Logiqical MCP Server

logiqical npm v0.5.0

Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.

Trust grade
A
92/100
Last scanned get badge →
Trust
A · 92/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
High
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 92/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−6 capability blast radius (high) — client exposure if the model is manipulated
−2 publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 1

critical Completed toxic-flow trifecta across toolsMTC-FLOW-002

This server (without client built-ins) exposes a complete data-exfiltration chain: social_messages → bridge_tokens → social_send_message. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.

Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.

Location: flow social_messages → bridge_tokens → social_send_message

Tools 91

Each tool and what it can reach — statically extracted from the published source.

  • bridge_tokensreads sensitive data
  • social_messagesingests untrusted input
  • social_send_messagenetwork egress
  • agent_registerno sensitive capability
  • bridge_chainsno sensitive capability
  • bridge_infono sensitive capability
  • bridge_quoteno sensitive capability
  • bridge_routesno sensitive capability
  • bridge_statusno sensitive capability
  • buy_and_stakeno sensitive capability
Show 81 more tools ↓
  • call_contractno sensitive capability
  • copy_calculate_ordersno sensitive capability
  • copy_executeno sensitive capability
  • copy_get_positionsno sensitive capability
  • defi_savax_infono sensitive capability
  • defi_savax_quoteno sensitive capability
  • defi_savax_stakeno sensitive capability
  • defi_savax_unstakeno sensitive capability
  • defi_vault_depositno sensitive capability
  • defi_vault_infono sensitive capability
  • defi_vault_quoteno sensitive capability
  • defi_vault_withdrawno sensitive capability
  • dex_balanceno sensitive capability
  • dex_quoteno sensitive capability
  • dex_swapno sensitive capability
  • dex_token_infono sensitive capability
  • dex_tokensno sensitive capability
  • get_addressno sensitive capability
  • get_balanceno sensitive capability
  • get_balancesno sensitive capability
  • launchpad_buyno sensitive capability
  • launchpad_overviewno sensitive capability
  • launchpad_quoteno sensitive capability
  • launchpad_recentno sensitive capability
  • launchpad_sellno sensitive capability
  • launchpad_tokenno sensitive capability
  • market_arena_priceno sensitive capability
  • market_avax_priceno sensitive capability
  • market_priceno sensitive capability
  • market_searchno sensitive capability
  • market_topno sensitive capability
  • market_trendingno sensitive capability
  • perps_arbitrum_usdc_balanceno sensitive capability
  • perps_cancel_ordersno sensitive capability
  • perps_close_positionno sensitive capability
  • perps_deposit_infono sensitive capability
  • perps_deposit_usdcno sensitive capability
  • perps_ordersno sensitive capability
  • perps_place_orderno sensitive capability
  • perps_positionsno sensitive capability
  • perps_registerno sensitive capability
  • perps_registration_statusno sensitive capability
  • perps_trading_pairsno sensitive capability
  • perps_update_leverageno sensitive capability
  • perps_wallet_addressno sensitive capability
  • policy_budgetno sensitive capability
  • policy_getno sensitive capability
  • policy_setno sensitive capability
  • send_avaxno sensitive capability
  • sign_messageno sensitive capability
  • signals_fundingno sensitive capability
  • signals_marketno sensitive capability
  • signals_scanno sensitive capability
  • signals_summaryno sensitive capability
  • signals_technicalno sensitive capability
  • signals_whalesno sensitive capability
  • social_conversationsno sensitive capability
  • social_create_threadno sensitive capability
  • social_followno sensitive capability
  • social_like_threadno sensitive capability
  • social_meno sensitive capability
  • social_post_tradeno sensitive capability
  • social_search_usersno sensitive capability
  • social_top_usersno sensitive capability
  • social_unfollowno sensitive capability
  • social_update_profileno sensitive capability
  • social_user_by_handleno sensitive capability
  • stake_arenano sensitive capability
  • stake_infono sensitive capability
  • swap_buy_arenano sensitive capability
  • swap_quote_buyno sensitive capability
  • swap_quote_sellno sensitive capability
  • swap_sell_arenano sensitive capability
  • tickets_balanceno sensitive capability
  • tickets_buyno sensitive capability
  • tickets_buy_priceno sensitive capability
  • tickets_feesno sensitive capability
  • tickets_sellno sensitive capability
  • tickets_sell_priceno sensitive capability
  • tickets_supplyno sensitive capability
  • unstake_arenano sensitive capability

Toxic flows 1

Cross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).

What this scan could not see

Versions 1

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v0.5.0 latest A 92/100 1 1.9.0 2026-07-24

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 92/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/logiqical/badge.svg)](https://mcptrustchecker.com/registry/logiqical)
HTML
<a href="https://mcptrustchecker.com/registry/logiqical"><img src="https://mcptrustchecker.com/registry/logiqical/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/logiqical/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan logiqical --online

Use the free API → How scoring works

More in Gaming & Entertainment