CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
execufunction-mcp avatar

ExecuFunction

execufunction-mcp/mcp-server
authSTDIOregistry active
Summary

Connects Claude or Cursor to ExecuFunction's API via personal access token, exposing about 70 tools across projects, tasks, notes, calendar events, and CRM contacts. The standout feature is codebase indexing: you can register repos, run full or incremental git-aware scans, then search semantically across indexed code or query git blame and commit history. It also stores encrypted secrets in a vault, links tasks to specific files or commits, and includes a datasets module for querying structured data with aggregation, bucketing, and timeseries transforms. Reach for this if you want an AI that can read your task backlog, search your indexed codebase, and create calendar events or tasks without leaving the editor.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Siftable MCP Server

A Model Context Protocol server that exposes Siftable tools to IDE clients like Cursor, Claude Desktop, and VS Code.

ExecuFunction 0.4.0.0 hosted compatibility

The npm package is 1.2.42; the hosted and source projection profile is 1.33.0. Projection 1.33.0 recognizes natural-language source-search intent and returns the retired capability card with local recovery rather than routing the request to curated code memories. Projection 1.32.0 added an explicit no_matches discovery outcome, rejects generic-operation and weak-prefix-only capability matches, preserves canonical compound-intent matches, and captures HTTP status classes in failure receipts. Projection 1.31.0 added governed lead-discovery scope requirements. Projection 1.29.0 added managed work-lease sessions for hosted clients while keeping claim tokens server-side. Projection 1.28.0 added four governed lead-discovery tools and five app-equivalent person/organization enrichment tools.

Lead discovery is disabled by default. When enabled, it requires separately granted lead_discovery:read or lead_discovery:write scopes; mcp:* does not imply either scope. Hosted baseline catalogs therefore omit company search until request_capability approval and a catalog refresh expose the hosted-capable tool. A company search is bounded to one paid Crustdata request, shows a maximum charge before dispatch, settles the actual provider credits, and saves results only as review candidates. Canonical CRM records are created through lead_discovery_import_plan_create followed by the existing crm_import_plan_approve and crm_import_plan_apply review gates.

Person enrichment returns stored profile and fact proposals. Apply accepts only proposal field names and fact IDs rehydrated from the completed run; it does not accept free-form replacements and is not retry-safe. Organization enrichment remains the app's paid preview-only flow and cannot apply canonical CRM changes.

1.2.42 compatibility note

Version 1.2.42 closes the publication-readiness audit. Natural-language source search discovery returns the canonical retired/local-only recovery card, while curated code-memory discovery remains distinct. The hosted setup guide now gives exact ChatGPT and Codex configuration steps.

1.2.41 compatibility note

Version 1.2.41 closes two hosted audit failures. Dataset routes reject malformed dataset UUIDs at the HTTP boundary, and MCP receipts preserve the resulting 400 as bad_request. find_capability now requires a direct domain signal plus an aligned operation; unrelated intent returns queryOutcome: no_matches with empty capability lanes and rephrase guidance. Exact tool names, removed-tool cards, and virtual orientation tools bypass semantic rejection.

1.2.40 compatibility note

Version 1.2.40 addresses the third round of live agent QA (the 2026-08-22 hosted audit).

  • claimability is honest about lifecycle and lease state, not only dependencies: state is one of ready, waiting, dependency_failed, leased, lease_expired, blocked, in_review, human_review_gate, or terminal, with claimable, reason, and nextAction alongside blockedBy. Claimed, running, cancelled, and done work no longer advertise ready; claimable is the authoritative boolean (a lease_expired item and a legacy-converted blocked placeholder whose predecessors are satisfied are claimable: true because an explicit claim recovers them). Claiming a non-claimable item by ID returns a 409 that names the state (lease_active, work_item_terminal, …) instead of not_found. The CLI and TUI gate on claimable when the server provides it.
  • agent_work_list and work_item_list hide done/failed/cancelled items by default (includeTerminal: true or an explicit status shows them), print their ordering rule, and document that higher queueRank sorts earlier, 0 is the default, and negative ranks are deferred (they sort after 0).
  • work_item_heartbeat says that a heartbeat on claimed work starts it (claimed → running, same as work_item_start); resultSummary passed to start, heartbeat, or release is now persisted instead of silently dropped.
  • task_get lists the executable work joined to the task (first ten, with a marker when more exist; "none yet" with the work_item_create hint when empty) when the connection can read work items; a missing scope keeps the capability hint and an upstream failure is reported as such (single attempt, no retry).
  • entity_graph reports each record's own status where it has one (a completed task is completed, not active; notes/datasets active/archived; connected projects now carry their name and status instead of [untitled entity]/active) — migration V400 fixes the SQL function that labelled every non-note node active and never joined projects. Other node types keep their type-specific label in that slot (organization industry, person relationship, news published date).
  • note_search ranks full-text matches (websearch syntax) ahead of semantic neighbours, then literal-substring fallbacks, instead of sorting raw scores on different scales; scores are comparable within a source, not across.
  • object_find distinguishes an unknown object type key from a known type with zero records.
  • Code-memory listings label a confirmed fact without chunk evidence as not_recorded (confirmed; no source-chunk evidence recorded) so the evidence gap is visible without downgrading human-admitted facts.

Projection 1.25.0 keeps hosted OAuth catalogs limited to tools callable with the current token. find_capability still discovers tools that need scope elevation, and those tools appear after authorization and a catalog refresh. The server initialization guidance is also shorter so clients do not repeat a large instruction block across tool descriptions.

1.2.39 compatibility note

Version 1.2.39 addresses the second round of live agent QA.

  • work_item_requeue also returns a claimed/running item whose lease has expired to the queue, without the original claim token; active leases are still never requeued. work_item_list labels expired leases inline ([claimed · lease expired <time>]), and work_item_get prefixes its JSON with a Lease: expired <time> — … header saying the item is claimable as-is or requeueable, instead of showing plain claimed.
  • work_item_revision_history / work_item_verification_history say so in a sentence when there is nothing recorded instead of printing [].
  • object_find names the object type it searched and points at schema_introspect / people_search / organization_search when nothing matches, instead of a bare "No objects found."
  • schema_introspect summarises datasets (title, ID, rows, field count) by default; includeDatasetFields: true restores the per-field dump.
  • dataset_quality_check counts blank strings as missing values and returns a versioned structured result. Frequently repeated values are observations; they are only quality violations when a field is declared unique.

Projection 1.22.0 records the schema_introspect input schema and the tool description changes.

1.2.38 compatibility note

Version 1.2.38 makes the agent path to work authority direct instead of a scavenger hunt (decision 2026-08-20, after live use from Grok and Claude).

  • Hosted OAuth first connect (no scope parameter, or scopes_supported copied by the client) is issued mcp:* work:read work:write behind the consent screen. Vault and AI scopes remain step-up/CLI-only.
  • Tools the connection could acquire through step-up are presented on tools/list; calling one before approval returns an in-band tool error carrying the same elevation link (or CLI/PAT guidance). The HTTP 403 insufficient_scope challenge is now issued only for request_capability in challenge mode.
  • Elevation links live for one hour (was ten minutes); after an approval the server publishes tools/list_changed so subscribed clients refresh, and the guidance tells the agent to refresh the tool list or restart the connector if the tools are still hidden.
  • find_capability, request_capability, and context_current render a compact text summary (name, availability, next step) instead of the full JSON; the complete projections remain in structuredContent.
  • task_get and the task tool descriptions no longer claim work:read is missing; they point at work_item_list with taskId and defer to request_capability only when the tool is not callable.
  • "Stable handles" in generic list text now name the field each ID came from and group repeats, so a projectId shared by twenty rows reads as one project reference rather than twenty new records.

Projection 1.21.0 records the presented-tool and description changes. Reconnect hosted MCP clients after upgrade to refresh the projection 1.21.0 schemas.

1.2.37 compatibility note

Version 1.2.37 makes scope step-up reachable from the agent's seat on hosted OAuth connections instead of depending on the client re-running OAuth.

  • request_capability (inspect) now returns elevation — a short-lived (ten-minute), owner-bound approval link for the connected OAuth token, replayable by the owner within its window — on Streamable HTTP whenever the missing scopes are elevatable (work:read, work:write) and the server supplied capabilityAcquisition.createElevationGrant. The user opens the link, re-authenticates, approves on the first-party consent screen, and the existing token is widened in place; the agent retries the tool without reconnecting. recommendedNextAction.type is open_elevation_url in that case and reconnectRequired is false. The reconnect guidance remains the fallback for connections that cannot be elevated.
  • find_capability, context_current, and direct gated-tool rejections point at that path instead of at a client reconnect.
  • Hosted OAuth now accepts an explicit work:write request (consent-gated); in 1.2.37 the authorize default when a client omits scope was mcp:* work:read and scopes_supported advertised only that pair (both widened to the full work family in 1.2.38).

Projection 1.20.0 records the request_capability output schema and description change. Reconnect hosted MCP clients after upgrade to refresh the projection 1.20.0 schemas.

1.2.36 compatibility note

Version 1.2.36 prepares the hosted endpoint for ChatGPT plugin-directory publication without changing the stdio tool surface.

  • upload_document no longer advertises filePath on the hosted profile: the hosted schema requires inline content and filename, and a filePath argument is rejected with a normalized bad_request failure at the MCP boundary, at executeTool, and inside SiftClient unless the client was constructed with allowLocalFiles. Only the local stdio entrypoint sets that flag; hosted and remote clients can never reach the server's filesystem.
  • Hosted tools now carry OpenAI-only hints under _meta, which other MCP clients ignore by specification: securitySchemes listing only the scopes the connected OAuth client can actually request (baseline mcp:*), and tool-invocation status strings derived from each tool's title.
  • Every catalog tool now publishes an outputSchema: the 27 read-only query tools that lacked one declare the sift.action_receipt envelope with a text/plain result, matching what tools/call already returns.
  • Projections and catalog digests are computed from the transport-shaped schema, so hosted find_capability and schemaDigest describe the tool surface the client is actually presented.

Projection 1.19.0 records the hosted upload_document schema and the envelope output schemas. Reconnect hosted MCP clients after upgrade to refresh the projection 1.19.0 schemas.

1.2.35 compatibility note

Version 1.2.35 closes the remaining contract divergences found in the 1.2.32 review.

  • schema_introspect now exposes datasets only when both the deployment-wide dataset switch and the caller's feature grant allow the dataset routes. Its dataset and object-type queries now run with the caller's RLS identity.
  • code_memory_delete returned 500 for every memory that had ever existed. V351 gave the lifecycle event log an ON DELETE CASCADE foreign key and an append-only trigger that raised unconditionally, so the cascade aborted every delete. V389 lets the referential cascade through while still refusing a direct edit of the log, repairs two lineage foreign keys that would have nulled a NOT NULL owner column, and returns an orphaned predecessor to needs_review with an audit event when its successor is deleted.
  • Human admission actions are no longer callable over MCP. code_memory_confirm, code_memory_reject, code_memory_edit, and code_memory_supersede are hidden and refused on both hosted and local agent transports. Agents may store candidates or mark facts needs_review; a human curates them in the Siftable interface.
  • project_get_context reported each task's workflow phase in its status field and left phase null. Both are now the real column values, on open, blocked, and overdue tasks alike.

Projection 1.18.0 records that human-curation boundary and removes four tools from the presented agent surface.

This release requires migration V389__code_memory_delete_cascade.sql. code_memory_delete continues to fail until it is applied.

1.2.34 compatibility note

Version 1.2.34 closes a set of defects where a call succeeded but the answer was wrong or incomplete.

  • Writing a person with a company returned 500 unconditionally. The organization upsert named a unique index that became partial in V357 without supplying its predicate, so Postgres could not infer the conflict target.
  • Authored content is no longer stripped in transit. The request pipeline ran striptags() over every string, which deleted < from filter operators, turned List<String> into List, and removed markup from note titles — silently, and for every MCP call, because the content allowlist only matched top-level body keys. HTML is now escaped where it is rendered instead.
  • A range comparison (> >= < <=) against a text-typed column with a numeric value is rejected with the retype path, instead of quietly comparing as text where '99' sorts above '199'. Sorting such a column returns a warning rather than an unmarked, plausible, wrong order.
  • dataset_query now carries warnings in its structured result.
  • task_get now carries the full task brief structurally — rationale, deliverable, verification, approachConstraints, acceptanceCriteria, and scope. Structured-first clients previously received a task with no definition of done.

Reconnect MCP clients after upgrade to refresh the projection 1.18.0 schemas.

1.2.33 compatibility note

Version 1.2.33 repairs hosted OAuth token exchange. The authorization server looked up a hashed authorization code with a consumed_at IS NULL filter against a table that consumes codes by deletion and has no such column, so every fresh Connect from Cursor, Codex, or any other remote client failed with Internal Server Error after Google consent. Existing authenticated sessions were unaffected. Tool contracts and projection 1.16.0 schemas are unchanged; no reconnect is required beyond retrying a login that previously failed.

1.2.32 compatibility note

Version 1.2.32 adds an explicit, metadata-only repository_project_link mutation so an agent can persist the project selected from context_current.projectCandidates. It also keeps unsupported-client matches in a secondary discovery lane and suppresses zero-score full-text note hits.

Reconnect MCP clients after upgrade to refresh the projection 1.16.0 schemas.

Hosted remote clients

The recommended hosted endpoint is:

https://siftable.io/api/v1/mcp

Claude remote connectors, Cursor, Codex, Devin, Kimi Code, and Antigravity can connect over Streamable HTTP. Prefer URL-only OAuth configuration: an authorize request that omits scope is issued mcp:* work:read work:write by default behind the first-party consent form, and anything missing later can be approved in place through the one-hour link request_capability returns (Streamable HTTP only; legacy /sse sessions reconnect instead). A configured Authorization header selects static PAT mode; that token's scopes cannot be expanded by an OAuth challenge or an elevation link.

Client configuration keys and callback behavior differ (url in Cursor, Codex, and Kimi; serverUrl in Antigravity; UI-managed connections in Claude and Devin). See docs/runbooks/hosted-mcp-client-compatibility.md for the provider-grounded matrix and verification flow.

The npm package remains the local stdio path for clients that need an authorized checkout or cannot use the hosted endpoint.

1.2.31 compatibility note

This release keeps task collection totals stable across cursor pages, resolves repository context through durable identities under transaction-scoped RLS, and returns explicit project candidates instead of auto-linking repositories by name. Project resources now paginate with opaque cursors and surface backend failures, while graph and people results provide usable canonical labels. Reconnect MCP clients after upgrade to refresh the projection 1.15.0 schemas.

1.2.30 compatibility note

This release requires caller-stable idempotency keys for agent creation, work claims and lifecycle transitions, code-memory writes, document uploads, Vault entry creation, and governed approval, execution-grant, and materialization requests. Same-key retries replay the original authoritative response; changed payloads conflict. Vault receipts retain metadata or runner-encrypted ciphertext, never plaintext. ai_generate remains explicitly non-retry-safe because streamed provider output is not persisted for replay. Reconnect MCP clients after upgrade to refresh the projection 1.14.0 schemas.

1.2.29 compatibility note

This release makes hosted capability inspection terminal and reconnect-safe, adds task-state and governed-approval invariants, and puts stable IDs and typed details into project, task, dataset, schema, people, organization, and calendar results. Retired source-index/search names route to local checkout search while curated code memories remain available. The dataset_create, dataset_mutate, dataset_schema_modify, and dataset_materialize_result tools require a caller-stable idempotencyKey. Reusing the same key with the same payload replays the original result; reusing it with a changed payload is rejected. Existing MCP sessions must reconnect to refresh their cached tool schemas before invoking these mutations. Direct REST callers remain backward compatible when the Idempotency-Key header is omitted.

Privacy Policy

The server sends tool calls to the Siftable API at the configured SIFT_API_URL (by default https://siftable.io) and to nothing else. It stores no data locally beyond the environment it is started with, and the personal access token is only ever sent to that API. Siftable's privacy policy, covering collection, use, storage, sharing, retention, and contact details, is at https://siftable.io/privacy.html.

Distribution artifacts

@siftable/mcp-server is published from the monorepo; the public source mirror at https://github.com/execufunction-mcp/mcp-server is refreshed with scripts/mirror-mcp-server.sh and cannot build on its own.

ArtifactCommandWhere it goes
npm packagenpm publish --workspace @siftable/mcp-servernpx @siftable/mcp-server for stdio clients
Claude Desktop extensionnpm run pack:mcpb --workspace @siftable/mcp-serverbuild/siftable.mcpb; attach to the GitHub release and submit through the desktop-extension form
MCP Registry entrynpm run publish:registry --workspace @siftable/mcp-server after mcp-publisher login githubio.github.Tom-R-Main/mcp-server, which points at the npm package

manifest.json is the desktop-extension manifest; its version must match package.json and the bundle build asserts it. The bundle carries its own production node_modules, so it runs without the monorepo.

Quick Start

1. Create a Personal Access Token

  1. Go to Siftable → Settings → Developer → Access Tokens
  2. Click "Create Token"
  3. Name it (e.g., "Cursor MCP")
  4. Select mcp:* for baseline MCP access, then add the specific scope families your workflows need (for example projects:read, tasks:write, or work:read). mcp:* is not universal authorization.
  5. Save the token immediately - it's only shown once!

2. Configure Your MCP Client

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "siftable": {
      "command": "npx",
      "args": ["@siftable/mcp-server"],
      "env": {
        "SIFT_API_URL": "https://siftable.io",
        "SIFT_PAT": "sift_pat_your_token_here"
      }
    }
  }
}
Cursor

Add to your Cursor MCP settings:

{
  "siftable": {
    "command": "npx",
    "args": ["@siftable/mcp-server"],
    "env": {
      "SIFT_API_URL": "https://siftable.io",
      "SIFT_PAT": "sift_pat_your_token_here"
    }
  }
}
VS Code

Configure in your MCP extension settings.

3. Restart Your IDE

After configuration, restart your IDE to load the MCP server.

Available Tools

Orientation and capability acquisition

Start every new client session with context_current. It reports the effective workspace, project, repository, transport, presented/effective scopes, missing requestable scopes, and recommended next calls. Hosted MCP returns a null checkout plus a reason unless the client explicitly provides a root hint.

Use find_capability as the discovery entry point when a tool is absent or an operation is unauthorized. Call request_capability in inspect mode to get a structured recovery plan without triggering an authorization challenge; use challenge mode only when the client can render the standards-compliant OAuth action from the HTTP 403 response.

When no candidate meets the discovery confidence contract, find_capability returns queryOutcome: no_matches, zero counts, and empty lanes. Rephrase with both a Siftable domain and operation, or inspect tools/list; do not treat a zero-result response as authorization evidence.

task_* manages human planning. work_* manages executable agent work. Prefer the stable IDs returned by collection and mutation results in follow-on calls.

ToolDescriptionMutates
context_currentResolve principal, owner, project, repository, checkout, and effective capability contextNo
find_capabilityDiscover callable, missing, requestable, and unsupported capabilitiesNo
request_capabilityInspect recovery or request an OAuth authorization challengeNo

Projects

ToolDescriptionMutates
project_listList projects with status filtering, bounded cursor pagination, stable IDs, and compact summariesNo
project_createCreate a new projectYes
project_updateUpdate project name, summary, status, emojiYes
project_archiveArchive a project (destructive)Yes
project_get_contextGet full project context (tasks, notes, signals)No

Tasks

ToolDescriptionMutates
task_listList human planning tasks with project/status/phase/effort/title filtersNo
task_getGet a single human planning task with full detailsNo
task_createCreate a human planning task with priority, phase, effort, acceptance criteriaYes
task_updateUpdate human planning task fields (title, status, priority, phase, effort, scope)Yes
task_deleteDelete a task (destructive)Yes
task_bulk_deletePreview or bulk delete tasks by IDs or filterYes
task_completeMark a task as completeYes

Agents

ToolDescriptionMutates
agent_listList user-visible agent aliases and capabilitiesNo
agent_getGet an agent alias by slug or IDNo
agent_createCreate an agent aliasYes
agent_updateUpdate alias metadata, capabilities, or permissionsYes
agent_disableDisable an alias without deleting historyYes
agent_work_listList executable work assigned to an aliasNo

Work Items

ToolDescriptionMutates
work_item_listList work items with authoritative dependency claimabilityNo
work_item_getGet work details, dependencies, satisfaction, and claimabilityNo
work_item_createCreate bounded work with optional UUID dependsOn edgesYes
work_item_dependencies_replaceAtomically replace a work item's UUID dependenciesYes
work_item_claimClaim queued executable work with a leaseYes
work_dependency_policy_getGet a project's default dependency gateNo
work_dependency_policy_updateSet a project's default dependency gateYes
work_item_startMark claimed work runningYes
work_item_heartbeatExtend a leaseYes
work_item_blockMark work blockedYes
work_item_reviewMark work as needing reviewYes
work_item_completeComplete work with summary/artifactsYes
work_item_failMark work failedYes
work_item_releaseRelease work back to the queueYes
work_item_cancelCancel workYes

Knowledge / Notes

ToolDescriptionMutates
note_listList notes with type, project, archive, and title filtersNo
note_getGet a single note with full contentNo
note_searchSemantic search across knowledge baseNo
note_createCreate a new note (markdown)Yes
note_updateUpdate note title, content, or typeYes
note_deleteDelete a note (destructive)Yes
note_bulk_deletePreview or bulk delete notes by IDs or filterYes

People

ToolDescriptionMutates
people_searchSearch contacts with fuzzy or exact/prefix filtersNo
person_createCreate a contactYes
person_updateUpdate a contactYes
person_deleteDelete a contact (destructive)Yes
people_bulk_deletePreview or bulk delete contacts by IDs or filterYes
person_enrichment_availabilityCheck identity readiness and current app prices without dispatching providersNo
person_enrichment_runRun paid, idempotent app-equivalent enrichment and return stored proposals and billing evidenceYes
person_enrichment_applyApply selected stored profile fields and facts from a settled run; not retry-safeYes

Organizations

ToolDescriptionMutates
organization_searchSearch organizations with fuzzy or exact/prefix filtersNo
organization_createCreate an organizationYes
organization_updateUpdate an organizationYes
organization_deleteDelete an organization (destructive)Yes
organization_bulk_deletePreview or bulk delete organizations by IDs or filterYes
organization_enrichment_availabilityCheck provider availability and current app prices without dispatching providersNo
organization_enrichment_previewRun the paid, idempotent app preview and save evidence without canonical CRM writesYes

Lead Discovery

ToolDescriptionMutates
lead_discovery_company_searchRun one bounded paid company search and stage source-backed review candidatesYes
lead_discovery_candidate_listList candidates and their CRM match/review stateNo
lead_discovery_candidate_reviewShortlist or reject one candidate with a recorded reasonYes
lead_discovery_import_plan_createCreate a durable CRM import plan from shortlisted candidates; approval and apply remain separateYes

See Headless CRM import plans for the approval and apply lifecycle shared by CLI and MCP.

Calendar

ToolDescriptionMutates
calendar_list_eventsList calendar events for a date rangeNo
calendar_create_eventCreate a new calendar eventYes
calendar_update_eventUpdate a calendar eventYes
calendar_delete_eventDelete a calendar event (destructive)Yes

Local Source Context

ToolDescriptionMutates
git_blame_symbolRun git blame on a local file rangeNo

Source inspection and search stay local to an authorized checkout through Git, rg, the editor, or agent-native tools. Siftable stores curated code memories; it does not index or semantically search repository source.

Code Memories

ToolDescriptionMutates
code_memory_storeStore a curated code factYes
code_memory_searchSearch stored code factsNo
code_memory_listList all stored code memoriesNo
code_memory_deleteDelete a code memory (destructive)Yes

Vault / Secrets

ToolDescriptionMutates
vault_listList vault entries (metadata only)No
vault_createStore a new encrypted secretYes
vault_updateUpdate vault entry metadataYes
vault_searchSearch vault entries by name/descriptionNo
vault_auditInspect the Vault audit trailNo
vault_materialization_requestRequest approval for one exact materialization destinationYes
vault_materialization_statusCheck materialization status without returning secret bytesNo
capability_listList governed Vault execution capabilitiesNo
capability_describeDescribe a governed Vault execution capabilityNo
capability_executeExecute a governed capability without exposing secret bytesYes

vault_read is retired. MCP never returns plaintext secret bytes; use a governed capability or an explicitly approved materialization instead.

Entity Graph

ToolDescriptionMutates
entity_graphTraverse the entity relationship graphNo
schema_introspectDiscover the full data model and entity typesNo

Document Upload

ToolDescriptionMutates
upload_documentUpload a PDF, Markdown, or text file into KnowledgeYes

Datasets (feature flag: DATASETS_ENABLED=true)

ToolDescriptionMutates
dataset_listList datasetsNo
dataset_createCreate a datasetYes
dataset_queryQuery records by filters/sortsNo
dataset_mutateCreate/update/delete records (destructive)Yes
dataset_schema_modifyAdd/update/delete fields (destructive)Yes
dataset_summarizeSummarize schema and sample rowsNo
dataset_facetsValue distributions for fieldsNo
dataset_quality_checkMissing-value metrics, invalid values, uniqueness issues, repeated-value observationsNo
dataset_aggregateGrouped metrics (count, avg, sum, etc.)No
dataset_bucketBucket numeric/date fields into rangesNo
dataset_rankRank records by sorts or weighted formulaNo
dataset_analyzeGenerate natural-language insightsNo
dataset_compareCompare metrics across segmentsNo
dataset_exportExport records as CSVNo
dataset_join_rowsSelf-join with alias-scoped fieldsNo
dataset_compute_fieldsCompute derived columns (lag, diff, rolling)No
dataset_timeseriesTime series analysis with transformsNo
dataset_materialize_resultSave derived result as a new datasetYes
dataset_plot_resultValidate chart payload from derived resultNo

Ontology (feature flag: DATASET_ONTOLOGY_ENABLED=true)

ToolDescriptionMutates
object_findFind objects by type and property filtersNo
object_linksTraverse graph links for an objectNo
object_action_runRun a declarative action on an object (destructive)Yes

Usage Examples

1. Get project context and create a task

User prompt: "Get context for my auth project and create a task to fix the token refresh bug"

Tools invoked:

  1. project_list — Lists projects to find the auth project
  2. project_get_context — Retrieves tasks, notes, and signals for the project
  3. task_create — Creates a human planning task with title, description, and project linkage

Result: The AI reads existing project context (open tasks, recent notes) to avoid duplicates, then creates a well-scoped task linked to the correct project.

To run an agent, create a linked executable work item with work_item_create and set taskId to the parent human task. Task tools should track planning state; work item tools should track execution, leases, artifacts, verification, and review state.

Dependencies are authoritative UUID references. Pass dependsOn as an array of { workItemId, requiredGate? }, where requiredGate is done or commands_passed. An omitted gate resolves through the project's work-dependency policy. List and get results expose the resolved dependencies projection and derived claimability (ready, waiting, or dependency_failed). Replace the complete edge set with work_item_dependencies_replace; use an empty array to remove every dependency. Historical verified gates are normalized to commands_passed during the verifier-retirement migration.

Lease-owned lifecycle calls (start, heartbeat, block, review, and fail) require both the claimOwner and claimToken returned by work_item_claim; release requires the active token. complete accepts credentials for lease-owned completion but leaves them optional so a human can resolve needs_review without a lease. cancel is likewise tokenless. Claim tokens remain omitted from get/list output and should not be logged or persisted by clients.

2. Knowledge search and note creation

User prompt: "Search for our deployment process and create a note summarizing the steps"

Tools invoked:

  1. note_search — Searches the knowledge base for "deployment process"
  2. code_memory_search — Searches stored code facts for deployment-related memories
  3. note_create — Creates a new note with a markdown summary of the deployment steps

Result: The AI synthesizes information from existing notes and code memories into a single reference note, linked to the relevant project.

Resources

The server also exposes project context bundles as MCP resources:

  • exf://projects/{id}/context - Full context bundle for a project

Environment Variables

VariableRequiredDescription
SIFT_API_URLYesSiftable API URL
SIFT_PATYesPersonal Access Token

Legacy EXF_API_URL and EXF_PAT remain supported for existing MCP configs.

Development

# Install dependencies
npm install

# Run in development mode
npm run dev

# Test with MCP Inspector
npm run inspect

# Build for production
npm run build

Security

  • PATs are stored as SHA-256 hashes - plaintext is never stored
  • Tokens can be revoked at any time from Siftable Settings
  • Use minimal scopes for your use case
  • Never commit tokens to version control

Scopes

ScopeDescription
mcp:*Core project, task, calendar, knowledge, and people operations
projects:readRead project data
projects:writeCreate/update projects
tasks:readRead tasks
tasks:writeCreate/update/complete tasks
knowledge:readSearch/read notes
knowledge:writeCreate notes
calendar:readView calendar/free slots
calendar:writeCreate calendar events
people:readSearch/view contacts
people:writeCreate/update contacts
work:readRead executable work queues
work:writeMutate executable work queues
lead_discovery:readRead lead-discovery runs and candidates
lead_discovery:writeDispatch paid searches and review/import candidates
vault:metadata:readRead Vault metadata and materialization status
vault:manageCreate/update Vault metadata and request materializations
vault:audit:readRead the Vault audit trail

Troubleshooting

"SIFT_API_URL environment variable is required"

Make sure you've configured the env section in your MCP client config.

"Invalid token"

  1. Check that your token starts with sift_pat_ or legacy exf_pat_
  2. Verify the token hasn't been revoked
  3. Check the token hasn't expired

Tools not appearing

  1. Restart your IDE after configuration changes
  2. Check IDE logs for MCP errors
  3. Try running npm run inspect to test the server directly

License

MIT

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Configuration

EXF_API_URL*

ExecuFunction API URL (e.g. https://execufunction.com)

EXF_PAT*secret

Personal Access Token (create at Settings → Developer → Access Tokens)

Categories
Sales & MarketingDocuments & KnowledgeFinance & CommerceProductivity & Office
Registryactive
Package@execufunction/mcp-server
TransportSTDIO
AuthRequired
UpdatedMar 10, 2026
View on GitHub

Related Sales & Marketing MCP Servers

View all →
favcrm avatar
FavCRM — Agentic CRM

favcrm/favcrm

**Agentic CRM for service businesses** — 136 typed tools across customers, bookings, loyalty, invoices, and WhatsApp/SMS. Hosted at `api.favcrm.io/mcp`. ### What it does - **Customers & loyalty** — segments, memberships, rewards, points - **Bookings** — create, confirm, cancel, no-show; capacity-aware schedules - **Commerce** — invoices, payments, products, orders, inventory - **Communications** — WhatsApp, SMS, email with templates - **CRM core** — contacts, tasks, tickets, deals, campaigns ### Auth API key (`fav_mcp_...`). Sign up free at [favcrm.io](https://favcrm.io) → Settings → API Keys. **Free tier:** 100 customers + 200 bookings/month. No credit card. ### Quickstart Install snippets, examples, and smoke tests: [github.com/favcrm/mcp](https://github.com/favcrm/mcp)
fenglucc avatar
ko-financial-data

fenglucc/ko-financial-data

Real SEC, 13F, insider, congress & macro data your AI agent can cite. 24 tools — institutional 13F holdings (85M+ rows), insider & congress trades, spot-Bitcoin-ETF ownership, company financials, and Treasury/Fed/BLS macro series. Every answer traces back to the original SEC filing. Free tier: 200 calls/day.
fenglucc avatar
ko-financial-data

fenglucc/ko-financial-data-7b403c37

Real SEC, 13F, insider, congress & macro data your AI agent can cite. 24 tools — institutional 13F holdings (85M+ rows), insider & congress trades, spot-Bitcoin-ETF ownership, company financials, and Treasury/Fed/BLS macro series. Every answer traces back to the original SEC filing. Free tier: 200 calls/day.
framesail avatar
Framesail

framesail/framesail

Create long-form (faceless YouTube) videos end to end from any MCP client: script, locked character references, storyboard, voiceover, and final video editing — with characters and style held consistent across every shot. Making long-form AI video today means 8+ tabs stitched by hand — an LLM for the script, a voice model, an image model, a video model — with characters drifting between tools and style resetting at every export. Framesail replaces the patchwork: the whole pipeline runs in one place and manages your video's context end to end. Six stages: Style (paste images, videos, or YouTube links and Framesail reverse-engineers the look, voice, and direction), Script (write it yourself or generate it in your narrative style), Reference images (auto-generated for every character, place, and prop), Voiceover (one narrator or many characters, with word-level timing), Storyboard (planned scene by scene), and Editor (captions, music, SFX, then export). No black box: you control every prompt, asset, model, and setting.
gentry-ai-bot avatar
Contentforge

gentry-ai-bot/contentforge

Content pipeline MCP server — image sourcing, SEO, affiliate links, and CMS publishing.
growgeltsolutions avatar
Hecher CRM

growgeltsolutions/hecher-mcp

Hecher CRM for Chabad shluchim — donors, donations, activities, and reports across your Mosads