The secure registry for MCP servers and skills.
Every bundle scanned. Every trust score public. Open source from day one.
Built for MCP security
MCPB Format
One standardized package format for all MCP servers. Python, Node, or binary, all installed the same way.
Built-in Security Scans
25 controls, 5 domains. Trust score on every publish. L1 through L4 certification.
Learn about certification →Open Source Registry
Entire stack is Apache 2.0. Self-hostable with federation, policies, and audit logging.
Want the full security architecture? Read the whitepaper →
Why not npm, PyPI, or Docker Hub?
| General-purpose registries | mpak | |
|---|---|---|
| Packaging | Language-specific (npm, pip, Docker) | One format (MCPB) for all runtimes |
| Install experience | Requires runtime, deps, config | Single command, zero deps |
| Security scanning | Generic CVE checks | MCP-specific: 25 controls, 5 domains |
| Trust visibility | None or hidden | Public trust score on every package |
| Enterprise governance | Limited or paid add-on | Self-hostable, federation, audit logs |
Extend your AI
Bundles
Capabilities
Pre-built servers that give your AI new abilities. Connect to databases, call APIs, access file systems. Every bundle scanned with 25 security controls.
- Database access
- API integrations
- File operations
mpak bundle pull [package]Browse bundles →Skills
Expertise
Instructions that teach your AI new behaviors and domain knowledge. Shape how it thinks and responds.
- Code review patterns
- Writing styles
- Domain expertise
mpak skill install @org/skillBrowse skills →Built something for AI?
Publish bundles or skills to mpak. Security scanning, verified provenance, one-command installs.
Install the CLI
npm install -g @nimblebrain/mpakThen run mpak search to get started