Smithery
Search, install and host MCP servers and AI agent skills
Overview
Smithery indexes thousands of MCP servers and, since 2026, agent skills, letting developers search, install and deploy them locally via CLI or hosted on Smithery's infrastructure. Built for teams wiring tools into Claude, Cursor and other agent runtimes.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 12 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- 3 namespaces
- Managed OAuth
- Persistent connections
- 100 namespaces
- Managed OAuth
- Persistent connections
- Custom namespace limits
- Dedicated support
What you can produce with Smithery
- Searchable registry of thousands of MCP servers
- Agent-skills (SKILL.md) catalog alongside MCP servers
- Open-source CLI (smithery-ai/cli) for install and connection management
- Hosted/remote deployment for MCP servers
- Managed OAuth for server connections
- Search-by-intent tool discovery
ASEAN Perspective
Smithery in Southeast Asia
ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).
Smithery solved a real problem early: before it existed, finding and running MCP servers meant hunting through scattered GitHub repos and hand-editing JSON configs. Its registry now covers thousands of servers plus a newer agent-skills catalog, with an open-source CLI that handles auth and connection management so you're not pasting API keys into config files by hand.
The catch, and it's a big one: in 2026 security researchers found a path-traversal flaw in Smithery's own build pipeline that let attackers pull secrets out of the build environment, exposing API keys tied to roughly 3,000 hosted servers. Separate scans of the top 100 listed servers found security issues in about one in five, mostly prompt-injection-style tool descriptions. Treat it as a useful discovery layer, not a vetted marketplace — audit anything before you connect it to production credentials.
What people say
Developer sentiment on Smithery splits pretty cleanly along a before/after line. Before 2026, it was largely praised as the default answer to "where do I find MCP servers" — infrastructure blogs like WorkOS pointed to it as a central hub, and its CLI made local installs less painful than manually wiring stdio transports. The registry's search-by-intent feature, where you describe what you need rather than browse by category, gets called out specifically as useful once the catalog grew past a few hundred entries.
The reputation took a real hit in 2026. Security researchers at GitGuardian disclosed a path-traversal vulnerability in Smithery's smithery.yaml build configuration: setting dockerBuildPath to a directory-traversal string let an attacker make the platform's Docker builder pull in files from outside the intended build context, including credentials. The exposure reportedly touched more than 3,000 hosted MCP servers and thousands of associated API keys before it was patched — cybersecuritynews.com and a widely cited MCP breach timeline both logged it as one of the more serious incidents in the protocol's short history.
Independent scans of the listings themselves haven't been reassuring either. A dev.to writeup that scanned 100 servers pulled from Smithery found security findings on 22 of them, with the most common issue being tool-description injection — descriptions crafted to plant instructions for the calling agent rather than just describe the tool. That's a structural risk of any open registry model, not unique to Smithery, but it means the "thousands of servers" figure is a discovery surface, not a stamp of safety.
Net effect: people using it for prototyping and personal projects mostly still like it — installation friction genuinely goes down. Teams evaluating it for anything touching real credentials or production data are now doing so with the 2026 breach as the reference case, and several MCP hosting comparisons published afterward list stricter sandboxing and provenance-checking as differentiators against Smithery specifically.
Summary of public user & expert reviews, compiled by RECATOOLS.
About this listing
This entry was compiled from publicly available data including Smithery's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Smithery unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Smithery directly →
Spotted something out of date? Suggest an update →
Smithery in the news
Developer Tools
npm v12 Is Here, and It Turns Off a Default That Has Run Arbitrary Code for a Decade
Developer Tools
DuneSlide: Two Cursor Flaws Turn a Zero-Click Prompt Injection Into Code Execution
Developer Tools
npm v12 Flips Three Install Defaults From Automatic to Opt-In — Prepare Your Pipelines Now
More in Code & Dev Tools