Is OpenShopGraph MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
2 low
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 1833ms20/20
- Tool poisoning8 tool descriptions checked13/15
- Auth qualityAPI key sent as a header8/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (2)
- lowUnusually long tool description (over 2,000 characters)
poison.long-descriptiontool list_coupons: …List currently USABLE discount codes/coupons, optionally filtered by shop_domain (e.g. "otto.de"). A code is withheld from `results` when it is EXPIRED (valid_until has passed), when a real checkout test PROVED it does not work (verification_status "verified_rejected"), or when a display policy suppresses it on this channel/country. Nothing is withheld silently: `total_count` is how many codes the query found before any of that, and `withheld` breaks the difference down by reason ({expired, verified_rejected, reserved_test_domain, policy}) — total_count minus results.length always equals the sum of `withheld`, and `note` states the same balance in one sentence. So an empty `results` NEVER has to be guessed at: read `total_count` and `note` to tell "this shop has no codes at all" apart from "it has codes and every one of them is proven dead". An UNKNOWN or internal-review shop_domain is a different answer again — it is an error ("shop not found"), not an empty list; and a backend failure is reported as a failure, never as an empty list. Each result carries validUntil: an ISO timestamp when the code has a stated expiry, or null when it is open-ended — null means unlimited, NOT unknown-and-expired. Re-check validUntil against the current time before relaying a code. Each result ALSO carries verificationStatus, the verdict of a real checkout test against this exact code: "verified_applied" means the code was proven to work by an actual checkout attempt with proof on file — safe to recommend; "unverified" means no proof exists either way yet — treat it as unknown, NOT as a negative signal, and do not imply it was tested and failed. ("verified_rejected" is defined as before but no longer appears in `results` — it is counted in `withheld.verified_rejected` instead.) lastVerifiedAt is the ISO timestamp of that most recent test, or null if the code was never tested. A non-null lastVerifiedAt on an "unverified" code means it WAS tested but the test was inconclusive — it is not the same as a code that was never attempted.… - lowNo source repository listed
maint.no-repo
Overall 64/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what OpenShopGraph does
- BestPrice ShoppingRead-only shopping decisions, product search, offers, and price history for Greece.not reviewedGrowingA
- ShopwareQuery and safely manage a Shopware 6 shop: products, orders, customers, stock, audits, reports.not reviewedEstablishedB
Apiguru Amazon DataLive Amazon product, review, search, deal, offer/stock and seller data across 20 marketplaces.not reviewedGrowingA