Mmcp.market

Is OpenShopGraph MCP server safe?

Probably. Read the findings first.

C64/100grade C

Use with care. Some checks failed or could not be verified.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

2 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 1833ms20/20
  • Tool poisoning8 tool descriptions checked13/15
  • Auth qualityAPI key sent as a header8/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (2)

  • lowUnusually long tool description (over 2,000 characters)poison.long-description
    tool list_coupons: …List currently USABLE discount codes/coupons, optionally filtered by shop_domain (e.g. "otto.de"). A code is withheld from `results` when it is EXPIRED (valid_until has passed), when a real checkout test PROVED it does not work (verification_status "verified_rejected"), or when a display policy suppresses it on this channel/country. Nothing is withheld silently: `total_count` is how many codes the query found before any of that, and `withheld` breaks the difference down by reason ({expired, verified_rejected, reserved_test_domain, policy}) — total_count minus results.length always equals the sum of `withheld`, and `note` states the same balance in one sentence. So an empty `results` NEVER has to be guessed at: read `total_count` and `note` to tell "this shop has no codes at all" apart from "it has codes and every one of them is proven dead". An UNKNOWN or internal-review shop_domain is a different answer again — it is an error ("shop not found"), not an empty list; and a backend failure is reported as a failure, never as an empty list. Each result carries validUntil: an ISO timestamp when the code has a stated expiry, or null when it is open-ended — null means unlimited, NOT unknown-and-expired. Re-check validUntil against the current time before relaying a code. Each result ALSO carries verificationStatus, the verdict of a real checkout test against this exact code: "verified_applied" means the code was proven to work by an actual checkout attempt with proof on file — safe to recommend; "unverified" means no proof exists either way yet — treat it as unknown, NOT as a negative signal, and do not imply it was tested and failed. ("verified_rejected" is defined as before but no longer appears in `results` — it is counted in `withheld.verified_rejected` instead.) lastVerifiedAt is the ISO timestamp of that most recent test, or null if the code was never tested. A non-null lastVerifiedAt on an "unverified" code means it WAS tested but the test was inconclusive — it is not the same as a code that was never attempted.…
  • lowNo source repository listedmaint.no-repo
Overall 64/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what OpenShopGraph does

  • BestPrice Shopping
    Read-only shopping decisions, product search, offers, and price history for Greece.
    A
  • Shopware
    Query and safely manage a Shopware 6 shop: products, orders, customers, stock, audits, reports.
    B
  • Apiguru Amazon Data
    Live Amazon product, review, search, deal, offer/stock and seller data across 20 marketplaces.
    A

OpenShopGraph reviews, tools and install