# io.github.Coinlooter/mcp (npm · payflowagent-mcp)

PayFlowAgent suite: token intel, DeFi, enrich, Base trust (x402).

- Trust score: 63/100 (medium)
- Change this week: +55
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `payflowagent-mcp`: 63/100 (this document), [markdown](https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp.md), [page](https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp)

## Channel facts

- Registry: `npm`
- Package: `payflowagent-mcp`
- Version: `0.1.6`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (112 of 116), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (112 of 116), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 4 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 49/100
  - AI-judged instruction clarity (fair).
  - Tool/resource definitions use about 856 tokens (~77/item across 11 items; 11 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 95/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 86% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add coinlooter-mcp -- npx -y payflowagent-mcp
```

### Codex

```bash
codex mcp add coinlooter-mcp -- npx -y payflowagent-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "coinlooter-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "payflowagent-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add coinlooter-mcp --command npx --arg -y --arg payflowagent-mcp
```

### Hermes

```yaml
mcp_servers:
  coinlooter-mcp:
    command: "npx"
    args: ["-y", "payflowagent-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "coinlooter-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "payflowagent-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 63, +42)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [functional improvement] Stability: unverified → 0.23
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Schema quality: unverified → fair
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT

### 2026-07-31 (score 21, −7)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 28, −22)

- [security regression] Install scripts: pass → unverified
- [security regression] Known CVEs: partial → unverified
- [security regression] Provenance: fail → unverified
- [functional regression] License: pass → unverified
- [functional regression] Dependency health: partial → unverified
- [functional regression] Maintenance: pass → unverified
- [functional] Licence: MIT

### 2026-07-29 (score 50, +22)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT

### 2026-07-28 (score 28, +20)

- [functional regression] Dependency health: partial → unverified
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: pass
- [functional] First check of Schema quality: unverified
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 86
- [functional] Package version: 0.1.4 → 0.1.6

### 2026-07-27 (score 8)

First indexed and scored.

## MCP tools (11)

### `score_token` (~55 tokens)

Token-Score (kostenlos)

Kostenloser, rate-limitierter Score (0-100) inkl. riskLevel und action fuer einen nad.fun-Token auf Monad. Antwort enthaelt upsell zum bezahlten decide_token.

Input parameters:

- `token` (string, required)

### `decide_token` (~61 tokens)

Voller Report (bezahlt, x402)

Bezahlt (USDC via x402). Entscheidungsfertiger Report fuer einen nad.fun-Token: Score, riskLevel, action, erklaerende Faktoren, Graduation-Fortschritt und 5-Minuten-Momentum.

Input parameters:

- `token` (string, required)

### `token_summary` (~54 tokens)

Graduation + Momentum (bezahlt, x402)

Bezahlt (USDC via x402). Guenstiger Einstieg: Graduation-Fortschritt (Bonding-Curve %) + Momentum-Zusammenfassung fuer einen nad.fun-Token.

Input parameters:

- `token` (string, required)

### `screen_tokens` (~90 tokens)

Screening: gerankte Token-Liste (bezahlt, x402)

Bezahlt (USDC via x402). Gerankte Liste vorgescorter, frischer nad.fun-Token (score, riskLevel, action, Graduation, Holder). Ideal fuer Screener/Trading-Agenten.

Input parameters:

- `limit` (integer): Max. Anzahl Token (1-25, Default 10)
- `minScore` (integer): Nur Token mit Score >= minScore (0-100)

### `sample_yields` (~107 tokens)

Yield-Sample (kostenlos, Datafeed)

Kostenloser, rate-limitierter Datafeed-Probe: Top DeFi-Yield-Pools plus Opportunity-Vorschau (Score 0-100 + Gruende). Ideal vor yield_opportunities.

Input parameters:

- `chain` (string): Chain-Filter, z. B. Base, Ethereum
- `limit` (integer): Max. Pools in der APY-Liste (1-5, Default 5)
- `profile` (string): Risiko-Preset fuer die Vorschau (Default stable)

### `yield_opportunities` (~151 tokens)

Yield-Opportunities (bezahlt, x402, Datafeed)

Bezahlt (USDC via x402). Gerankte DeFi-Yield-Chancen mit Score (0-100), Rank und reasons[] — agent-tauglich, nicht nur APY-Sortierung. Profile: stable (Default), balanced, aggressive.

Input parameters:

- `chain` (string): Chain-Filter, z. B. Base
- `limit` (integer): Max. Ergebnisse (1-25, Default 10)
- `minApy` (number): Mindest-APY in %
- `minTvl` (number): Mindest-TVL in USD
- `profile` (string): Risiko/yield-Preset (Default stable)
- `stable` (boolean): Nur Stablecoin-Pools

### `sample_enrich` (~67 tokens)

Enrich-Sample (kostenlos)

Kostenloser, rate-limitierter Probe der Enrich-API: Sample-Suchergebnis-Form plus upsell zu web_search und scrape_url. Keine Upstream-Keys noetig.

Input parameters:

- `q` (string): Suchquery fuer die Sample-Form (Default: x402 protocol)

### `web_search` (~73 tokens)

Web-Search (bezahlt, x402, Enrich)

Bezahlt (USDC via x402). Live Google-SERP via Serper: title, URL, snippet. Kein Serper-API-Key auf Client-Seite — Pay-per-call.

Input parameters:

- `limit` (integer): Max. Treffer (1-10, Default 5)
- `q` (string, required): Suchquery

### `scrape_url` (~71 tokens)

URL scrape (bezahlt, x402, Enrich)

Bezahlt (USDC via x402). Oeffentliche http(s)-URL zu Markdown oder Text scrapen (Firecrawl). Kein Firecrawl-API-Key auf Client-Seite.

Input parameters:

- `format` (string): Ausgabeformat (Default markdown)
- `url` (string, required): Oeffentliche http(s)-URL

### `check_wallet_lite` (~69 tokens)

Wallet-Trust (kostenlos)

Kostenloser, rate-limitierter Counterparty-Check auf Base: verdict (accept/caution/reject) + score. Antwort enthaelt upsell zu check_wallet. Ideal bevor ein x402-Server einen Payer bedient.

Input parameters:

- `address` (string, required): EVM-Adresse auf Base

### `check_wallet` (~58 tokens)

Wallet-Trust Check (bezahlt, x402)

Bezahlt (USDC via x402). Verdict, Top-Gruende und canPay (USDC/ETH auf Base). Fuer x402-Resource-Server und Payment-Agenten.

Input parameters:

- `address` (string, required): EVM-Adresse auf Base

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp#diagnostics

## Score history

- 2026-08-03: 63
- 2026-08-02: 63
- 2026-08-01: 21
- 2026-07-31: 21
- 2026-07-30: 28
- 2026-07-29: 50
- 2026-07-28: 28
- 2026-07-27: 8

## Links

- npm package: https://www.npmjs.com/package/payflowagent-mcp
- Socket report: https://socket.dev/npm/package/payflowagent-mcp
- Repository: https://github.com/Coinlooter/payflowagent-mcp
- Changelog RSS feed: https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/coinlooter-mcp/payflowagent-mcp
