https://x402-services-production.up.railway.app/mcp
Remote
v1.0.0
Published by x402-services-production.up.railway.app — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
77 pay-per-call x402 tools for AI trading & on-chain agents: prices, sniping, perps, RH Chain, MEV
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "exec_quote" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool exec_quote
Tool "exec_slippage" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool exec_slippage
Tool "exec_sandwich" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool exec_sandwich
Tool "exec_gas" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool exec_gas
Untrusted-input tools ([read, read_structured, pubsub_poll, inbox_poll]) co-exist with external-action tools ([schedule, deadman_register, inbox_create, inbox_poll, exec_quote, exec_slippage, exec_sandwich, exec_gas]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [read, read_structured, pubsub_poll, inbox_poll] → sinks [schedule, deadman_register, inbox_create, inbox_poll, exec_quote, exec_slippage, exec_sandwi
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow read → schedule
Tool "read" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool read · inputSchema.properties.url
Tool "read_structured" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool read_structured · inputSchema.properties.url
Tool "schedule" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool schedule · inputSchema.properties.url
Tool "deadman_register" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool deadman_register · inputSchema.properties.url
Tool "exec_quote" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool exec_quote
Tool "exec_slippage" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool exec_slippage
Tool "exec_sandwich" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool exec_sandwich
Tool "exec_gas" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool exec_gas
Each tool and what it can reach — enumerated from the running server.
inbox_pollingests untrusted inputnetwork egressdeadman_registernetwork egressexec_gasruns code / shellexec_quoteruns code / shellexec_sandwichruns code / shellexec_slippageruns code / shellinbox_createnetwork egresspubsub_pollingests untrusted inputreadingests untrusted inputread_structuredingests untrusted inputschedulenetwork egressagent_reputationno sensitive capabilityai_chatno sensitive capabilityai_chat_prono sensitive capabilityai_modelsno sensitive capabilityanalytics_indicatorsno sensitive capabilityanalytics_ohlcvno sensitive capabilityanalytics_price_atno sensitive capabilityboard_getno sensitive capabilityboard_setno sensitive capabilitybusiness_daysno sensitive capabilitycalcno sensitive capabilitycatalysts_calendarno sensitive capabilitycatalysts_governanceno sensitive capabilitycatalysts_searchno sensitive capabilitycatalysts_unlocksno sensitive capabilitycompliance_labelno sensitive capabilitycompliance_riskno sensitive capabilitycompliance_screenno sensitive capabilitycompliance_taintno sensitive capabilitycounterno sensitive capabilitycron_explainno sensitive capabilitycrypto_activityno sensitive capabilitycrypto_balancesno sensitive capabilitycrypto_contractno sensitive capabilitycrypto_convertno sensitive capabilitycrypto_ensno sensitive capabilitycrypto_gasno sensitive capabilitycrypto_priceno sensitive capabilitycrypto_tokenno sensitive capabilitycrypto_txno sensitive capabilitycrypto_yieldsno sensitive capabilitydatetimeno sensitive capabilitydeadman_pingno sensitive capabilitydiffno sensitive capabilityescrow_createno sensitive capabilityescrow_listno sensitive capabilityescrow_resolveno sensitive capabilityescrow_statusno sensitive capabilityextractno sensitive capabilityidempotencyno sensitive capabilityjsonschemano sensitive capabilitylending_healthno sensitive capabilitylending_liquidationsno sensitive capabilitylending_ratesno sensitive capabilitylinks_checkno sensitive capabilitylock_acquireno sensitive capabilitylock_releaseno sensitive capabilitymarkdownno sensitive capabilitymemory_getno sensitive capabilitymemory_setno sensitive capabilityoptions_chainno sensitive capabilityoptions_greeksno sensitive capabilityoptions_maxpainno sensitive capabilityoptions_priceno sensitive capabilityoptions_volno sensitive capabilityperps_basisno sensitive capabilityperps_fundingno sensitive capabilityperps_funding_arbno sensitive capabilityperps_marketsno sensitive capabilityperps_moversno sensitive capabilityperps_oino sensitive capabilityportfolio_pnlno sensitive capabilityportfolio_riskno sensitive capabilityportfolio_taxlotsno sensitive capabilityportfolio_valueno sensitive capabilitypredict_arbno sensitive capabilitypredict_feargreedno sensitive capabilitypredict_marketno sensitive capabilitypredict_oddsno sensitive capabilitypredict_trendingno sensitive capabilitypreflightno sensitive capabilitypubsub_publishno sensitive capabilityqueue_popno sensitive capabilityqueue_pushno sensitive capabilityratelimitno sensitive capabilityregexno sensitive capabilityrh_arbno sensitive capabilityrh_basisno sensitive capabilityrh_catalystsno sensitive capabilityrh_depthno sensitive capabilityrh_dislocationno sensitive capabilityrh_funding_arbno sensitive capabilityrh_funding_scanno sensitive capabilityrh_gainersno sensitive capabilityrh_gap_radarno sensitive capabilityrh_liquidity_mapno sensitive capabilityrh_momentumno sensitive capabilityrh_new_listingsno sensitive capabilityrh_oracle_deviationno sensitive capabilityrh_perp_fundingno sensitive capabilityrh_perp_oino sensitive capabilityrh_poolno sensitive capabilityrh_premiumno sensitive capabilityrh_session_clockno sensitive capabilityrh_spreadno sensitive capabilityrh_stockno sensitive capabilityrh_stocksno sensitive capabilityrh_tvlno sensitive capabilityrh_verifyno sensitive capabilityrh_whale_flowno sensitive capabilityrh_yieldsno sensitive capabilityrhchain_activityno sensitive capabilityrhchain_balanceno sensitive capabilityrhchain_blockno sensitive capabilityrhchain_callno sensitive capabilityrhchain_contractno sensitive capabilityrhchain_gasno sensitive capabilityrhchain_logsno sensitive capabilityrhchain_nonceno sensitive capabilityrhchain_registryno sensitive capabilityrhchain_token_transfersno sensitive capabilityrhchain_txno sensitive capabilityrhchain_usdgno sensitive capabilityrhchain_watchno sensitive capabilitysafety_approvalsno sensitive capabilitysafety_decodeno sensitive capabilitysafety_guardrailno sensitive capabilitysafety_simulateno sensitive capabilityschedule_cronno sensitive capabilityschedule_statusno sensitive capabilityscout_rankingsno sensitive capabilityscout_serviceno sensitive capabilitysnipe_holdersno sensitive capabilitysnipe_honeypotno sensitive capabilitysnipe_impactno sensitive capabilitysnipe_newpairsno sensitive capabilitysnipe_pairno sensitive capabilitysnipe_rhno sensitive capabilitysnipe_safetyno sensitive capabilitysnipe_searchno sensitive capabilitysnipe_trendingno sensitive capabilitysnipe_walletno sensitive capabilitysol_graduatingno sensitive capabilitysol_launchesno sensitive capabilitysol_rug_checkno sensitive capabilityton_accountno sensitive capabilityton_agent_walletno sensitive capabilityton_balanceno sensitive capabilityton_blockno sensitive capabilityton_dnsno sensitive capabilityton_gramno sensitive capabilityton_jettonno sensitive capabilityton_jetton_holdersno sensitive capabilityton_nftsno sensitive capabilityton_priceno sensitive capabilityton_transfersno sensitive capabilityton_txno sensitive capabilitywallet_reputationno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.0 latest |
A 94/100 | 13 | 1.13.0 | 2026-09-06 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan https://x402-services-production.up.railway.app/mcp --online
<img src="./public/logo.png" alt="1Money Logo" width="200"/>
Signed verification attestations for agent decisions: business, price, freshness, claim checks.
Actual Budget MCP server exposing API functionality
MCP server for Actual Budget - query and manage your personal finances through Claude
The Adyen Model Context Protocol server allows you to integrate with Adyen APIs through LLMs function calling utilizing various Clients. It currently supports the following tools:
Trusted agent-commerce hub: discover, trust-check, and route x402 payments with failover.