io.github.ciinkwia/agent-tool-finder
REMOTE · CLINK-LITHIUM-VAULT.FLY.DEV · SCANNED SEP 24
Free search across ~35,000 agent tools (x402 bazaar + MCP registry) by plain-language need.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 16 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2261 tokens (~141/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management97
- Stability observed for 29 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 96% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 16 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.ciinkwia/agent-tool-finder MCP server?
io.github.ciinkwia/agent-tool-finder is a hosted endpoint at https://clink-lithium-vault.fly.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · clink-lithium-vault.fly.dev
claude mcp add --transport http ciinkwia-agent-tool-finder 'https://clink-lithium-vault.fly.dev/mcp'
{
"mcpServers": {
"ciinkwia-agent-tool-finder": {
"url": "https://clink-lithium-vault.fly.dev/mcp"
}
}
} {
"servers": {
"ciinkwia-agent-tool-finder": {
"type": "http",
"url": "https://clink-lithium-vault.fly.dev/mcp"
}
}
} [mcp_servers.ciinkwia-agent-tool-finder] url = "https://clink-lithium-vault.fly.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ciinkwia-agent-tool-finder": {
"type": "remote",
"url": "https://clink-lithium-vault.fly.dev/mcp",
"enabled": true
}
}
} openclaw mcp add ciinkwia-agent-tool-finder --url 'https://clink-lithium-vault.fly.dev/mcp' --transport streamable-http
mcp_servers:
ciinkwia-agent-tool-finder:
url: "https://clink-lithium-vault.fly.dev/mcp" {
"McpServers": {
"ciinkwia-agent-tool-finder": {
"Transport": "http",
"Url": "https://clink-lithium-vault.fly.dev/mcp"
}
}
} assistant mcp add ciinkwia-agent-tool-finder -t streamable-http -u 'https://clink-lithium-vault.fly.dev/mcp'
{
"mcpServers": {
"ciinkwia-agent-tool-finder": {
"type": "http",
"url": "https://clink-lithium-vault.fly.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 24 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- The server changed its declared name: agent-tool-finder → clinks-shop security
- Schema quality: 185 → 141 ▲ functional
- Stability: pass → 0.97 functional
- Server version: 0.1.0 → 0.2.0 functional
- New tool “buy_credits” functional
- New tool “credits_balance” functional
- New tool “pdf_text” functional
- New tool “pm_odds” functional
- New tool “pm_search” functional
- New tool “pm_ticker_events” functional
- New tool “sec_insider” functional
- New tool “ticker_brief” functional
- New tool “translate_text” functional
- New tool “x_digest” functional
- New tool “x_profile” functional
- New tool “x_search” functional
- New tool “x_ticker_pulse” functional
- 14 Sept 26 −1
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 358 → 557 ▼ functional
- New tool “request_agent_tool” functional
- 13 Sept 26 0
- HSTS header: unverified → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 2 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- 12 Sept 26 0
- HSTS header: fail → unverified ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- 10 Sept 26 0
- Stability: 0.97 → pass security
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://clink-lithium-vault.fly.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.fly.dev | CN=YE1,O=Let's Encrypt,C=US | 21 Aug 2026 | 19 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 688c4daf5300c51e0a5c1f6837a3a67a868 |
| SANs: *.fly.dev | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of clink-lithium-vault.fly.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| fly.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://clink-lithium-vault.fly.dev/mcp | Verified | 200 | |
| http (plaintext) | http://clink-lithium-vault.fly.dev/mcp | HTTPS enforced | 301 | https://clink-lithium-vault.fly.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
agent_market_stats ~66
Get current size and shape of the agent tool market: how many paid x402 endpoints and MCP servers exist, how many have real paying users, and total measured spend over the last 30 days. Useful for deciding whether a capability is well supplied before you build it yourself. Free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
buy_credits ~154
Add shop credits by paying with a Stripe Shared Payment Token (SPT) — the credential Muse hands a seller after its human approves a spend in Link. amount_usd must be 5, 10, 25 or 50 (Stripe's own fee makes anything smaller lose money). With no existing key on this connection, opens a new account and returns a NEW key ONCE — save it and send it as Authorization: Bearer <key> on every later call. With a valid key already presented, tops up that key's account instead.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usd | number | yes | – |
| spt | string | yes | the Shared Payment Token (spt_...) granted by the agent's Stripe Link session |
No output schema declared.
No examples provided.
credits_balance ~37
Check the shop-credits balance for the key on this connection (Authorization: Bearer ck_live_… or X-Clink-Key). Free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
find_agent_tools ~251
Find an API, data source, or MCP server that can do something you cannot do on your own. Searches 35,000+ agent-callable tools: ~14,000 paid x402 endpoints and ~21,000 MCP servers, in one place. Use it whenever you need outside data or a capability you lack — web search, onchain and crypto data, company or people lookup, scraping, maps, weather, documents, financial data, travel, and more. Returns what each tool does, how to call or install it, and what it costs. Free to use.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | – | Optional. 'x402' for paid pay-per-call HTTP endpoints, 'mcp' for installable MCP servers. Omit to search both. |
| limit | number | – | Optional. Max results, 1-25. Default 8. |
| max_price_usd | number | – | Optional. Only return paid endpoints at or below this price per call. |
| need | string | yes | What you need, in plain language. Describe the capability or data, not a tool name. Example: 'historical lithium spodumene prices' or 'check if a wallet holds an NFT'. |
No output schema declared.
No examples provided.
pdf_text ~106
Convert a public PDF to plain text — full extracted text in one call, up to 25MB / 500k chars, with page count and a likely_scanned flag (text-based PDFs only, no OCR). Costs $0.01 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | public http(s) URL of a PDF file |
No output schema declared.
No examples provided.
pm_odds ~129
Prediction market odds — a finished read for one question: best-matching market on Polymarket AND Kalshi, implied probability, cross-platform gap, 7-day history, one-line summary. Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.02 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| q | string | yes | a question, e.g. 'will the fed cut rates in september' |
No output schema declared.
No examples provided.
pm_search ~144
Prediction market search — live markets from Polymarket AND Kalshi matching a question or topic, ranked by relevance: implied probability, 24h/7d change, volume, close date, URL. Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.01 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | 1-50, default 20 |
| q | string | yes | a question or topic, e.g. 'fed rate cut september' |
No output schema declared.
No examples provided.
pm_ticker_events ~139
Open prediction markets mentioning a US stock ticker or company, Polymarket + Kalshi in one call: implied probability, 24h change, volume, close date, URL. Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.01 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | 1-50, default 20 |
| q | string | yes | a ticker (TSLA) or company name (Tesla) |
No output schema declared.
No examples provided.
request_agent_tool ~173
Ask clink's shop to BUILD a tool or data source that nobody sells yet. Use this right after find_agent_tools comes back unsatisfied. clink reads every request the same day; buildable asks ship as pay-per-call x402 endpoints, usually within a week. Returns a request id and a status URL; pass `notify` (email or https webhook) to be told the moment it ships.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_usd | number | – | Optional. What one call is worth to you, in USD — helps clink price it. |
| notify | string | – | Optional. An email address or https webhook URL to ping when it ships (or is declined). |
| want | string | yes | What you need, plain language, 3-500 chars. Describe the data or capability and how you'd call it. |
No output schema declared.
No examples provided.
sec_insider ~169
SEC Form 4 insider trading for one US stock ticker — every insider buy/sell/grant/gift in the window (name, role, date, code, shares, price, shares owned after, filing URL) plus open-market buy vs sell totals. Source: SEC EDGAR. Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.01 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| days | number | – | 1-365, default 90 |
| limit | number | – | 1-25, default 25 |
| ticker | string | yes | e.g. AAPL |
No output schema declared.
No examples provided.
ticker_brief ~123
One-call US stock ticker brief — X/Twitter activity (24h), prediction markets, SEC Form 4 insider activity (90d), and the latest 8-K, bundled. Each section fails independently. Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.04 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | e.g. NVDA |
No output schema declared.
No examples provided.
translate_text ~133
Translate text — up to 2,000 chars, any language pair, source auto-detected when omitted. Returns clean JSON: detected source language + full translation. Costs $0.01 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| source_lang | string | – | optional; auto-detected when omitted |
| target_lang | string | yes | language to translate into, e.g. 'English', 'es' |
| text | string | yes | text to translate, up to 2,000 chars |
No output schema declared.
No examples provided.
x_digest ~101
X/Twitter trend digest — live tweet search PLUS an AI-written summary: sentiment, key themes, driving accounts, notable posts. Same query syntax as x_search. Costs $0.05 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Advanced X search query, e.g. '#bitcoin min_faves:50' |
No output schema declared.
No examples provided.
x_profile ~94
X/Twitter profile lookup — display name, bio, follower/following counts, verified status, location, join date, profile URL for one handle. Costs $0.02 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| username | string | yes | X handle, e.g. elonmusk |
No output schema declared.
No examples provided.
x_search ~121
Live X/Twitter search for AI agents — advanced search syntax (from:user, "exact phrase", #hashtag, since:/until:, min_faves:, lang:). Up to 20 newest tweets with author, likes, retweets, views, URL. Costs $0.02 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Advanced X search query, e.g. 'from:elonmusk lithium' |
No output schema declared.
No examples provided.
x_ticker_pulse ~159
X/Twitter activity for one US stock ticker — post volume vs the prior window, top posts, most active accounts, keyword topic flags (earnings, guidance, lawsuit, SEC investigation, recall, M&A, layoffs, upgrade/downgrade, short report, dividend, buyback, CEO). Facts only — this is not investment advice, a price target, or a buy/sell/hold signal. Costs $0.02 per call, paid from clink's shop credits (get a key with buy_credits or at /buy/credits). A failed or empty call is free.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | e.g. TSLA or $TSLA |
| window | string | – | default 24h |
No output schema declared.
No examples provided.
What is the io.github.ciinkwia/agent-tool-finder MCP server?
io.github.ciinkwia/agent-tool-finder is an MCP server listed in the public MCP registry as io.github.ciinkwia/agent-tool-finder. Free search across ~35,000 agent tools (x402 bazaar + MCP registry) by plain-language need. This page covers its hosted endpoint (https://clink-lithium-vault.fly.dev/mcp).
Is the io.github.ciinkwia/agent-tool-finder MCP server safe to use?
io.github.ciinkwia/agent-tool-finder scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.ciinkwia/agent-tool-finder MCP server expose?
io.github.ciinkwia/agent-tool-finder exposes 16 tools: find_agent_tools, agent_market_stats, request_agent_tool, x_search, x_profile, and 11 more. Their descriptions and schemas cost roughly 2,099 tokens of context every time the server is loaded.
Does the io.github.ciinkwia/agent-tool-finder MCP server require authentication?
No. We connected to io.github.ciinkwia/agent-tool-finder without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.ciinkwia/agent-tool-finder MCP server still maintained?
io.github.ciinkwia/agent-tool-finder is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.