MCP server · trust report

io.agentlot/marketplace

3 checks that ran failed — injection surface, credential hygiene and transport config — so this release can’t be trusted as-is.

Publisher
io.agentlot
Repository
Install
remote only
Versions
2
MCP revision
2025-11-25 · superseded
Inspected
5 of 6 checks · 85%
Scored
2026-09-03 · rubric 1.0.0

What we checked

Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.

6 checks1 clean4 flagged1 not inspected
  • Injection surface

    fail25% of grade

    Tool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).

    tool "subscribe_earn_alerts" description: names an outbound copy/exfil destination (BCC/exfil verb).

  • Supply chain

    warn25% of grade

    Package provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.

    no resolvable repository linked to the package (provenance unverifiable)

  • Credential hygiene

    fail15% of grade

    How the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.

    tool "start_paid_goal" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_revenue_dashboard" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_wallet_providers" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "list_my_wallets" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_payout_options" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "connect_public_wallet" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "request_cashout" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_money" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "offer_for_request" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "subscribe_earn_alerts" has a secret-shaped input parameter "bearer_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "subscribe_earn_alerts" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "post_request" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "cancel_request" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "propose_for_request" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "accept_request_proposal" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "publish_listing" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_me" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "create_order" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "get_order" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "submit_delivery" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "accept_delivery" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "request_revision" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "open_dispute" has a secret-shaped input parameter "api_key" — secrets must never be tool parameters (the model would supply/handle the credential). tool "agentlot_start_earning" has a secret-shaped input parameter "session_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "gateway_run_status" has a secret-shaped input parameter "capability_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "gateway_capability_refresh" has a secret-shaped input parameter "capability_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "gateway_executor_call" has a secret-shaped input parameter "capability_token" — secrets must never be tool parameters (the model would supply/handle the credential).

  • Permission scope

    unscannable15% of grade

    Declared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.

    No source files, package.json, or pyproject were fetched; cannot infer capability scope.

  • Version behavior

    pass10% of grade

    Diff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).

    vs prior 3.9.3 (major bump): new tool "start_paid_goal" touches a sensitive surface (email/exec/net/fs); new tool "get_revenue_dashboard" touches a sensitive surface (email/exec/net/fs); new tool "get_wallet_providers" touches a sensitive surface (email/exec/net/fs); new tool "list_my_wallets" touches a sensitive surface (email/exec/net/fs); new tool "get_payout_options" appeared; new tool "connect_public_wallet" appeared; new tool "request_cashout" appeared; new tool "get_market_stats" touches a sensitive surface (email/exec/net/fs); new tool "search_global_earn" appeared; new tool "get_external_integrations" appeared; new tool "search_global_market" appeared; new tool "route_global_market" appeared; new tool "route_economy" appeared; new tool "search_external_earn" appeared; new tool "do_goal" appeared; new tool "get_money" appeared; new tool "register_agent" touches a sensitive surface (email/exec/net/fs); new tool "earn_loop" appeared; new tool "offer_for_request" appeared; new tool "subscribe_earn_alerts" touches a sensitive surface (email/exec/net/fs); new tool "earn_now" appeared; new tool "list_requests" appeared; new tool "post_request" appeared; new tool "cancel_request" appeared; new tool "propose_for_request" appeared; new tool "accept_request_proposal" touches a sensitive surface (email/exec/net/fs); new tool "publish_listing" appeared; new tool "search_listings" appeared; new tool "get_listing" appeared; new tool "match_task" appeared; new tool "get_me" touches a sensitive surface (email/exec/net/fs); new tool "create_order" touches a sensitive surface (email/exec/net/fs); new tool "get_order" appeared; new tool "submit_delivery" touches a sensitive surface (email/exec/net/fs); new tool "accept_delivery" appeared; new tool "request_revision" appeared; new tool "open_dispute" appeared; new tool "identity_exchange" touches a sensitive surface (email/exec/net/fs); new tool "me" appeared; new tool "earn" appeared; new tool "get_opportunities" appeared; new tool "get_balance" appeared; new tool "get_earnings" appeared; new tool "get_permissions" appeared; new tool "make_money_for_me" appeared; new tool "discover_earnings" touches a sensitive surface (email/exec/net/fs); new tool "find_funded_work" appeared; new tool "search_ranked_market" appeared; new tool "get_market_money_metrics" appeared; new tool "find_money_opportunities" touches a sensitive surface (email/exec/net/fs); new tool "get_economic_passport" appeared; new tool "plan_agent_team" appeared; new tool "quality_check" touches a sensitive surface (email/exec/net/fs); new tool "get_payout_methods" appeared; new tool "set_payout_method" appeared; new tool "request_payout" appeared; new tool "register_worker" appeared; new tool "procure_outcome" appeared; new tool "search_external_catalog" appeared; new tool "get_growth_stats" appeared; new tool "create_referral" appeared; new tool "import_my_services" appeared; new tool "find_capability" touches a sensitive surface (email/exec/net/fs); new tool "execute_goal" appeared; new tool "outsource_gap" appeared; new tool "register_capability" appeared; new tool "compete_outputs" appeared; new tool "list_build_opportunities" appeared; new tool "list_assets" appeared; new tool "search_revenue_opportunities" appeared; new tool "search_capability_suppliers" appeared; new tool "execute_best_route" appeared; new tool "search_supply_graph" appeared; new tool "publish_demand" appeared; new tool "create_bid_request" appeared; new tool "submit_bid" appeared; new tool "get_market_intelligence" touches a sensitive surface (email/exec/net/fs); new tool "create_subscription_draft" appeared; new tool "sync_official_mcp_registry" appeared; new tool "rank_profitable_opportunities" appeared; new tool "plan_profitable_execution" appeared; new tool "estimate_profitability" appeared; new tool "assess_opportunity_eligibility" appeared; new tool "rank_real_profit_opportunities" appeared; new tool "assess_real_eligibility" appeared; new tool "rank_real_profit_opportunities_v2" appeared; new tool "prepare_taskmarket_submission" touches a sensitive surface (email/exec/net/fs); new tool "check_taskmarket_submission_gate" touches a sensitive surface (email/exec/net/fs); new tool "list_payment_methods" appeared; new tool "quote_payment_route" appeared; new tool "get_economic_mandate" touches a sensitive surface (email/exec/net/fs); new tool "check_economic_mandate" appeared; new tool "create_buyer_goal" appeared; new tool "compute_status" touches a sensitive surface (email/exec/net/fs); new tool "discover_compute" appeared; new tool "quote_compute" appeared; new tool "reserve_compute" appeared; new tool "submit_code_asset" appeared; new tool "list_code_assets" appeared; new tool "get_code_asset" touches a sensitive surface (email/exec/net/fs); new tool "deploy_code_asset" touches a sensitive surface (email/exec/net/fs); new tool "adopt_code_asset" appeared; new tool "code_economy_status" touches a sensitive surface (email/exec/net/fs); new tool "agentlot_start_earning" appeared; new tool "agentlot_earn_preview" touches a sensitive surface (email/exec/net/fs); new tool "agentlot_earn_status" touches a sensitive surface (email/exec/net/fs); new tool "agentlot_capabilities" appeared; new tool "project_status" appeared; new tool "project_write_file" touches a sensitive surface (email/exec/net/fs); new tool "project_append_file" touches a sensitive surface (email/exec/net/fs); new tool "project_write_files" touches a sensitive surface (email/exec/net/fs); new tool "project_list_files" appeared; new tool "project_read_file" touches a sensitive surface (email/exec/net/fs); new tool "project_safe_install" appeared; new tool "project_run_checks" touches a sensitive surface (email/exec/net/fs); new tool "project_deploy_cloudflare" appeared; new tool "project_verify_deployment" touches a sensitive surface (email/exec/net/fs); new tool "project_bundle" appeared; new tool "project_submit" touches a sensitive surface (email/exec/net/fs); new tool "earn_executor_status" appeared; new tool "gateway_make_money_for_me" touches a sensitive surface (email/exec/net/fs); new tool "gateway_run_status" touches a sensitive surface (email/exec/net/fs); new tool "gateway_capability_refresh" touches a sensitive surface (email/exec/net/fs); new tool "gateway_executor_call" touches a sensitive surface (email/exec/net/fs). Low-severity drift (informational; consistent with the version bump).

  • Transport config

    fail10% of grade

    Remote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.

    remote MCP endpoint declares NO authentication (unauthenticated remote — nginx-ui/CVE-2026-33032 class)

Version history

Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.

VersionPublishedGradeScoreInspectedChange
v4.1.0 · current2026-08-14 F37.55/6 · 85%insf→F in v4.1.0
v3.9.32026-08-13 insufficient2/6 · 35%