Sealed
Per-call paid skills for AI agents, run server-side: inputs in, outputs back. The body never ships.
Open source Open in the app JSON README (API)
About
Per-call paid skills for AI agents, run server-side: inputs in, outputs back. The body never ships.
Details
- Kind
- MCP servers
- Topic
- No topic detected
- Publisher
- edwardyen724-g
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 0.1.0
- Last push
- 2026-08-11T18:39:43Z
- Repository state
- ativo
- Language
- JavaScript
- License
- MIT
- Added
- 2026-08-29 03:02:44
- Updated
- 2026-08-29 03:02:44
- Origin id
io.github.edwardyen724-g/sealed
README
# sealed-mcp
Thin [MCP](https://modelcontextprotocol.io) stdio client for [Sealed](https://sealed.run) — the skill marketplace where **your skill runs sealed**.
This package is a pure proxy. It connects your MCP-capable agent to a remote Sealed server and exposes two tools:
| Tool | What it does | Annotations |
|---|---|---|
| `list_skills` | Lists the public skill catalog (name, description, input schema, price per call) | `readOnlyHint: true` |
| `run_skill` | Runs a skill **server-side** and returns only its output + price/mode meta. Each call spends wallet balance at the listed per-call price. | `readOnlyHint: false`, `destructiveHint: false` |
**Skill bodies never reach this process.** Skills execute on Sealed's infrastructure; this client only carries your inputs up and the output back. There is no local execution mode — `SEALED_API_URL` is required.
Zero runtime dependencies. Plain Node 18+ (uses the global `fetch`).
> npm naming: this package targets the unscoped name `sealed-mcp` and carries `mcpName: io.github.edwardyen724-g/sealed` for the official MCP registry. If that npm name is unavailable at publish time, the fallbacks are the scoped names `@sealed/mcp` or `@sealedrun/mcp` — update `package.json`, registry drafts, and install snippets together.
## Install / configure
### Claude Code
```sh
claude mcp add sealed --env SEALED_API_URL=https://sealed.run --env SEALED_API_KEY=sealed_sk_… -- npx -y sealed-mcp
```
### Cursor / Windsurf
Add to `~/.cursor/mcp.json` (Cursor) or `~/.codeium/windsurf/mcp_config.json` (Windsurf):
```json
{
"mcpServers": {
"sealed": {
"command": "npx",
"args": ["-y", "sealed-mcp"],
"env": {
"SEALED_API_URL": "https://sealed.run",
"SEALED_API_KEY": "sealed_sk_…"
}
}
}
}
```
### Generic stdio MCP client
Spawn the binary and speak newline-delimited JSON-RPC 2.0 over stdin/stdout (`initialize`, `tools/list`, `tools/call`):
```sh
SEALED_API_URL=https://sealed.run SEALED_API_KEY=sealed_sk_… npx -y sealed-mcp
```
## Environment variables
| Variable | Required | Purpose |
|---|---|---|
| `SEALED_API_URL` | **Yes** | Base URL of the Sealed API (e.g. `https://sealed.run`). The client exits with an error if unset. |
| `SEALED_API_KEY` | No | Your Sealed API key (`sealed_sk_…`), sent as the bearer token. Without it, calls run unauthenticated and most servers will reject paid runs. |
## Errors you may see
Fixed, non-leaking error strings: `unauthorized` (bad/missing key), `insufficient funds` (top up your wallet), `output blocked by leak gate`, `unknown skill: <id>`, `cannot reach the Sealed API`. Server error bodies are never echoed.
## Links
- Website: https://sealed.run
- Get an API key: sign up at your Sealed server's `/signup` endpoint (production emails you a single-use sign-in link that shows the key once)