MCP servers for payments, accounting, crypto, stock-market data and e-commerce platforms. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.
Security scan results for the Aifinpay MCP server.
Security scan results for the X402 MCP server.
Security scan results for the Sap MCP server.
Security scan results for the Geometra MCP server.
Security scan results for the Gocushy MCP server.
Security scan results for the Revealui MCP server.
Security scan results for the Formlab MCP server.
Security scan results for the Xrpl Utilities MCP server.
Security scan results for the Vaaya MCP server.
Security scan results for the Korea Stock MCP server.
Security scan results for the Bizfile MCP server.
Security scan results for the Finmap MCP server.
Security scan results for the Mpp32 MCP server.
Security scan results for the X402node MCP server.
Security scan results for the X402 Bazaar MCP server.
Security scan results for the Octagon MCP server.
Security scan results for the Madeonsol MCP server.
Security scan results for the Claracars MCP server.
Security scan results for the Stock Scanner MCP server.
Security scan results for the Stockmatrix MCP server.
Security scan results for the Gate402 MCP server.
Security scan results for the Capitol Trades MCP server.
Security scan results for the Crypto Price MCP server.
Security scan results for the Optionsahoy MCP server.
When an AI assistant checks an order, reconciles a ledger or quotes a crypto price, it usually reaches that system through a finance and commerce MCP server: a Model Context Protocol integration bridging assistants like Claude or Cursor to payment processors such as Stripe and PayPal, accounting suites like QuickBooks and Xero, crypto exchanges and wallets, stock-market data feeds, and e-commerce backends such as Shopify or WooCommerce. Few integration types sit this close to live balances and customer records, so entries here earn some of the sharpest security scrutiny in the MCP Trust Registry.
Day-to-day use leans read-heavy and workflow-shaped. An assistant can stream live stock or crypto quotes into a research brief, match invoices in an accounting ledger against bank transactions, or keep an online store running: updating listings, checking order status and drafting refunds for a human to approve. Combined with servers from the Databases category, it can also join payment events to internal records for reconciliation and reporting.
The threat model here is unusually concrete. A malicious or over-permissioned server holding a payment or exchange API key is not just reading data; a write-scoped token can issue refunds, create payouts or place orders. Before connecting one:
Only if someone hands it credentials with those permissions. The Model Context Protocol carries text and tool calls, not funds; the danger is a write-scoped payment or exchange key given to an over-permissioned server. Prefer read-only keys and review a server's Trust Score and findings first.