Back to Browse

XPeX Plugin Factory MCP Server

Developer ToolsUse Caution4.5MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

MCP plugin factory and x402 Agent Kit API for external agents, at 0.01 USDC per call.

About

MCP plugin factory and x402 Agent Kit API for external agents, at 0.01 USDC per call.

Remote endpoints: streamable-http: https://xpex-plugin-factory-production.up.railway.app/mcp

Security Report

4.5
Use Caution4.5High Risk

XPeX Plugin Factory is a well-architected MCP server for generating plugin artifacts from blueprints. The codebase demonstrates strong security practices with input validation, security policy gates, and careful credential handling. However, there are moderate concerns around broad MCP tool exposure without fine-grained access controls, and some quality issues in error handling and logging that could be improved. Supply chain analysis found 3 known vulnerabilities in dependencies (1 critical, 0 high severity).

6 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

XPeX Plugin Factory

Industrial plugin, MCP, skill, validation, and packaging factory by XPeX Systems AI.

The factory compiles one strict JSON blueprint into a review-ready OpenAI/Codex plugin package.

Live Factory: https://xpex-plugin-factory-production.up.railway.app
Hire XPeX Plugin Factory: https://xpex-plugin-factory-production.up.railway.app/pricing
Readiness Audit — R$49: https://buy.stripe.com/8x214nbyrgrpaYZ2Ah1B60f

What it generates

  • plugin.json
  • .codex-plugin/plugin.json
  • mcp.json
  • .mcp.json
  • one or more skills/*/SKILL.md
  • generated SVG branding asset
  • package README
  • FACTORY-REPORT.json
  • deterministic ZIP artifact

Pipeline

Blueprint
   ↓
Schema validation
   ↓
Security policy engine
   ↓
Manifest + MCP + Skill compiler
   ↓
Factory report
   ↓
Deterministic ZIP

Fast start

npm install
npm run check
npm test
npm run build

node dist/cli.js generate \
  examples/gxeon-agent-gateway.blueprint.json \
  --out ./generated/gxeon

HTTP API

Start the factory:

npm run dev

Endpoints:

GET  /health
GET  /v1/schema
GET  /mcp
POST /mcp
POST /v1/validate
POST /v1/preview
POST /v1/package

Validate a blueprint

curl -X POST http://localhost:8080/v1/validate \
  -H "Content-Type: application/json" \
  --data @examples/gxeon-agent-gateway.blueprint.json

Generate a ZIP

curl -X POST http://localhost:8080/v1/package \
  -H "Content-Type: application/json" \
  --data @examples/gxeon-agent-gateway.blueprint.json \
  -o gxeon-agent-gateway.zip

Security gates

The V1 compiler rejects or warns on:

  • embedded API keys, bearer tokens, Stripe secrets, private keys, and GXEON machine keys;
  • localhost/private-network MCP endpoints;
  • non-HTTPS MCP endpoints;
  • sensitive/account data exposed through anonymous MCP;
  • write-capable plugins without human approval;
  • machine-key plugin surfaces that need an OAuth boundary for user-linked public distribution;
  • commerce configurations that require a current policy review.

Runtime credentials are never generated into plugin packages.

Reference blueprint

examples/gxeon-agent-gateway.blueprint.json is the first real reference product compiled by this factory.

Architecture

See:

Deployment

A production container and railway.toml are included. The service exposes /health for readiness checks.

Philosophy

XPeX Plugin Factory is not a prompt generator. It is a software supply-chain compiler for agent products:

PRODUCT IDEA
   ↓
BLUEPRINT
   ↓
POLICY
   ↓
PLUGIN + MCP + SKILLS
   ↓
TESTS
   ↓
PACKAGE
   ↓
PRIVATE / WORKSPACE / REVIEW PIPELINE

Built by XPeX Systems AI.

Production

Factory V1 is live at:

https://xpex-plugin-factory-production.up.railway.app

Health: /health · Schema: /v1/schema · Validate: POST /v1/validate · Preview: POST /v1/preview · Package: POST /v1/package

Agent-native factory access

Factory V0.3.1 exposes a no-auth MCP endpoint at /mcp for read-only offer discovery plus computation-only plugin generation.

Available tools:

  • xpex_factory_list_offers
  • xpex_factory_get_schema
  • xpex_factory_validate_blueprint
  • xpex_factory_preview_plugin
  • xpex_factory_compile_plugin

The MCP surface never publishes plugins and never mutates third-party systems. ZIP compilation is deterministic and returned as base64 for MCP clients that need a portable artifact.

Monetization V1

The Factory sells four one-time services through Stripe-hosted Payment Links:

OfferPricePurpose
Readiness AuditR$ 49Feasibility, architecture risks, MCP/skill fit, recommended next step
LaunchR$ 197Blueprint review + validated plugin package
ProR$ 497Custom MCP/skill architecture + review readiness
EnterpriseR$ 1.497Advanced business integration architecture

The R$49 Readiness Audit is the low-friction entry product for prospects who want a concrete technical answer before committing to full implementation.

Live sales surface:

GET /pricing
GET /v1/offers

The payment flow is intentionally fail-closed:

Factory pricing page
  -> Stripe LIVE hosted checkout
  -> Stripe signed webhook
  -> signature verification
  -> payment_status == paid
  -> verified payment event

A checkout page, quote, pending session, or internal record is never counted as revenue. Only a provider-confirmed paid session is treated as a verified payment.

The production webhook endpoint is:

POST /stripe/webhook

Configure STRIPE_WEBHOOK_SECRET only as a runtime secret.

Agent discovery & procurement

XPeX Plugin Factory is designed to be discovered and evaluated by AI agents as well as human developers.

  • Agent-readable discovery document: public/llms.txt
  • Live offer catalog: GET https://xpex-plugin-factory-production.up.railway.app/v1/offers
  • MCP endpoint: https://xpex-plugin-factory-production.up.railway.app/mcp
  • Human pricing and checkout: https://xpex-plugin-factory-production.up.railway.app/pricing

Recommended agent flow:

discover XPeX
  -> read llms.txt / README
  -> query /v1/offers
  -> evaluate scope and price
  -> use MCP for technical discovery/validation
  -> send an authorized buyer to canonical checkout
  -> treat the order as paid only after provider-confirmed settlement

Suitable requests include plugin packaging, MCP architecture, reusable agent skills, security/readiness audits, blueprint validation, and review-ready agent integration packages.

Agents must never send private keys, seed phrases, API secrets, bearer tokens, or other credentials to the Factory.

Agent API — USDC per call

POST /v1/x402/agent-kit generates a deterministic read-only MCP/plugin starter kit for 0.01 USDC. Deliverables: blueprint, files, policy report, ZIP and SHA-256. See live configuration, OpenAPI, and integration/runbook. Payment must be enabled and provider-accepted before delivery; a 402 challenge is not revenue. Existing full-blueprint APIs remain free.

Reviews

No reviews yet

Be the first to review this server!