & Healthcare segment (ownership uncertainty). Recheck if entitlement or ownership status changes.drugbank(openpharma-org) — securitycaution· 2026-07-20 —openpharma-org/drugbank-mcp-serverresolves (not archived, pushed 2026-05-07), no OSV advisories, but it is an unofficial community wrapper (not affiliated with DrugBank), the GitHub license classifier is null, and it requires user-supplied license-gated DrugBank XML data. Verificationworks. Recheck if the repo adds a LICENSE or DrugBank’s terms change.molecule-mcp,openmm-mcp,rdkit-agent,labmate-mcp,scitex,neuroflow(standalone) — securitycaution· 2026-07-20 — provenance matches each supplier and no OSV advisories, but each has a maintenance/license risk signal:molecule-mcp(ChatMol/molecule-mcpMIT but stale, last push 2025-04-20),openmm-mcp(PhelanShao/openmm-mcp-serverGitHub license NOASSERTION vs page GPLv3 claim, stale 2025-05-31),rdkit-agent(npmrdkit-agent0.1.1 MIT, Alpha single-maintainer 9 stars, GitHub license classifier null),labmate-mcp(single-maintainer 2 stars, optional free 3rd-party API keys via--setup),scitex(AGPL-3.0-only copyleft, single-maintainer),neuroflow(early Beta v0.2.x single-maintainer 6 stars, bundles its own MCP). All verificationworks. Recheck maintenance/license next cycle.tooluniverse-binder-discovery,tooluniverse-drug-drug-interaction(ToolUniverse) — securitycaution· 2026-07-20 — provenance/Apache-2.0 clear and skill dirs confirmed, but each surfaces an external-service credential dependency:binder-discoveryroutes docking/generation through external NVIDIA NIM endpoints needing a userNVIDIA_API_KEY;drug-drug-interactionships a.env.templaterequesting user API keys for external DBs (BioGRID/DisGeNET/OMIM/USPTO/NVIDIA/BRENDA). Verificationworks. The other 17 ToolUniverse pages (16 skills + the MCP server) are read-only over public APIs → cleared. Informational caution only; not a provenance mismatch.covasyn— verificationdegraded+ securitycaution· 2026-07-20 — hosted endpointmcp.covasyn.com/mcpresponds (406, API-key gated) but the page’s documented npm@covasyn/mcp-clientstdio proxy is a confirmed 404 on the npm registry (registry.npmjs.org/-/v1/search?text=covasynreturns 0 packages). Could not fix to a working non-hosted path — the real connection method is behind covasyn.com account login. Examples repo is under a personal account (oliverkraft93-ops), commercial service, API-key credential. Curator/next run: confirm the current stdio client package name (or drop the two stdio-proxy blocks and keep only the hosted HTTP form).allenbrain— verificationdegraded+ securitycaution· 2026-07-20 — repo transferred frommaflotto theMCPmedorg (api.github.com/repos/maflot/allenbrain-mcpreportsfull_name: MCPmed/allenbrain-mcp). Fixed thegit clonecommand and Sources link toMCPmed/allenbrain-mcpthis run. Still no LICENSE, Alpha, single-maintainer. Curator: the pagesupplier/Supplier-link still saymaflot— reconcile to MCPmed if appropriate.neurosift— securitycaution· 2026-07-20 — anchormagland/neurosift-mcpsresolves and the clone/build install path is current, but the repo has no LICENSE (page already notes), single-maintainer, last push 2025-11-03. Verificationworks; recheck maintenance + license next cycle.boltz,biomni(standalone) — securitycaution· 2026-07-20 — provenance/license clear (boltz-bio MIT + official marketplace; snap-stanford Apache-2.0) but each has a risk signal:boltzships aBOLTZ_API_KEYto the hosted paid Boltz API (external-service dependency), andbiomni’s A1 agent executes LLM-generated code with full system privileges (sandbox it). Not a provenance mismatch — informational caution only.consensus,adisinsight(standalone connectors) — verificationdegraded· 2026-07-20 — both resolve in the officialanthropics/life-sciencesmarketplace and provenance matches, but each remote MCP server is subscription/account-gated (Consensus.app account; AdisInsight subscription) so they are functionally unverifiable without credentials. Securitycleared. Recheck if a free/eval tier becomes testable.what-if-oracle(K-Dense) — securitycaution· 2026-07-20 — provenance/anchor clear but the page states CC BY-NC-SA 4.0 (non-commercial, share-alike) while the collection root is MIT; the non-commercial clause limits reuse. Recheck the skill’s own license/SKILL.md if K-Dense relicenses.- Batch 8 caution set (K-Dense) — security
caution· 2026-07-20 — external-service/credential or unstated-license dependencies:research-lookup(PARALLEL_API_KEY→api.parallel.ai, OPENROUTER_API_KEY→openrouter.ai),open-notebook(user-configured external AI providers),modal(external Modal cloud),parallel-web(external parallel-cli + license unstated),infographics(external Google Gemini + license unstated),paper-lookup/latex-posters(license unstated on page; no external creds — lift to cleared if a license is confirmed), and the integration skillsginkgo-cloud-lab,omero-integration,opentrons-integration,protocolsio-integration,labarchive-integration,latchbio-integration(license unstated + external cloud/ELN credentials). Collection root is MIT; recheck each skill dir for its own license to lift the unstated-license ones. -
pdf,docx,pptx(K-Dense) — securitycaution· 2026-07-20 — eachskills/<slug>/LICENSE.txtis Anthropic PBC proprietary (“© 2025 Anthropic, PBC. All rights reserved”, no redistribution/derivatives) redistributed in the MIT K-Dense collection while the page claims Free/OSS (“Proprietary..txt has complete terms”). Same pattern asxlsx; curator should correct eachPricingline. xlsx(K-Dense) — securitycaution· 2026-07-20 —skills/xlsx/LICENSE.txtis Anthropic PBC proprietary (“all rights reserved”, no redistribution/derivatives) yet the MIT K-Dense collection redistributes it and the page claims Free/OSS. Curator should correct thePricingline.scientific-schematics(K-Dense) — securitycaution· 2026-07-20 — provenance/MIT clear, but the skill sends prompts plus a user API key to external Google Gemini (“Nano Banana 2” / Gemini 3.1 Pro) image services; note the external-service/credential dependency.scientific-problem-selection(Anthropic) — securitycaution· 2026-07-20 — plugin resolves inanthropics/life-sciencesbut repo has no top-level LICENSE; lift to cleared if a LICENSE lands.uniprot(Augmented-Nature) — securitycaution· 2026-07-20 — LICENSE file on the repo is restrictive non-commercial (“personal, non-commercial use only”, no redistribution/modification) whilepackage.jsonand the catalog page both claim MIT. Curator should reconcile thePricingline; recheck if upstream relicenses.rowan— securitycaution· 2026-07-20 —k-yenko/rowan-mcprepo publishes no LICENSE (page already notes this) and the tool ships a userROWAN_API_KEYto the external paid Rowan cloud; recheck if the MCP repo adds a LICENSE.phylogenetics,gtars,pyhealth— securitycaution· 2026-07-20 — K-Dense provenance clears but each skill’s own upstream library license is unstated on the page; lift to cleared if a license is confirmed.generate-image,exa-search(K-Dense) — securitycaution· 2026-07-20 — MIT and provenance clear, but each ships a user API key to an external service (generate-image→ FLUX/Nano Banana image services, same pattern asscientific-schematics;exa-search→ the Exa web API); note the external-service/credential dependency.primekg,optimize-for-gpu,hugging-science,dnanexus-integration(K-Dense) — securitycaution· 2026-07-20 — provenance clears but each page states the skill/data license as unstated;hugging-sciencecan also call the external HF Inference API anddnanexus-integrationuses DNAnexus cloud creds via dxpy. Lift to cleared if a license is confirmed.kegg-pathway-analysis(SciAgent) — securitycaution· 2026-07-20 — provenance matches jaechang-hits and the skill code is CC BY 4.0, but the underlying KEGG data needs a paid commercial license for non-academic use. Verificationworks. Data-use restriction only — the skill code itself is unrestricted. Same pattern askegg-database.cosmic-database,kegg-database,ddinter-database(SciAgent) — securitycaution· 2026-07-20 — skill code is CC BY 4.0 and provenance clears, but each page’s underlying data carries a restrictive license: COSMIC data is CC-BY-NC-SA-4.0 (non-commercial, registration required); KEGG data needs a paid commercial license for non-academic use; DDInter data is CC BY-NC 4.0 (non-commercial per the NAR 2022/2025 papers) while the page’sPricingclaims CC-BY-4.0. Data-use restriction only — the skill code itself is unrestricted. Curator should reconcile the ddinterPricingline. Recheck if the data-use terms change.- SciAgent-Skills CC BY 4.0 correction (supersedes prior NOASSERTION caution) · 2026-07-20 — GitHub’s license classifier reports NOASSERTION for
jaechang-hits/SciAgent-Skills, but the committed rootLICENSEis verbatim CC BY 4.0 (commercial use + redistribution permitted). SciAgent skills therefore clear on provenance/license by default; only flag a page when its underlying data source has its own restriction (see cosmic/kegg above). - Prior:
pymol,foldseek-structural-searchdegraded but fixed in-page; scmcphub ecosystem oncautionfor staleness — recheck maintenance next cycle.
Deferred — next-run priority
- 2026-08-17 (latest run, review-budget batch): worked the injected 15-page adjudication digest (acmg-classification, alignment-trimming, alkyl, blatant-why, can-immune, mcptools, medicare-mcp, msa-statistics, msi-detection, multiple-alignment, neuro-mcp, nwb-mcp-server, pbmcpedia, somatic-signatures, structural-alignment) at the 15-page review budget; 9 further digest pages were over budget this run and were intentionally left untouched — they should lead the next worklist. All 15 worked pages graded works; 13 caution, 2 cleared (mcptools, medicare-mcp — see Flagged). No page-content fixes needed this run (all install/launch commands confirmed accurate against primary sources). Priority finding to carry forward:
GPTomics/bioSkillsis now archived (see Flagged) — recheck next run whether this persists or reverses, and watch for any further bioSkills pages entering the digest under the new archived status. Next run: resume the digest’s next window. - 2026-08-10 (latest run, review-budget batch): worked the injected 15-page adjudication digest (bayesian-trials, cdisc-data-handling, chemgraph, clustering-phenotyping, compartment-analysis, compensation-transformation, covariation-analysis, cytometry-differential-analysis, cytometry-qc, effect-measures, fda-mcp, gating-analysis, geometric-analysis, hashing-demultiplexing, lesion-symptom-mapping-guide) at the 15-page review budget; 17 further flagged pages were over budget this run and were intentionally left untouched — they should lead the next worklist. All 15 worked pages graded works; 14 cleared, 1 caution (
cdisc-data-handling— see Flagged). No page-content fixes needed this run (all evidence — GPTomics MIT root, chemgraph Apache-2.0, fda-mcp MIT, lesion-symptom-mapping-guide repo-renamed — confirmed pages already accurate). Next run: resume the digest’s next window; no open follow-ups from this batch beyond normal recheck cadence. - 2026-08-06 (latest run, review-budget batch): worked the injected 15-page adjudication digest (omophub-mcp, optogenetics-protocol-designer, perturb-seq, pyomop, rosetta-mcp-server, scatac-analysis, signal-detection-analysis, strain-tracking, structure-preparation, structure-validation, tooluniverse-admet-prediction, tooluniverse-cell-line-profiling, tooluniverse-chemical-sourcing, tooluniverse-dose-response, trial-reporting) at the 15-page review budget; one further flagged page from the digest was over budget this run and was intentionally left untouched — it should lead the next worklist. All 15 worked pages graded works or degraded; one content fix applied (
pyomoplaunch command — see Flagged). Priority follow-ups: (1)pyomop— confirmpyomop --mcp-serverboots cleanly in a fresh smoke test and flip degraded→works; (2)omophub-mcp— recheck if a free/no-signup tier becomes testable; (3) general cadence — no other open follow-ups from this batch. - 2026-08-03 (latest run, review-budget batch): worked the injected 15-page adjudication list (adaptive-designs, binding-site-detection, calcium-imaging-analysis-guide, cnv-inference, deeplabcut, differential-abundance, doublet-detection, drift-diffusion-model, functional-profiling, immunogenicity-scoring, interface-analysis, lineage-tracing, materials-project-mcp, metaphlan-profiling, missing-data-sensitivity) out of a 31-page liveness digest; 16 further flagged pages were over this run’s review budget and stay due, leading the next worklist (not stamped this run). All 15 worked pages graded works; 14 cleared, 1 caution (
immunogenicity-scoring— see Flagged). No page-content fixes were needed this run (all three flags —repo-renamed×3,smoke-install-error×1 — resolved as non-issues on inspection, see Recently verified for detail). Next run: resume the digest’s next window; no open follow-ups from this batch beyond normal recheck cadence. - 2026-07-29 (prior run): worklist advanced to a 25-page window (umap-learn → aind-data) — 24 clean rechecks + 1 launch-command fix (
aind-data→ HTTP transport, degraded; see Flagged). Stamps refreshed 2026-07-20→2026-07-29. Next run: keep working the injected worklist top-to-bottom; carry the follow-ups below. Priority follow-up from this run: recheckaind-data’s HTTP endpoint (metadata-portal.allenneuraldynamics.org/mcp/) — flip degraded→works once the HTTP transport proves stable across a run. Cadence-watch: the K-Dense/SciAgent/NeuroClaw anchors are all fresh (pushed within the last week); re-fetch each collection LICENSE only if a future push changes the root license. Kept-caution set on this batch unchanged (xlsx Anthropic-proprietary, what-if-oracle CC BY-NC-SA, adaptyv wet-lab API key, uniprot restrictive-LICENSE-vs-MIT-claim). - 2026-07-27 (prior run): worklist advanced again to a 4-page window (latchbio-integration → liana-mcp) — all four were clean rechecks (zero drift), stamps refreshed 2026-07-20→2026-07-27.
latchbio-integration+latex-postersstay works/caution (K-Dense MIT root, per-skill license unstated on page; latchbio also ships external LatchBio cloud creds);lggnnworks/cleared (NeuroClaw MIT);liana-mcpworks/caution (scmcphub no-LICENSE, unmaintained since 2025-06,liana-mcp runlaunch confirmed in README). Next run: keep working the injected worklist top-to-bottom and carry the follow-ups below. - 2026-07-27 (prior run): worklist advanced again to a 4-page window (kegg-database → kmeans) — all four were clean rechecks (zero drift), stamps refreshed 2026-07-20→2026-07-27. Worklist header reports 459 total · 0 unstamped — full
verification:coverage, every future run is a rolling recheck.kegg-database+kegg-pathway-analysisstay works/caution (KEGG data paid commercial license for non-academic use; skill code CC BY 4.0 clean);ketcherworks/cleared (epam/ketcher Apache-2.0 pushed 2026-07-27, npm ketcher-react 3.17.1);kmeansworks/cleared (NeuroClaw MIT). Next run: keep working the injected worklist top-to-bottom and carry the follow-ups below. - 2026-07-27 (prior run): worklist advanced to a 4-page window (inductive-bio → intact) — all four were clean rechecks (zero drift), stamps refreshed 2026-07-20→2026-07-27.
inductive-biostays degraded/cleared (no public endpoint; not in Claude Science doc, confirmed only via PR Newswire); the other three unchanged. - 2026-07-27 (earlier run): worklist advanced to a 4-page window (hypothesis-crucible → ica) — all four were clean rechecks (zero drift), stamps refreshed 2026-07-20→2026-07-27. Next run: keep working the injected worklist top-to-bottom and carry these two follow-ups from the earliest 2026-07-27 pass —
- 2026-07-27 (earlier run): worklist advanced (admetlab-mcp → npi-registry) — the 12 unstamped pages were all stamped, bringing the catalog to full coverage. Next run: keep working the injected worklist top-to-bottom and prioritize these two fresh follow-ups — (1)
novomcp: fetch the newNovoMCP/novomcpREADME, confirm thelocalhost:8018/mcpself-host launch command, reconcile LICENSE (NOASSERTION vs Apache-2.0 site claim) — likely flips degraded/unknown → works/caution; (2)drug-pipeline-mcp: recheck PyPI fordrug-pipeline-mcp(404 on all 3 endpoints this run) — if it appears, flip degraded → works; if still absent, hand the pip/uvx-vs-git-source discrepancy to the curator. Also,cdxml-toolkitandchimerax-mcpare good smoke-queue candidates ONLY if the sandbox can satisfy their GUI/ChemDraw/ChimeraX prerequisites — otherwise leave them as static-confirmed works. - RESOLVED 2026-07-22: the selector loop is broken — this run served a NEW window (ketcher → medical-terminologies-mcp) instead of the stuck 10x-genomics-cloud→autodock 25 that re-served five times. The same-date rotation the maintainer added is advancing the pointer, so coverage is now progressing across the ~447-page catalog on a rolling basis. Next run: keep working whatever fresh worklist is injected top-to-bottom; the stuck batch is behind us. All 25 pages this window were clean rechecks (zero drift). Note for cadence:
K-Dense-AI/scientific-agent-skillshad a fresh push (2026-07-20→2026-07-21) — provenance/MIT unchanged, but re-fetch its LICENSE/skill dirs if a future push changes the collection license. - DONE 2026-07-20 (worklist maintenance batch #5, same 10x-genomics-cloud → autodock-vina-docking list served a FIFTH time): all 25 rechecked again against fresh source fetches — zero drift, no fixes. Fifth consecutive identical batch; the selector loop is unchanged and still self-perpetuating. Maintainer action still needed (verifier cannot self-correct):
scripts/select_verify_targets.pyuses a stable verified_on-oldest tie-break, and because the whole catalog is uniformly dated 2026-07-20 the same 25 slugs sort first every run, so the pointer never advances and the other ~420 pages are never rechecked. Fix options unchanged from batch #3/#4: add a secondary tie-break to the selector (e.g. round-robin hash of slug against run date/commit) OR have the workflow advance a rotating cursor so successive runs serve different windows. Until the selector changes, every maintenance run keeps re-verifying only these 25 with a green “complete” count while coverage silently stalls — exactly the blind-spot classVERIFIER_AGENT.mdwarns about. This run’s anchor re-fetches (all unchanged, backing existing grades): NeuroClaw MIT/2026-07-14/75★, K-Dense MIT/2026-07-20/31.3k★, DeepMind science-skills Apache-2.0/2026-07-07/2469★, GPTomics bioSkills MIT/2026-07-18/1042★, DeepMind alphafold Apache-2.0/2026-04-22/14.7k★, Augmented-Nature AlphaFold+BioStudies NOASSERTION/2025-12-21, SciAgent-Skills NOASSERTION-classifier-CC-BY-4.0-root/2026-06-15/278★, PyPI arxiv-mcp-server 0.5.1 + aind-data-mcp 0.4.5, MCPmed/allenbrain-mcp no-LICENSE/2026-04-01/3★, life-sciences marketplace still lists adisinsight+10x-genomics. - DONE 2026-07-20 (worklist maintenance batch #4, same 10x-genomics-cloud → autodock-vina-docking list served a FOURTH time): all 25 rechecked again against fresh source fetches — zero drift, no fixes. This is now the fourth consecutive identical batch. The selector loop is fully confirmed:
select_verify_targets.pyuses a stable verified_on-oldest tie-break, and because the whole catalog is uniformly dated 2026-07-20 the same 25 slugs sort first every run, so the pointer never advances and the other ~420 pages are never rechecked. Maintainer action needed — this run cannot self-correct the loop (the verifier must not bumpverified_onbeyond the run date, and all pages already carry today’s date): add a secondary tie-break to the selector (e.g. round-robin hash of slug against the run date/commit) OR have the workflow advance a rotating cursor so successive runs serve different windows. Until the selector changes, every maintenance run will keep re-verifying only these 25 with a green “complete” count while coverage silently stalls — exactly the blind-spot classVERIFIER_AGENT.mdwarns about. - DONE 2026-07-20 (worklist maintenance batch #3, same 10x-genomics-cloud → autodock-vina-docking list served a THIRD time): all 25 rechecked again against fresh source fetches — zero drift, no fixes. The selector keeps re-serving the identical 25 because the whole catalog is uniformly dated 2026-07-20, so verified_on-oldest ties resolve to the same slug ordering every run. This is now a confirmed selector loop: the
select_verify_targets.pytie-break is stable, so a uniformly-dated catalog re-serves the same batch indefinitely. Recommendation for the maintainer: add a secondary tie-break (e.g. round-robin by hashing slug against run date) or advanceverified_onon rechecked pages so the pointer moves — otherwise the other ~420 pages never get rechecked. Until then, treat any page as a fair recheck target; the three rechecks of these 25 have all confirmed unchanged. - DONE 2026-07-20 (worklist maintenance batch #2, same 10x-genomics-cloud → autodock-vina-docking list): all 25 rechecked again against fresh source fetches; 24 unchanged, 1 micro-fixed (
arxivsecurity_note version 0.5.0→0.5.1, grade unchanged). The selector re-served the identical batch because these are the 25 oldestverified_on(all 2026-07-20) — next run should still resume from the top of a freshly-computed worklist; if it keeps re-serving the same 25, the whole catalog is now uniformly dated 2026-07-20 and any page is a fair recheck target. - DONE 2026-07-20 (worklist maintenance batch #1, 10x-genomics-cloud → autodock-vina-docking): all 25 rechecked against fresh source fetches; 24 unchanged, 1 fixed (
autodock-vina-dockingcaution→cleared — SciAgent root LICENSE is CC BY 4.0, superseding the stale NOASSERTION caution). Next run: resume from the top of a freshly-computed worklist (verified_on-oldest first). Cadence-watch items on this batch —alphagenome/adisinsight/10x-genomics-cloudstay degraded (signup/subscription/paid gated; retest for a free tier); the Augmented-Nature pair (alphafold,arrayexpress) andallenbrainstay caution (restrictive/absent LICENSE); recheck K-Denseastropy/aeon/arboreto/anndataBSD-3-wrapper claims only if K-Dense relicenses. Lesson reconfirmed: anyjaechang-hits/SciAgent-Skillspage whose security_note cites GitHub NOASSERTION is stale — the committed root LICENSE is CC BY 4.0, so those clear by default unless the page overstates its own data-source license. biomcp— recheck next clean run to flip degraded→works: the launch command was corrected tobiomcp servethis run (auto-fix ⇒ degraded per rubric). Nothing else off; verify the four occurrences still readserveand stamp works. New guardrail now live — the launch-command static check catches this whole class (a package resolves but its documented invocation is dead/renamed), so it applies to every future MCP-server/CLI stamp, not just biomcp.- DONE 2026-07-20 (launch-command sweep): every catalog entry with a trailing launch subcommand verb was validated against upstream; only
biomcpwas wrong (fixed). scmcphubrun,bci-mcp serve,rdkit-agent mcp,chatspatial server,scitex mcp startall confirmed correct. Remaining lower-risk launch shapes not individually re-fetched this pass (entrypoint/module paths —python -m <mod>.serverforblast/gwas-mcp/spikelab,uv run ... startforfhir-momentum,mcp run ./server.pyforchemlint): re-confirm these against each repo’s README on the normal maintenance cadence. - DONE 2026-07-20 (worklist batch): the 7 unstamped worklist pages are all stamped —
mygene(works/cleared);alphafold,gene-ontology,brian2,clinical-trial-protocol,cms-coverage(works/caution);biorender(degraded/cleared). The 8 already-stamped worklist items were rechecked against fresh source fetches (NeuroClaw MIT/maintained; K-Dense MIT/maintained + smoke-installable) and left at their existing 2026-07-20 grades. Curator handoff:alphafold+gene-ontologyPricingrows were falsely claiming MIT/OSS for the Augmented-Nature wrapper code, which is actually a restrictive personal non-commercial LICENSE (GitHub NOASSERTION) — verifier fixed the Pricing lines this run; curator owns any further wording. Same license pattern now confirmed across the Augmented-Nature MCP-server family (uniprot,human-protein-atlas,alphafold,gene-ontology,arrayexpress/BioStudies, OpenTargets fallback) — treat any otherAugmented-Nature/*-MCP-Serverpage’s MIT/OSS claim as suspect and fetch its raw LICENSE before stamping. Next run: resume from the top of a freshly-computed worklist (bootstrap should now be complete-or-near — confirm coverage) and keep rechecking the degraded/broken items below on cadence. - DONE 2026-07-20 (maintenance recheck pass 3): re-fetched all five open priority items + two staleness-cadence caution items, none regraded —
openneurostill broken (repo + endpoint 404 for the 4th consecutive run; refreshed note/flag/table row to “fourth consecutive run” — curator: strong signal to remove/replace),glygenstill 503,open-targetssource repoopentargets/platform-mcpstill Apache-2.0/current + official endpoint still GET-untestable,covasynnpm@covasyn/mcp-clientstill 0 results,morningstill absent fromanthropics/skills/skills/. Staleness rechecks unchanged (notes already accurate):scanpy(scmcphub/scanpy-mcp BSD-3 pushed 2025-06-27),blast(bio-mcp/bio-mcp-blast license null pushed 2025-06-29). Coverage re-confirmed 440/440. Next cycle: keep rechecking these on cadence (gradeglygenbroken if 503 persists AND self-host repo regresses; retestopen-targetsofficial endpoint with a real MCP client; watchnovomcpfor a public client/free tier) and lift the no-LICENSEanthropics/healthcareskills to cleared if a LICENSE lands. - DONE 2026-07-20 (maintenance recheck):
openneuroregraded broken + flagged (repo + hosted endpoint 404 for the 2nd consecutive run — hand off to curator for removal/replacement). Confirmed-unchanged rechecks (leave dated 2026-07-20, revisit on cadence):glygen(hosted endpoint still 503 — retest next cycle; consider degraded→broken if the hosted endpoint stays down AND the self-host repo regresses),open-targets(official endpointinitializestill untestable via GET WebFetch — retest with a client; source repo redirectopentargets/open-targets-platform-mcp→opentargets/platform-mcpstill resolves Apache-2.0),covasyn(hosted 406 API-key-gated, npm@covasyn/mcp-clientstill absent — curator to reconcile the stdio client package name),novomcp(recheck for a public client/free tier). Still open on the LICENSE-lands cadence: the no-LICENSEanthropics/healthcareskills (fraud-detection/procedure-coding/clinical-note-extract/prior-auth-review/icd-10-codes/scientific-problem-selection) andmorning(locate the correct plugin/bundle). Smoke-note refresh done forrdkit-skill+scikit-bio(git ENOENT resolved; both K-Dense slugs now pass vianpx skills add). - DONE 2026-07-20 (pass 30): the final 16 unstamped pages are all stamped (
npi-registry,pubmed,fhir-wso2,proto-okn,aind-data,mhc-binding-prediction,drug-repurposing,hypothesis-crucible→ works/cleared;fraud-detection,procedure-coding,clinical-note-extract,openfda,cbioportal,arrayexpress→ works/caution;bio-research,10x-genomics-cloud→ degraded — see Flagged). A full-catalog sweep confirms 440 of 440 tool pages now carry^verification:— the bootstrap enumeration is complete. Next-run priority shifts to RECHECKING the degraded/caution pages on their own cadence rather than fresh enumeration:openneuro(repo + endpoint 404 — if still 404 grade broken + setflagged:),morning(locate correct plugin/bundle),open-targets(retest official MCPinitialize),glygen/novomcp/covasyn(retest hosted endpoints), and the no-LICENSEanthropics/healthcareskills (fraud-detection/procedure-coding/clinical-note-extract/prior-auth-review/icd-10-codes/scientific-problem-selection) — lift to cleared if a LICENSE lands. Enumeration reminder: Grepcountgives false “Found 0” for line-1 matches; usefiles_with_matchescount (440) vs the LS file total to detect any newly-added unstamped pages. - DONE 2026-07-20: the 12 previously-deferred tail pages are all stamped (
tcr-epitope-binding,single-cell-rna-qc,pdbe,medical-terminologies-mcp,indication-dossier→ works/cleared;pynibs,ontology-lookup-service,prior-auth-review,icd-10-codes→ works/caution;open-targets,openneuro,morning→ degraded — see Flagged). Next-run priority: RECHECK the three degraded pages —openneuro(repo + hosted endpoint both 404 this run; if still 404 next run grade broken + setflagged:),morning(locate the correct plugin/bundle or reconcile the Claude Science claim),open-targets(retest the official MCPinitializeendpoint). Then continue enumerating any still-unstamped catalog pages: Grepcatalog/tools/*.mdfor files lacking^verification:(Bash multi-op is gated; the Task/subagent tool 404’d on the sonnet model previously — use Grep pattern compares to enumerate). Confirm each page’ssupplier:+ anchor before stamping. - Standalone MCP / plugin / connector batch — DONE 2026-07-20 (see Recently verified): 15 unstamped non-K-Dense/non-SciAgent pages stamped —
rdkit-mcp,spikelab,seqera,healthlake-mcp,scholar-gateway,synapse(works/cleared);molecule-mcp,openmm-mcp,rdkit-agent,labmate-mcp,scitex,drugbank,neuroflow(works/caution);novomcp,cortellis(degraded). Remaining standalone unstamped candidates for next run:blast(bio-mcp org, recheck LICENSE),scanpy/decoupler-mcp/liana-mcp/cellrank-mcp(scmcphub, smoke-queued), plus any other non-K-Dense/non-SciAgent MCP servers surfaced by an LS sweep ofcatalog/tools/. - NeuroClaw supplier — DONE 2026-07-20 (all pages stamped): this pass stamped the final 6 (
qsiprep-tool,run_models,spacenet,wmh-segmentation,nii2dcm,nilearn-tool) on top of the earlier 25 + the*-skill.mddataset pages.nii2dcmnote reflects MIT skill code wrapping BSD-3-Clause upstream. No NeuroClaw pages remain unstamped. - Anthropic
tool_type: Claude.ai Connectorpages — DONE 2026-07-20 (all 21 stamped this pass; see Recently verified). The 16 Anthropic-hosted featured-connector data sources + ketcher = works/cleared; medidata = works/cleared (marketplace + published endpoint); owkin/revvity-signals/inductive-bio = degraded/cleared (provenance confirmed, no publicly resolvable endpoint). No connector pages remain unstamped. - This run stamped SciAgent non-database skill batch 4 (15
supplier: SciAgentskills: mdanalysis-trajectory, sar-analysis, smina-molecular-docking, multiqc-qc-reports, plannotate-plasmid-annotation, sgrna-design-guide, libsbml-network-modeling, plotly-interactive-plots, napari-image-viewer, opencv-bioimage-analysis, cellpose-cell-segmentation, scikit-image-processing, celltypist-cell-annotation, harmony-batch-correction, simpleitk-image-registration — allworks/cleared) plus the 4 GPTomics bioSkills pages (neoantigen-prediction, epitope-prediction, scirpy-analysis, mhc-class-ii-prediction — anchorGPTomics/bioSkillsMIT, allworks/cleared). SciAgent anchor re-confirmedjaechang-hits/SciAgent-Skills(CC BY 4.0 root LICENSE, pushed 2026-06-15, updated 2026-07-20; new parent dirdata-visualization/confirmed this run). Parent dirs STILL hold many more unstamped SciAgent skills — confirm each catalog page issupplier: SciAgentAND its parent contents dir before stamping:structural-biology-drug-discovery/remaining: pubchem-compound-search, pdb-database (some may be-databaseor already stamped — checksupplier:and existing stamp).genomics-bioinformatics/qc/remaining: busco-status-interpretation.lab-automation/remaining: opentrons-protocol-api, pylabrobot (check supplier — pylabrobot may be K-Dense).medical-imaging/remaining: histolab-wsi-processing, pydicom-medical-imaging (some are K-Dense pages — check supplier).proteomics-protein-engineering/remaining: adaptyv-bio, esm-protein-language-model, matchms-spectral-matching, pyopenms-mass-spectrometry (check supplier).systems-biology-multiomics/remaining: cobrapy-metabolic-modeling, lamindb-data-management (check supplier — lamindb/cobrapy have K-Dense pages).scientific-computing/(aeon, astropy-astronomy, dask-parallel-computing, exploratory-data-analysis, geopandas-geospatial, hypogenic-hypothesis-generation, matlab-scientific-computing, networkx-graph-analysis, neurokit2, neuropixels-analysis, nextflow-workflow-engine, polars-dataframes, pyhealth, pymatgen, pymoo, scikit-learn-machine-learning, shap-model-explainability, simpy-discrete-event-simulation, sympy-symbolic-math, torch-geometric-graph-neural-networks, transformers-bio-nlp, umap-learn, vaex-dataframes, zarr-python — many have separate non-SciAgent catalog pages, checksupplier:before stamping),cell-biology/remaining (flowio-flow-cytometry),genomics-bioinformatics/single-cell/remaining (anndata-data-structure, cellxgene-census, scanpy-scrna-seq, scvi-tools-single-cell),data-visualization/remaining (any non-plotly siblings — confirm via contents API). Watch for per-skill data/tool license restrictions (only flag if the page overstates its license, e.g. kegg).
- Prior run stamped the entire ToolUniverse family (19 pages: 1 MCP server + 18 skills) against
mims-harvard/ToolUniverseApache-2.0 + PyPItooluniverse1.0.22 — allworks, 17 cleared and 2 caution (binder-discovery,drug-drug-interaction; see Flagged). Tooling reminders that held again: OSVapi.osv.dev/v1/queryis POST-only (WebFetch GET → 405) so use GitHubrepos/<org>/<repo>/security-advisories(GET); the Read cache invalidates across files AND a MultiEdit right after a fresh Read can trip the permission gate — the reliable pattern is Read-then-two-single-Edits per file, stamped strictly sequentially. - Prior run (pass 15) stamped a second non-K-Dense standalone batch:
evo2,scgpt,proteinmpnn,solublempnn,openfold3,chatspatial,biocontextai(works/cleared),neurosift(works/caution),allenbrain+covasyn(degraded/caution; see Flagged). - Good next standalone batches (still many unstamped non-K-Dense pages): the remaining
supplier: SciAgentskill pages that are NOT-database(e.g.deseq2-differential-expression,star-rna-seq-aligner,gatk-variant-calling,snakemake-workflow-engine, the many*-analysis/aligner/annotation skills) — same anchorjaechang-hits/SciAgent-Skills(CC BY 4.0 root LICENSE) but confirm each skill’s parent dir via contents API; theGPTomics bioSkillspages are DONE (all 4 stamped 2026-07-20); Anthropicanthropics/life-sciencesskill/connector pages (metabolights,complex-portal,rfam,intact,bindingdb,clinical-trial-protocol,finngen, etc. — verify each in the marketplace’s.claude-plugin/marketplace.json+<name>/.claude-plugin/plugin.json); and standalone repo/PyPI-anchored servers (biomcpandtooluniversefamily done;blast,scanpy,drugbank,openneuro). - Next bootstrap batch: work the remaining unstamped
supplier: K-Densecatalog pages, confirming eachskills/<slug>dir with a directcontents/skills/<slug>fetch (the summarized listing is unreliable in both directions). Then continue with remaining non-K-Dense unstamped suppliers (standalone MCP servers / skills) — a large share of the unstamped pages are outside the K-Dense anchor. Editing lesson (holds every run): stamp each file strictly sequentially (read-then-two-edits per file); parallel edits across files trip the read-cache/permission gate. - Note (superseded 2026-07-20): a prior note claimed
scipy,seurat,squidpy,spatialdata,survival-analysis,systems-biology,tensorflow,torchetc. were absent from the K-Denseskills/tree. This run’s clean tail fetch shows several of those names (scipy,seurat,squidpy,spatialdata,survival-analysis,systems-biology,tensorflow) DO appear in the listing. Given the summarized listing is unreliable in both directions, do NOT treat any slug as present or absent from the list alone — confirm with a directcontents/skills/<slug>fetch before stamping (or declining) each catalog page. - Curator handoff:
xlsx,pdf,docx,pptxpagePricinglines falsely claim Free/OSS (each skill’s upstream LICENSE.txt is Anthropic PBC proprietary) — verifier stamped securitycaution; curator owns the Pricing corrections. - scmcphub ecosystem (
scanpy,cellrank-mcp,decoupler-mcp,liana-mcp) — recheck for a maintenance bump or archival; currently ~13 months stale. gromacs-mcp— recheck upstream for a published LICENSE file; graded caution until then.blast(bio-mcp org) — recheck for a published LICENSE and a maintenance bump; caution until then.- SciAgent
-databaseremainder (bootstrap) — RESOLVED this run (batch 2):biorxiv,interpro,hmdb,gtopdb,emdb,brenda,unichem,uspto,zinc,reactome,pride,openalex,opentargets,metabolomics-workbench,dailymed,fda,ddinterall stamped, plusstring-database-ppi. Key lesson: these skills do NOT all live underskills/genomics-bioinformatics/databases/— they are scattered acrossstructural-biology-drug-discovery/,proteomics-protein-engineering/,systems-biology-multiomics/,scientific-writing/,scientific-computing/(the path is in each page’sNotesline “The skill directory upstream isskills/<...>”). Confirm each by fetching that parent contents endpoint. Still to do: the Google DeepMindunibind/gtexpages (different anchorgoogle-deepmind/science-skills; verify separately). NOTE:ensembl-database.mdhas no catalog page (present in repo listing only) — do not chase it. - SUPERSEDED 2026-07-20: the old note that SciAgent-Skills entries (
bcftools-variant-manipulation,autodock-vina-docking, …) are caution due to GitHub NOASSERTION is wrong — the committed root LICENSE is CC BY 4.0. Those Augmented-Nature/SciAgent skill pages clear on provenance/license by default; recheck each only for its own data-source or per-skill license. chemcp— recheck for a LICENSE file committed to the repo to reconcile the ISC npm metadata.
Smoke-test queue
The scripts/select_smoke_targets.py selector is authoritative for what the quarantined smoke job
may install/boot (open, no-auth, no-cost Skills/MCP servers only). List slugs here to prioritize the
next run’s smoke batch; leave empty to let the selector pick by age.
Note (2026-07-27): the latest batch is 12/12 pass — openfda-mcp-server (npx), bci-mcp (npx),
biomcp (uv tool), anndata/arboreto (pip), and the K-Dense CLI batch (npx skills add
K-Dense-AI/scientific-agent-skills, several aeon/astropy/bids slugs) all install/boot cleanly. The
lone non-pass was cdxml-toolkit boot_error, and that is a false negative — the resolver backtracked
to v0.5.1 (no cdxml-mcp entry point); the current v0.5.17 metadata does carry the entry point, so
the page stays works. Node in-sandbox is v20.19.2 (skills@1.5.20 wants >=22.20.0) — harmless
EBADENGINE warning, install still succeeds. Next smoke priorities:
alkyl(Kdevos12) — no smoke result yet; static-onlyworksthis run, real install would upgrade the evidence.blatant-why(001TMF) — no smoke result yet; check whether a no-key code path exists before queuing (ships optional external API keys).medicare-mcp(openpharma-org) — no smoke result yet; no published npm package, would need agit clone && npm install && npm run buildsmoke path rather than a plain install.nwb-mcp-server(Ben Hardcastle) — no smoke result yet;uvx nwb-mcp-server --root_dir data --glob_pattern "*.nwb"needs a sample.nwbfixture to boot meaningfully.pbmcpedia(MCPmed) — no smoke result yet;git clone && npm install && npm start -- --transport stdio, no API key required.scanpy(pip install scanpy-mcp)decoupler-mcp(pip install decoupler-mcp)liana-mcp(pip install liana-mcp)cellrank-mcp(pip install cellrank-mcp)protein-mcp-server(npx -y @cyanheads/protein-mcp-server@latest) — stamped works by static bin resolution this run; a boot smoke would upgrade the evidence to a real verdict.- Aging K-Dense slugs — CLI batch confirmed installable in-sandbox; keep rotating fresh slugs to capture boot verdicts.
- From the 2026-08-03 batch,
smoke_eligible: true/smoke_status: nullin liveness.json (bioSkills Python skills — no external creds):binding-site-detection,cnv-inference,doublet-detection,functional-profiling,immunogenicity-scoring,interface-analysis,metaphlan-profiling— good candidates for the next smoke rotation. lineage-tracing— recheck the smoke job’s target string next run; the current smoke installs the stale/deprecatedpip install cassiopeia-lineage(PyPI 1.0.4, install_error on Py3.12) instead of the page’s actual recommendedpip install git+https://github.com/YosefLab/Cassiopeia@master— false negative, do not regrade from this alone; consider updating the selector’s target to the git install.- NOT smoke candidates:
cdxml-toolkit(Windows + ChemDraw),chimerax-mcp(GUI + ChimeraX) — queue only if the sandbox can satisfy those GUI/native prerequisites. - From the 2026-08-10 batch,
smoke_eligible: true/smoke_status: nullin liveness.json (bioSkills R/Python skills — no external creds):clustering-phenotyping,compartment-analysis,compensation-transformation,covariation-analysis,cytometry-differential-analysis,cytometry-qc,effect-measures,gating-analysis,geometric-analysis,hashing-demultiplexing— good candidates for the next smoke rotation (note several need R/Bioconductor installs, not just pip).