Cheapest Grocery Basket
REMOTE · GROCERY-BASKET.BOWLING-ANTHONY.WORKERS.DEV · SCANNED SEP 26
Where to buy a whole grocery list today: local prices, per-unit and cross-store comparison.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 5 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1278 tokens (~255/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Cheapest Grocery Basket MCP server?
Cheapest Grocery Basket is a hosted endpoint at https://grocery-basket.bowling-anthony.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · grocery-basket.bowling-anthony.workers.dev
claude mcp add --transport http com-mcpscores-cheapest-grocery-basket 'https://grocery-basket.bowling-anthony.workers.dev/mcp'
{
"mcpServers": {
"com-mcpscores-cheapest-grocery-basket": {
"url": "https://grocery-basket.bowling-anthony.workers.dev/mcp"
}
}
} {
"servers": {
"com-mcpscores-cheapest-grocery-basket": {
"type": "http",
"url": "https://grocery-basket.bowling-anthony.workers.dev/mcp"
}
}
} [mcp_servers.com-mcpscores-cheapest-grocery-basket] url = "https://grocery-basket.bowling-anthony.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-mcpscores-cheapest-grocery-basket": {
"type": "remote",
"url": "https://grocery-basket.bowling-anthony.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add com-mcpscores-cheapest-grocery-basket --url 'https://grocery-basket.bowling-anthony.workers.dev/mcp' --transport streamable-http
mcp_servers:
com-mcpscores-cheapest-grocery-basket:
url: "https://grocery-basket.bowling-anthony.workers.dev/mcp" {
"McpServers": {
"com-mcpscores-cheapest-grocery-basket": {
"Transport": "http",
"Url": "https://grocery-basket.bowling-anthony.workers.dev/mcp"
}
}
} assistant mcp add com-mcpscores-cheapest-grocery-basket -t streamable-http -u 'https://grocery-basket.bowling-anthony.workers.dev/mcp'
{
"mcpServers": {
"com-mcpscores-cheapest-grocery-basket": {
"type": "http",
"url": "https://grocery-basket.bowling-anthony.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 22 Sept 26 0
- Stability: 0.97 → pass security
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 26 Sept 2026 · Probed https://grocery-basket.bowling-anthony.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=bowling-anthony.workers.dev | CN=WE1,O=Google Trust Services,C=US | 22 Sept 2026 | 21 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 99977672261024f133ad95ab21127b5 |
| SANs: bowling-anthony.workers.dev, *.bowling-anthony.workers.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of grocery-basket.bowling-anthony.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://grocery-basket.bowling-anthony.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://grocery-basket.bowling-anthony.workers.dev/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cheapest_basket Cheapest way to buy a whole list, including splitting stores ~305
The complete buying decision for a shopping list: the cheapest single store that can fill it, AND the cross-store optimum that buys each line wherever it is cheapest, with the dollar savings between them and how many stops that costs. Every line carries substitutes at the other stores with the exact extra cost of choosing them, so a shopper can collapse a two-stop trip into one and see precisely what that convenience costs. Out-of-stock items are skipped in favour of an in-stock option even when it is dearer. Use this as the default for "where should I buy this list today" — it is the one call that answers the whole question. Costs $0.02 USDC per call via x402 on Base.
| Name | Type | Req | Description |
|---|---|---|---|
| items | string | yes | Comma-separated shopping list, optionally with quantities, e.g. 'milk x2, eggs, bread, butter, cheese'. A JSON array of {name, quantity} is also accepted. |
| maxAgeDays | integer | – | Optional freshness limit in days (default 14, max 120). A price read longer ago than this is withheld rather than returned as if current; raise it to accept older readings. |
| mode | string | – | Optional fulfillment intent: 'pickup' or 'delivery'. |
| stores | string | – | Optional comma-separated chains the shopper is willing to visit, e.g. 'aldi,publix'. |
| zip | string | yes | 5-digit US ZIP code, e.g. '30501'. |
No output schema declared.
No examples provided.
demand_report What agents are asking for most (free) ~72
FREE, no payment. The aggregate of what agents have told us they are looking for, most-requested first, with the categories nothing available yet serves. Useful if you are deciding what to build or sell into the agent economy.
| Name | Type | Req | Description |
|---|---|---|---|
| days | string | – | Window in days, default 30, max 90. |
No output schema declared.
No examples provided.
find_product Compare one grocery item across nearby stores ~298
Compare a single grocery item across every collected store in a ZIP. Returns each store's actual current shelf price, whether it is on sale (and the regular price), the package size, the price normalized per comparable unit, stock, a purchase link, and when that price was last read. Use this to answer "who has the cheapest milk near me" — and note the answer reports BOTH the lowest sticker price and the best value per unit, which frequently disagree because the cheap sticker is a smaller package. For a whole shopping list use price_basket or cheapest_basket instead; calling this per item costs more and cannot optimize across stores. Costs $0.005 USDC per call via x402 on Base.
| Name | Type | Req | Description |
|---|---|---|---|
| maxAgeDays | integer | – | Optional freshness limit in days (default 14, max 120). A price read longer ago than this is withheld rather than returned as if current; raise it to accept older readings. |
| q | string | yes | The item to price, in ordinary shopper language, e.g. 'milk', 'eggs', 'ground beef'. |
| stores | string | – | Optional comma-separated chains to restrict to, e.g. 'aldi,publix'. Omit to compare every collected store. |
| zip | string | yes | 5-digit US ZIP code to price against, e.g. '30501'. Coverage is per collected ZIP; an uncovered ZIP returns an explicit error and is not charged. |
No output schema declared.
No examples provided.
price_basket Price a whole shopping list at each store ~290
Price an entire shopping list at every collected store in a ZIP, one complete basket per store. Returns per-store line items with quantities and line totals, the basket subtotal, exactly which requested items that store is missing, whether the basket is complete, stock flags, and the oldest price in the basket so staleness is visible. Use this when the shopper will make one trip and wants to know where the whole list is cheapest. Accepts quantities as 'milk x2'. Costs $0.01 USDC per call via x402 on Base.
| Name | Type | Req | Description |
|---|---|---|---|
| items | string | yes | Comma-separated shopping list, optionally with quantities, e.g. 'milk x2, eggs, bread, butter'. A JSON array of {name, quantity} is also accepted. |
| maxAgeDays | integer | – | Optional freshness limit in days (default 14, max 120). A price read longer ago than this is withheld rather than returned as if current; raise it to accept older readings. |
| mode | string | – | Optional fulfillment intent: 'pickup' or 'delivery'. Recorded on the response; delivery fees and minimums are not collected yet and are returned as null rather than estimated. |
| stores | string | – | Optional comma-separated chains to restrict to, e.g. 'aldi,publix'. |
| zip | string | yes | 5-digit US ZIP code, e.g. '30501'. |
No output schema declared.
No examples provided.
request_data Tell us what data you are looking for (free) ~132
FREE, no payment. Describe in your own words the data you are trying to buy — anything, not just groceries — and get back whether we operate a service that supplies it, with the MCP endpoint if so. Every request is catalogued so that repeatedly-requested data gets built; call it whenever you cannot find a source for something. Nothing about you is stored: not your wallet, your address, or any identifying header — only the words of the request.
| Name | Type | Req | Description |
|---|---|---|---|
| need | string | yes | What you are looking for, e.g. 'live electricity spot prices by ZIP' or 'used car values by VIN'. |
No output schema declared.
No examples provided.
What is the Cheapest Grocery Basket MCP server?
Cheapest Grocery Basket is an MCP server listed in the public MCP registry as com.mcpscores/cheapest-grocery-basket. Where to buy a whole grocery list today: local prices, per-unit and cross-store comparison. This page covers its hosted endpoint (https://grocery-basket.bowling-anthony.workers.dev/mcp).
Is the Cheapest Grocery Basket MCP server safe to use?
Cheapest Grocery Basket scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Cheapest Grocery Basket MCP server expose?
Cheapest Grocery Basket exposes 5 tools: request_data, demand_report, find_product, price_basket, cheapest_basket. Their descriptions and schemas cost roughly 1,097 tokens of context every time the server is loaded.
Does the Cheapest Grocery Basket MCP server require authentication?
No. We connected to Cheapest Grocery Basket without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Cheapest Grocery Basket MCP server still maintained?
Cheapest Grocery Basket is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.