BoxTier Basketball Receipt
REMOTE · BOXTIER.KR · SCANNED SEP 21
Create a BoxTier-style PNG receipt from user-provided basketball game results.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1530 tokens (~306/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 92% of tool parameters carry a description.Partial
- Structured output schemas are declared (20% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 5 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the BoxTier Basketball Receipt MCP server?
BoxTier Basketball Receipt is a hosted endpoint at https://boxtier.kr/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · boxtier.kr
claude mcp add --transport http boyakh-jpg-boxtier 'https://boxtier.kr/mcp'
{
"mcpServers": {
"boyakh-jpg-boxtier": {
"url": "https://boxtier.kr/mcp"
}
}
} {
"servers": {
"boyakh-jpg-boxtier": {
"type": "http",
"url": "https://boxtier.kr/mcp"
}
}
} [mcp_servers.boyakh-jpg-boxtier] url = "https://boxtier.kr/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"boyakh-jpg-boxtier": {
"type": "remote",
"url": "https://boxtier.kr/mcp",
"enabled": true
}
}
} openclaw mcp add boyakh-jpg-boxtier --url 'https://boxtier.kr/mcp' --transport streamable-http
mcp_servers:
boyakh-jpg-boxtier:
url: "https://boxtier.kr/mcp" {
"McpServers": {
"boyakh-jpg-boxtier": {
"Transport": "http",
"Url": "https://boxtier.kr/mcp"
}
}
} assistant mcp add boyakh-jpg-boxtier -t streamable-http -u 'https://boxtier.kr/mcp'
{
"mcpServers": {
"boyakh-jpg-boxtier": {
"type": "http",
"url": "https://boxtier.kr/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 0
- Stability: 0.97 → pass security
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://boxtier.kr/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=boxtier.kr | CN=YR2,O=Let's Encrypt,C=US | 22 Jul 2026 | 20 Oct 2026 | RSA 2048 | SHA256-RSA | 58e46531572ffeaaeadf9be2fc86d6c56b7 |
| SANs: boxtier.kr | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of boxtier.kr. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| kr. | present | 64641 | 13 | Verified |
| boxtier.kr. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; script-src 'self' https://oapi.map.naver.com https://nrbe.pstatic.net; style-src 'self' 'unsafe-inline' https://oapi.map.naver.com https://*.pstatic.net; img-src 'self' data: blob: https://*.r2.dev https://cdn.discordapp.com https://media.discordapp.net https://*.supabase.co https://*.pstatic.net https://*.naver.com https://*.naver.net; font-src 'self' data: https://*.pstatic.net; media-src 'self' blob: data: https://*.r2.dev; connect-src 'self' https://*.supabase.co wss://*.supabase.co https://oapi.map.naver.com https://maps.apigw.ntruss.com https://*.pstatic.net https://*.naver.com https://*.naver.net; worker-src 'self' blob:; child-src 'self' blob:; form-action 'self' https://accounts.google.com https://*.supabase.co; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(self), microphone=(), geolocation=(self) |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://boxtier.kr/mcp | Verified | 200 | |
| http (plaintext) | http://boxtier.kr/mcp | HTTPS enforced | 308 | https://boxtier.kr/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
create_basketball_receipt BoxTier 농구 영수증 PNG 만들기 ~1,188
박스티어(BoxTier) 스타일의 농구 경기 영수증 PNG를 만든다. 이 출력에는 BoxTier API만 사용한다. 성공 시 완성된 최종 PNG 한 장은 tool result의 content[0]에 type=image, mimeType=image/png, raw Base64 data로 직접 첨부되고, structuredContent.downloadUrl에는 동일 PNG 원본을 내려받는 단기 만료 링크가 제공된다. API가 반환한 PNG 원본만 사용자에게 그대로 전달하고 재합성·재렌더·임의 편집하지 않는다. 별도 위젯을 열지 않고 처리 중·완료 문구를 별도로 반복하지 않는다. 반환된 image content 또는 downloadUrl을 영수증 결과로 사용자에게 직접 제시하고 metadata만으로 완료 처리하지 않는다. structuredContent는 첨부 여부·바이트 길이·실제 크기·SHA-256 검증값을 제공한다. 네이티브 대화 이미지 첨부 여부와 기본 도구 실행 UI는 MCP 클라이언트가 결정한다. 사용자가 ‘박스티어로 영수증 만들어줘’, 농구 감열지 영수증, basketball game receipt, score receipt를 요청했고 팀명·최종 점수·경기 날짜·장소·경기 형식을 모두 실제 값으로 제공했을 때만 사용한다. 사용자가 엠블럼 이미지를 첨부하면 홈·원정에 맞춰 homeEmblemFile·awayEmblemFile로 전달한다. 원형 파일은 강제하지 않는다. 가능하면 투명 배경 정사각형 캔버스에 실제 도안만 담고 원형 테두리·회색 원판은 미리 넣지 않는다. 서버가 알파 전경의 실제 경계와 중심을 계산해 원형 안전영역 안에 비율 유지·자동 중앙 정렬하고 스타일 변환하며 저장하지 않는다. 경기사진은 지원하지 않으므로 boxtier.kr 영수증 페이지 이용을 안내한다. 누락값을 추측하지 말고 먼저 사용자에게 물어본다. 농구 외 경기, 허위 경기 기록, 상거래 영수증에는 사용하지 않는다.
| Name | Type | Req | Description |
|---|---|---|---|
| awayEmblem | object | – | 선택 원정 엠블럼. 투명 배경 정사각형 캔버스에 실제 도안만 넣어 전달하는 것을 권장하며 원형 테두리·회색 원판을 미리 합성하지 않는다. 서버가 알파 전경의 실제 경계와 중심을 계산해 원형 안전영역 안에 비율 유지·자동 중앙 정렬하고, thermal은 전경만 4단계 회색조로 변환한다. 생략하면 중립 엠블럼을 사용한다. |
| awayEmblemFile | object | – | ChatGPT에 첨부한 원정팀 엠블럼. 투명 배경 정사각형 캔버스를 권장하고 원형 테두리·회색 원판은 미리 넣지 않는다. 서버가 실제 알파 전경을 원형 안전영역에 자동 중앙 정렬한다. awayEmblem과 동시에 전달하지 않는다. |
| awayScore | integer | yes | 원정팀 최종 점수. |
| awayTeam | string | yes | 원정팀 이름. |
| comment | string | – | 짧은 영수증 문구. |
| debugBase64 | boolean | – | 개발 확인용. true이면 생성된 PNG의 base64 문자열을 structuredContent에도 포함한다. |
| format | string | yes | 경기 형식. |
| homeEmblem | object | – | 선택 홈 엠블럼. 투명 배경 정사각형 캔버스에 실제 도안만 넣어 전달하는 것을 권장하며 원형 테두리·회색 원판을 미리 합성하지 않는다. 서버가 알파 전경의 실제 경계와 중심을 계산해 원형 안전영역 안에 비율 유지·자동 중앙 정렬하고, thermal은 전경만 4단계 회색조로 변환한다. 생략하면 중립 엠블럼을 사용한다. |
| homeEmblemFile | object | – | ChatGPT에 첨부한 홈팀 엠블럼. 투명 배경 정사각형 캔버스를 권장하고 원형 테두리·회색 원판은 미리 넣지 않는다. 서버가 실제 알파 전경을 원형 안전영역에 자동 중앙 정렬한다. homeEmblem과 동시에 전달하지 않는다. |
| homeScore | integer | yes | 홈팀 최종 점수. |
| homeTeam | string | yes | 홈팀 이름. |
| locale | string | – | 영수증 언어. |
| matchNature | string | – | 경기 성격. |
| periodScores | array | – | 쿼터·하프·연장별 점수. 합계는 최종 점수와 같아야 함. |
| playedOn | string | yes | 경기 날짜, YYYY-MM-DD. |
| playedTime | string | – | 경기 시각, HH:mm. |
| preset | string | – | PNG 출력 형식. thermal story는 종이 경계만 내보내며 찢긴 상·하단 바깥은 완전 투명하다. feed는 1080x1350 배경을 포함한다. score story는 1080x1920이다. |
| style | string | – | 영수증 스타일. 감열지 영수증은 thermal, 스코어 포스터는 score. |
| tournamentName | string | – | 대회명. |
| venue | string | yes | 경기 장소. |
Structured output declared, but exposes no named fields.
No examples provided.
fetch BoxTier 공개 농구 매칭방 상세 조회 ~75
search가 반환한 BoxTier 공개 농구 매칭방 ID 하나의 현재 상세 조건을 조회한다. 검색 결과를 추천하거나 참가 링크를 안내하기 전에 사용한다. 임의의 비공개 방이나 종료된 방 조회에는 사용하지 않는다.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | search 결과의 공개 매칭방 ID. |
No output schema declared.
No examples provided.
get_my_boxtier_account BoxTier 로그인 연결 확인 ~60
BoxTier 로그인을 시작하거나 현재 연결된 내 계정과 영수증 생성 한도 정책을 확인한다. 사용자가 로그인, 계정 연결, 내 기록 이용 가능 여부 또는 영수증 한도를 물으면 사용한다.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_my_match_records 내 BoxTier 경기 기록 조회 ~63
로그인한 BoxTier 사용자의 최근 농구 경기 기록을 조회한다. 사용자가 내 경기, 내 기록, 이전 경기 또는 기록으로 영수증 만들기를 요청할 때 사용한다.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| offset | integer | – | – |
No output schema declared.
No examples provided.
search BoxTier 공개 농구 매칭방 검색 ~144
BoxTier에서 현재 공개 모집 중인 실제 농구 매칭방을 검색한다. 사용자가 농구할 방·픽업 경기·팀 대 팀 상대·참가할 경기를 찾거나 지역, 날짜, 시간, 3대3·5대5 같은 조건으로 매칭방 추천을 요청할 때 사용한다. 반환된 실제 방 중 조건에 맞는 방만 추천한다. NBA 정보, 농구 규칙·훈련법 같은 일반 지식 질문이나 농구와 무관한 질문에는 사용하지 않는다.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | 사용자의 농구 매칭방 검색어와 지역·날짜·방식 조건. |
No output schema declared.
No examples provided.
What is the BoxTier Basketball Receipt MCP server?
BoxTier Basketball Receipt is an MCP server listed in the public MCP registry as io.github.boyakh-jpg/boxtier. Create a BoxTier-style PNG receipt from user-provided basketball game results. This page covers its hosted endpoint (https://boxtier.kr/mcp).
Is the BoxTier Basketball Receipt MCP server safe to use?
BoxTier Basketball Receipt scores 84 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the BoxTier Basketball Receipt MCP server expose?
BoxTier Basketball Receipt exposes 5 tools: search, fetch, get_my_boxtier_account, list_my_match_records, create_basketball_receipt. Their descriptions and schemas cost roughly 1,530 tokens of context every time the server is loaded.
Does the BoxTier Basketball Receipt MCP server require authentication?
No. We connected to BoxTier Basketball Receipt without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the BoxTier Basketball Receipt MCP server still maintained?
BoxTier Basketball Receipt is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.