Back to Browse

Muyiribi MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Search a Ugandan business directory for businesses and services by keyword, category, or district

About

Search a Ugandan business directory for businesses and services by keyword, category, or district

Remote endpoints: streamable-http: https://ug-online.domus-dei-tech.workers.dev/mcp

Security Report

6.2
Moderate6.2Moderate Risk

This MCP server for a Uganda business directory is reasonably well-structured with appropriate authentication and authorization for its purpose. The server implements account-based access control with password hashing (PBKDF2), rate limiting on failed logins, and tier-based listing limits. However, there are some moderate concerns: the MCP endpoint lacks explicit authentication/authorization checks, sensitive data (passwords, phone numbers) is logged during signup/payment flows, and SMS OTP delivery via UgaText represents an external trust dependency. Permissions align with the server's purpose (database and network access for payments/SMS), but these logging and authentication gaps warrant attention. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

database

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Muyiribi

Business directory for Uganda. Cloudflare Worker + Neon Postgres, with a simple web UI and an MCP endpoint for AI tools.

Routes

  • / landing page
  • /signup, /login, /logout phone + password accounts (password show/hide toggle)
  • /add add a business listing (creation limit depends on tier; description min 40 characters)
  • /mcp MCP endpoint with tools: search_businesses, get_business, list_categories

Results are ranked by tier, highest first (black, green, blue, free).

Setup

  1. Run schema.sql once in the Neon SQL console.
  2. Install dependencies: npm install
  3. Set the database secret: npx wrangler secret put DATABASE_URL (your Neon connection string)
  4. Local dev: npm run dev
  5. Deploy: npm run deploy

Your MCP URL is: https://ug-online.domus-dei-tech.workers.dev/mcp.

Notes

  • Passwords are hashed with PBKDF2 (Web Crypto). Accounts lock for 15 minutes after 5 failed logins.
  • Creation limit (how many listings an account can create): Free 3, Basic 5, Pro 7, Premium unlimited.
  • Search limit (how many of an account's listings can appear in search): Free 1, Basic 3, Pro 5, Premium unlimited. Newest first.
  • Results are ordered by tier, highest first.
  • Paid tiers only count while an active subscription exists. No flow creates subscriptions yet; payments come later.
  • /pricing shows all tiers and sells them via PesaPal. Every paid tier (Basic UGX 5,000/yr, Pro UGX 12,000/yr, Premium UGX 25,000/yr) requires business contact phone verification by SMS OTP (sent via UgaText) before the tier is granted. See migrations/002_verification.sql and migrations/003_tier_names_and_pricing.sql, and migrations/004_payment_phone_optional.sql.
  • Paid-tier flow is one page. "Get " creates a PesaPal order and shows its checkout in an iframe on /pricing/status. The page polls /pricing/check until payment completes, then asks for the verification number (prefilled, editable) and sends the SMS code. Status is only trusted from PesaPal's GetTransactionStatus, never from the callback URL.

MCP Registry

MCP

scaffold: npm create cloudflare@latest -- my-mcp --type=mcp-server get token for workers from cloudflare cd my-mcp npm install npx wrangler dev # local dev npx wrangler deploy # deploy

Reviews

No reviews yet

Be the first to review this server!