Mmcp.market

Reputation MCP server

not responding
by tradallo.com·com.tradallo/reputation·v0.3.2·1 stars

Query cryptographically-verified trading reputations (humans + AI agents). ed25519-signed.

C64/100grade C
What users say
No reviews yet
Be the first
Safety scan
C64/100

full report

Adoption
Growing

1 stars35 downloads/wk

Reviews

Write one

Nobody has reviewed Reputation yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Reputation tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it

1 high
  • Code scan7 source files scanned25/25
  • Live reliabilityremote unreachable: AbortError: This operation was aborted0/20
  • –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 140 days ago8/15
  • Maintainer identityregistry namespace matches repository owner; website matches verified namespace9/10

Findings (1)

  • highRemote endpoint did not respondreliability.unreachable

    AbortError: This operation was aborted

Overall 64/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Reputation in Claude Code, Cursor or VS Code

claude mcp add --transport http reputation https://mcp.tradallo.com/mcp
Add to Cursor

What the publisher says

From the Reputation repository's README, as published. We do not edit it. Read it on GitHub

@tradallo/reputation

MCP server + TypeScript client + CLI for the Tradallo Verified Record Protocol. Three ways to query cryptographically-verified human and agent trading records:

# CLI — pretty terminal cards, no install required
npx @tradallo/reputation card alpha-momentum-v3 --agent

# MCP — drop into Claude Desktop / Cursor / any MCP client (config below)

# Programmatic — typed TS/JS client
import { TradalloClient } from "@tradallo/reputation";

Every response is JCS-canonicalized + ed25519-verified against Tradallo's published pubkey at tradallo.com/.well-known/tradallo-pubkeys.json before being surfaced. The signature lives in the envelope; this client fetches the pubkey registry, resolves the keyid, verifies the signature, and only then returns the data. Replay protection via servedat + maxageseconds.

Install

Claude Desktop

Add to your claudedesktopconfig.json (Settings → Developer → Edit Config):

{
  "mcpServers": {
    "tradallo-reputation": {
      "command": "npx",
      "args": ["-y", "@tradallo/reputation"]
    }
  }
}

Restart Claude Desktop. The Tradallo tools should appear in the tool palette.

Cursor

Add to ~/.cursor/mcp.json (or via Cursor Settings → MCP):

{
  "mcpServers": {
    "tradallo-reputation": {
      "command": "npx",
      "args": ["-y", "@tradallo/reputation"]
    }
  }
}

Generic MCP client

npx @tradallo/reputation

Speaks MCP over stdio.

Local dev / staging

Point at your own deploy by setting TRADALLOBASEURL:

{
  "mcpServers": {
    "tradallo-reputation": {
      "command": "npx",
      "args": ["-y", "@tradallo/reputation"],
      "env": { "TRADALLO_BASE_URL": "http://localhost:3000" }
    }
  }
}

CLI

The same binary doubles as a terminal CLI when invoked with a subcommand:

# Pretty card with verification status, stats, version metadata
npx @tradallo/reputation card alpha-momentum-v3 --agent

# Raw verified JSON (for piping into jq, etc.)
npx @tradallo/reputation track-record alpha-momentum-v3 --agent

# Discovery
npx @tradallo/reputation search --min-sharpe 1.5 --min-trades 200 --sort-by sharpe

# Agent version history
npx @tradallo/reputation versions alpha-momentum-v3

# Paginated UTRs
npx @tradallo/reputation utrs alpha-momentum-v3 --limit 50

# Look up a specific UTR by hash
npx @tradallo/reputation verify <sha256-hex> alpha-momentum-v3

# Help
npx @tradallo/reputation help

NOCOLOR=1 disables ANSI. TRADALLOBASE_URL overrides the API base.

Programmatic client

Embed the verifying client in your own TS/JS code:

import { TradalloClient } from "@tradallo/reputation";

const client = new TradalloClient(); // defaults to https://tradallo.com

// Throws if signature invalid, replay window expired, or pubkey unknown.
// Returns the verified `data` payload (not the envelope wrapper).
const record = await client.getSigned<{ stats: { all_time: { sharpe_ratio: number | null } } }>(
  "/api/v1/agents/alpha-momentum-v3/track-record",
);

if ((record.stats.all_time.sharpe_ratio ?? 0) >= 1.5) {
  // ... delegate capital, copy trades, etc.
}

The verification flow happens INSIDE getSigned. If anything fails — bad signature, expired envelope, unknown key, schema mismatch — the call throws. You never see unverified data.

Tools

gettrackrecord(handle, principal_type?)

Fetch a verified track record for a Tradallo profile or agent.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Reputation: common questions

Is Reputation MCP server safe?
With care: it is graded C, so read the findings first (64/100). Read the Reputation safety report
How do I install Reputation?
It runs remotely at mcp.tradallo.com. Add it to Claude Code, Cursor, VS Code or Claude Desktop with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Reputation need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Reputation maintained?
The last commit was 147 days ago (2026-05-04). The latest release is v0.3.2.
Is Reputation up?
0% of our last 28 checks got an answer. We check remote servers about four times a day.

More from tradallo.com →