sealed-mcp
Thin MCP stdio client for Sealed — the skill marketplace where your skill runs sealed.
This package is a pure proxy. It connects your MCP-capable agent to a remote Sealed server and exposes two tools:
| Tool | What it does | Annotations |
|---|---|---|
list_skills | Lists the public skill catalog (name, description, input schema, price per call) | readOnlyHint: true |
run_skill | Runs a skill server-side and returns only its output + price/mode meta. Each call spends wallet balance at the listed per-call price. | readOnlyHint: false, destructiveHint: false |
Skill bodies never reach this process. Skills execute on Sealed's infrastructure; this client only carries your inputs up and the output back. There is no local execution mode — SEALED_API_URL is required.
Zero runtime dependencies. Plain Node 18+ (uses the global fetch).
npm naming: this package targets the unscoped name
sealed-mcpand carriesmcpName: io.github.edwardyen724-g/sealedfor the official MCP registry. If that npm name is unavailable at publish time, the fallbacks are the scoped names@sealed/mcpor@sealedrun/mcp— updatepackage.json, registry drafts, and install snippets together.
Install / configure
Claude Code
claude mcp add sealed --env SEALED_API_URL=https://sealed.run --env SEALED_API_KEY=sealed_sk_… -- npx -y sealed-mcp
Cursor / Windsurf
Add to ~/.cursor/mcp.json (Cursor) or ~/.codeium/windsurf/mcp_config.json (Windsurf):
{
"mcpServers": {
"sealed": {
"command": "npx",
"args": ["-y", "sealed-mcp"],
"env": {
"SEALED_API_URL": "https://sealed.run",
"SEALED_API_KEY": "sealed_sk_…"
}
}
}
}
Generic stdio MCP client
Spawn the binary and speak newline-delimited JSON-RPC 2.0 over stdin/stdout (initialize, tools/list, tools/call):
SEALED_API_URL=https://sealed.run SEALED_API_KEY=sealed_sk_… npx -y sealed-mcp
Environment variables
| Variable | Required | Purpose |
|---|---|---|
SEALED_API_URL | Yes | Base URL of the Sealed API (e.g. https://sealed.run). The client exits with an error if unset. |
SEALED_API_KEY | No | Your Sealed API key (sealed_sk_…), sent as the bearer token. Without it, calls run unauthenticated and most servers will reject paid runs. |
Errors you may see
Fixed, non-leaking error strings: unauthorized (bad/missing key), insufficient funds (top up your wallet), output blocked by leak gate, unknown skill: <id>, cannot reach the Sealed API. Server error bodies are never echoed.
Links
- Website: https://sealed.run
- Get an API key: sign up at your Sealed server's
/signupendpoint (production emails you a single-use sign-in link that shows the key once)