io.github.rezearcher/tech-risk
io.github.rezearcher/tech-risk · 1.2.0
x402 MCP for agents: crypto prices, funding, DeFi yields, Polymarket, Base RPC + MCP security.
Nobody here has read this server's code, because it publishes none. The description above is the maker's own, from the registry. A connection test shows whether it answers and what tools it says it has; it never calls a tool, so it cannot show what one does with your data.
Where it sits in the directory's order
What can be seen from outside, weighed as the directory publishes.
Observable signals: 45 of 100 points (at most 60 here)
| Input | Points | What was seen |
|---|---|---|
| Source published | held at 0 | No entry here publishes source: that is what puts it in this directory. |
| Licence stated | held at 0 | With no files, there is nothing for a licence to be stated in or held against. |
| Advisory state | held at 0 | Advisory databases index packages, and these entries publish none, so there is nothing to look up. |
| Auth declared | 0 of 15 | The registry entry declares no key. That is what it declares, not a finding that it has no protection. |
| Latest connection test reached it | 20 of 20 |
Where it answers
https://x402-data-api.sigrunner.workers.dev/mcpstreamable-http
Connection test
The MCP handshake, then a request for the tool list, with no key and no data of yours. Run nightly, and by anyone, at most once every ten minutes per server.
It completed the handshake and listed 22 tools.
- Protocol
- 2025-06-18
- Calls itself
- x402-data-api 0.1.0
- Handshake time
- 265 ms
- HTTP status
- 200
The tools it lists (22, as of 7 days ago)
The tool-description rules found nothing in these descriptions. They look for instructions aimed at a model and for hidden characters; they cannot see what a tool does when it runs.
enrich_tech_riskSecurity enrichment: tech-stack fingerprint + CVE mapping + EPSS + CISA KEV + verdict (clear/review/block) for a domain. Cost: $0.005 USDC per call (x402 micropayment).
enrich_domainFirmographic + tech-stack enrichment: RDAP registrant/registrar, DNS records, full subdomain enumeration + certificate-transparency history, tech-stack fingerprint, verdict (clear/review/block, based on domain age) for a domain. Cost: $0.005 USDC per call via the shared MCP payment gate (the direct HTTP endpoint GET /enrich/domain is $0.01 — MCP tools/call is gated at a flat $0.005 per request).
scan_mcp_serverSecurity-audit a target MCP server for prompt-injection / tool-poisoning. Fetches the server's advertised tools and statically analyzes each for hidden instructions, data-exfiltration hints, dangerous capabilities, cross-tool shadowing, and invisible-unicode payloads (OWASP LLM01/LLM08). Returns findings + a 0-100 risk score + verdict (clear/review/block). Cost: $0.005 USDC per scan via x402 (GET /scan/mcp HTTP variant is $0.10).
scan_mcp_previewFREE preview scan of a target MCP server for tool-poisoning / prompt-injection. Returns issue count, severity breakdown, risk score, and verdict (clear/review/block) — but NOT which tools or the evidence. Use this to check any MCP server (including your own) at no cost; if issues are found, call the paid scan_mcp_server for the itemized findings + remediation. No payment required.
crypto_pricesLive spot token prices (price, change_24h, symbol, confidence, timestamp) for CoinGecko ids, sourced from DefiLlama. Cost: $0.005 USDC per call via x402.
crypto_fundingLive cross-venue perpetual-futures funding rates from Hyperliquid+OKX+dYdX (per-venue rate, arb spread in bps, cheapest-long/richest-short venue, premium/basis, annualized_hl, annualized_okx, LONGS_PAY/SHORTS_PAY/NEUTRAL signal, next_funding_ts, mark/oracle price, open interest, day volume), ranked by volume. Venues that are unreachable or don't list a given coin are omitted per-coin — Hyperliquid is always present. Cost: $0.005 USDC per call via x402.
How this entry becomes a listing
For the maker. The catalogue lists what it can read, and this server publishes nothing to read yet. There are two routes, and only the first is open today.
Publish the source Open today
- Put the server's source in a public repository on github.com, with a licence.
- Keep a server.json in that repository naming this server,
io.github.rezearcher/tech-risk, and declare the repository in it:"repository": { "url": "https://github.com/owner/repo", "source": "github" }, adding"subfolder"when the server lives in a folder. - Publish that version to the official MCP registry.
- The nightly registry sweep records the declaration. This page stays, dated, and says the source is declared but not yet read.
- The catalogue reads declared repositories at a pinned commit, in batches run by hand, and lists the servers that meet the batch's rules (among them a server.json at that commit naming the server, an https endpoint and a licence). When it lists this server, this page links to the listing. There is no schedule, so no date can be promised.
List it through the maker studio Not open yet
From the official MCP registry, last updated there 84 days ago. The registry entry · x402-data-api.sigrunner.workers.dev