io.github.barneywohl/hugging-bay
NPM · HUGGING-BAY-MCP · 2 COMPONENTS · SCANNED SEP 20
Verified open AI artifact search, trust evidence, downloads, and agent workflows from Hugging Bay.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- No production dependencies, so there is no dependency health to assess. View diagnostics → Pass
Provenance & Transparency19
- Repository check failed: the declared repository URL returned HTTP 404. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 9 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability71
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 5178 tokens (~50/item across 102 items; 102 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage68
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 3% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_saved_search" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 102 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.barneywohl/hugging-bay MCP server?
io.github.barneywohl/hugging-bay runs locally as an npm package, launched with npx -y hugging-bay-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · hugging-bay-mcp
claude mcp add barneywohl-hugging-bay -- npx -y hugging-bay-mcp
{
"mcpServers": {
"barneywohl-hugging-bay": {
"command": "npx",
"args": [
"-y",
"hugging-bay-mcp"
]
}
}
} {
"servers": {
"barneywohl-hugging-bay": {
"command": "npx",
"args": [
"-y",
"hugging-bay-mcp"
]
}
}
} codex mcp add barneywohl-hugging-bay -- npx -y hugging-bay-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"barneywohl-hugging-bay": {
"type": "local",
"command": [
"npx",
"-y",
"hugging-bay-mcp"
],
"enabled": true
}
}
} openclaw mcp add barneywohl-hugging-bay --command npx --arg -y --arg hugging-bay-mcp
mcp_servers:
barneywohl-hugging-bay:
command: "npx"
args: ["-y", "hugging-bay-mcp"] {
"McpServers": {
"barneywohl-hugging-bay": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"hugging-bay-mcp"
]
}
}
} assistant mcp add barneywohl-hugging-bay -t stdio -c npx -a -y hugging-bay-mcp
{
"mcpServers": {
"barneywohl-hugging-bay": {
"command": "npx",
"args": [
"-y",
"hugging-bay-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −3
- Stability: pass → 0.83 functional
- 16 Sept 26 +1
- Stability: 0.97 → pass security
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 −4
- Stability: pass → 0.77 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/hugging-bay-mcp@0.1.2
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 0 packages
| Packages resolved | 0 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
apply_publisher_application ~105
Submit a public publisher namespace application for manual review. Does not create accounts or tokens automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| acceptedTerms | boolean | yes | – |
| artifactTypes | array | yes | – |
| contact | string | yes | – |
| displayName | string | yes | – |
| expectedUploads | string | – | – |
| intendedUse | string | yes | – |
| namespace | string | yes | – |
| provenancePlan | string | yes | – |
| sourceUrl | string | yes | – |
| website | string | – | – |
No output schema declared.
No examples provided.
approve_mirror_batch ~54
Revalidate selected paths and approve a durable mirror batch. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| note | string | – | – |
| riskOverride | object | – | – |
No output schema declared.
No examples provided.
cancel_upload_session ~35
Cancel a pending upload session. Requires HUGGING_BAY_TOKEN with session owner/admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
check_storage ~43
Run an admin storage round-trip diagnostic. Writes, heads, reads, range-reads, and deletes a disposable object. Requires HUGGING_BAY_TOKEN with admin role.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
compare_artifacts ~33
Compare up to six Hugging Bay artifact ids or owner/name repos side by side.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | yes | – |
No output schema declared.
No examples provided.
complete_upload_session ~39
Verify uploaded objects and complete a large-upload session. Requires HUGGING_BAY_TOKEN with session owner/admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
create_mirror_batch ~101
Create a durable reviewed mirror batch from current readiness rows. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| candidateLimit | number | – | – |
| includeReviewedRiskyWeights | boolean | – | – |
| includeSupportOnly | boolean | – | – |
| limit | number | – | – |
| maxPlannedBytes | number | – | – |
| note | string | – | – |
| requestedOnly | boolean | – | – |
| targetHostedFiles | number | – | – |
No output schema declared.
No examples provided.
create_publisher_api_key ~49
Create an additional scoped publisher automation token. Plaintext token is returned once.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedOwners | array | – | – |
| displayName | string | – | – |
| purpose | string | – | – |
No output schema declared.
No examples provided.
create_upload_session ~52
Create signed large-upload URLs for a publisher release. Requires HUGGING_BAY_TOKEN with publisher/admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| files | array | yes | – |
| name | string | yes | – |
| owner | string | yes | – |
No output schema declared.
No examples provided.
delete_saved_search ~43
Delete one saved catalog watchlist for HUGGING_BAY_TOKEN.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Deprecated alias for searchId. |
| searchId | string | yes | – |
No output schema declared.
No examples provided.
expand_hf_detail_metadata ~142
Expand selected Hugging Face metadata rows with file-list details. Requires HUGGING_BAY_TOKEN with admin role. Production web services may disable this unless a monitored maintenance env flag is enabled; use direct workers for bulk expansion.
| Name | Type | Req | Description |
|---|---|---|---|
| backoffMs | number | – | – |
| dryRun | boolean | – | – |
| force | boolean | – | – |
| limit | number | – | – |
| maxRuntimeMs | number | – | – |
| missingSizes | boolean | – | – |
| preferRuntime | boolean | – | – |
| q | string | – | – |
| requestedOnly | boolean | – | – |
| retries | number | – | – |
| timeoutMs | number | – | – |
No output schema declared.
No examples provided.
extend_hf_import ~67
Plan a metadata-only continuation from a completed Hugging Face import run. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| pageSize | number | – | – |
| preset | string | – | – |
| previousRunId | string | yes | – |
| targetRecords | number | – | – |
No output schema declared.
No examples provided.
get_admin_mirror_queue ~50
List admin mirror queue rows with exact useful runtime/support file candidates. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| requestedOnly | boolean | – | – |
No output schema declared.
No examples provided.
get_agent_discovery ~49
Return the single-call agent discovery contract for answer engines, OpenClaw/Hermes-style agents, MCP clients, OpenAPI users, crawlers, citation targets, and bounded API entrypoints.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_agent_tasks ~32
Return intent-specific agent action plans for RAG embeddings, hosted downloads, commercial-safe search, and mirror prioritization.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_ai_bot_allowlist ~31
Return the machine-readable AI crawler/user-agent allowlist, official verification links, and WAF guidance.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_ai_mention_monitor ~29
Return prompt-level answer-engine monitoring targets, expected citations, crawler signals, and claim boundaries.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_ai_mention_results ~61
Return observed answer-engine mention and citation results, including provider, prompt, status, citation rank, wrong-claim flags, and bounded excerpts.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| promptId | string | – | – |
| provider | string | – | – |
No output schema declared.
No examples provided.
get_ai_search_guidance ~42
Return citation-ready AI-search guidance for ChatGPT, Perplexity, Gemini, Claude, Grok, OpenClaw, Hermes, and local agents.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_answer_pack ~37
Fetch one citation-ready answer pack with short answer, canonical citation targets, extraction APIs, and ranked rows.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | – |
No output schema declared.
No examples provided.
get_artifact ~28
Fetch a full artifact record by Hugging Bay artifact id.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_artifact_bundle ~38
Fetch one artifact's metadata, card, trust bundle, hosted files, and mirror readiness in one response.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_artifact_card ~35
Fetch a repo-grade artifact card as JSON or Markdown.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| markdown | boolean | – | – |
No output schema declared.
No examples provided.
get_artifact_distribution ~35
Fetch one artifact's hosted download state, upstream source, and reviewed peer-assisted fallback metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_artifact_insights ~47
Fetch decision-ready artifact insights with best-fit labels, trust gaps, runner commands, benchmark evidence, hardware estimate, hosted files, and mirror readiness.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_artifact_metadata ~32
Fetch agent-oriented artifact metadata with provenance, hosting, and safe next steps.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_artifact_reviews ~40
Fetch public community ratings, reviews, and verified-run attestations for an artifact.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| limit | number | – | – |
No output schema declared.
No examples provided.
get_catalog_coverage ~22
Return public catalog scale, source coverage, and readiness facts.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_citation_pack ~55
Fetch a one-call AI citation pack with safe claims, avoid claims, citation order, proof URLs, and extraction rows.
| Name | Type | Req | Description |
|---|---|---|---|
| q | string | – | – |
| query | string | – | – |
| slug | string | – | – |
No output schema declared.
No examples provided.
get_community_signals ~33
Fetch aggregate public community trust signals, recent reviews, and top helpful reviews.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
No output schema declared.
No examples provided.
get_download_plan ~45
Fetch hosted-only download instructions, signed manifest URL, SHA-256 hashes, and CLI commands for one artifact.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| tool | string | – | – |
No output schema declared.
No examples provided.
get_evidence_rollups ~35
Fetch global public evidence rollups by benchmark, tool, hardware, and artifact type.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
No output schema declared.
No examples provided.
get_health ~18
Return Hugging Bay public health and persistence state.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_import_run ~37
Fetch one import run with its cursors. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| runId | string | yes | – |
No output schema declared.
No examples provided.
get_import_status ~28
Fetch admin import/mirror job status. Requires HUGGING_BAY_TOKEN with admin role.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_indexing_status ~27
Fetch sitemap, URL batch, and crawl-readiness status for search engines and agents.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_local_kit ~49
Fetch copyable local-use commands, required files, warnings, and next actions for one artifact, optionally filtered by runtime tool.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| tool | string | – | – |
No output schema declared.
No examples provided.
get_manifest_signing_key ~23
Fetch public manifest signing key metadata used to verify signed manifests.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_mirror_batch ~41
Fetch one durable mirror batch with selected files and review/run state. Requires HUGGING_BAY_TOKEN with admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_mirror_pack ~27
Fetch one curated pack with artifact rows by slug.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | – |
No output schema declared.
No examples provided.
get_mirror_readiness ~43
Return mirror candidates with readiness scores, blockers, compatible tools, and selected safe files.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| requestedOnly | boolean | – | – |
No output schema declared.
No examples provided.
get_mirror_scale_plan ~81
Return a reviewed-mirror batch plan with selected files, byte totals, storage readiness, commands, and blockers. Does not execute mirroring.
| Name | Type | Req | Description |
|---|---|---|---|
| candidateLimit | number | – | – |
| limit | number | – | – |
| maxPlannedBytes | number | – | – |
| requestedOnly | boolean | – | – |
| targetHostedFiles | number | – | – |
No output schema declared.
No examples provided.
get_open_source_radar ~31
Return popular, newest, and non-Hugging Face open-source AI records in one bounded response.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_peer_fallbacks ~38
Fetch one artifact's reviewed torrent/magnet fallback bundle, scoped to hosted-file hashes and reviewer evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_publisher_application_status ~41
Fetch sanitized public status for one publisher namespace application.
| Name | Type | Req | Description |
|---|---|---|---|
| caseId | string | yes | – |
| id | string | – | Deprecated alias for caseId. |
No output schema declared.
No examples provided.
get_publisher_dashboard ~34
Return publisher-owned releases, release blockers, and upload sessions. Requires HUGGING_BAY_TOKEN with publisher/admin role.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_publisher_profile ~43
Fetch one public publisher namespace profile with releases, hosted files, claim state, and trust stats.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| namespace | string | yes | – |
No output schema declared.
No examples provided.
get_publisher_release_template ~49
Return a copyable Hugging Bay release manifest template for labs, including source URLs, hashes, runtime notes, upload-session body, and reviewed fallback fields.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | – | – |
No output schema declared.
No examples provided.
get_publisher_workflow ~27
Return publisher application, large-upload, release-check, and publishing workflow for agents.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_ranking ~32
Fetch one Hugging Bay ranking as JSON so agents do not scrape ranking HTML.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | – |
No output schema declared.
No examples provided.
What is the io.github.barneywohl/hugging-bay MCP server?
io.github.barneywohl/hugging-bay is an MCP server listed in the public MCP registry as io.github.barneywohl/hugging-bay. Verified open AI artifact search, trust evidence, downloads, and agent workflows from Hugging Bay. This page covers its npm package (hugging-bay-mcp).
Is the io.github.barneywohl/hugging-bay MCP server safe to use?
io.github.barneywohl/hugging-bay scores 74 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.barneywohl/hugging-bay MCP server expose?
io.github.barneywohl/hugging-bay exposes 102 tools: get_health, get_catalog_coverage, get_open_source_radar, get_trending, get_traffic, and 97 more. Their descriptions and schemas cost roughly 5,178 tokens of context every time the server is loaded.
Is the io.github.barneywohl/hugging-bay MCP server still maintained?
io.github.barneywohl/hugging-bay is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.barneywohl/hugging-bay MCP server under?
io.github.barneywohl/hugging-bay declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.