Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Selling here
All guides
Selling hereBeginner· 6 min read

Get your listing verified

The one thing to remember

Three things fail more submissions than everything else combined: secrets in history, an overbroad manifest, and no declared egress.

What you will be able to do

Submit a listing that passes on the first attempt.

Figure

How Get your listing verified works, in one picture

1Clear your history, not just your working tree2Declare exactly what you do, and no more3Give us something to run4Expect findings, and do not hide them

The same argument as the text, as a chain. Each step is what makes the next one possible.

  1. 1

    Clear your history, not just your working tree

    The most common failure is a credential that was committed once, removed in a later commit, and is still sitting in history where anyone can read it. Removing the file does not remove the secret.

    Rotate anything that was ever committed, then rewrite history or start a clean repository. A rotated key in history is a finding; a live one is a fail.

    This is the single most common reason a first submission does not pass.

  2. 2

    Declare exactly what you do, and no more

    Your listing draft, in the maker console

    Your manifest lists the tools you expose, the scopes you need and the hosts you may contact. We compare it against what the software actually does, and a mismatch fails in both directions.

    Asking for more than you use fails. So does using something you did not declare. The narrow, accurate manifest is both the easy pass and the thing buyers read first.

  3. 3

    Give us something to run

    Agents are measured, not described. Provide a sandbox entry point and a handful of representative tasks, and they are run for the success rate, median time and cost per run once the sandbox runs: it waits on isolated infrastructure and has run nothing yet.

    You can submit without this. Your listing will simply show blanks where the numbers go, and blanks convert badly, because buyers have been told to read them as absent evidence.

  4. 4

    Expect findings, and do not hide them

    Verified with findings is a normal outcome and it is displayed as information rather than as a failure. Most real software has a dependency advisory somewhere.

    What is not survivable is a manifest that understates what the software does. That is the one category we treat as disqualifying rather than informational, because it is the shape of a real attack.

You have got it when

Your submission passed, or the findings it raised are ones you chose to accept.

Open the catalogue on ooruby

Read next

Selling here
Pricing your listing
How verification works
What a Verified badge actually means
Glossary
MCP
Glossary
MCP server
Glossary
AI agent
The bottom line

Three things fail more submissions than everything else combined: secrets in history, an overbroad manifest, and no declared egress.

See the recent listings

Newly listed companies, and the lock-up dates that are about to make a lot of shares sellable.